PT-2026-5950 · Git+1 · Fpdf

Published

2026-02-03

·

Updated

2026-02-03

·

CVE-2025-65875

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FPDF versions prior to 1.87
Description An arbitrary file upload flaw in the AddFont() function allows attackers to execute arbitrary code by uploading a crafted PHP file.
Recommendations Update to a version later than 1.86. As a temporary workaround, consider restricting access to the AddFont() function until the update is applied.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-65875

Affected Products

Fpdf