Pearweb
Vendor:
First CVE: Feb 3, 2026 · Active for under a year
9
Total CVEs
More Total CVEs than 86% of tracked products
9.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
9.2
Avg CVSS
Higher Avg CVSS than 85% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pearweb over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 3, 2026
5 months ago
Most Recent CVE
Feb 3, 2026
172 days ago
CVE Severity & Scoring
Pearweb9 CVEs
22%
78%
All CVEs352,708 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25240CRITICAL PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability can occur in user::maintains() when role filters are | Feb 3, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-25238CRITICAL PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription deletion may allow attackers to | Feb 3, 2026 | 9.8 | 29 | NO | NO |
CVE-2026-25241CRITICAL PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get/<package>/<version> endpoint allows r | Feb 3, 2026 | 9.8 | 27 | NO | NO |
CVE-2026-25237CRITICAL PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() with the /e modifier in bug update email handling can enable | Feb 3, 2026 | 9.8 | 27 | NO | NO |
CVE-2026-25236CRITICAL PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to unsafe literal substitution fo | Feb 3, 2026 | 9.8 | 27 | NO | NO |
CVE-2026-25234CRITICAL PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in category deletion can allow an attacker with acce | Feb 3, 2026 | 9.8 | 27 | NO | NO |
CVE-2026-25233CRITICAL PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadmap role check allows non-lead maintainers to create, update, | Feb 3, 2026 | 9.1 | 26 | NO | NO |
CVE-2026-25239HIGH PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in apidoc queue insertion can allow query manipulati | Feb 3, 2026 | 7.5 | 22 | NO | NO |
CVE-2026-25235HIGH PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable verification hashes may allow attackers to guess verification tokens a | Feb 3, 2026 | 7.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Pearweb
Top CWEs
Versions
No cataloged versions.