PHPUnit is a widely embedded unit-testing framework for PHP applications, where its deep integration into development and CI/CD pipelines amplifies the impact of flaws in test execution and code-handling logic. The observed weakness classes—centered on unsafe deserialization, code injection, argument injection, and cross-site scripting—reflect the framework's role in executing and reporting on untrusted test inputs and dynamically generated test artifacts. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpunit Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9841CRITICAL Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, | Jun 27, 2017 | 9.8 | 99 | YES | YES |
CVE-2026-41570HIGH PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child processes (used for isolated/PHPT test execution) as -d name=valu | May 8, 2026 | 7.8 | 31 | NO | NO |
CVE-2026-24765HIGH PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of co | Jan 27, 2026 | 7.8 | 29 | NO | NO |
CVE-2013-4744MEDIUM Cross-site scripting (XSS) vulnerability in the PHPUnit extension before 3.5.15 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Jul 1, 2013 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpunit Project.
Media articles that mention a CVE ID that affects a product developed by Phpunit Project — matched by CVE ID, not by vendor name.