Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 25 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:softvision:webpdf:*:*:*:*:*:*:*:* |
Mon, 23 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-918 | |
| Metrics |
cvssV3_1
|
Fri, 20 Feb 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Softvision
Softvision webpdf |
|
| Vendors & Products |
Softvision
Softvision webpdf |
Thu, 19 Feb 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not check if internal or external resources are requested in the uploaded files and allows for protocols such as http:// and file:///. This allows an attacker to upload an XML or HTML file in the application, which when rendered to a PDF allows for internal port scanning and Local File Inclusion (LFI). | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-23T13:50:12.035Z
Reserved: 2025-08-16T00:00:00.000Z
Link: CVE-2025-55853
Updated: 2026-02-23T13:49:51.548Z
Status : Analyzed
Published: 2026-02-19T15:16:11.190
Modified: 2026-03-25T20:27:53.097
Link: CVE-2025-55853
No data.
OpenCVE Enrichment
Updated: 2026-02-20T10:11:35Z