php
72 articles with this tag
CRITICAL
HIGH
LOW
MEDIUM
CRITICAL
HIGH
HIGH
INFO
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
CRITICAL
INFO
CRITICAL
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
MEDIUM
MEDIUM
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
INFO
HIGH
CRITICAL
CRITICAL
MEDIUM
HIGH
INFO
HIGH
HIGH
HIGH
INFO
HIGH
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
MEDIUM
[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE
USN-8743-1: PHP vulnerabilities
[NEU] [niedrig] Laravel: Schwachstelle ermöglicht Cross-Site Scripting
USN-8734-1: PHP vulnerabilities
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
RHSA-2026:62614: Important: php security, bug fix, and enhancement update
RHSA-2026:62334: Important: php:7.4 security, bug fix, and enhancement update
RHSA-2026:61903: Important: php:8.2 security, bug fix, and enhancement update
[UPDATE] [hoch] PHP: Mehrere Schwachstellen
[NEU] [kritisch] TYPO3 Extensions: Mehrere Schwachstellen
[UPDATE] [hoch] Drupal: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des Dienstes
RHSA-2026:57574: Important: php:8.2 security, bug fix, and enhancement update
RHSA-2026:57539: Important: php:8.3 security, bug fix, and enhancement update
Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code
RHSA-2026:56969: Important: php8.4 security, bug fix, and enhancement update
[NEU] [hoch] Joomla: Mehrere Schwachstellen
[NEU] [hoch] Roundcube Webmail: Mehrere Schwachstellen
CVE-2007-3205 The parse_str function in (1) PHP, (2) Hardened-PHP, and (3) Suhosin, when called without a second parameter, might allow remote attackers to overwrite arbitrary variables by specifying variable names and values in the string to be parsed. NOTE: it is not clear whether this is a design limitation of the function or a bug in PHP, although it is likely to be regarded as a bug in Hardened-PHP and Suhosin.
[NEU] [hoch] WordPress: Mehrere Schwachstellen
PHP Multiple Vulnerabilities
DSA-6406-1 php8.4 - security update
Multiples vulnérabilités dans PHP (31 juillet 2026)
USN-8564-1: PHP vulnerabilities
[NEU] [kritisch] WordPress: Mehrere Schwachstellen ermöglichen Codeausführung
[NEU] [hoch] Drupal Module: Mehrere Schwachstellen
[NEU] [hoch] Joomla: Mehrere Schwachstellen
[NEU] [mittel] Composer: Mehrere Schwachstellen
[webapps] Joomla Extension 4.1.4 - PHP Object injection
[NEU] [mittel] Roundcube: Mehrere Schwachstellen
DSA-6377-1 php8.4 - security update
RHSA-2026:34354: Important: php:7.4 security update
RHSA-2026:33449: Important: php security update
I tried a Local AI model (Qwen 3.6 27b) for security research and it works surprisingly well.
[NEU] [mittel] Drupal: Mehrere Schwachstellen
[NEU] [kritisch] Drupal Core: Mehrere Schwachstellen
CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
Getting the PID from random numbers in PHP
[NEU] [hoch] TYPO3 Core: Mehrere Schwachstellen
RHSA-2026:23388: Important: php security update
Famous Chollima Targets PHP Developers Through Compromised Packagist Package
RHSA-2026:22305: Important: php:8.2 security update
RHSA-2026:22142: Important: php:8.3 security update
RHSA-2026:22143: Important: php:8.2 security update
[webapps] MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution
USN-8336-1: PHP vulnerabilities
[NEU] [hoch] Roundcube Webmail: Mehrere Schwachstellen
Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer
Drupal admins rushing to patch maximum severity SQL injection vulnerability
USN-8272-1: Smarty vulnerability
[NEU] [mittel] Composer: Schwachstelle ermöglicht Offenlegung von Informationen
Multiples vulnérabilités dans PHP (11 mai 2026)
[NEU] [mittel] Drupal (Obfuscate): Schwachstelle ermöglicht Cross-Site Scripting
[NEU] [mittel] TYPO3 Core: Schwachstelle ermöglicht Offenlegung von Informationen
[NEU] [hoch] Composer: Mehrere Schwachstellen ermöglichen Codeausführung
New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released
CVE-2026-22666: Dolibarr 23.0.0 dol_eval() whitelist bypass -> RCE (full write-up + PoC)
[webapps] Jumbo Website Manager - Remote Code Execution
Microsoft Details Cookie-Controlled PHP Web Shells Persisting via Cron on Linux Servers
[NEU] [hoch] Joomla CMS: Mehrere Schwachstellen
[NEU] [hoch] Roundcube: Mehrere Schwachstellen
Perfex CRM: Autologin cookie fed into unserialize() gives unauthenticated RCE
[UPDATE] [hoch] TYPO3 Core: Mehrere Schwachstellen
Fake Laravel Packages on Packagist Deploy RAT on Windows, macOS, and Linux
DSA-6154-1 php8.2 - security update
PHP Server-Side Request Forgery (SSRF) | Security Vulnerability Database | Sourcery
PHP Server-Side Request Forgery (SSRF) Vulnerability (CVE-2025-1220) - Web Application Vulnerabilities | Invicti
Multiple Vulnerabilities in PHP Could Allow for Remote Code Execution
[UPDATE] [hoch] PHP: Mehrere Schwachstellen
[UPDATE] [hoch] PHP: Mehrere Schwachstellen
[UPDATE] [hoch] PHP: Mehrere Schwachstellen
NCSC-2026-0050 [1.00] [M/H] Kwetsbaarheid verholpen in PEAR
[UPDATE] [mittel] PHP: Mehrere Schwachstellen