Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 25

Количество 25

fstec логотип

BDU:2026-09671

3 месяца назад

Уязвимость менеджера фоновых процессов PHP-FPM интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный JavaScript-код (XSS)

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2026-6735

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2026-6735

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-6735

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2026-6735

3 месяца назад

XSS within PHP-FPM status endpoint

EPSS: Низкий
debian логотип

CVE-2026-6735

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-7qg2-v9fj-4mwv

3 месяца назад

XSS within PHP-FPM status endpoint

EPSS: Низкий
rocky логотип

RLSA-2026:22305

около 2 месяцев назад

Important: php:8.2 security update

EPSS: Низкий
rocky логотип

RLSA-2026:22143

около 2 месяцев назад

Important: php:8.2 security update

EPSS: Низкий
rocky логотип

RLSA-2026:22142

около 2 месяцев назад

Important: php:8.3 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22305

около 2 месяцев назад

ELSA-2026-22305: php:8.2 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22143

около 1 месяца назад

ELSA-2026-22143: php:8.2 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22142

около 1 месяца назад

ELSA-2026-22142: php:8.3 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:23388

около 2 месяцев назад

Important: php security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-23388

15 дней назад

ELSA-2026-23388: php security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2091-1

2 месяца назад

Security update for php7

EPSS: Низкий
rocky логотип

RLSA-2026:34354

29 дней назад

Important: php:7.4 security update

EPSS: Низкий
rocky логотип

RLSA-2026:22649

около 2 месяцев назад

Important: php8.4 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-34354

29 дней назад

ELSA-2026-34354: php:7.4 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22649

14 дней назад

ELSA-2026-22649: php8.4 security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-09671

Уязвимость менеджера фоновых процессов PHP-FPM интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный JavaScript-код (XSS)

CVSS3: 6.1
0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-6735

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 6.1
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6735

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 5.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-6735

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 6.1
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-6735

XSS within PHP-FPM status endpoint

0%
Низкий
3 месяца назад
debian логотип
CVE-2026-6735

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-7qg2-v9fj-4mwv

XSS within PHP-FPM status endpoint

0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:22305

Important: php:8.2 security update

около 2 месяцев назад
rocky логотип
RLSA-2026:22143

Important: php:8.2 security update

около 2 месяцев назад
rocky логотип
RLSA-2026:22142

Important: php:8.3 security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-22305

ELSA-2026-22305: php:8.2 security update (IMPORTANT)

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-22143

ELSA-2026-22143: php:8.2 security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-22142

ELSA-2026-22142: php:8.3 security update (IMPORTANT)

около 1 месяца назад
rocky логотип
RLSA-2026:23388

Important: php security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-23388

ELSA-2026-23388: php security update (IMPORTANT)

15 дней назад
suse-cvrf логотип
SUSE-SU-2026:2091-1

Security update for php7

2 месяца назад
rocky логотип
RLSA-2026:34354

Important: php:7.4 security update

29 дней назад
rocky логотип
RLSA-2026:22649

Important: php8.4 security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-34354

ELSA-2026-34354: php:7.4 security update (IMPORTANT)

29 дней назад
oracle-oval логотип
ELSA-2026-22649

ELSA-2026-22649: php8.4 security update (IMPORTANT)

14 дней назад

Уязвимостей на страницу