Pear

Pearweb

9 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.11%
  • Veröffentlicht 03.02.2026 18:31:17
  • Zuletzt bearbeitet 05.02.2026 17:55:10

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get/<package>/<version> endpoint allows remote attackers to execute arbitrary SQL via a crafted package version...

  • EPSS 0.04%
  • Veröffentlicht 03.02.2026 18:31:01
  • Zuletzt bearbeitet 05.02.2026 17:56:13

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability can occur in user::maintains() when role filters are provided as an array and interpolated into an IN (...) clause. This i...

  • EPSS 0.04%
  • Veröffentlicht 03.02.2026 18:30:53
  • Zuletzt bearbeitet 05.02.2026 18:00:51

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in apidoc queue insertion can allow query manipulation if an attacker can influence the inserted filename value. This issu...

  • EPSS 0.04%
  • Veröffentlicht 03.02.2026 18:30:14
  • Zuletzt bearbeitet 05.02.2026 18:01:30

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription deletion may allow attackers to inject SQL via a crafted email value. This issue has been patched in v...

  • EPSS 0.11%
  • Veröffentlicht 03.02.2026 18:29:54
  • Zuletzt bearbeitet 05.02.2026 18:05:46

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() with the /e modifier in bug update email handling can enable PHP code execution if attacker-controlled content reaches the evaluat...

  • EPSS 0.04%
  • Veröffentlicht 03.02.2026 18:29:46
  • Zuletzt bearbeitet 05.02.2026 18:06:21

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to unsafe literal substitution for an IN (...) list. This issue has been patched in version 1.33.0.

  • EPSS 0.04%
  • Veröffentlicht 03.02.2026 18:29:39
  • Zuletzt bearbeitet 05.02.2026 18:07:35

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable verification hashes may allow attackers to guess verification tokens and potentially verify election account requests without authorization....

  • EPSS 0.03%
  • Veröffentlicht 03.02.2026 18:29:19
  • Zuletzt bearbeitet 05.02.2026 18:08:05

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in category deletion can allow an attacker with access to the category manager workflow to inject SQL via a category id. T...

  • EPSS 0.05%
  • Veröffentlicht 03.02.2026 18:29:13
  • Zuletzt bearbeitet 05.02.2026 18:09:05

PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadmap role check allows non-lead maintainers to create, update, or delete roadmaps. This issue has been patched in version 1.33.0.