PECL PHP maintains a collection of community-contributed PHP extensions, with the durable signal centered around its Alternative PHP Cache (APC) component. This represents a niche but widely embedded extension layer rather than a core platform, making vulnerability scope limited to products that explicitly load and depend on these add-ons; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pecl Php over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1488MEDIUM Stack-based buffer overflow in apc.c in Alternative PHP Cache (APC) 3.0.11 through 3.0.16 allows remote attackers to execute arbitrary code via a long filename. | Mar 24, 2008 | 6.8 | 31 | NO | YES |
CVE-2010-3294MEDIUM Cross-site scripting (XSS) vulnerability in apc.php in the Alternative PHP Cache (APC) extension before 3.1.4 for PHP allows remote attackers to inject arbitrary web script or HTML | Sep 24, 2010 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pecl Php.
Media articles that mention a CVE ID that affects a product developed by Pecl Php — matched by CVE ID, not by vendor name.