PHP Proxy is a narrowly scoped web-forwarding tool that enables clients to route requests through a proxy layer implemented in PHP, serving a focused use case in web infrastructure. The vendor's disclosed vulnerabilities reflect the input-handling and request-processing surface inherent to a forwarding proxy, though the scope and pattern of weaknesses remain limited. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Php Proxy over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19458HIGH In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability than CVE-2018-19246. | Nov 22, 2018 | 7.5 | 61 | NO | YES |
CVE-2018-19246HIGH PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their web server) is used. This occu | Nov 13, 2018 | 7.5 | 47 | NO | YES |
CVE-2018-19784HIGH The str_rot_pass function in vendor/atholn1600/php-proxy/src/helpers.php in PHP-Proxy 5.1.0 uses weak cryptography, which makes it easier for attackers to calculate the authorizati | Dec 1, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-19785MEDIUM PHP-Proxy through 5.1.0 has Cross-Site Scripting (XSS) via the URL field in index.php. | Dec 1, 2018 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Php Proxy.
Media articles that mention a CVE ID that affects a product developed by Php Proxy — matched by CVE ID, not by vendor name.