PHP Group

First CVE: Apr 18, 2019Active for: 7 years
90
CVEs Published
More CVEs Published than 69% of tracked CNAs
11.3
Avg CVEs / Year
More Avg CVEs / Year than 57% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 58% of tracked CNAs
2.2%
In CISA KEV
Higher KEV Rate than 92% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by PHP Group as a CNA, 98.9% affect products that PHP Group develops as a vendor.

98.9%
Self-reported: 89Third-party: 1

Of all the CVEs published that affect products developed by PHP Group, 11.5% are self-published by PHP Group as a CNA.

11.5%
88.5%
Self-published: 89Published by other CNAs: 688

Trends Over Time

The number and severity of CVEs published by PHP Group over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 2019
7 years ago
Most Recent CVE
Jul 3, 2026
21 days ago

Top CVEs

All CVEs published by PHP Group as a CNA, regardless of affected vendor or product.

90 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows m
Jun 9, 20249.899YESYES
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buff
Oct 28, 20199.898YESYES
In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect
Jun 16, 20228.861NONO
In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treat
Sep 28, 20226.551NONO
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of th
Apr 29, 20249.447NONO
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP ob
May 10, 20269.845NONO
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queri
May 10, 20269.842NONO
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: 
Jun 9, 20248.842NONO
Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's b
Apr 29, 20246.541NONO
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler obje
May 10, 20269.840NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA90 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local6 (6.7%)
Network83 (92.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.1%)
Attack Complexity
Low79 (87.8%)
High11 (12.2%)
Unknown0 (0.0%)
User Interaction
None78 (86.7%)
Unknown0 (0.0%)
Required12 (13.3%)
Privileges Required
Low10 (11.1%)
High0 (0.0%)
None80 (88.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (90 CVEs).

CISA KEV
2 CVEs
2.2% of CVEs· 92nd percentile
Metasploit
2 CVEs
2.2% of CVEs· 92nd percentile
Nuclei
1 CVE
1.1% of CVEs· 80th percentile
ExploitDB
2 CVEs
2.2% of CVEs· 89th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by PHP Group as a CNA.

Media Mentions

Media articles that mention a CVE ID published by PHP Group as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs