Skip to main content

PHP Security Center

Filter By Severity
CVE Severity      Type Type Subject Date Date Affected Versions Affected Versions Fixed Products
CVE-2026-9672 High

Remote Code Execution

Malformed GIF files processed with GD extension lead to potential arbitrary code execution

2026-08-01

7.2.0-7.2.34
7.3.0-7.3.33
7.4.0-7.4.33
8.1.0-8.1.34
8.2.0-8.2.32
8.3.0-8.3.32
8.4.0-8.4.23
8.5.0-8.5.8
ZendPHP 7.2
ZendPHP 7.3
ZendPHP 7.4
ZendPHP 8.1
ZendPHP 8.2
ZendPHP 8.3
ZendPHP 8.4
ZendPHP 8.5
ZendServer 2021.4.7
CVE-2026-17543 Critical

SQL Injection

SQL injection via improper backslash escaping in Postgres

2026-07-30

7.2.0-7.2.34
7.3.0-7.3.33
7.4.0-7.4.33
8.1.0-8.1.34
8.2.0-8.2.32
8.3.0-8.3.32
8.4.0-8.4.23
8.5.0-8.5.8
ZendPHP 7.2
ZendPHP 7.3
ZendPHP 7.4
ZendPHP 8.1
ZendPHP 8.2
ZendPHP 8.3
ZendPHP 8.4
ZendPHP 8.5
ZendServer 2021.4.7
CVE-2026-17544 Critical

Remote Code Execution

Arbitrary code execution via out-of-bounds write in bccomp()

2026-07-30

8.4.0-8.4.23
8.5.0-8.5.8
ZendPHP 8.4
ZendPHP 8.5
CVE-2026-7260 Moderate

Denial of Service

php: PHP: Denial of Service via circular symbolic links in phar archives

2026-07-30

7.2.0-7.2.34
7.3.0-7.3.33
7.4.0-7.4.33
8.1.0-8.1.34
8.2.0-8.2.32
8.3.0-8.3.32
8.4.0-8.4.23
8.5.0-8.5.8
ZendPHP 7.2
ZendPHP 7.3
ZendPHP 7.4
ZendPHP 8.1
ZendPHP 8.2
ZendPHP 8.3
ZendPHP 8.4
ZendPHP 8.5
ZendServer 2021.4.7
CVE-2026-12184 High

Denial of Service

TLS Cleanup Crash

2026-07-03

8.3.0-8.3.31
8.4.0-8.4.20
8.5.0-8.5.5
ZendPHP 8.3
ZendPHP 8.4
ZendPHP 8.5
CVE-2026-14355 Moderate

Denial of Service

Buffer allocation flaw in OpenSSL

2026-07-03

7.2.0-7.2.34
7.3.0-7.3.33
7.4.0-7.4.33
8.1.0-8.1.34
8.2.0-8.2.31
8.3.0-8.3.31
8.4.0-8.4.22
8.5.0-8.5.7
ZendPHP 7.2
ZendPHP 7.3
ZendPHP 7.4
ZendPHP 8.0
ZendPHP 8.1
ZendPHP 8.2
ZendPHP 8.3
ZendPHP 8.4
ZendPHP 8.5
ZendServer 2021.4.6
CVE-2026-29078 Moderate

Remote Code Execution

Out-of-bounds read and write when traversing DOM contents

2026-05-13

8.4.0-8.4.20
8.5.0-8.5.5
ZendPHP 8.4
ZendPHP 8.5
CVE-2026-29079 Critical

Cross-Site Request Forgery

Type-confusion in HTML fragment parsing

2026-05-13

8.4.0-8.4.20
8.5.0-8.5.5
ZendPHP 8.4
ZendPHP 8.5
CVE-2025-14179 Critical

Cross-Site Request Forgery

Invalid NULL byte handling in Firebird prepared queries

2026-05-10

8.1.0-8.1.34
8.2.0-8.2.30
8.3.0-8.3.30
8.4.0-8.4.20
8.5.0-8.5.5
ZendPHP 8.1
ZendPHP 8.2
ZendPHP 8.3
ZendPHP 8.4
ZendPHP 8.5
CVE-2026-6104 Critical

Cross-Site Request Forgery

NUL byte in mbstring encoding leads to out-of-bounds read

2026-05-10

8.4.0-8.4.20
8.5.0-8.5.5
ZendPHP 8.4
ZendPHP 8.5
Page
Sort by severity
Sort by type
Sort by date
Sort by php versions affected