Known vulnerabilities in PHP

Vendor: PHP Group
Software: PHP
Software CPE: cpe:2.3:a:php_group:php:*:*:*:*:*:*:*:*
Total vulnerabilities: 689
Public exploits: 155
Known exploited (KEV): 5
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting PHP PHP is affected by 689 known vulnerabilities: 6 critical, 124 high, 368 medium, 191 low Critical High Medium Low

Vulnerabilities (689)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140834 - Out-of-bounds write
CVE-2026-17544
CWE-787 Medium
No
No
8.4.24, 8.5.9 03.08.2026 SB2026080395
SB2026080397
SB2026080398
and 1 more
#VU140833 - Uncontrolled Recursion
CVE-2026-7260
CWE-674 Low
No
No
8.2.33, 8.3.33, 8.4.24, 8.5.9 03.08.2026 SB2026080395
SB2026080397
SB2026080398
and 5 more
#VU140832 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-17543
CWE-89 High
No
No
8.2.33, 8.3.33, 8.4.24, 8.5.9 03.08.2026 SB2026080395
SB2026080397
SB2026080398
and 5 more
#VU140831 - Improper input validation
CVE-2026-9672
CWE-20 Medium
No
No
8.2.33, 8.3.33, 8.4.24, 8.5.9 03.08.2026 SB2026080395
SB2026080396
SB2026080603
and 3 more
#VU137285 - Uncaught Exception
CVE-2026-12184
CWE-248 Medium
No
No
8.3.32, 8.4.21, 8.5.6 09.07.2026 SB2026051001
SB2026071918
SB2026071919
and 5 more
#VU137286 - Memory corruption
CVE-2026-14355
CWE-119 Medium
No
No
8.2.32, 8.3.32, 8.4.23, 8.5.8 09.07.2026 SB2026070955
SB2026070956
SB2026071356
and 16 more
#VU130908 - Improper Encoding or Escaping of Output
CVE-2026-7263
CWE-116 Medium
No
No
8.4.21, 8.5.6 10.05.2026 SB2026051001
SB2026051416
SB2026051523
and 3 more
#VU130909 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-6735
CWE-79 Medium
No
No
8.2.31, 8.3.31, 8.4.21, 8.5.6 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 19 more
#VU130910 - NULL Pointer Dereference
CVE-2026-7259
CWE-476 Medium
No
No
8.2.31, 8.3.31, 8.4.21, 8.5.6 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 14 more
#VU130911 - Out-of-bounds read
CVE-2026-6104
CWE-125 Medium
No
No
8.4.21, 8.5.6 10.05.2026 SB2026051001
SB2026051416
SB2026051523
and 3 more
#VU130912 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2025-14179
CWE-89 High
No
No
8.2.31, 8.3.31, 8.4.21, 8.5.6 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 19 more
#VU130913 - Use After Free
CVE-2026-6722
CWE-416 Medium
No
No
8.2.31, 8.3.31, 8.4.21, 8.5.6 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 17 more
#VU130914 - Use After Free
CVE-2026-7261
CWE-416 Medium
No
No
8.2.31, 8.3.31, 8.4.21, 8.5.6 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 17 more
#VU130915 - NULL Pointer Dereference
CVE-2026-7262
CWE-476 Medium
No
No
8.2.31, 8.3.31, 8.4.21, 8.5.6 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 19 more
#VU130916 - Integer overflow
CVE-2026-7568
CWE-190 Medium
No
No
8.2.31, 8.3.31, 8.4.21, 8.5.6 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 19 more
#VU130917 - Type conversion
CVE-2026-7258
CWE-704 Medium
No
No
8.2.31, 8.3.31, 8.4.21, 8.5.6 10.05.2026 SB2026051001
SB20260511112
SB20260513120
and 17 more
#VU130918 - Integer overflow
CVE-2026-42371
CWE-190 Medium
No
No
8.5.6 10.05.2026 SB2026051001
SB2026051002
SB2026051003
and 9 more
#VU120272 - Missing release of memory after effective lifetime
CVE-2025-14177
CWE-401 Medium
Available
No
8.1.34, 8.2.30, 8.3.29, 8.4.16, 8.5.1 23.12.2025 SB2025122340
SB2025122342
SB2026010709
and 20 more
#VU120271 - Heap-based Buffer Overflow
CVE-2025-14178
CWE-122 High
No
No
8.1.34, 8.2.30, 8.3.29, 8.4.16, 8.5.1 23.12.2025 SB2025122340
SB2025122342
SB2026010709
and 33 more
#VU120270 - NULL Pointer Dereference
CVE-2025-14180
CWE-476 Medium
No
No
8.1.34, 8.2.30, 8.3.29, 8.4.16, 8.5.1 23.12.2025 SB2025122340
SB2025122342
SB2026010709
and 18 more


Showing elements 1 - 20 out of 689