Browse all 6 CVE security advisories affecting flightphp. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-42552 | Flight: Sensitive information disclosure via default error handler in flightphp/core — core CWE-209 | 7.5 | High | 2026-05-13 |
| CVE-2026-42551 | Flight: HTTP method override enabled by default enables CSRF escalation and middleware bypass in flightphp/core — core CWE-436 | 7.5 | High | 2026-05-13 |
| CVE-2026-42550 | Flight: SQL Injection via unvalidated identifiers in SimplePdo::insert / update / delete — core CWE-89 | 8.8 | High | 2026-05-13 |
| CVE-2026-42549 | Flight: Path traversal in `make:controller` CLI creates arbitrary directories outside project root — core CWE-22 | 4.4 | Medium | 2026-05-13 |
| CVE-2026-42548 | Flight: Reflected XSS via unvalidated JSONP callback in Flight::jsonp() — core CWE-79 | - | - | 2026-05-13 |
| CVE-2014-125127 | Denial of Service (DoS) vulnerability in mikecao/flight — core CWE-770 | 7.5 | High | 2025-09-03 |
This page lists every published CVE security advisory associated with flightphp. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.