Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Phpunit Project

First CVE: Jul 1, 2013Active for: 13 yearsTotal CVEs: 4

PHPUnit is a widely embedded unit-testing framework for PHP applications, where its deep integration into development and CI/CD pipelines amplifies the impact of flaws in test execution and code-handling logic. The observed weakness classes—centered on unsafe deserialization, code injection, argument injection, and cross-site scripting—reflect the framework's role in executing and reporting on untrusted test inputs and dynamically generated test artifacts. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
More Total CVEs than 79% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
25.0%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Phpunit Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 2013
13 years ago
Most Recent CVE
May 8, 2026
77 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-9841CRITICAL
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring,
Jun 27, 20179.899YESYES
CVE-2026-41570HIGH
PHPUnit is a testing framework for PHP. In versions 12.5.21 and 13.1.5, PHPUnit forwards PHP INI settings to child processes (used for isolated/PHPT test execution) as -d name=valu
May 8, 20267.831NONO
CVE-2026-24765HIGH
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of co
Jan 27, 20267.829NONO
CVE-2013-4744MEDIUM
Cross-site scripting (XSS) vulnerability in the PHPUnit extension before 3.5.15 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Jul 1, 20134.314NONO
View all 4 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
25%
50%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (50.0%)
Network1 (25.0%)
Unknown1 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (75.0%)
High0 (0.0%)
Unknown1 (25.0%)
User Interaction
None3 (75.0%)
Unknown1 (25.0%)
Required0 (0.0%)
Privileges Required
Low2 (50.0%)
High0 (0.0%)
None1 (25.0%)
Unknown1 (25.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
1 CVE
25.0% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
25.0% of CVEs· 97th percentile
ExploitDB
1 CVE
25.0% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Phpunit Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Phpunit Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Phpunit Project's Products

View all 2 CNAs →

Top CWEs