CRA Readiness Snapshot
What you would have to assess for ENISA reporting tomorrow
No dependency in this snapshot currently appears in CISA's Known Exploited Vulnerabilities catalog. Today, nothing would trigger the 24-hour early-warning obligation of CRA Art. 14. That can change any day a new KEV entry lands, which is exactly what continuous monitoring is for.
⚠ No lockfile — SBOM is not reproducible
This scan is based on a manifest (composer.json), not a lockfile. 6 of 6 dependencies are version ranges, so the exact shipped versions — and their transitive dependencies — cannot be verified. Under the CRA's full obligations (11 December 2027) you must produce a machine-readable SBOM of what you actually ship. Committing a lockfile is the single highest-impact fix in this report.
All findings (23)
| Package | Version | Advisory | Severity | EPSS | Fixed in | Summary |
|---|---|---|---|---|---|---|
| dompdf/dompdf | ^3.1 | CVE-2022-28368 | CRITICAL | 82.4% | 1.2.1 | Remote code injection in dompdf/dompdf |
| dompdf/dompdf | ^3.1 | CVE-2014-2383 | MODERATE | 39.2% | 0.6.1 | DOMPDF Arbitrary File Read |
| dompdf/dompdf | ^3.1 | CVE-2010-4879 | HIGH | 5.2% | 0.6.1 | DOMPDF Remote File Inclusion Vulnerability |
| dompdf/dompdf | ^3.1 | CVE-2022-41343 | HIGH | 4.7% | 2.0.1 | Dompdf allows remote file inclusion because URI validation failure does not halt font registration |
| dompdf/dompdf | ^3.1 | CVE-2014-5013 | HIGH | 4.5% | 0.6.2 | DOMPDF Remote Code Execution |
| dompdf/dompdf | ^3.1 | CVE-2023-23924 | CRITICAL | 3.6% | 2.0.2 | Dompdf vulnerable to URI validation failure on SVG parsing |
| dompdf/dompdf | ^3.1 | CVE-2023-24813 | CRITICAL | 2.5% | 2.0.3 | URI validation failure on SVG parsing. Bypass of CVE-2023-23924 |
| dompdf/dompdf | ^3.1 | CVE-2014-5011 | MODERATE | 1.5% | 0.6.2 | DOMPDF Information Disclosure |
| dompdf/dompdf | ^3.1 | CVE-2023-50262 | MODERATE | 1.5% | 2.0.4 | Denial of service caused by infinite recursion when parsing SVG images |
| dompdf/dompdf | ^3.1 | CVE-2021-3838 | CRITICAL | 1.4% | 2.0.0 | Deserialization of Untrusted Data in dompdf/dompdf |
| dompdf/dompdf | ^3.1 | CVE-2014-5012 | MODERATE | 1.2% | 0.6.2 | DOMPDF denial of service vulnerability |
| dompdf/dompdf | ^3.1 | CVE-2022-2400 | MODERATE | 1.2% | 2.0.0 | Dompdf before v2.0.0 vulnerable to chroot check bypass |
| dompdf/dompdf | ^3.1 | CVE-2022-0085 | MODERATE | 1.0% | 2.0.0 | Server-Side Request Forgery in dompdf/dompdf |
| dompdf/dompdf | ^3.1 | CVE-2021-3902 | CRITICAL | 1.0% | 2.0.0 | Improper Restriction of XML External Entity Reference in dompdf/dompdf |
| dompdf/dompdf | ^3.1 | CVE-2026-59942 | MODERATE | 0.7% | 3.1.6 | Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps |
| squizlabs/php_codesniffer dev | ^3.5 | CVE-2026-67434 | HIGH | 0.7% | 3.13.6 | PHP_CodeSniffer gitblame report command injection via crafted filename |
| dompdf/dompdf | ^3.1 | CVE-2026-59941 | MODERATE | 0.5% | 3.1.6 | Dompdf: Uncontrolled resource consumption based on declared BMP dimensions |
| dompdf/dompdf | ^3.1 | CVE-2026-55555 | LOW | 0.4% | 3.1.6 | Dompdf: File existence oracle via font-face stylesheet declaration |
| dompdf/dompdf | ^3.1 | CVE-2026-56722 | MODERATE | 0.3% | 3.1.6 | Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI |
| dompdf/dompdf | ^3.1 | CVE-2026-55554 | LOW | 0.3% | 3.1.6 | Dompdf: Chroot Validation Bypass |
| dompdf/dompdf | ^3.1 | CVE-2026-59943 | MODERATE | 0.3% | 3.1.6 | Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem |
| squizlabs/php_codesniffer dev | ^3.5 | GHSA-3988-h75v-hwf6 | HIGH | — | 3.0.1 | Arbitrary shell execution |
| squizlabs/php_codesniffer dev | ^3.5 | GHSA-mhfv-8rc9-w38c | HIGH | — | 2.8.1 | Arbitrary shell execution |
SBOM summary
6 direct dependencies scanned (0 pinned to exact versions) from composer.json. Vulnerability data: OSV.dev · exploitation status: CISA KEV · exploit probability: FIRST EPSS. Findings on unpinned dependencies cover the full constraint range and may not apply to the exact version deployed.
Using ENISA's CRA Maturity Assessment Model for SMEs? This snapshot provides evidence for the Vulnerability Management domain and the product-level technical documentation question (1.3) under Governance & Documentation.
This snapshot is an automated readiness assessment, not legal advice and not a conformity assessment under the CRA.