Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

PHP Group — Vulnerabilities & Security Advisories 102

Browse all 102 CVE security advisories affecting PHP Group. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PHP Group operates as a prominent developer of open-source software, primarily known for creating the PHP scripting language and related web development tools. With 78 recorded Common Vulnerabilities and Exposures, the organization’s codebase has historically been susceptible to critical security flaws, including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. These issues often stem from improper input validation and memory management errors within legacy components. While PHP Group actively maintains a security advisory process to patch identified weaknesses, the sheer volume of disclosed CVEs highlights the complexity of securing widely adopted, legacy-heavy infrastructure. The organization’s response to major incidents typically involves rapid security updates and detailed advisories, aiming to mitigate risks for the extensive global community of developers relying on its technologies for web application deployment.

Found 101 results / 102 Clear Filters
Top products by PHP Group: PHP PHP Imagick extension
CVE ID Title CVSS Severity Published
CVE-2022-31630 OOB read due to insufficient input validation in imageloadfont() — PHP CWE-131 6.5 Medium 2022-11-14
CVE-2022-31629 $_COOKIE names string replacement (. -> _): cookie integrity vulnerabilities — PHP CWE-20 6.5 - 2022-09-28
CVE-2022-31628 phar wrapper can occur dos when using quine gzip file — PHP CWE-674 2.3 Low 2022-09-28
CVE-2022-31627 Heap buffer overflow in finfo_buffer — PHP CWE-590 7.7 High 2022-07-28
CVE-2022-31626 mysqlnd/pdo password buffer overflow — PHP CWE-120 7.5 High 2022-06-16
CVE-2022-31625 Freeing unallocated memory in php_pgsql_free_params() — PHP CWE-590 8.1 High 2022-06-16
CVE-2021-21708 UAF due to php_filter_float() failing — PHP CWE-416 8.2 High 2022-02-27
CVE-2021-21707 Special characters break path parsing in XML functions — PHP CWE-159 5.3 Medium 2021-11-29
CVE-2021-21703 PHP-FPM memory access in root process leading to privilege escalation — PHP CWE-787 7.8 High 2021-10-25
CVE-2021-21706 ZipArchive::extractTo may extract outside of destination dir — PHP CWE-24 5.3 Medium 2021-10-04
CVE-2021-21705 Incorrect URL validation in FILTER_VALIDATE_URL — PHP CWE-20 4.3 Medium 2021-10-04
CVE-2021-21704 Multiple vulnerabilities in Firebird client extension — PHP CWE-125 5.0 Medium 2021-10-04
CVE-2021-21702 Null Dereference in SoapClient — PHP CWE-476 5.3 Medium 2021-02-15
CVE-2020-7071 FILTER_VALIDATE_URL accepts URLs with invalid userinfo — PHP CWE-20 5.3 Medium 2021-02-15
CVE-2020-7069 Wrong ciphertext/tag in AES-CCM encryption for a 12 bytes IV — PHP CWE-20 5.4 Medium 2020-10-02
CVE-2020-7070 PHP parses encoded cookie names so malicious `__Host-` cookies can be sent — PHP CWE-20 4.3 Medium 2020-10-02
CVE-2020-7068 Use of freed hash key in the phar_parse_zipfile function — PHP CWE-416 4.8 Medium 2020-09-09
CVE-2019-11048 Temporary files are not cleaned after OOM when parsing HTTP request data — PHP CWE-400 5.3 Medium 2020-05-20
CVE-2020-7067 OOB Read in urldecode() — PHP CWE-125 7.5 High 2020-04-27
CVE-2020-7065 mb_strtolower (UTF-32LE): stack-buffer-overflow at php_unicode_tolower_full — PHP CWE-121 7.4 High 2020-04-01
CVE-2020-7066 get_headers() silently truncates after a null byte — PHP CWE-170 5.3 Medium 2020-04-01
CVE-2020-7064 Use-of-uninitialized-value in exif — PHP CWE-125 6.5 Medium 2020-04-01
CVE-2020-7063 Files added to tar with Phar::buildFromIterator have all-access permissions — PHP CWE-281 5.5 Medium 2020-02-27
CVE-2020-7061 heap-buffer-overflow in phar_extract_file — PHP CWE-125 6.5 Medium 2020-02-27
CVE-2020-7062 Null Pointer Dereference in PHP Session Upload Progress — PHP CWE-476 7.5 High 2020-02-27
CVE-2020-7059 OOB read in php_strip_tags_ex — PHP CWE-125 6.5 Medium 2020-02-10
CVE-2020-7060 global buffer-overflow in mbfl_filt_conv_big5_wchar — PHP CWE-125 6.5 Medium 2020-02-10
CVE-2019-11050 Use-after-free in exif parsing under memory sanitizer — PHP CWE-125 4.8 Medium 2019-12-23
CVE-2019-11046 Buffer underflow in bc_shift_addsub — PHP CWE-125 3.7 Low 2019-12-23
CVE-2019-11047 Heap-buffer-overflow READ in exif — PHP CWE-125 4.8 Medium 2019-12-23

This page lists every published CVE security advisory associated with PHP Group. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.