PHP Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for PHP products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
22
In CISA KEV
7
Beyond CISA KEV
15
Sensor Observed
2
Virtual Patch Available
1
PHP KEVs Added by Year
22 PHP KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-48611
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to... |
phpBB | Confirmed | Not in CISA | 20 Jul 2026 |
|
CVE-2020-24949
Privilege escalation in PHP-Fusion 9.03.50 downloads/downloads.php allows an authenticated user (not admin) to send a crafted request to the server... |
PHP-Fusion | High | Not in CISA | 15 Jun 2026 |
|
CVE-2020-20300
SQL injection vulnerability in the wp_where function in WeiPHP 5.0. |
WeiPHP 5.0 | High | Not in CISA | 14 Apr 2026 |
|
CVE-2020-22165
PHPGurukul Hospital Management System in PHP v4.0 has a SQL injection vulnerability in \hms\user-login.php. Remote unauthenticated users can... |
Hospital Management System | High | Not in CISA | 13 Feb 2026 |
|
CVE-2023-40748
PHPJabbers Food Delivery Script 3.0 has a SQL injection (SQLi) vulnerability in the "q" parameter of index.php. |
Food Delivery Script | High | Not in CISA | 26 Jan 2026 |
|
CVE-2019-9762
A SQL Injection was discovered in PHPSHE 1.7 in include/plugin/payment/alipay/pay.php with the parameter id. The vulnerability does not need any... |
PHPSHE 1.7 | High | Not in CISA | 30 Dec 2025 |
|
CVE-2017-6090
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute... |
PhpCollab | High | Not in CISA | 05 Jul 2025 |
|
CVE-2022-47945
ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled... |
ThinkPHP Framework | Confirmed | Not in CISA | 21 Jun 2025 |
|
CVE-2016-10033
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command... |
PHPMailer | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2012-2376
Buffer overflow in the com_print_typeinfo function in PHP 5.4.3 and earlier on Windows allows remote attackers to execute arbitrary code via... |
PHP | High | Not in CISA | 21 May 2012 |
|
CVE-2011-4075
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby... |
phpLDAPadmin | High | Not in CISA | 02 Nov 2011 |
|
CVE-2008-5227
Unspecified vulnerability in PHPCow allows remote attackers to execute arbitrary code via unknown vectors, related to a "file inclusion... |
PHPCow | High | Not in CISA | 25 Nov 2008 |
|
CVE-2019-5127
A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable... |
YouPHPTube" | High | Not in CISA | 25 Apr 2025 |
|
CVE-2019-5129
A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable... |
YouPHPTube | High | Not in CISA | 25 Apr 2025 |
|
CVE-2019-5128
A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable... |
YouPHPTube | High | Not in CISA | 27 Apr 2025 |
|
CVE-2019-9082
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via... |
ThinkPHP | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2017-9841
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data... |
PHPUnit | Confirmed | In CISA | 15 Feb 2022 |
|
CVE-2009-1151
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject... |
phpMyAdmin | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2012-1823
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query... |
PHP | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2019-11043
Underflow in PHP-FPM can lead to RCE |
PHP | Confirmed | In CISA | 25 Mar 2022 |
|
CVE-2024-4577
Argument Injection in PHP-CGI |
PHP | Confirmed | In CISA | 12 Jun 2024 |
|
CVE-2021-44892
A Remote Code Execution (RCE) vulnerability exists in ThinkPHP 3.x.x via value[_filename] in index.php, which could let a malicious user obtain... |
ThinkPHP 3.x.x | High | Not in CISA | 10 Feb 2022 |
Common Vulnerability Classes (CWE)
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 4
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') 4
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 4
- CWE-287 — Improper Authentication 1
- CWE-306 — Missing Authentication for Critical Function 1
- CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer 1
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
- CWE-88 — Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology