Security Risk Category
PHP Security Risks — Page 3
Published vulnerability pages connected to PHP. Each page keeps one canonical URL and focused remediation guidance.
199 published PHP risks
PHP risks
Showing 73–108 of 199 published risks.
CVE-2026-45756 in Symfony JSON Path
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonPath component compiles attacker-controlled match() and search() filter patterns directly into preg_match()...
Updated Jul 15, 2026
CVE-2026-45063 in Symfony Security HTTP
Symfony Security HTTP can spoof a certificate identity when X509Authenticator parses a crafted DN.
Updated Jul 15, 2026
CVE-2026-45064 in Symfony HTML Sanitizer
Symfony HTML Sanitizer can leave visual-spoofing BiDi characters in sanitized URLs.
Updated Jul 15, 2026
CVE-2026-45069 in Symfony Security HTTP
Symfony Security HTTP can accept OIDC tokens that miss required audience, issuer, or expiry claims.
Updated Jul 15, 2026
CVE-2026-45070 in Symfony MIME
Symfony MIME can allow email header injection through unsafe MIME parameter names.
Updated Jul 15, 2026
CVE-2026-45073 in Symfony Cache
Symfony Cache can build unsafe SQL when an untrusted cache prefix reaches PdoAdapter clear.
Updated Jul 15, 2026
CVE-2026-45075 in Symfony Security HTTP
Symfony Security HTTP can let HEAD requests bypass checks that only allow GET requests.
Updated Jul 15, 2026
CVE-2026-45133 in Symfony YAML
Symfony YAML can crash a worker when it parses very deeply nested YAML input.
Updated Jul 15, 2026
CVE-2026-45304 in Symfony YAML
Symfony YAML can use too much memory when crafted aliases expand recursively.
Updated Jul 15, 2026
CVE-2026-45305 in Symfony YAML
Symfony YAML can hang on crafted YAML because of slow regex backtracking.
Updated Jul 15, 2026
CVE-2026-45071 in Symfony DomCrawler
Symfony DomCrawler can read local files when it parses attacker-controlled XML content.
Updated Jul 15, 2026
CVE-2026-47212 in Symfony Twilio Notifier
Symfony Twilio Notifier ignored the Twilio signature header, so fake webhook events could be accepted.
Updated Jul 15, 2026
CVE-2026-47984 in Adobe Commerce
Adobe Commerce has an authorization issue that can let an attacker gain unauthorized read and write access.
Updated Jul 15, 2026
CVE-2026-47988 in Adobe Commerce
Adobe Commerce has an authorization issue that can let an attacker gain unauthorized read and write access.
Updated Jul 15, 2026
CVE-2026-47992 in Adobe Commerce
Adobe Commerce has a SQL injection issue that can lead to code execution for a high-privilege attacker.
Updated Jul 15, 2026
CVE-2026-47994 in Adobe Commerce
Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.
Updated Jul 15, 2026
CVE-2026-47995 in Adobe Commerce
Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.
Updated Jul 15, 2026
CVE-2026-47996 in Adobe Commerce
Adobe Commerce has an authorization issue that can let a high-privilege attacker bypass rules and read data.
Updated Jul 15, 2026
CVE-2026-47997 in Adobe Commerce
Adobe Commerce has an authorization issue that can let an attacker bypass rules and read data.
Updated Jul 15, 2026
CVE-2026-47998 in Adobe Commerce
Adobe Commerce has an authorization issue that can let an attacker bypass rules and read data.
Updated Jul 15, 2026
CVE-2026-47999 in Adobe Commerce
Adobe Commerce has a stored XSS issue that can let a high-privilege user place script in vulnerable fields.
Updated Jul 15, 2026
CVE-2026-48000 in Adobe Commerce
Adobe Commerce has an open redirect issue that can send a user to an attacker-controlled site.
Updated Jul 15, 2026
CVE-2026-48001 in Adobe Commerce
Adobe Commerce can expose limited sensitive information under certain conditions.
Updated Jul 15, 2026
CVE-2026-48356 in Adobe Commerce
Adobe Commerce allows dangerous file upload in a way that can lead to code execution after user interaction.
Updated Jul 15, 2026
CVE-2026-48358 in Adobe Commerce
Adobe Commerce has an output escaping issue that can lead to code execution without user interaction.
Updated Jul 15, 2026
CVE-2026-48371 in Adobe Commerce
Adobe Commerce has a stored XSS issue that can let a low-privilege user place script in vulnerable fields.
Updated Jul 15, 2026
CVE-2026-48489 in Symfony Security HTTP
Symfony Security HTTP can let a failed login request reach protected GET routes when failure forwarding is enabled.
Updated Jul 15, 2026
CVE-2026-48747 in Symfony Mailomat Mailer
Symfony Mailomat Mailer lets the request choose the HMAC algorithm for webhook signature checks.
Updated Jul 15, 2026
CVE-2026-48760 in Symfony HTML Sanitizer
Symfony HTML Sanitizer can leave encoded visual-spoofing characters in URLs after sanitizing them.
Updated Jul 15, 2026
CVE-2026-48761 in Symfony HTML Sanitizer
Symfony HTML Sanitizer can miss URL attributes in allowed HTML and let unsafe URLs pass through.
Updated Jul 15, 2026
CVE-2026-48784 in Symfony Routing
Symfony Routing can generate a URL that collapses to a different path when dot segments are normalized.
Updated Jul 15, 2026
Grand Photography WordPress <= 5.7.8 - Unauthenticated PHP Object Injection
Grand Photography WordPress has a PHP object injection issue. An unauthenticated attacker may trigger unsafe code paths. No patch is known, so remove or replace it until fixed.
Updated Jul 15, 2026
Directorist: AI-Powered Business Directory, Listings & Classified Ads <= 8.8.2 - Authenticated (Subscriber+) PHP Object Injection
Directorist: AI-Powered Business Directory, Listings & Classified Ads has a PHP object injection issue. An unauthenticated attacker may trigger unsafe code paths. No patch is known, so remove or replace it until fixed.
Updated Jul 15, 2026
777 <= 1.13.0 - Unauthenticated PHP Object Injection
777 has a PHP object injection issue. An unauthenticated attacker may trigger unsafe code paths. No patch is known, so remove or replace it until fixed.
Updated Jul 15, 2026
CVE-2026-45065 in Symfony Routing
Symfony Routing can accept a route value that should fail validation, which can create an off-site redirect-style URL.
Updated Jul 15, 2026
CVE-2026-45066 in Symfony HTML Sanitizer
Symfony HTML Sanitizer can bypass allowed link or media host rules because some URLs are parsed differently than expected.
Updated Jul 15, 2026
