Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 23

Количество 23

github логотип

GHSA-7qg2-v9fj-4mwv

3 месяца назад

XSS within PHP-FPM status endpoint

EPSS: Низкий
ubuntu логотип

CVE-2026-6735

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2026-6735

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-6735

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 6.1
EPSS: Низкий
msrc логотип

CVE-2026-6735

3 месяца назад

XSS within PHP-FPM status endpoint

EPSS: Низкий
debian логотип

CVE-2026-6735

3 месяца назад

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2026-09671

3 месяца назад

Уязвимость менеджера фоновых процессов PHP-FPM интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный JavaScript-код (XSS)

CVSS3: 6.1
EPSS: Низкий
rocky логотип

RLSA-2026:22305

2 месяца назад

Important: php:8.2 security update

EPSS: Низкий
rocky логотип

RLSA-2026:22143

2 месяца назад

Important: php:8.2 security update

EPSS: Низкий
rocky логотип

RLSA-2026:22142

2 месяца назад

Important: php:8.3 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22305

2 месяца назад

ELSA-2026-22305: php:8.2 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22143

около 1 месяца назад

ELSA-2026-22143: php:8.2 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-22142

около 1 месяца назад

ELSA-2026-22142: php:8.3 security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:23388

2 месяца назад

Important: php security update

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2091-1

2 месяца назад

Security update for php7

EPSS: Низкий
rocky логотип

RLSA-2026:34354

около 1 месяца назад

Important: php:7.4 security update

EPSS: Низкий
rocky логотип

RLSA-2026:22649

2 месяца назад

Important: php8.4 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-34354

около 1 месяца назад

ELSA-2026-34354: php:7.4 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-33449

около 1 месяца назад

ELSA-2026-33449: php security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2037-1

3 месяца назад

Security update for php8

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-7qg2-v9fj-4mwv

XSS within PHP-FPM status endpoint

0%
Низкий
3 месяца назад
ubuntu логотип
CVE-2026-6735

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 6.1
0%
Низкий
3 месяца назад
redhat логотип
CVE-2026-6735

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 5.4
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-6735

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS3: 6.1
0%
Низкий
3 месяца назад
msrc логотип
CVE-2026-6735

XSS within PHP-FPM status endpoint

0%
Низкий
3 месяца назад
debian логотип
CVE-2026-6735

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before ...

CVSS3: 6.1
0%
Низкий
3 месяца назад
fstec логотип
BDU:2026-09671

Уязвимость менеджера фоновых процессов PHP-FPM интерпретатора языка программирования PHP, позволяющая нарушителю выполнить произвольный JavaScript-код (XSS)

CVSS3: 6.1
0%
Низкий
3 месяца назад
rocky логотип
RLSA-2026:22305

Important: php:8.2 security update

2 месяца назад
rocky логотип
RLSA-2026:22143

Important: php:8.2 security update

2 месяца назад
rocky логотип
RLSA-2026:22142

Important: php:8.3 security update

2 месяца назад
oracle-oval логотип
ELSA-2026-22305

ELSA-2026-22305: php:8.2 security update (IMPORTANT)

2 месяца назад
oracle-oval логотип
ELSA-2026-22143

ELSA-2026-22143: php:8.2 security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-22142

ELSA-2026-22142: php:8.3 security update (IMPORTANT)

около 1 месяца назад
rocky логотип
RLSA-2026:23388

Important: php security update

2 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2091-1

Security update for php7

2 месяца назад
rocky логотип
RLSA-2026:34354

Important: php:7.4 security update

около 1 месяца назад
rocky логотип
RLSA-2026:22649

Important: php8.4 security update

2 месяца назад
oracle-oval логотип
ELSA-2026-34354

ELSA-2026-34354: php:7.4 security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-33449

ELSA-2026-33449: php security update (IMPORTANT)

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2037-1

Security update for php8

3 месяца назад

Уязвимостей на страницу