Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

PHP Group — Vulnerabilities & Security Advisories 102

Browse all 102 CVE security advisories affecting PHP Group. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PHP Group operates as a prominent developer of open-source software, primarily known for creating the PHP scripting language and related web development tools. With 78 recorded Common Vulnerabilities and Exposures, the organization’s codebase has historically been susceptible to critical security flaws, including remote code execution, cross-site scripting, and privilege escalation vulnerabilities. These issues often stem from improper input validation and memory management errors within legacy components. While PHP Group actively maintains a security advisory process to patch identified weaknesses, the sheer volume of disclosed CVEs highlights the complexity of securing widely adopted, legacy-heavy infrastructure. The organization’s response to major incidents typically involves rapid security updates and detailed advisories, aiming to mitigate risks for the extensive global community of developers relying on its technologies for web application deployment.

Found 101 results / 102 Clear Filters
Top products by PHP Group: PHP PHP Imagick extension
CVE ID Title CVSS Severity Published
CVE-2026-92842 OOB read / info leak in convert.* stream filters when line-break-chars contains NUL — PHP CWE-122 5.9 Medium 2026-09-25
CVE-2026-91768 IPv6 ACL bypass in FastCGI listen.allowed_clients due to partial address comparison (memcmp 12 bytes) — PHP CWE-1023 6.5 Medium 2026-09-25
CVE-2026-91769 TLS Hostname Verification Falls Back to CN After SAN Mismatch — PHP CWE-297 4.3 Medium 2026-09-25
CVE-2026-91767 Heap-buffer-overflow in php_openssl_matches_wildcard_name on crafted server cert wildcard CN — PHP CWE-122 6.5 Medium 2026-09-25
CVE-2025-1218 Various packet overreads in mysqlnd_writeprotocol.c — PHP CWE-122 3.4 Low 2026-09-25
CVE-2026-91766 Cross-origin credential leak in HTTP stream wrapper redirects — PHP CWE-200 5.9 Medium 2026-09-25
CVE-2026-91765 SOAP: Unbounded Recursion in Server-Side cleanup_xml_node — PHP CWE-674 7.5 High 2026-09-25
CVE-2025-14181 Integer overflow to buffer overflow in soap HTTP parsing — PHP CWE-190 6.5 Medium 2026-09-25
CVE-2026-17545 PHP on Windows: Reserved Device Names Are Not Rejected Before File/Stream I/O which can cause DoS — PHP CWE-67 6.9 Medium 2026-09-25
CVE-2026-6103 Phar TAR phar_tar_number() Integer Overflow - Archive Entry Injection — PHP CWE-190 4.3 Medium 2026-09-25
CVE-2026-93682 Out-of-bounds read in the HTTP stream wrapper when following a redirect with an empty Location header — PHP CWE-125 5.8 Medium 2026-09-25
CVE-2026-7260 Stack overflow in phar with circular symlinks — PHP CWE-121 5.4 Medium 2026-07-30
CVE-2026-17544 Out-of-bounds write in bccomp() via crafted operand and scale — PHP CWE-787 8.1 High 2026-07-30
CVE-2026-17543 SQL injection in ext-pgsql via E'...' backslash breakout — PHP CWE-89 8.1 High 2026-07-30
CVE-2026-7263 DoS attack via DOMNode::C14N() — PHP CWE-404 7.5 - 2026-05-10
CVE-2026-6104 Global buffer over-read in mb_convert_encoding() with attacker-supplied encoding — PHP CWE-125 9.1 - 2026-05-10
CVE-2026-7258 Out-of-bounds read in urldecode() on NetBSD — PHP CWE-125 7.5 - 2026-05-10
CVE-2026-6722 Use-After-Free in SOAP using Apache map — PHP CWE-416 9.5 Critical 2026-05-10
CVE-2026-7259 Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() — PHP CWE-476 7.5 - 2026-05-10
CVE-2026-7261 SoapServer session-persisted object use-after-free via SOAP header fault — PHP CWE-416 8.8 - 2026-05-10
CVE-2026-7262 NULL pointer dereference in SOAP apache:Map decoder with missing <value> — PHP CWE-476 7.5 - 2026-05-10
CVE-2025-14179 SQL injection in pdo_firebird via NUL bytes in quoted strings — PHP CWE-89 9.8 - 2026-05-10
CVE-2026-7568 Signed integer overflow in metaphone() — PHP CWE-190 9.1 - 2026-05-10
CVE-2026-6735 XSS within PHP-FPM status endpoint — PHP CWE-79 6.1 - 2026-05-10
CVE-2025-14177 Information Leak of Memory in getimagesize — PHP CWE-125 9.1 - 2025-12-27
CVE-2025-14178 Heap buffer overflow in array_merge() — PHP CWE-787 6.5 Medium 2025-12-27
CVE-2025-14180 NULL Pointer Dereference in PDO quoting — PHP CWE-476 7.5 - 2025-12-27
CVE-2025-1735 pgsql extension does not check for errors during escaping — PHP CWE-89 5.9 Medium 2025-07-13
CVE-2025-1220 Null byte termination in hostnames — PHP CWE-918 3.7 Low 2025-07-13
CVE-2025-6491 NULL Pointer Dereference in PHP SOAP Extension via Large XML Namespace Prefix — PHP CWE-476 5.9 Medium 2025-07-13

This page lists every published CVE security advisory associated with PHP Group. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.