Php Everywhere Project maintains a focused web application product where the observed vulnerability signal centers on code-injection and cross-site request forgery issues, reflecting the input-handling and state-management demands of server-side scripting. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Php Everywhere Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24665HIGH PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg block by any user able to edit posts. | Feb 16, 2022 | 8.8 | 29 | NO | NO |
CVE-2022-24663HIGH PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, which can be used by any authenticated user. | Feb 16, 2022 | 8.8 | 29 | NO | NO |
CVE-2022-24664HIGH PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts. | Feb 16, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-23227HIGH Cross-Site Request Forgery (CSRF) vulnerability in Alexander Fuchs PHP Everywhere plugin <= 2.0.2 versions. | Jan 13, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Php Everywhere Project.
Media articles that mention a CVE ID that affects a product developed by Php Everywhere Project — matched by CVE ID, not by vendor name.