Количество 74
Количество 74
CVE-2026-6735
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.
CVE-2026-6735
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.
CVE-2026-6735
XSS within PHP-FPM status endpoint
CVE-2026-6735
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...
GHSA-7qg2-v9fj-4mwv
XSS within PHP-FPM status endpoint
BDU:2026-09671
Уязвимость менеджера фоновых процессов PHP-FPM интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный JavaScript-код (XSS)
ROS-20260901-80-0020
Уязвимость php 8.5
ROS-20260901-80-0019
Уязвимость php 8.4
ROS-20260901-80-0018
Уязвимость php 8.3
ROS-20260901-80-0017
Уязвимость php
ROS-20260901-73-0015
Уязвимость php 8.4
ROS-20260901-73-0014
Уязвимость php 8.3
ROS-20260901-73-0013
Уязвимость php
CVE-2026-7258
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.
CVE-2026-7258
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.
CVE-2026-7258
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.
CVE-2026-7258
Out-of-bounds read in urldecode() on NetBSD
CVE-2026-7258
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...
GHSA-m8rr-4c36-8gq4
Out-of-bounds read in urldecode()
BDU:2026-08591
Уязвимость функции urldecode() интерпретатора языка программирования PHP, позволяющая нарушителю вызвать отказ в обслуживании
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-6735 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page. | CVSS3: 5.4 | 0% Низкий | 4 месяца назад | |
CVE-2026-6735 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page. | CVSS3: 6.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-6735 XSS within PHP-FPM status endpoint | 0% Низкий | 4 месяца назад | ||
CVE-2026-6735 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ... | CVSS3: 6.1 | 0% Низкий | 4 месяца назад | |
GHSA-7qg2-v9fj-4mwv XSS within PHP-FPM status endpoint | 0% Низкий | 4 месяца назад | ||
BDU:2026-09671 Уязвимость менеджера фоновых процессов PHP-FPM интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный JavaScript-код (XSS) | CVSS3: 6.1 | 0% Низкий | 4 месяца назад | |
ROS-20260901-80-0020 Уязвимость php 8.5 | CVSS3: 6.1 | 0% Низкий | 14 дней назад | |
ROS-20260901-80-0019 Уязвимость php 8.4 | CVSS3: 6.1 | 0% Низкий | 14 дней назад | |
ROS-20260901-80-0018 Уязвимость php 8.3 | CVSS3: 6.1 | 0% Низкий | 14 дней назад | |
ROS-20260901-80-0017 Уязвимость php | CVSS3: 6.1 | 0% Низкий | 14 дней назад | |
ROS-20260901-73-0015 Уязвимость php 8.4 | CVSS3: 6.1 | 0% Низкий | 14 дней назад | |
ROS-20260901-73-0014 Уязвимость php 8.3 | CVSS3: 6.1 | 0% Низкий | 14 дней назад | |
ROS-20260901-73-0013 Уязвимость php | CVSS3: 6.1 | 0% Низкий | 14 дней назад | |
CVE-2026-7258 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-7258 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service. | CVSS3: 5.9 | 0% Низкий | 4 месяца назад | |
CVE-2026-7258 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
CVE-2026-7258 Out-of-bounds read in urldecode() on NetBSD | 0% Низкий | 4 месяца назад | ||
CVE-2026-7258 In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ... | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
GHSA-m8rr-4c36-8gq4 Out-of-bounds read in urldecode() | 0% Низкий | 4 месяца назад | ||
BDU:2026-08591 Уязвимость функции urldecode() интерпретатора языка программирования PHP, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу