Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2021-37704

27
FAUCET Score

CVE-2021-37704 is a medium-severity information disclosure vulnerability affecting PhpFastCache versions prior to 6.1.5, 7.1.2, and 8.0.7. If the /vendor directory, where PhpFastCache is installed, is publicly accessible, an attacker can expose the phpinfo() output, potentially revealing sensitive system configuration details. The attack complexity is low, requiring only network access and low privileges, with a CVSS score of 4.3. While not actively exploited in the wild and not on CISA's KEV catalog, a Nuclei template exists for detection, and there is minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 6.1.5CPE matchmatch criteria
cpe:2.3:a:phpfastcache:phpfastcache:*:*:*:*:*:*:*:*
>= 7.0.0, < 7.1.2CPE matchmatch criteria
cpe:2.3:a:phpfastcache:phpfastcache:*:*:*:*:*:*:*:*
>= 8.0.0, < 8.0.7CPE matchmatch criteria
cpe:2.3:a:phpfastcache:phpfastcache:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.4MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
6.13%
Probability of exploitation in next 30 days
EPSS Percentile
92.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2021-37704 · Aug 14, 2021
This CVE's current EPSS score of 0.0613 is in the 98th percentile among its peer group of 21,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

composerpatch availablevia ghsa
Product: phpfastcache/phpfastcacheFixed in: 6.1.5
composerpatch availablevia ghsa
Product: phpfastcache/phpfastcacheFixed in: 7.1.2
composerpatch availablevia ghsa
Product: phpfastcache/phpfastcacheFixed in: 8.0.7
github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

composerGHSA-cvh5-p6r6-g2qcmedium

Exposed phpinfo() leadked via documentation files

Aug 30, 2021

References

github.com / flextype/flextype/issues/567
ExploitIssue TrackingThird Party Advisory
github.com / PHPSocialNetwork/phpfastcache/blob/master/CHANGELOG.md
Release NotesThird Party Advisory
github.com / PHPSocialNetwork/phpfastcache/commit/41a77d0d8f126dbd6fbedcd9e6a82e86cdaafa51
PatchThird Party Advisory
github.com / PHPSocialNetwork/phpfastcache/pull/813
PatchThird Party Advisory
github.com / PHPSocialNetwork/phpfastcache/pull/814
Third Party Advisory
github.com / PHPSocialNetwork/phpfastcache/pull/815
Third Party Advisory
github.com / PHPSocialNetwork/phpfastcache/security/advisories/GHSA-cvh5-p6r6-g2qc
Third Party Advisory
packagist.org / packages/phpfastcache/phpfastcache
ProductThird Party Advisory