Security Risk Category

PHP Security Risks — Page 4

Published vulnerability pages connected to PHP. Each page keeps one canonical URL and focused remediation guidance.

199 published PHP risks

PHP risks

Showing 109–144 of 199 published risks.

lowEPSS 0.005

CVE-2026-45753 in Symfony HTML Sanitizer

Symfony HTML Sanitizer can miss JavaScript URLs in some attributes, which can allow cross-site scripting in sanitized HTML.

CVE-2026-45753phpweb-applicationinput-validationxss

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-45755 in Symfony Mailtrap Mailer

Symfony Mailtrap Mailer does not verify the Mailtrap webhook signature, so a remote attacker can send fake webhook events.

CVE-2026-45755phpweb-applicationinput-validationauthentication-bypass

Updated Jul 15, 2026

highEPSS 0.003

CVE-2026-47767 in Symfony Runtime

Symfony Runtime can still let a crafted web request change APP_ENV or APP_DEBUG on affected patched versions, bypassing an earlier fix.

CVE-2026-47767phpweb-applicationinput-validation

Updated Jul 15, 2026

highEPSS 0.005

CVE-2026-45068 in Symfony Mailer

Symfony Mailer can pass a dash-prefixed recipient address to SendmailTransport in an unsafe way, which can let an attacker inject sendmail arguments.

CVE-2026-45068phpweb-applicationremote-code-executioninput-validation

Updated Jul 15, 2026

infoEPSS 0.001

CVE-2026-58034 in MediaWiki CheckUser

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation CheckUser. This vulnerability is associated with program files modules/ext.CheckUser.TempAccounts/components/blockConnectedTempAccountsField.Vue. This issue affects CheckUser: from 1.46.0-rc.0 before 1.46.0.

CVE-2026-58034phpweb-applicationxss

Updated Jul 15, 2026

infoEPSS 0.001

CVE-2026-58035 in MediaWiki

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Special.Block/SpecialBlock.Vue.

CVE-2026-58035phpweb-applicationxss

Updated Jul 15, 2026

info

CVE-2026-13706 in MediaWiki UrlShortener

Improper input validation vulnerability in Wikimedia Foundation UrlShortener. This vulnerability is associated with program files includes/UrlShortenerUtils.Php.

CVE-2026-13706phpweb-applicationinput-validation

Updated Jul 15, 2026

info

CVE-2026-13707 in MediaWiki OAuth

Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/Backend/MWOAuthServer.Php. This issue affects OAuth: from * through 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-13707phpweb-applicationauthentication-bypass

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-58024 in MediaWiki

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiUserrights.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58024phpapi-securityweb-applicationinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.005

CVE-2026-58025 in MediaWiki

Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Import/WikiImporter.Php, includes/Import/WikiRevision.Php, includes/Logging/LogEntryBase.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58025phpweb-applicationremote-code-executionfile-write

Updated Jul 15, 2026

infoEPSS 0.004

CVE-2026-58026 in MediaWiki

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Parser/Parser.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58026phpweb-applicationinformation-disclosure

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-58027 in MediaWiki AbuseFilter

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/Api/QueryAbuseFilters.Php. This issue affects AbuseFilter: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58027phpapi-securityweb-applicationinformation-disclosure

Updated Jul 15, 2026

infoEPSS 0.003

CVE-2026-58028 in MediaWiki and CentralAuth

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation CentralAuth. This vulnerability is associated with program files includes/Api/ApiFormatBase.Php, includes/Api/ApiHelp.Php, includes/ResourceLoader/Module.Php, includes/Hooks/Handlers/PageDisplayHookHandler.Php, includes/LogFormatter/PermissionChangeLogFormatter.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9; CentralAuth: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58028phpapi-securityweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-58029 in MediaWiki

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiChangeAuthenticationData.Php, includes/Api/ApiLinkAccount.Php, includes/Api/ApiRemoveAuthenticationData.Php, includes/Specials/SpecialLinkAccounts.Php, includes/Specials/SpecialUnlinkAccounts.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58029phpapi-securityweb-applicationauthentication-bypass

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-58030 in MediaWiki SyntaxHighlight_GeSHi

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation SyntaxHighlight_GeSHi. This vulnerability is associated with program files includes/SyntaxHighlight.Php. This issue affects SyntaxHighlight_GeSHi: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58030phpweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-58032 in MediaWiki

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Api/index.Js. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58032phpapi-securityweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.004

CVE-2026-58033 in MediaWiki

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Actions/InfoAction.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58033phpweb-applicationinformation-disclosure

Updated Jul 15, 2026

lowEPSS 0.002

CVE-2026-58036 in MediaWiki

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiQueryAllUsers.Php, includes/Api/ApiQueryUsers.Php, includes/Permissions/PermissionManager.Php, includes/User/UserGroupManager.Php.

CVE-2026-58036phpapi-securityweb-applicationinformation-disclosure

Updated Jul 15, 2026

infoEPSS 0.003

CVE-2026-58037 in MediaWiki

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Language/Language.Php, includes/Logging/BlockLogFormatter.Php, includes/Logging/LogFormatter.Php, includes/Logging/PatrolLogFormatter.Php, includes/Logging/RenameuserLogFormatter.Php, includes/Logging/TagLogFormatter.Php, includes/Specials/SpecialVersion.Php. This issue affects MediaWiki: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58037phpweb-applicationxss

Updated Jul 15, 2026

infoEPSS 0.002

CVE-2026-58038 in MediaWiki Timeline

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files includes/Timeline.Php, scripts/EasyTimeline.Pl. This issue affects timeline: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-58038phpweb-applicationxss

Updated Jul 15, 2026

infoEPSS 0.003

CVE-2026-8857 in MediaWiki Timeline

A vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files scripts/EasyTimeline.Pl, includes/Timeline.Php. This issue affects timeline: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

CVE-2026-8857phpweb-applicationremote-code-execution

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-58520 in MediaWiki UrlShortener Extension

URL redirection to untrusted site ('open redirect') vulnerability in The Wikimedia Foundation Mediawiki - UrlShortener Extension allows Cross-Site Flashing. This issue affects Mediawiki - UrlShortener Extension: from * before 1.43.9, 1.44.6, 1.45.4.

CVE-2026-58520phpweb-applicationopen-redirect

Updated Jul 15, 2026

mediumEPSS 0.003

CVE-2026-58521 in MediaWiki Cargo Extension

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4.

CVE-2026-58521phpweb-applicationsql-injection

Updated Jul 15, 2026

medium

CVE-2026-14358 in MediaWiki Charts Extension

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - Charts Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - Charts Extension: from * before 1.43.9,1.44.6,1.45.4.

CVE-2026-14358phpweb-applicationxss

Updated Jul 15, 2026

mediumEPSS 0.002

CVE-2026-58517 in MediaWiki WikiLambda Extension

Improper neutralization of input terminators vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension allows Authentication Bypass. This issue affects Mediawiki - WikiLambda Extension: from * before 1.43.9,1.44.6,1.45.4.

CVE-2026-58517phpweb-applicationauthentication-bypass

Updated Jul 14, 2026

medium

CVE-2026-14363 in MediaWiki Cargo Extension

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo Extension allows SQL Injection. This issue affects Mediawiki - Cargo Extension: from * before 1.43.9,1.44.6,1.45.4.

CVE-2026-14363phpweb-applicationsql-injection

Updated Jul 14, 2026

medium

CVE-2026-14355 php vulnerability

In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.

CVE-2026-14355phpmemory-corruption

Updated Jul 14, 2026

highEPSS 0.005

TheGem Theme Elements <= 5.11.1 - Authenticated (Contributor+) Local File Inclusion

The TheGem Theme Elements plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.11.1. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.

CVE-2026-57804wordpressphpauthorization-bypasspath-traversal

Updated Jul 13, 2026

highEPSS 0.005

Billey <= 2.1.8 - Authenticated (Contributor+) Local File Inclusion

The Billey theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.1.8. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.

CVE-2026-57790wordpressphpauthorization-bypasspath-traversal

Updated Jul 13, 2026

mediumEPSS 0.003

RTMKit <= 2.0.7 - Authenticated (Contributor+) Limited Local File Inclusion via 'template' Parameter

The RTMKit (rometheme-for-elementor) plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.0.7 This is due to insufficient path validation on the 'template' parameter in the render_templates AJAX endpoint, which is used directly in a require/include statement without sanitization. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute files on the server ending in _templates.php, allowing the execution of any PHP code in those files.

CVE-2026-5137wordpressphppath-traversal

Updated Jul 13, 2026

mediumEPSS 0.004

Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value'

The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up to, and including, 1.5.1. The function reads raw_value from Elementor Pro's Form_Record object for upload-type fields and passes it directly to PHP's copy() without validating that the value corresponds to a legitimately uploaded file — when no file is present in $_FILES, raw_value reflects the attacker-controlled POST string. copy() accepts both local filesystem paths and URL sources, so the attacker can target any file readable by the PHP process or supply an attacker-controlled remote URL. Elementor Pro is a prerequisite for triggering the code path (it owns the elementor_pro/forms/new_record hook and populates the Form_Record object), but the bug itself is entirely in Contact Form Entries' handler. This could allow unauthenticated attackers to disclose arbitrary files on the affected site's server. The file is copied to a directory unknown to the attacker; the hashed directory name provides defense-in-depth but is generated from non-cryptographic sources (uniqid() + rand()) and should not be relied upon as the primary mitigation.

CVE-2026-9145wordpressphppath-traversalfile-write

Updated Jul 13, 2026

highEPSS 0.005

Brook - Agency Business Creative WordPress Theme <= 2.9.0 - Authenticated (Contributor+) Local File Inclusion

The Brook - Agency Business Creative WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.9.0. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.

CVE-2026-57791wordpressphpauthorization-bypasspath-traversal

Updated Jul 13, 2026

highEPSS 0.005

Golo Framework <= 1.7.3 - Authenticated (Contributor+) Local File Inclusion

The Golo Framework plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.7.3. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.

CVE-2026-57794wordpressphpauthorization-bypasspath-traversal

Updated Jul 13, 2026

highEPSS 0.003

SportsPress Pro <= 2.7.29 - Authenticated (Contributor+) Local File Inclusion

The SportsPress Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 2.7.29. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other "safe" file types can be uploaded and included.

CVE-2026-57749wordpressphpauthorization-bypasspath-traversal

Updated Jul 13, 2026

highEPSS 0.003

Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameter

The Request a Quote plugin for WordPress is vulnerable to Code Injection in versions up to, and including, 2.5.5 via the emd_delete_file AJAX action. This is due to the emd_delete_file() handler deriving a PHP function name from the attacker-controlled $_POST['path'] parameter and invoking it dynamically via the variable-function call $sess_name(), and the handler being registered for wp_ajax_nopriv with its only protection being a nonce that the plugin prints into the public quote-form page via wp_localize_script. This makes it possible for unauthenticated attackers to invoke arbitrary zero-argument PHP functions on the server, such as phpinfo(), potentially exposing sensitive server configuration and credentials, or executing other destructive built-in PHP functions.

CVE-2026-14249wordpressphpremote-code-execution

Updated Jul 13, 2026

criticalEPSS 0.007

Printcart Web to Print Product Designer for WooCommerce <= 2.5.2 - Unauthenticated Arbitrary File Deletion

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is due to insufficient path validation in the store_design_data() function, which constructs a filesystem path from the user-supplied 'nbd_item_key' POST parameter sanitized only with sanitize_text_field() — which does not strip path traversal sequences — and then passes that path directly to Nbdesigner_IO::delete_folder() and PHP's rename(). The nonce protecting the nbd_save_customer_design AJAX action is freely obtainable by unauthenticated users via the nbd_check_use_logged_in endpoint. This makes it possible for unauthenticated attackers to delete arbitrary files on the affected site's server which may make remote code execution possible.

CVE-2026-9725wordpresswoocommercephpremote-code-execution

Updated Jul 13, 2026