Vulnerabilities > Wkhtmltopdf
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-08-22 | CVE-2022-35583 | Server-Side Request Forgery (SSRF) vulnerability in Wkhtmltopdf 0.12.6 wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. | 9.8 |
2022-08-15 | CVE-2020-21365 | Path Traversal vulnerability in multiple products Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations. | 7.5 |