Php

Php

728 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.78%
  • Veröffentlicht 10.05.2026 04:00:09
  • Zuletzt bearbeitet 24.07.2026 08:10:00

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value eleme...

Medienbericht
  • EPSS 0.44%
  • Veröffentlicht 10.05.2026 03:51:14
  • Zuletzt bearbeitet 25.07.2026 11:10:00

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containin...

  • EPSS 0.46%
  • Veröffentlicht 10.05.2026 03:42:36
  • Zuletzt bearbeitet 24.07.2026 08:10:00

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string ...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 10.05.2026 03:27:00
  • Zuletzt bearbeitet 24.07.2026 08:10:00

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS...

Medienbericht Exploit
  • EPSS 0.48%
  • Veröffentlicht 27.12.2025 19:33:23
  • Zuletzt bearbeitet 08.01.2026 22:03:28

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-ch...

  • EPSS 0.44%
  • Veröffentlicht 27.12.2025 19:27:41
  • Zuletzt bearbeitet 24.01.2026 11:15:49

In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, a heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE,...

Medienbericht Exploit
  • EPSS 0.73%
  • Veröffentlicht 27.12.2025 19:21:20
  • Zuletzt bearbeitet 09.01.2026 20:23:40

In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 when using the PDO PostgreSQL driver with PDO::ATTR_EMULATE_PREPARES enabled, an invalid character sequence (such as \x99) in a pre...

  • EPSS 1%
  • Veröffentlicht 13.07.2025 22:27:48
  • Zuletzt bearbeitet 04.11.2025 22:16:06

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. This could cause crashes if Postgres server rejects the stri...

Exploit
  • EPSS 0.54%
  • Veröffentlicht 13.07.2025 22:18:36
  • Zuletzt bearbeitet 04.11.2025 22:16:06

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like pars...

Exploit
  • EPSS 0.99%
  • Veröffentlicht 13.07.2025 22:15:23
  • Zuletzt bearbeitet 04.11.2025 22:16:43

In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and a...