CVE-2025-65875: Untrusted Font Upload / Path Injection Can Lead to PHP Execution When Using FPDF
FPDF’s font definitions are PHP and are included at runtime; if an app allows attacker-controlled font definition paths/files, it can lead to code execution.
