Security Risk Category

PHP Security Risks — Page 3

Published vulnerability pages connected to PHP. Each page keeps one canonical URL and focused remediation guidance.

199 published PHP risks

PHP risks

Showing 73–108 of 199 published risks.

highEPSS 0.005

CVE-2026-45756 in Symfony JSON Path

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonPath component compiles attacker-controlled match() and search() filter patterns directly into preg_match()...

CVE-2026-45756phpweb-applicationinput-validationdenial-of-service

Updated Jul 15, 2026

criticalEPSS 0.003

CVE-2026-45063 in Symfony Security HTTP

Symfony Security HTTP can spoof a certificate identity when X509Authenticator parses a crafted DN.

CVE-2026-45063phpweb-applicationauthentication-bypasscryptography

Updated Jul 15, 2026

lowEPSS 0.005

CVE-2026-45064 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can leave visual-spoofing BiDi characters in sanitized URLs.

CVE-2026-45064phpweb-applicationinput-validation

Updated Jul 15, 2026

highEPSS 0.002

CVE-2026-45069 in Symfony Security HTTP

Symfony Security HTTP can accept OIDC tokens that miss required audience, issuer, or expiry claims.

CVE-2026-45069phpweb-applicationauthentication-bypass

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-45070 in Symfony MIME

Symfony MIME can allow email header injection through unsafe MIME parameter names.

CVE-2026-45070phpweb-applicationinput-validation

Updated Jul 15, 2026

mediumEPSS 0.005

CVE-2026-45073 in Symfony Cache

Symfony Cache can build unsafe SQL when an untrusted cache prefix reaches PdoAdapter clear.

CVE-2026-45073phpweb-applicationsql-injection

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-45075 in Symfony Security HTTP

Symfony Security HTTP can let HEAD requests bypass checks that only allow GET requests.

CVE-2026-45075phpweb-applicationauthorization-bypasscsrf

Updated Jul 15, 2026

highEPSS 0.006

CVE-2026-45133 in Symfony YAML

Symfony YAML can crash a worker when it parses very deeply nested YAML input.

CVE-2026-45133phpweb-applicationinput-validationdenial-of-service

Updated Jul 15, 2026

highEPSS 0.008

CVE-2026-45304 in Symfony YAML

Symfony YAML can use too much memory when crafted aliases expand recursively.

CVE-2026-45304phpweb-applicationinput-validationdenial-of-service

Updated Jul 15, 2026

highEPSS 0.007

CVE-2026-45305 in Symfony YAML

Symfony YAML can hang on crafted YAML because of slow regex backtracking.

CVE-2026-45305phpweb-applicationinput-validationdenial-of-service

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-45071 in Symfony DomCrawler

Symfony DomCrawler can read local files when it parses attacker-controlled XML content.

CVE-2026-45071phpweb-applicationinput-validationinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-47212 in Symfony Twilio Notifier

Symfony Twilio Notifier ignored the Twilio signature header, so fake webhook events could be accepted.

CVE-2026-47212phpweb-applicationauthentication-bypasscryptography

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-47984 in Adobe Commerce

Adobe Commerce has an authorization issue that can let an attacker gain unauthorized read and write access.

CVE-2026-47984phpweb-applicationauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-47988 in Adobe Commerce

Adobe Commerce has an authorization issue that can let an attacker gain unauthorized read and write access.

CVE-2026-47988phpweb-applicationauthorization-bypass

Updated Jul 15, 2026

highEPSS 0.196

CVE-2026-47992 in Adobe Commerce

Adobe Commerce has a SQL injection issue that can lead to code execution for a high-privilege attacker.

CVE-2026-47992phpweb-applicationremote-code-executionsql-injection

Updated Jul 15, 2026

highEPSS 0.009

CVE-2026-47994 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.

CVE-2026-47994phpbrowserweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.007

CVE-2026-47995 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can help an attacker gain more access through a victim browser.

CVE-2026-47995phpbrowserweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.185

CVE-2026-47996 in Adobe Commerce

Adobe Commerce has an authorization issue that can let a high-privilege attacker bypass rules and read data.

CVE-2026-47996phpweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.006

CVE-2026-47997 in Adobe Commerce

Adobe Commerce has an authorization issue that can let an attacker bypass rules and read data.

CVE-2026-47997phpweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.006

CVE-2026-47998 in Adobe Commerce

Adobe Commerce has an authorization issue that can let an attacker bypass rules and read data.

CVE-2026-47998phpweb-applicationauthorization-bypassinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.115

CVE-2026-47999 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can let a high-privilege user place script in vulnerable fields.

CVE-2026-47999phpweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.007

CVE-2026-48000 in Adobe Commerce

Adobe Commerce has an open redirect issue that can send a user to an attacker-controlled site.

CVE-2026-48000phpweb-applicationopen-redirect

Updated Jul 15, 2026

lowEPSS 0.006

CVE-2026-48001 in Adobe Commerce

Adobe Commerce can expose limited sensitive information under certain conditions.

CVE-2026-48001phpweb-applicationinformation-disclosure

Updated Jul 15, 2026

criticalEPSS 0.283

CVE-2026-48356 in Adobe Commerce

Adobe Commerce allows dangerous file upload in a way that can lead to code execution after user interaction.

CVE-2026-48356phpweb-applicationremote-code-executionfile-upload

Updated Jul 15, 2026

criticalEPSS 0.009

CVE-2026-48358 in Adobe Commerce

Adobe Commerce has an output escaping issue that can lead to code execution without user interaction.

CVE-2026-48358phpweb-applicationremote-code-executioninput-validation

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-48371 in Adobe Commerce

Adobe Commerce has a stored XSS issue that can let a low-privilege user place script in vulnerable fields.

CVE-2026-48371phpweb-applicationxss

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-48489 in Symfony Security HTTP

Symfony Security HTTP can let a failed login request reach protected GET routes when failure forwarding is enabled.

CVE-2026-48489phpweb-applicationauthentication-bypassauthorization-bypass

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-48747 in Symfony Mailomat Mailer

Symfony Mailomat Mailer lets the request choose the HMAC algorithm for webhook signature checks.

CVE-2026-48747phpweb-applicationauthentication-bypasscryptography

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-48760 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can leave encoded visual-spoofing characters in URLs after sanitizing them.

CVE-2026-48760phpweb-applicationinput-validation

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-48761 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can miss URL attributes in allowed HTML and let unsafe URLs pass through.

CVE-2026-48761phpweb-applicationinput-validationxss

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-48784 in Symfony Routing

Symfony Routing can generate a URL that collapses to a different path when dot segments are normalized.

CVE-2026-48784phpweb-applicationinput-validationopen-redirect

Updated Jul 15, 2026

criticalEPSS 0.003

Grand Photography WordPress <= 5.7.8 - Unauthenticated PHP Object Injection

Grand Photography WordPress has a PHP object injection issue. An unauthenticated attacker may trigger unsafe code paths. No patch is known, so remove or replace it until fixed.

CVE-2026-57770wordpressphpfile-writefile-deletion

Updated Jul 15, 2026

criticalEPSS 0.003

Directorist: AI-Powered Business Directory, Listings & Classified Ads <= 8.8.2 - Authenticated (Subscriber+) PHP Object Injection

Directorist: AI-Powered Business Directory, Listings & Classified Ads has a PHP object injection issue. An unauthenticated attacker may trigger unsafe code paths. No patch is known, so remove or replace it until fixed.

CVE-2026-59518wordpressphpfile-writefile-deletion

Updated Jul 15, 2026

criticalEPSS 0.004

777 <= 1.13.0 - Unauthenticated PHP Object Injection

777 has a PHP object injection issue. An unauthenticated attacker may trigger unsafe code paths. No patch is known, so remove or replace it until fixed.

CVE-2026-57738wordpressphpfile-writefile-deletion

Updated Jul 15, 2026

lowEPSS 0.004

CVE-2026-45065 in Symfony Routing

Symfony Routing can accept a route value that should fail validation, which can create an off-site redirect-style URL.

CVE-2026-45065phpweb-applicationinput-validationopen-redirect

Updated Jul 15, 2026

lowEPSS 0.005

CVE-2026-45066 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can bypass allowed link or media host rules because some URLs are parsed differently than expected.

CVE-2026-45066phpweb-applicationinput-validationauthorization-bypass

Updated Jul 15, 2026