Pear, a PHP library and component project, maintains a distributed set of reusable packages spanning web infrastructure, cryptography, and data-handling utilities, making its vulnerabilities relevant across a broad ecosystem of downstream applications despite its modest direct product count. Vulnerabilities affecting this vendor skew strongly toward critical severity, reflecting the foundational role these libraries play in application logic, data processing, and security operations. The exposure recurs through structural weaknesses endemic to dynamic code and data handling: SQL injection in database abstraction layers, code injection in templating and evaluation contexts, regular-expression denial-of-service conditions, and exposure of sensitive information through improper access controls, patterns that arise repeatedly across products such as PearWeb, the core Pear framework, DataGrid datasources, GPG cryptography handling, and HTML/AJAX components. Defenders should treat Pear package updates with urgency, particularly in legacy deployments where multiple older components may coexist, since remediation requires coordinated rebuilds across dependent applications rather than a single vendor patch. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pear over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5677CRITICAL PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect | Feb 6, 2017 | 9.8 | 31 | NO | NO |
CVE-2026-25240CRITICAL PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability can occur in user::maintains() when role filters are | Feb 3, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-25238CRITICAL PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription deletion may allow attackers to | Feb 3, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-25241CRITICAL PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get/<package>/<version> endpoint allows r | Feb 3, 2026 | 9.8 | 27 | NO | NO |
CVE-2026-25237CRITICAL PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() with the /e modifier in bug update email handling can enable | Feb 3, 2026 | 9.8 | 27 | NO | NO |
CVE-2026-25236CRITICAL PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to unsafe literal substitution fo | Feb 3, 2026 | 9.8 | 27 | NO | NO |
CVE-2026-25234CRITICAL PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in category deletion can allow an attacker with acce | Feb 3, 2026 | 9.8 | 27 | NO | NO |
CVE-2009-4025HIGH Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows remote attackers to execute arbitrary shel | Nov 29, 2009 | 10.0 | 27 | NO | NO |
CVE-2009-4024HIGH Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to execute arbitrary shell commands via the | Nov 29, 2009 | 10.0 | 27 | NO | NO |
CVE-2006-0869MEDIUM Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attacker | Feb 23, 2006 | 6.4 | 27 | NO | YES |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pear.
Media articles that mention a CVE ID that affects a product developed by Pear — matched by CVE ID, not by vendor name.