Vulnerability index

Browse CVEs

301 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

PHP MEDIUM 5.5
CVE-2026-7260

Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from…

Fix: 8.2.33 / 8.3.33+
Fix from $1,600 2026-07-30
PHP CRITICAL 9.8
CVE-2026-17543

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from…

Fix: 8.2.33 / 8.3.33+
Fix from $2,300 2026-07-30
PHP CRITICAL 9.8
CVE-2026-17544

Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP versions from 8.4.* before 8.4.24 and…

Fix: 8.4.24 / 8.5.9+
Fix from $2,300 2026-07-30
PHP MEDIUM 5.3
CVE-2026-14355

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenS…

Fix: 8.2.32 / 8.3.32+
Fix from $1,600 2026-07-03
PHP HIGH 7.5
CVE-2026-7263

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorrectly, causing a circular linked li…

Fix: 8.4.21 / 8.5.6+
Fix from $1,950 2026-05-10
PHP CRITICAL 9.1
CVE-2026-6104

In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte is passed to mb_convert_encoding() …

Fix: 8.4.21 / 8.5.6+
Fix from $2,300 2026-05-10
PHP CRITICAL 9.8
CVE-2026-6722

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mech…

Fix: 8.2.31 / 8.3.31+
Fix from $2,300 2026-05-10
PHP CRITICAL 9.8
CVE-2026-7261

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSIS…

Fix: 8.2.31 / 8.3.31+
Fix from $2,300 2026-05-10
PHP HIGH 7.5
CVE-2026-7258

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass si…

Fix: 8.2.21 / 8.3.31+
Fix from $1,950 2026-05-10
PHP HIGH 7.5
CVE-2026-7262

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, t…

Fix: 8.2.31 / 8.3.31+
Fix from $1,950 2026-05-10
PHP HIGH 7.5
CVE-2026-7568

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metap…

Fix: 8.2.31 / 8.3.31+
Fix from $1,950 2026-05-10
PHP MEDIUM 6.5
CVE-2026-7259

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma…

Fix: 8.2.31 / 8.3.31+
Fix from $1,600 2026-05-10
PHP MEDIUM 6.1
CVE-2026-6735

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows…

Fix: 8.2.31 / 8.3.31+
Fix from $1,600 2026-05-10
PHP CRITICAL 9.8
CVE-2025-14179

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL…

Fix: 8.2.31 / 8.3.31+
Fix from $2,300 2026-05-10
Frankenphp CRITICAL 9.8
CVE-2026-24895

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, FrankenPHP’s CGI path splitting logic improperly handles Unicode characters durin…

Fix: 1.11.2+
Fix from $2,300 2026-02-12
Frankenphp HIGH 7.5
CVE-2026-24894

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctl…

Fix: 1.11.2+
Fix from $1,950 2026-02-12
PHP HIGH 8.2
CVE-2025-14178

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, a heap buffer overflow occurs…

Fix: 8.1.34 / 8.2.30+
Fix from $1,950 2025-12-27
PHP HIGH 7.5
CVE-2025-14177

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function m…

Fix: 8.1.34 / 8.2.30+
Fix from $1,950 2025-12-27
PHP HIGH 7.5
CVE-2025-14180

In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 when using the PDO PostgreSQL …

Fix: 8.1.34 / 8.2.30+
Fix from $1,950 2025-12-27
PHP HIGH 7.5
CVE-2025-1735

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the under…

Fix: 8.1.33 / 8.2.29+
Fix from $1,950 2025-07-13
PHP MEDIUM 5.3
CVE-2025-1220

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation th…

Fix: 8.1.33 / 8.2.29+
Fix from $1,600 2025-07-13
PHP MEDIUM 5.9
CVE-2025-6491

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly l…

Fix: 8.1.33 / 8.2.29+
Fix from $1,600 2025-07-13
PHP HIGH 8.1
CVE-2024-11235

In PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5, a code sequence involving __set handler or ??=  operator and exceptions can lead to a use…

Fix: 8.3.19 / 8.4.5+
Fix from $1,950 2025-04-04
PHP CRITICAL 9.8
CVE-2025-1861

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the respo…

Fix: 8.1.31 / 8.2.26+
Fix from $2,300 2025-03-30
PHP HIGH 7.3
CVE-2025-1736

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, th…

Fix: 8.1.32 / 8.2.28+
Fix from $1,950 2025-03-30
PHP MEDIUM 5.3
CVE-2025-1734

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server…

Fix: 8.1.32 / 8.2.28+
Fix from $1,600 2025-03-30
PHP MEDIUM 5.3
CVE-2025-1219

In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using t…

Fix: 8.1.32 / 8.2.28+
Fix from $1,600 2025-03-30
PHP CRITICAL 9.1
CVE-2022-31631

In PHP versions 8.0.* before 8.0.27, 8.1.* before 8.1.15, 8.2.* before 8.2.2 when using PDO::quote() function to quote user-supplied data for SQLite,…

Fix: 8.0.27 / 8.1.15+
Fix from $2,300 2025-02-12
PHP HIGH 8.2
CVE-2024-11233

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data…

Fix: 8.1.31 / 8.2.26+
Fix from $1,950 2024-11-24
PHP CRITICAL 9.8
CVE-2024-11236

In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit sy…

Fix: 8.1.31 / 8.2.26+
Fix from $2,300 2024-11-24