VDB
Sign up

package

Packagist/pontedilana/php-weasyprint

pkg:packagist/pontedilana/php-weasyprint

HIGH8.1Packagist
GHSA-2fmj-p74r-3wjm· CVE-2026-49286

PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)

Modified: 9/10/2026

HIGH8.2Packagist
GHSA-f5gc-qxf8-mh9g· CVE-2026-49260

php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)

Modified: 9/10/2026