php
18 known vulnerabilities affecting php products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-6722 | Medium | 0.9% | 9.8 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a… | |
| CVE-2026-7262 | Medium | 0.8% | 7.5 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a… | |
| CVE-2026-6104 | Medium | 0.5% | 9.1 | In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding nam… | |
| CVE-2026-7568 | Medium | 0.5% | 7.5 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a… | |
| CVE-2025-14179 | Medium | 0.4% | 9.8 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a… | |
| CVE-2026-17544 | Medium | 0.4% | 9.8 | Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with s… | |
| CVE-2026-7263 | Medium | 0.4% | 7.5 | In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() meth… | |
| CVE-2026-7258 | Medium | 0.3% | 7.5 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a… | |
| CVE-2026-17543 | Medium | 0.3% | 9.8 | Improper escaping of backslashes in attacker-provided parameters would allow for… | |
| CVE-2026-7261 | Medium | 0.3% | 9.8 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a… | |
| CVE-2019-11045 | Low | 8.8% | 3.7 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryI… | |
| CVE-2019-11050 | Low | 7.6% | 4.8 | When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif… | |
| CVE-2019-11044 | Low | 5.1% | 3.7 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP… | |
| CVE-2019-11049 | Low | 4.2% | 6.5 | In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom h… | |
| CVE-2019-11046 | Low | 4.1% | 3.7 | In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath ext… | |
| CVE-2026-6735 | Low | 0.2% | 6.1 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8… | |
| CVE-2026-7259 | Low | 0.2% | 6.5 | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a… | |
| CVE-2026-7260 | Low | 0.1% | 5.5 | Circular symbolic links in phar archives could lead to unbounded recursion, exha… |