Количество 37
Количество 37
RLSA-2026:22305
Important: php:8.2 security update
RLSA-2026:22143
Important: php:8.2 security update
RLSA-2026:22142
Important: php:8.3 security update
ELSA-2026-22305
ELSA-2026-22305: php:8.2 security update (IMPORTANT)
ELSA-2026-22143
ELSA-2026-22143: php:8.2 security update (IMPORTANT)
RLSA-2026:23388
Important: php security update
SUSE-SU-2026:2091-1
Security update for php7
RLSA-2026:22649
Important: php8.4 security update
SUSE-SU-2026:2037-1
Security update for php8
SUSE-SU-2026:1958-1
Security update for php8
SUSE-SU-2026:1957-1
Security update for php8
openSUSE-SU-2026:20745-1
Security update for php8
CVE-2026-6735
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.
CVE-2026-6735
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.
CVE-2026-6735
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.
CVE-2026-6735
XSS within PHP-FPM status endpoint
CVE-2026-6735
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...
GHSA-7qg2-v9fj-4mwv
XSS within PHP-FPM status endpoint
CVE-2026-7258
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.
CVE-2026-7258
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
RLSA-2026:22305 Important: php:8.2 security update | около 2 месяцев назад | |||
RLSA-2026:22143 Important: php:8.2 security update | около 2 месяцев назад | |||
RLSA-2026:22142 Important: php:8.3 security update | около 2 месяцев назад | |||
ELSA-2026-22305 ELSA-2026-22305: php:8.2 security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2026-22143 ELSA-2026-22143: php:8.2 security update (IMPORTANT) | около 1 месяца назад | |||
RLSA-2026:23388 Important: php security update | около 2 месяцев назад | |||
SUSE-SU-2026:2091-1 Security update for php7 | 2 месяца назад | |||
RLSA-2026:22649 Important: php8.4 security update | около 2 месяцев назад | |||
SUSE-SU-2026:2037-1 Security update for php8 | 2 месяца назад | |||
SUSE-SU-2026:1958-1 Security update for php8 | 2 месяца назад | |||
SUSE-SU-2026:1957-1 Security update for php8 | 2 месяца назад | |||
openSUSE-SU-2026:20745-1 Security update for php8 | 3 месяца назад | |||
CVE-2026-6735 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page. | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-6735 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page. | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-6735 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page. | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
CVE-2026-6735 XSS within PHP-FPM status endpoint | 0% Низкий | 3 месяца назад | ||
CVE-2026-6735 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ... | CVSS3: 6.1 | 0% Низкий | 3 месяца назад | |
GHSA-7qg2-v9fj-4mwv XSS within PHP-FPM status endpoint | 0% Низкий | 3 месяца назад | ||
CVE-2026-7258 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-7258 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service. | CVSS3: 5.9 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу