Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2026-7260 Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from… PHP 8.2.33 / 8.3.33+ Fix from $1,6002026-07-30 CRITICAL 9.8 CVE-2026-17543 Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from… PHP 8.2.33 / 8.3.33+ Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-17544 Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and… PHP 8.4.24 / 8.5.9+ Fix from $2,3002026-07-30 MEDIUM 5.3 CVE-2026-14355 In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenS… PHP 8.2.32 / 8.3.32+ Fix from $1,6002026-07-03 HIGH 7.5 CVE-2026-7263 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked li… PHP 8.4.21 / 8.5.6+ Fix from $1,9502026-05-10 CRITICAL 9.1 CVE-2026-6104 In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() … PHP 8.4.21 / 8.5.6+ Fix from $2,3002026-05-10 CRITICAL 9.8 CVE-2026-6722 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mech… PHP 8.2.31 / 8.3.31+ Fix from $2,3002026-05-10 CRITICAL 9.8 CVE-2026-7261 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSIS… PHP 8.2.31 / 8.3.31+ Fix from $2,3002026-05-10 HIGH 7.5 CVE-2026-7258 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass si… PHP 8.2.21 / 8.3.31+ Fix from $1,9502026-05-10 HIGH 7.5 CVE-2026-7262 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, t… PHP 8.2.31 / 8.3.31+ Fix from $1,9502026-05-10 HIGH 7.5 CVE-2026-7568 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metap… PHP 8.2.31 / 8.3.31+ Fix from $1,9502026-05-10 MEDIUM 6.5 CVE-2026-7259 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma… PHP 8.2.31 / 8.3.31+ Fix from $1,6002026-05-10 MEDIUM 6.1 CVE-2026-6735 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows… PHP 8.2.31 / 8.3.31+ Fix from $1,6002026-05-10 CRITICAL 9.8 CVE-2025-14179 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL… PHP 8.2.31 / 8.3.31+ Fix from $2,3002026-05-10 CRITICAL 9.8 CVE-2026-24895 FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode characters durin… Frankenphp 1.11.2+ Fix from $2,3002026-02-12 HIGH 7.5 CVE-2026-24894 FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctl… Frankenphp 1.11.2+ Fix from $1,9502026-02-12 HIGH 8.2 CVE-2025-14178 In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, a heap buffer overflow occurs… PHP 8.1.34 / 8.2.30+ Fix from $1,9502025-12-27 HIGH 7.5 CVE-2025-14177 In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function m… PHP 8.1.34 / 8.2.30+ Fix from $1,9502025-12-27 HIGH 7.5 CVE-2025-14180 In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 when using the PDO PostgreSQL … PHP 8.1.34 / 8.2.30+ Fix from $1,9502025-12-27 HIGH 7.5 CVE-2025-1735 In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the under… PHP 8.1.33 / 8.2.29+ Fix from $1,9502025-07-13 MEDIUM 5.3 CVE-2025-1220 In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation th… PHP 8.1.33 / 8.2.29+ Fix from $1,6002025-07-13 MEDIUM 5.9 CVE-2025-6491 In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly l… PHP 8.1.33 / 8.2.29+ Fix from $1,6002025-07-13 HIGH 8.1 CVE-2024-11235 In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??=  operator and exceptions can lead to a use… PHP 8.3.19 / 8.4.5+ Fix from $1,9502025-04-04 CRITICAL 9.8 CVE-2025-1861 In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the respo… PHP 8.1.31 / 8.2.26+ Fix from $2,3002025-03-30 HIGH 7.3 CVE-2025-1736 In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, th… PHP 8.1.32 / 8.2.28+ Fix from $1,9502025-03-30 MEDIUM 5.3 CVE-2025-1734 In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server… PHP 8.1.32 / 8.2.28+ Fix from $1,6002025-03-30 MEDIUM 5.3 CVE-2025-1219 In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using t… PHP 8.1.32 / 8.2.28+ Fix from $1,6002025-03-30 CRITICAL 9.1 CVE-2022-31631 In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite,… PHP 8.0.27 / 8.1.15+ Fix from $2,3002025-02-12 HIGH 8.2 CVE-2024-11233 In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data… PHP 8.1.31 / 8.2.26+ Fix from $1,9502024-11-24 CRITICAL 9.8 CVE-2024-11236 In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit sy… PHP 8.1.31 / 8.2.26+ Fix from $2,3002024-11-24