CVE-2024-51058: Tcpdf Project Tcpdf

Medium severity, CVSS 6.2. EPSS: 0.8% chance of exploitation in the next 30 days.

Local File Inclusion (LFI) vulnerability has been discovered in TCPDF 6.7.5. This vulnerability enables a user to read arbitrary files from the server's file system through <img> src tag, potentially exposing sensitive information.

Affected products

Published 2024-11-26. Last modified 2026-06-17.