pontedilana has 4 CVEs on record. The busiest recent month was June 2026 with 4. The median CVSS is 7.3 (high).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 0 prev 4
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-49286High· 8.1PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)45CVE-2026-49260High· 8.2php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)45CVE-2026-49359Medium· 6.5PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option36CVE-2026-49358Low· 3.0PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles17
pontedilana vulnerabilities
CVEs affecting pontedilana, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-49260High· 8.2php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)
php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)
▾ Twilightpontedilana · pontedilana/php-weasyprintEPSS 0.22%via GHSA
CVE-2026-49286High· 8.1PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)
PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)
▾ Twilightpontedilana · pontedilana/php-weasyprintEPSS 0.95%via GHSA
CVE-2026-49358Low· 3.0PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles
PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles
▾ Sunlitpontedilana · pontedilana/php-weasyprintEPSS 0.15%via GHSA
CVE-2026-49359Medium· 6.5PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option
PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option
▾ Sunlitpontedilana · pontedilana/php-weasyprintEPSS 0.42%via GHSA