{"schema_version":1,"title":"PHP Group PHP vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 23 vulnerabilities in PHP Group PHP: 0 in the last 7 days and 4 in the last 90 days, 9 of them critical and 3 exploited in the wild. The most recent, CVE-2026-7260, was published on 30 July 2026.","url":"https://junglewise.ai/threats/technologies/php","json_url":"https://junglewise.ai/threats/technologies/php.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/php","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":9,"all_time":23,"critical":9,"exploited":3,"last_7_days":0,"last_30_days":0,"last_90_days":4,"last_365_days":13},"latest":[{"cve":"CVE-2026-7260","cvss":5.5,"slug":"cve-2026-7260-php-phar-uncontrolled-recursion-in-phar-get-link-source","title":"PHP Phar uncontrolled recursion in phar_get_link_source","severity":"info","exploited":false,"published_at":"2026-07-30T12:19:04.3+00:00","url":"https://junglewise.ai/threats/cve-2026-7260-php-phar-uncontrolled-recursion-in-phar-get-link-source"},{"cve":"CVE-2026-17544","cvss":8.1,"slug":"cve-2026-17544-php-bcmath-out-of-bounds-write-in-bccomp","title":"PHP BCMath out-of-bounds write in bccomp","severity":"info","exploited":false,"published_at":"2026-07-30T12:17:27.347+00:00","url":"https://junglewise.ai/threats/cve-2026-17544-php-bcmath-out-of-bounds-write-in-bccomp"},{"cve":"CVE-2026-17543","cvss":8.1,"slug":"cve-2026-17543-php-ext-pgsql-sql-injection-in-pg-select-and-related-functions","title":"PHP ext-pgsql SQL injection in pg_select and related functions","severity":"info","exploited":false,"published_at":"2026-07-30T12:17:27.12+00:00","url":"https://junglewise.ai/threats/cve-2026-17543-php-ext-pgsql-sql-injection-in-pg-select-and-related-functions"},{"cve":"CVE-2026-14355","cvss":5.6,"slug":"cve-2026-14355-php-openssl-extension-heap-overflow-in-aes-wrap-pad","title":"PHP OpenSSL extension heap overflow in AES-WRAP-PAD","severity":"medium","exploited":false,"published_at":"2026-07-03T21:16:55.783+00:00","url":"https://junglewise.ai/threats/cve-2026-14355-php-openssl-extension-heap-overflow-in-aes-wrap-pad"},{"cve":"CVE-2026-7263","cvss":7.5,"epss":0.0027,"slug":"cve-2026-7263-php-domnode-c14n-denial-of-service-via-circular-linked-list","title":"PHP DOMNode::C14N() denial of service via circular linked list","severity":"high","exploited":false,"published_at":"2026-05-10T06:16:08.343+00:00","url":"https://junglewise.ai/threats/cve-2026-7263-php-domnode-c14n-denial-of-service-via-circular-linked-list"},{"cve":"CVE-2026-6104","cvss":9.1,"epss":0.0044,"slug":"cve-2026-6104-php-mbstring-out-of-bounds-read-in-mb-convert-encoding","title":"PHP mbstring out-of-bounds read in mb_convert_encoding","severity":"critical","exploited":false,"published_at":"2026-05-10T06:16:07.397+00:00","url":"https://junglewise.ai/threats/cve-2026-6104-php-mbstring-out-of-bounds-read-in-mb-convert-encoding"},{"cve":"CVE-2026-7568","cvss":7.5,"epss":0.0024,"slug":"cve-2026-7568-php-signed-integer-overflow-in-metaphone-function","title":"PHP signed integer overflow in metaphone function","severity":"high","exploited":false,"published_at":"2026-05-10T05:16:11.92+00:00","url":"https://junglewise.ai/threats/cve-2026-7568-php-signed-integer-overflow-in-metaphone-function"},{"cve":"CVE-2026-7262","cvss":7.5,"epss":0.0045,"slug":"cve-2026-7262-php-soap-extension-null-pointer-dereference-in-apache-map-decoder","title":"PHP SOAP extension NULL pointer dereference in apache:Map decoder","severity":"high","exploited":false,"published_at":"2026-05-10T05:16:11.78+00:00","url":"https://junglewise.ai/threats/cve-2026-7262-php-soap-extension-null-pointer-dereference-in-apache-map-decoder"},{"cve":"CVE-2026-7261","cvss":9.8,"epss":0.003,"slug":"cve-2026-7261-php-soapserver-use-after-free-in-soap-persistence-session","title":"PHP SoapServer use-after-free in SOAP_PERSISTENCE_SESSION","severity":"critical","exploited":false,"published_at":"2026-05-10T05:16:11.64+00:00","url":"https://junglewise.ai/threats/cve-2026-7261-php-soapserver-use-after-free-in-soap-persistence-session"},{"cve":"CVE-2026-7259","cvss":6.5,"epss":0.002,"slug":"cve-2026-7259-php-mbstring-null-pointer-dereference-in-mb-regex-encoding","title":"PHP mbstring NULL pointer dereference in mb_regex_encoding","severity":"medium","exploited":false,"published_at":"2026-05-10T05:16:11.507+00:00","url":"https://junglewise.ai/threats/cve-2026-7259-php-mbstring-null-pointer-dereference-in-mb-regex-encoding"},{"cve":"CVE-2026-7258","cvss":7.5,"epss":0.0034,"slug":"cve-2026-7258-php-out-of-bounds-read-in-urldecode-leading-to-denial-of-service","title":"PHP out-of-bounds read in urldecode leading to denial of service","severity":"high","exploited":false,"published_at":"2026-05-10T05:16:11.36+00:00","url":"https://junglewise.ai/threats/cve-2026-7258-php-out-of-bounds-read-in-urldecode-leading-to-denial-of-service"},{"cve":"CVE-2026-6722","cvss":9.8,"epss":0.0051,"slug":"cve-2026-6722-php-soap-extension-use-after-free-remote-code-execution","title":"PHP SOAP extension use-after-free remote code execution","severity":"critical","exploited":false,"published_at":"2026-05-10T05:16:11.07+00:00","url":"https://junglewise.ai/threats/cve-2026-6722-php-soap-extension-use-after-free-remote-code-execution"},{"cve":"CVE-2025-14179","cvss":9.8,"epss":0.0026,"slug":"cve-2025-14179-php-pdo-firebird-sql-injection-via-nul-bytes-in-quoted-strings","title":"PHP PDO Firebird SQL injection via NUL bytes in quoted strings","severity":"critical","exploited":false,"published_at":"2026-05-10T05:16:09.853+00:00","url":"https://junglewise.ai/threats/cve-2025-14179-php-pdo-firebird-sql-injection-via-nul-bytes-in-quoted-strings"},{"cve":"CVE-2024-4577","cvss":9.8,"slug":"cve-2024-4577-php-cgi-os-command-injection-vulnerability","title":"PHP-CGI OS Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2024-06-12T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-4577-php-cgi-os-command-injection-vulnerability"},{"cve":"CVE-2012-1823","cvss":9.8,"slug":"cve-2012-1823-php-cgi-query-string-parameter-vulnerability","title":"PHP-CGI Query String Parameter Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2012-1823-php-cgi-query-string-parameter-vulnerability"},{"cve":"CVE-2019-11043","cvss":9.8,"slug":"cve-2019-11043-php-fastcgi-process-manager-fpm-buffer-overflow-vulnerability","title":"PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2019-11043-php-fastcgi-process-manager-fpm-buffer-overflow-vulnerability"},{"cve":"CVE-2016-10162","cvss":7.5,"slug":"cve-2016-10162-php-wddx-null-pointer-dereference-in-php-wddx-pop-element","title":"PHP WDDX NULL pointer dereference in php_wddx_pop_element","severity":"high","exploited":false,"published_at":"2017-01-24T21:59:00.307+00:00","url":"https://junglewise.ai/threats/cve-2016-10162-php-wddx-null-pointer-dereference-in-php-wddx-pop-element"},{"cve":"CVE-2016-10161","cvss":7.5,"slug":"cve-2016-10161-php-out-of-bounds-read-in-var-unserializer-c","title":"PHP out-of-bounds read in var_unserializer.c","severity":"high","exploited":false,"published_at":"2017-01-24T21:59:00.26+00:00","url":"https://junglewise.ai/threats/cve-2016-10161-php-out-of-bounds-read-in-var-unserializer-c"},{"cve":"CVE-2016-10160","cvss":9.8,"slug":"cve-2016-10160-php-off-by-one-error-in-phar-parse-pharfile","title":"PHP off-by-one error in phar_parse_pharfile","severity":"critical","exploited":false,"published_at":"2017-01-24T21:59:00.227+00:00","url":"https://junglewise.ai/threats/cve-2016-10160-php-off-by-one-error-in-phar-parse-pharfile"},{"cve":"CVE-2016-10159","cvss":7.5,"slug":"cve-2016-10159-php-integer-overflow-in-phar-parse-pharfile","title":"PHP integer overflow in phar_parse_pharfile","severity":"high","exploited":false,"published_at":"2017-01-24T21:59:00.18+00:00","url":"https://junglewise.ai/threats/cve-2016-10159-php-integer-overflow-in-phar-parse-pharfile"},{"cve":"CVE-2016-10158","cvss":7.5,"slug":"cve-2016-10158-php-exif-denial-of-service-in-exif-convert-any-to-int","title":"PHP EXIF denial of service in exif_convert_any_to_int","severity":"high","exploited":false,"published_at":"2017-01-24T21:59:00.133+00:00","url":"https://junglewise.ai/threats/cve-2016-10158-php-exif-denial-of-service-in-exif-convert-any-to-int"},{"cve":"CVE-1999-0238","cvss":10,"slug":"cve-1999-0238-php-php-cgi-arbitrary-file-disclosure","title":"PHP php.cgi arbitrary file disclosure","severity":"critical","exploited":false,"published_at":"1997-08-01T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0238-php-php-cgi-arbitrary-file-disclosure"},{"cve":"CVE-1999-0058","cvss":7.5,"slug":"cve-1999-0058-php-php-cgi-buffer-overflow-allows-shell-access","title":"PHP php.cgi buffer overflow allows shell access","severity":"high","exploited":false,"published_at":"1997-04-17T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0058-php-php-cgi-buffer-overflow-allows-shell-access"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"PHP Group PHP","slug":"php","vendor":{"name":"PHP Group","slug":"php-group","url":"https://junglewise.ai/threats/vendors/php-group"},"aliases":[],"category":"programming-language","homepage":"https://www.php.net/","repo_url":"https://github.com/php/php-src","description":"PHP is a popular general-purpose scripting language that is especially suited to web development.","url":"https://junglewise.ai/threats/technologies/php"},"most_severe":[{"cve":"CVE-2024-4577","cvss":9.8,"slug":"cve-2024-4577-php-cgi-os-command-injection-vulnerability","title":"PHP-CGI OS Command Injection Vulnerability","severity":"critical","exploited":true,"published_at":"2024-06-12T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2024-4577-php-cgi-os-command-injection-vulnerability"},{"cve":"CVE-2012-1823","cvss":9.8,"slug":"cve-2012-1823-php-cgi-query-string-parameter-vulnerability","title":"PHP-CGI Query String Parameter Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2012-1823-php-cgi-query-string-parameter-vulnerability"},{"cve":"CVE-2019-11043","cvss":9.8,"slug":"cve-2019-11043-php-fastcgi-process-manager-fpm-buffer-overflow-vulnerability","title":"PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2019-11043-php-fastcgi-process-manager-fpm-buffer-overflow-vulnerability"},{"cve":"CVE-1999-0238","cvss":10,"slug":"cve-1999-0238-php-php-cgi-arbitrary-file-disclosure","title":"PHP php.cgi arbitrary file disclosure","severity":"critical","exploited":false,"published_at":"1997-08-01T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0238-php-php-cgi-arbitrary-file-disclosure"},{"cve":"CVE-2026-6722","cvss":9.8,"epss":0.0051,"slug":"cve-2026-6722-php-soap-extension-use-after-free-remote-code-execution","title":"PHP SOAP extension use-after-free remote code execution","severity":"critical","exploited":false,"published_at":"2026-05-10T05:16:11.07+00:00","url":"https://junglewise.ai/threats/cve-2026-6722-php-soap-extension-use-after-free-remote-code-execution"},{"cve":"CVE-2026-7261","cvss":9.8,"epss":0.003,"slug":"cve-2026-7261-php-soapserver-use-after-free-in-soap-persistence-session","title":"PHP SoapServer use-after-free in SOAP_PERSISTENCE_SESSION","severity":"critical","exploited":false,"published_at":"2026-05-10T05:16:11.64+00:00","url":"https://junglewise.ai/threats/cve-2026-7261-php-soapserver-use-after-free-in-soap-persistence-session"},{"cve":"CVE-2025-14179","cvss":9.8,"epss":0.0026,"slug":"cve-2025-14179-php-pdo-firebird-sql-injection-via-nul-bytes-in-quoted-strings","title":"PHP PDO Firebird SQL injection via NUL bytes in quoted strings","severity":"critical","exploited":false,"published_at":"2026-05-10T05:16:09.853+00:00","url":"https://junglewise.ai/threats/cve-2025-14179-php-pdo-firebird-sql-injection-via-nul-bytes-in-quoted-strings"},{"cve":"CVE-2016-10160","cvss":9.8,"slug":"cve-2016-10160-php-off-by-one-error-in-phar-parse-pharfile","title":"PHP off-by-one error in phar_parse_pharfile","severity":"critical","exploited":false,"published_at":"2017-01-24T21:59:00.227+00:00","url":"https://junglewise.ai/threats/cve-2016-10160-php-off-by-one-error-in-phar-parse-pharfile"},{"cve":"CVE-2026-6104","cvss":9.1,"epss":0.0044,"slug":"cve-2026-6104-php-mbstring-out-of-bounds-read-in-mb-convert-encoding","title":"PHP mbstring out-of-bounds read in mb_convert_encoding","severity":"critical","exploited":false,"published_at":"2026-05-10T06:16:07.397+00:00","url":"https://junglewise.ai/threats/cve-2026-6104-php-mbstring-out-of-bounds-read-in-mb-convert-encoding"},{"cve":"CVE-2026-7262","cvss":7.5,"epss":0.0045,"slug":"cve-2026-7262-php-soap-extension-null-pointer-dereference-in-apache-map-decoder","title":"PHP SOAP extension NULL pointer dereference in apache:Map decoder","severity":"high","exploited":false,"published_at":"2026-05-10T05:16:11.78+00:00","url":"https://junglewise.ai/threats/cve-2026-7262-php-soap-extension-null-pointer-dereference-in-apache-map-decoder"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}