The PHP Group maintains a widely deployed scripting language and related tooling spanning core PHP, FrankenPHP, PEAR, and archive handling components that serve as infrastructure across a substantial portion of web applications globally. Observed vulnerability disclosures cluster around broadly categorized weaknesses that reflect the challenge of characterizing flaws in a large, legacy codebase; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Php Group over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2519MEDIUM Directory traversal vulnerability in the installer in PEAR 1.0 through 1.5.3 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the ( | May 22, 2007 | 6.8 | 29 | NO | YES |
CVE-2006-3016HIGH Unspecified vulnerability in session.c in PHP before 5.1.3 has unknown impact and attack vectors, related to "certain characters in session names," including special characters tha | Jun 14, 2006 | 9.3 | 23 | NO | NO |
CVE-2006-3018HIGH Unspecified vulnerability in the session extension functionality in PHP before 5.1.3 has unknown impact and attack vectors related to heap corruption. | Jun 14, 2006 | 7.5 | 22 | NO | NO |
CVE-2006-7205MEDIUM The array_fill function in ext/standard/array.c in PHP 4.4.2 and 5.1.2 allows context-dependent attackers to cause a denial of service (memory consumption) via a large num value. | May 24, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Php Group.
Media articles that mention a CVE ID that affects a product developed by Php Group — matched by CVE ID, not by vendor name.