Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

php — Vulnerabilities & Security Advisories 6

Browse all 6 CVE security advisories affecting php. AI-powered Chinese analysis, POCs, and references for each vulnerability.

PHP serves as a server-side scripting language primarily for web application development, powering dynamic content generation and database interactions. Historically, it has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insecure coding practices and insufficient input validation. While the current four CVEs indicate relatively low recent vulnerability counts, past incidents like the catastrophic RCE flaws in versions 4.3.9 and earlier demonstrate how misconfigurations and outdated implementations can lead to significant compromises. Its open-source nature allows for rapid patching, but legacy systems remain vulnerable, emphasizing the need for regular updates and secure coding practices to mitigate risks.

Found 3 results / 6Clear Filters
Top products by php: PHP frankenphp
High2026-07-30
Stack overflow in phar with circular symlinks · Advisory · php/php-src · GitHub
High2026-07-30
Out-of-bounds write in bccomp() via crafted operand and scale · Advisory · php/php-src · GitHub
Critical2026-07-30
SQL injection in ext-pgsql via E'...' backslash breakout · Advisory · php/php-src · GitHub
High2026-07-30
PHP
High2026-07-30
PHP
High2026-07-30
PHP
High2026-07-16
PHP
MediumCVE-2026-143552026-07-04
ext/openssl: Memory corruption (zend_mm_heap corrupted) in openssl_encrypt with AES-WRAP-PAD · Advisory · php/php-src ·
High2026-07-02
PHP
Unknown2026-07-02
PHP
High2026-07-02
PHP
Unknown2026-07-02
PHP
CriticalUSN-8336-12026-05-28
USN-8336-1: PHP vulnerabilities | Ubuntu security notices | Ubuntu
HighCVE-2026-72532026-05-10
DoS attack via DOMNode::C14N() · Advisory · php/php-src · GitHub
Medium2026-05-10
NULL pointer dereference in SOAP apache:Map decoder with missing <value> · Advisory · php/php-src · GitHub
MediumCVE-2025-72612026-05-10
SoapServer session-persisted object use-after-free via SOAP header fault · Advisory · php/php-src · GitHub
Critical2026-05-10
Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init() · Advisory · php/php-src · GitHub
HighCVE-2026-67222026-05-10
Use-After-Free in SOAP using Apache map with Remote Code Execution · Advisory · php/php-src · GitHub
HighCVE-2025-141792026-05-10
SQL injection in pdo_firebird via NUL bytes in quoted strings · Advisory · php/php-src · GitHub
CriticalCVE-2024-380762026-04-03
fix: URL-encode path params to prevent SSRF/path traversal (GHSA-vv7q… · PrefectHQ/fastmcp@40bdfb6 · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with php. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.