Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

PHP Group — Vulnerabilities & Security Advisories 102

Browse all 102 CVE security advisories affecting PHP Group. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PHP Group operates as a prominent developer of open-source software, primarily known for creating the PHP scripting language and related web development tools. With 78 recorded Common Vulnerabilities and Exposures, the organization’s codebase has historically been susceptible to critical security flaws, including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. These issues often stem from improper input validation and memory management errors within legacy components. While PHP Group actively maintains a security advisory process to patch identified weaknesses, the sheer volume of disclosed CVEs highlights the complexity of securing widely adopted, legacy-heavy infrastructure. The organization’s response to major incidents typically involves rapid security updates and detailed advisories, aiming to mitigate risks for the extensive global community of developers relying on its technologies for web application deployment.

Found 101 results / 102 Clear Filters
Top products by PHP Group: PHP PHP Imagick extension
CVE ID Title CVSS Severity Published
CVE-2024-11235 Reference counting in php_request_shutdown causes Use-After-Free — PHP CWE-416 9.8AI Critical AI 2025-04-04
CVE-2025-1861 Stream HTTP wrapper truncates redirect location to 1024 bytes — PHP CWE-131 6.5 - 2025-03-30
CVE-2025-1736 Stream HTTP wrapper header check might omit basic auth header — PHP CWE-20 5.3 - 2025-03-30
CVE-2025-1734 Streams HTTP wrapper does not fail for headers with invalid name and no colon — PHP CWE-20 7.5 - 2025-03-30
CVE-2025-1219 libxml streams use wrong content-type header when requesting a redirected resource — PHP 8.1 - 2025-03-30
CVE-2025-1217 Header parser of http stream wrapper does not handle folded headers — PHP CWE-20 7.5 - 2025-03-29
CVE-2022-31631 PDO::quote() may return unquoted string — PHP CWE-74 9.1 Critical 2025-02-12
CVE-2024-11233 Single byte overread with convert.quoted-printable-decode filter — PHP CWE-122 4.8 Medium 2024-11-24
CVE-2024-11234 Configuring a proxy in a stream context might allow for CRLF injection in URIs — PHP CWE-20 4.8 Medium 2024-11-24
CVE-2024-11236 Integer overflow in the firebird and dblib quoters causing OOB writes — PHP CWE-787 9.8 Critical 2024-11-24
CVE-2024-8929 Leak partial content of the heap through heap buffer over-read in mysqlnd — PHP CWE-200 5.8 Medium 2024-11-22
CVE-2024-8932 OOB access in ldap_escape — PHP CWE-787 9.8 Critical 2024-11-22
CVE-2024-9026 PHP-FPM logs from children may be altered — PHP CWE-158 3.3 Low 2024-10-08
CVE-2024-8927 cgi.force_redirect configuration is bypassable due to the environment variable collision — PHP 7.5 High 2024-10-08
CVE-2024-8926 PHP CGI Parameter Injection Vulnerability (CVE-2024-4577 bypass) — PHP CWE-78 8.1 High 2024-10-08
CVE-2024-8925 Erroneous parsing of multipart form data — PHP 3.1 Low 2024-10-08
CVE-2024-2408 PHP is vulnerable to the Marvin Attack — PHP 8.1 - 2024-06-09
CVE-2024-4577 Argument Injection in PHP-CGI — PHP CWE-78 9.8 Critical 2024-06-09
CVE-2024-5585 Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix) — PHP CWE-116 7.7 High 2024-06-09
CVE-2024-5458 Filter bypass in filter_var (FILTER_VALIDATE_URL) — PHP 5.3 Medium 2024-06-09
CVE-2024-1874 Command injection via array-ish $command parameter of proc_open() — PHP CWE-116 9.4 Critical 2024-04-29
CVE-2024-2757 PHP mb_encode_mimeheader runs endlessly for some inputs — PHP 7.5 High 2024-04-29
CVE-2024-3096 PHP function password_verify can erroneously return true when argument contains NUL — PHP CWE-20 6.5 Medium 2024-04-29
CVE-2024-2756 __Host-/__Secure- cookie bypass due to partial CVE-2022-31629 fix — PHP CWE-20 6.5 Medium 2024-04-29
CVE-2023-3824 Buffer overflow and overread in phar_dir_read() — PHP CWE-119 9.4 Critical 2023-08-11
CVE-2023-3823 Security issue with external entity loading in XML without enabling it — PHP 8.6 High 2023-08-11
CVE-2023-3247 Missing error check and insufficient random bytes in HTTP Digest authentication for SOAP — PHP CWE-252 2.6 Low 2023-07-22
CVE-2023-0568 Array overrun in common path resolve code — PHP CWE-131 7.5 High 2023-02-16
CVE-2023-0662 DoS vulnerability when parsing multipart request body — PHP CWE-400 7.5 High 2023-02-16
CVE-2023-0567 password_verify() always returns true for some invalid hashes — PHP 7.7 High 2023-02-16

This page lists every published CVE security advisory associated with PHP Group. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.