PHP Group
First CVE: Apr 18, 2019Active for: 7 years
90
CVEs Published
More CVEs Published than 69% of tracked CNAs
11.3
Avg CVEs / Year
More Avg CVEs / Year than 57% of tracked CNAs
7.3
Avg CVSS Score
Higher Avg CVSS Score than 58% of tracked CNAs
2.2%
In CISA KEV
Higher KEV Rate than 92% of tracked CNAs
Self-Reporting Analysis
Of all the CVEs published by PHP Group as a CNA, 98.9% affect products that PHP Group develops as a vendor.
98.9%
Self-reported: 89Third-party: 1
Of all the CVEs published that affect products developed by PHP Group, 11.5% are self-published by PHP Group as a CNA.
11.5%
88.5%
Self-published: 89Published by other CNAs: 688
Trends Over Time
The number and severity of CVEs published by PHP Group over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 18, 2019
7 years ago
Most Recent CVE
Jul 3, 2026
21 days ago
Top CVEs
All CVEs published by PHP Group as a CNA, regardless of affected vendor or product.
90 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-4577CRITICAL In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows m | Jun 9, 2024 | 9.8 | 99 | YES | YES |
CVE-2019-11043CRITICAL In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buff | Oct 28, 2019 | 9.8 | 98 | YES | YES |
CVE-2022-31626HIGH In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when pdo_mysql extension with mysqlnd driver, if the third party is allowed to supply host to connect | Jun 16, 2022 | 8.8 | 61 | NO | NO |
CVE-2022-31629MEDIUM In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the vulnerability enables network and same-site attackers to set a standard insecure cookie in the victim's browser which is treat | Sep 28, 2022 | 6.5 | 51 | NO | NO |
CVE-2024-1874CRITICAL In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of th | Apr 29, 2024 | 9.4 | 47 | NO | NO |
CVE-2026-6722CRITICAL In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP ob | May 10, 2026 | 9.8 | 45 | NO | NO |
CVE-2025-14179CRITICAL In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queri | May 10, 2026 | 9.8 | 42 | NO | NO |
CVE-2024-5585HIGH In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: | Jun 9, 2024 | 8.8 | 42 | NO | NO |
CVE-2024-2756MEDIUM Due to an incomplete fix to CVE-2022-31629 https://github.com/advisories/GHSA-c43m-486j-j32p , network and same-site attackers can set a standard insecure cookie in the victim's b | Apr 29, 2024 | 6.5 | 41 | NO | NO |
CVE-2026-7261CRITICAL In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler obje | May 10, 2026 | 9.8 | 40 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA90 CVEs
37%
33%
27%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local6 (6.7%)
Network83 (92.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.1%)
Attack Complexity
Low79 (87.8%)
High11 (12.2%)
Unknown0 (0.0%)
User Interaction
None78 (86.7%)
Unknown0 (0.0%)
Required12 (13.3%)
Privileges Required
Low10 (11.1%)
High0 (0.0%)
None80 (88.9%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (90 CVEs).
CISA KEV
2 CVEs
2.2% of CVEs· 92nd percentile
Metasploit
2 CVEs
2.2% of CVEs· 92nd percentile
Nuclei
1 CVE
1.1% of CVEs· 80th percentile
ExploitDB
2 CVEs
2.2% of CVEs· 89th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by PHP Group as a CNA.
Media Mentions
Media articles that mention a CVE ID published by PHP Group as a CNA — matched by CVE ID, not by organization name.