A cross-site scripting (XSS) vulnerability, identified as CVE-2022-28368, in the dompdf_project dompdf library has been added to the VulnCheck Known Exploited Vulnerabilities (KEV) catalog. The flaw was reportedly exploited 1635 days after its initial disclosure.
The CVE was reserved and published on April 3, 2022. However, it was not until September 24, 2026, that the vulnerability was first listed in a KEV catalog, specifically VulnCheck's. This marks a significant delay of approximately 4.5 years between disclosure and confirmed exploitation in the wild.
While VulnCheck KEV lists CVE-2022-28368 as exploited, neither the CISA KEV for US federal agencies nor the EUVD (European Union Vulnerability Database) from ENISA currently include this vulnerability. The CIRCL aggregator, which mirrors other catalogs, also does not list it independently. The claim of exploitation rests on a single catalog entry without corroboration from other major KEV sources.
Public evidence of exploitation was reportedly observed on September 24, 2026, with a blog post from socradar.io titled "Operation Master: Intrusion Monetization PIP" cited as the source. This report was collected by VulnCheck and CIRCL, though its contents have not been independently verified.
The vulnerability's CVSS score is currently listed as "none," indicating that a severity rating has not been assigned or is not available in the NVD record. However, its Exploit Prediction Scoring System (EPSS) percentile is notably high at 99.7%, with an 82.4% probability of exploitation, suggesting a significant risk despite the lack of a traditional CVSS score.






