pontedilana/php-weasyprint vulnerabilities
CVEs whose affected-version data names the pontedilana/php-weasyprint package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-49260High· 8.2php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)
php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)
▾ Twilightpontedilana · pontedilana/php-weasyprintEPSS 0.22%via GHSA
CVE-2026-49286High· 8.1PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)
PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)
▾ Twilightpontedilana · pontedilana/php-weasyprintEPSS 0.95%via GHSA
CVE-2026-49358Low· 3.0PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles
PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles
▾ Sunlitpontedilana · pontedilana/php-weasyprintEPSS 0.15%via GHSA
CVE-2026-49359Medium· 6.5PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option
PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option
▾ Sunlitpontedilana · pontedilana/php-weasyprintEPSS 0.42%via GHSA