
CVE-2025-65875 An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute arbitrary code via uploading a crafted PHP file. https://www.cve.org/CVERecord?id=CVE-2025-65875
Post summary
The text discloses an arbitrary file upload vulnerability in FPDF’s AddFont() function (v1.86 and earlier) that can lead to arbitrary code execution via a crafted PHP file, with no PoC, exploit, patch, or active exploitation mentioned.


