Vulnerabilities > Wkhtmltopdf

DATE CVE VULNERABILITY TITLE RISK
2022-08-22 CVE-2022-35583 Server-Side Request Forgery (SSRF) vulnerability in Wkhtmltopdf 0.12.6
wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source.
network
low complexity
wkhtmltopdf CWE-918
critical
9.8
2022-08-15 CVE-2020-21365 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations.
network
low complexity
wkhtmltopdf debian CWE-22
7.5