Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pear

First CVE: Dec 31, 2005Active for: 21 yearsTotal CVEs: 22
38.1
VTI Score
Medium

Pear, a PHP library and component project, maintains a distributed set of reusable packages spanning web infrastructure, cryptography, and data-handling utilities, making its vulnerabilities relevant across a broad ecosystem of downstream applications despite its modest direct product count. Vulnerabilities affecting this vendor skew strongly toward critical severity, reflecting the foundational role these libraries play in application logic, data processing, and security operations. The exposure recurs through structural weaknesses endemic to dynamic code and data handling: SQL injection in database abstraction layers, code injection in templating and evaluation contexts, regular-expression denial-of-service conditions, and exposure of sensitive information through improper access controls, patterns that arise repeatedly across products such as PearWeb, the core Pear framework, DataGrid datasources, GPG cryptography handling, and HTML/AJAX components. Defenders should treat Pear package updates with urgency, particularly in legacy deployments where multiple older components may coexist, since remediation requires coordinated rebuilds across dependent applications rather than a single vendor patch. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pear over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
Feb 3, 2026
171 days ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-5677CRITICAL
PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect
Feb 6, 20179.831NONO
CVE-2026-25240CRITICAL
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability can occur in user::maintains() when role filters are
Feb 3, 20269.829NONO
CVE-2026-25238CRITICAL
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription deletion may allow attackers to
Feb 3, 20269.829NONO
CVE-2026-25241CRITICAL
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get/<package>/<version> endpoint allows r
Feb 3, 20269.827NONO
CVE-2026-25237CRITICAL
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() with the /e modifier in bug update email handling can enable
Feb 3, 20269.827NONO
CVE-2026-25236CRITICAL
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to unsafe literal substitution fo
Feb 3, 20269.827NONO
CVE-2026-25234CRITICAL
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in category deletion can allow an attacker with acce
Feb 3, 20269.827NONO
CVE-2009-4025HIGH
Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows remote attackers to execute arbitrary shel
Nov 29, 200910.027NONO
CVE-2009-4024HIGH
Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to execute arbitrary shell commands via the
Nov 29, 200910.027NONO
CVE-2006-0869MEDIUM
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attacker
Feb 23, 20066.427NOYES
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
32%
32%
36%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (50.0%)
Unknown11 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (50.0%)
High0 (0.0%)
Unknown11 (50.0%)
User Interaction
None11 (50.0%)
Unknown11 (50.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None11 (50.0%)
Unknown11 (50.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.5% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pear.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pear — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pear's Products

View all 3 CNAs →

Top CWEs