Security Risk Category

PHP Security Risks — Page 6

Published vulnerability pages connected to PHP. Each page keeps one canonical URL and focused remediation guidance.

199 published PHP risks

PHP risks

Showing 181–199 of 199 published risks.

mediumEPSS 0.002

CVE-2026-55478 Snipe-IT vulnerability

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, POST /api/v1/kits/{kit_id}/licenses checks whether the caller can edit kits but does not authorize access to the referenced license object, allowing a low-privilege user with predefined-kit permissions to bind a license they should not be able to access or manage into a kit. This issue is fixed in version 8.6.2.

CVE-2026-55478phpapi-securityweb-applicationauthorization-bypass

Updated Jul 12, 2026

highEPSS 0.002

CVE-2026-55516 Snipe-IT vulnerability

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, PATCH or PUT /api/v1/maintenances/{maintenance_id} checks access to the current maintenance record and asset but then fills attacker-controlled fields including asset_id without re-authorizing the newly supplied asset, allowing an authorized user to move a maintenance record onto an asset outside their company scope. This issue is fixed in version 8.6.2.

CVE-2026-55516phpapi-securityweb-applicationauthorization-bypass

Updated Jul 12, 2026

highEPSS 0.003

CVE-2026-55843 Snipe-IT vulnerability

Snipe-IT is an IT asset/license management system. Prior to 8.6.0, UsersController::update() passes a missing permission request field through NormalizePermissionsPayloadAction and PreserveUnauthorizedPrivilegedPermissionsAction in a way that can overwrite a target user’s permissions with a sparse result, allowing an administrator updating another administrator, or a user with users.edit updating a regular account, to remove the target’s administrative or granular permissions. This issue is fixed in version 8.6.0.

CVE-2026-55843phpweb-applicationauthorization-bypassprivilege-escalation

Updated Jul 12, 2026

criticalCISA KEVEPSS 0.015

CVE-2026-48939 iCagenda for Joomla vulnerability

iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

CVE-2026-48939joomlaphpweb-applicationremote-code-execution

Updated Jul 12, 2026

mediumEPSS 0.003

CodeAstro Simple Online Leave Management System SQL Injection Vulnerability

A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /SimpleOnlineLeave/index.php. Executing a manipulation of the argument email can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

CVE-2026-15134phpsql-injection

Updated Jul 10, 2026

mediumEPSS 0.003

code-projects Online Food Order System SQL Injection Vulnerability

A security flaw has been discovered in code-projects Online Food Order System 1.0. This affects an unknown part of the file /edit_food_items.php. The manipulation of the argument update results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

CVE-2026-15135phpsql-injection

Updated Jul 10, 2026

mediumEPSS 0.003

code-projects Interview Management System SQL Injection Vulnerability

A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code of the file \inc\classes\View.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

CVE-2026-15137phpsql-injection

Updated Jul 10, 2026

mediumEPSS 0.007

WPFunnels WordPress Plugin Local File Inclusion Vulnerability

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.12.7 via the 'logKey' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

CVE-2026-13080wordpresswoocommercephpauthorization-bypass

Updated Jul 10, 2026

criticalEPSS 0.006

miniOrange OTP Login WordPress Plugin Administrator Account Takeover Vulnerability

The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to, and including, 5.5.1. This is due to the `um_reset_password_process_hook()` function performing no server-side verification that the OTP validation step was completed, and relying solely on a public `form_nonce` nonce that the plugin itself emits to unauthenticated visitors via the `moumprvar` JavaScript object on the Ultimate Member password reset page, while still accepting the attacker-controlled `username_b` parameter to target any WordPress user without role restriction or any binding to a previously validated OTP session. This makes it possible for unauthenticated attackers to obtain a freshly generated password-reset URL for an arbitrary Administrator account — returned in a 302 `Location` header — and use it to take full control of that account. Exploitation requires the Ultimate Member Password Reset Form integration to be active and the plugin to not be configured for phone-only reset.

CVE-2026-14245wordpressphpauthentication-bypassauthorization-bypass

Updated Jul 10, 2026

highEPSS 0.007

Popup Maker WordPress Plugin Authorization Bypass RCE Vulnerability

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.22.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with editor-level access and above, to install and activate an arbitrary plugin from an attacker-controlled URL, leading to remote code execution. Exploitation requires that a valid Popup Maker Pro license is active on the target site and that Popup Maker Pro is not yet installed, as these conditions are necessary for the legacy v1/connect/info endpoint to issue the bearer token used to satisfy the install endpoint's only non-spoofable validation check.

CVE-2026-8848wordpressphpsupply-chainremote-code-execution

Updated Jul 10, 2026

criticalEPSS 0.010

Blocksy Companion Pro Arbitrary File Upload RCE Vulnerability

The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachments function. This is due to the Custom Fonts extension registering a wp_check_filetype_and_ext filter that approves any filename containing .woff2 or .ttf as a substring via strpos() rather than validating that those strings appear as the final extension via PATHINFO_EXTENSION — allowing double-extension filenames such as shell.woff2.php to pass MIME validation and be handled as permitted font files. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. This vulnerability is only exploitable when the premium version of the plugin (blocksy-companion-pro) is installed with both the WooCommerce Extra (Advanced Reviews) and Custom Fonts extensions active; the free blocksy-companion plugin does not contain the vulnerable code paths.

CVE-2026-15158wordpresswoocommercephpremote-code-execution

Updated Jul 10, 2026

high

SOPlanning Audit Retention SQL Injection Vulnerability

SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands into the audit configuration form which is then saved. The execution is triggered when the audit functionality is accessed (by the attacker or another user). This issue was fixed in version 1.56.01.

CVE-2026-50644phpweb-applicationsql-injection

Updated Jul 10, 2026

critical

Balbooa Forms Joomla Extension Arbitrary File Upload RCE Vulnerability

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

CVE-2026-56291joomlaphpremote-code-executionfile-upload

Updated Jul 10, 2026

critical

Xerte Online Tools Antivirus Path Remote Code Execution Vulnerability

A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PHP interpreter, allowing an attacker to upload PHP data that will then be executed.

CVE-2026-12116phpremote-code-execution

Updated Jul 10, 2026

critical

Xerte Online Tools Setup Reinstallation Authentication Bypass RCE Vulnerability

A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, enabling attackers to reinstall the service to a remote database they control.

CVE-2026-14261phpremote-code-executionauthentication-bypass

Updated Jul 10, 2026

critical

AcyMailing Joomla Component SQL Injection Vulnerability

A SQLi vulnerability in AcyMailing component < 10.11.1 for Joomla was discovered. Exploiting this flaw can lead to unauthorized database access and data leakage.

CVE-2026-56292joomlaphpsql-injection

Updated Jul 10, 2026

criticalCISA KEVEPSS 0.014

JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code.

CVE-2026-48908phpfile-uploadfile-write

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.804

Widget Factory Joomla Content Editor Improper Access Control Vulnerability

Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.

CVE-2026-48907joomlaphpauthorization-bypass

Updated Jul 9, 2026

criticalCISA KEVEPSS 0.275

Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.

CVE-2026-45247phpremote-code-executionunsafe-deserialization

Updated Jul 9, 2026