| CVE-2026-9672 |
|
Remote Code Execution |
Malformed GIF files processed with GD extension lead to potential arbitrary code execution |
2026-08-01 |
7.2.0-7.2.34
7.3.0-7.3.33
7.4.0-7.4.33
8.1.0-8.1.34
8.2.0-8.2.32
8.3.0-8.3.32
8.4.0-8.4.23
8.5.0-8.5.8
|
ZendPHP 7.2
ZendPHP 7.3
ZendPHP 7.4
ZendPHP 8.1
ZendPHP 8.2
ZendPHP 8.3
ZendPHP 8.4
ZendPHP 8.5
ZendServer 2021.4.7
|
| CVE-2026-17543 |
|
SQL Injection |
SQL injection via improper backslash escaping in Postgres |
2026-07-30 |
7.2.0-7.2.34
7.3.0-7.3.33
7.4.0-7.4.33
8.1.0-8.1.34
8.2.0-8.2.32
8.3.0-8.3.32
8.4.0-8.4.23
8.5.0-8.5.8
|
ZendPHP 7.2
ZendPHP 7.3
ZendPHP 7.4
ZendPHP 8.1
ZendPHP 8.2
ZendPHP 8.3
ZendPHP 8.4
ZendPHP 8.5
ZendServer 2021.4.7
|
| CVE-2026-17544 |
|
Remote Code Execution |
Arbitrary code execution via out-of-bounds write in bccomp() |
2026-07-30 |
8.4.0-8.4.23
8.5.0-8.5.8
|
ZendPHP 8.4
ZendPHP 8.5
|
| CVE-2026-7260 |
|
Denial of Service |
php: PHP: Denial of Service via circular symbolic links in phar archives |
2026-07-30 |
7.2.0-7.2.34
7.3.0-7.3.33
7.4.0-7.4.33
8.1.0-8.1.34
8.2.0-8.2.32
8.3.0-8.3.32
8.4.0-8.4.23
8.5.0-8.5.8
|
ZendPHP 7.2
ZendPHP 7.3
ZendPHP 7.4
ZendPHP 8.1
ZendPHP 8.2
ZendPHP 8.3
ZendPHP 8.4
ZendPHP 8.5
ZendServer 2021.4.7
|
| CVE-2026-12184 |
|
Denial of Service |
TLS Cleanup Crash |
2026-07-03 |
8.3.0-8.3.31
8.4.0-8.4.20
8.5.0-8.5.5
|
ZendPHP 8.3
ZendPHP 8.4
ZendPHP 8.5
|
| CVE-2026-14355 |
|
Denial of Service |
Buffer allocation flaw in OpenSSL |
2026-07-03 |
7.2.0-7.2.34
7.3.0-7.3.33
7.4.0-7.4.33
8.1.0-8.1.34
8.2.0-8.2.31
8.3.0-8.3.31
8.4.0-8.4.22
8.5.0-8.5.7
|
ZendPHP 7.2
ZendPHP 7.3
ZendPHP 7.4
ZendPHP 8.0
ZendPHP 8.1
ZendPHP 8.2
ZendPHP 8.3
ZendPHP 8.4
ZendPHP 8.5
ZendServer 2021.4.6
|
| CVE-2026-29078 |
|
Remote Code Execution |
Out-of-bounds read and write when traversing DOM contents |
2026-05-13 |
8.4.0-8.4.20
8.5.0-8.5.5
|
ZendPHP 8.4
ZendPHP 8.5
|
| CVE-2026-29079 |
|
Cross-Site Request Forgery |
Type-confusion in HTML fragment parsing |
2026-05-13 |
8.4.0-8.4.20
8.5.0-8.5.5
|
ZendPHP 8.4
ZendPHP 8.5
|
| CVE-2025-14179 |
|
Cross-Site Request Forgery |
Invalid NULL byte handling in Firebird prepared queries |
2026-05-10 |
8.1.0-8.1.34
8.2.0-8.2.30
8.3.0-8.3.30
8.4.0-8.4.20
8.5.0-8.5.5
|
ZendPHP 8.1
ZendPHP 8.2
ZendPHP 8.3
ZendPHP 8.4
ZendPHP 8.5
|
| CVE-2026-6104 |
|
Cross-Site Request Forgery |
NUL byte in mbstring encoding leads to out-of-bounds read |
2026-05-10 |
8.4.0-8.4.20
8.5.0-8.5.5
|
ZendPHP 8.4
ZendPHP 8.5
|