{"schema_version":1,"title":"PHP vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in PHP: 10 in the last 7 days and 10 in the last 90 days, 3 of them critical and 2 exploited in the wild. The most recent, CVE-2026-92842, was published on 25 September 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/php","json_url":"https://junglewise.ai/threats/vendors/php.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/php","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":2,"all_time":15,"critical":3,"exploited":2,"last_7_days":10,"last_30_days":10,"last_90_days":10,"last_365_days":10},"latest":[{"cve":"CVE-2026-92842","cvss":5.9,"slug":"cve-2026-92842-the-convert-base64-encode-convert-quoted-printable-encode-and","title":"PHP stream filter heap information leak with NUL bytes in line-break-chars","severity":"medium","exploited":false,"published_at":"2026-09-25T22:18:49.943+00:00","url":"https://junglewise.ai/threats/cve-2026-92842-the-convert-base64-encode-convert-quoted-printable-encode-and"},{"cve":"CVE-2026-91768","cvss":6.5,"slug":"cve-2026-91768-the-ipv6-branch-of-the-fastcgi-client-access-check-compares-only","title":"PHP FastCGI access control bypass in IPv6 address comparison","severity":"medium","exploited":false,"published_at":"2026-09-25T22:18:49.807+00:00","url":"https://junglewise.ai/threats/cve-2026-91768-the-ipv6-branch-of-the-fastcgi-client-access-check-compares-only"},{"cve":"CVE-2026-91769","cvss":4.3,"slug":"cve-2026-91769-php-s-openssl-stream-peer-verification-checks-the-certificate-s","title":"PHP OpenSSL stream peer verification certificate validation bypass","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:24.913+00:00","url":"https://junglewise.ai/threats/cve-2026-91769-php-s-openssl-stream-peer-verification-checks-the-certificate-s"},{"cve":"CVE-2026-91767","cvss":6.5,"slug":"cve-2026-91767-php-openssl-matches-wildcard-name-in-ext-openssl-xp-ssl-c","title":"PHP OpenSSL heap-buffer overflow in wildcard certificate name matching","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:24.793+00:00","url":"https://junglewise.ai/threats/cve-2026-91767-php-openssl-matches-wildcard-name-in-ext-openssl-xp-ssl-c"},{"cve":"CVE-2026-91766","cvss":5.9,"slug":"cve-2026-91766-when-the-http-stream-wrapper-follows-a-redirect-it-forwards-the","title":"PHP HTTP stream wrapper credential leak on cross-origin redirect","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:24.673+00:00","url":"https://junglewise.ai/threats/cve-2026-91766-when-the-http-stream-wrapper-follows-a-redirect-it-forwards-the"},{"cve":"CVE-2026-91765","cvss":7.5,"slug":"cve-2026-91765-cleanup-xml-node-in-the-soap-xml-parser-recurses-once-per-xml","title":"PHP SOAP XML parser unbounded recursion denial of service","severity":"high","exploited":false,"published_at":"2026-09-25T21:17:24.55+00:00","url":"https://junglewise.ai/threats/cve-2026-91765-cleanup-xml-node-in-the-soap-xml-parser-recurses-once-per-xml"},{"cve":"CVE-2026-6103","cvss":4.3,"slug":"cve-2026-6103-phar-tar-number-parses-the-octal-size-field-of-a-tar-header-into-a","title":"PHP Phar TAR integer overflow in size parsing","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:23.79+00:00","url":"https://junglewise.ai/threats/cve-2026-6103-phar-tar-number-parses-the-octal-size-field-of-a-tar-header-into-a"},{"cve":"CVE-2026-17545","slug":"cve-2026-17545-on-windows-php-s-filesystem-and-stream-apis-do-not-reject","title":"PHP filesystem and stream APIs reserved device name handling","severity":"info","exploited":false,"published_at":"2026-09-25T21:17:23.253+00:00","url":"https://junglewise.ai/threats/cve-2026-17545-on-windows-php-s-filesystem-and-stream-apis-do-not-reject"},{"cve":"CVE-2025-14181","cvss":6.5,"slug":"cve-2025-14181-the-soap-http-client-guards-its-response-buffer-growth-with-a","title":"PHP SOAP HTTP client heap buffer overflow in response parsing","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:19.84+00:00","url":"https://junglewise.ai/threats/cve-2025-14181-the-soap-http-client-guards-its-response-buffer-growth-with-a"},{"cve":"CVE-2026-93682","cvss":5.8,"slug":"cve-2026-93682-when-the-http-stream-wrapper-follows-a-redirect-and-the-response","title":"PHP HTTP stream wrapper out-of-bounds read in redirect handling","severity":"medium","exploited":false,"published_at":"2026-09-25T20:17:47.597+00:00","url":"https://junglewise.ai/threats/cve-2026-93682-when-the-http-stream-wrapper-follows-a-redirect-and-the-response"},{"cve":"CVE-2019-11043","cvss":9.8,"slug":"cve-2019-11043-php-fastcgi-process-manager-fpm-buffer-overflow-vulnerability","title":"PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2019-11043-php-fastcgi-process-manager-fpm-buffer-overflow-vulnerability"},{"cve":"CVE-2016-10033","cvss":3.1,"epss":0.9971,"slug":"cve-2016-10033-phpmailer-command-injection-in-mailsend-function","title":"Remote code execution in PHPMailer","severity":"critical","exploited":true,"published_at":"2020-03-05T22:09:17+00:00","url":"https://junglewise.ai/threats/cve-2016-10033-phpmailer-command-injection-in-mailsend-function"},{"cve":"CVE-2016-5873","cvss":9.8,"slug":"cve-2016-5873-php-pecl-http-buffer-overflow-in-url-parsing","title":"PHP pecl_http buffer overflow in URL parsing","severity":"critical","exploited":false,"published_at":"2017-01-23T21:59:01.813+00:00","url":"https://junglewise.ai/threats/cve-2016-5873-php-pecl-http-buffer-overflow-in-url-parsing"},{"cve":"CVE-1999-0068","cvss":7.5,"slug":"cve-1999-0068-php-mylog-script-arbitrary-file-disclosure","title":"PHP mylog script arbitrary file disclosure","severity":"high","exploited":false,"published_at":"1997-10-19T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0068-php-mylog-script-arbitrary-file-disclosure"},{"cve":"CVE-1999-0346","cvss":5,"slug":"cve-1999-0346-php-mlog-script-arbitrary-file-disclosure","title":"PHP mlog script arbitrary file disclosure","severity":"medium","exploited":false,"published_at":"1997-10-16T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0346-php-mlog-script-arbitrary-file-disclosure"}],"vendor":{"hub":true,"name":"PHP","slug":"php","homepage":"https://www.php.net/","description":"A group that maintains the PHP general-purpose scripting language.","url":"https://junglewise.ai/threats/vendors/php"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":10}],"most_severe":[{"cve":"CVE-2019-11043","cvss":9.8,"slug":"cve-2019-11043-php-fastcgi-process-manager-fpm-buffer-overflow-vulnerability","title":"PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability","severity":"critical","exploited":true,"published_at":"2022-03-25T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2019-11043-php-fastcgi-process-manager-fpm-buffer-overflow-vulnerability"},{"cve":"CVE-2016-10033","cvss":3.1,"epss":0.9971,"slug":"cve-2016-10033-phpmailer-command-injection-in-mailsend-function","title":"Remote code execution in PHPMailer","severity":"critical","exploited":true,"published_at":"2020-03-05T22:09:17+00:00","url":"https://junglewise.ai/threats/cve-2016-10033-phpmailer-command-injection-in-mailsend-function"},{"cve":"CVE-2016-5873","cvss":9.8,"slug":"cve-2016-5873-php-pecl-http-buffer-overflow-in-url-parsing","title":"PHP pecl_http buffer overflow in URL parsing","severity":"critical","exploited":false,"published_at":"2017-01-23T21:59:01.813+00:00","url":"https://junglewise.ai/threats/cve-2016-5873-php-pecl-http-buffer-overflow-in-url-parsing"},{"cve":"CVE-2026-91765","cvss":7.5,"slug":"cve-2026-91765-cleanup-xml-node-in-the-soap-xml-parser-recurses-once-per-xml","title":"PHP SOAP XML parser unbounded recursion denial of service","severity":"high","exploited":false,"published_at":"2026-09-25T21:17:24.55+00:00","url":"https://junglewise.ai/threats/cve-2026-91765-cleanup-xml-node-in-the-soap-xml-parser-recurses-once-per-xml"},{"cve":"CVE-1999-0068","cvss":7.5,"slug":"cve-1999-0068-php-mylog-script-arbitrary-file-disclosure","title":"PHP mylog script arbitrary file disclosure","severity":"high","exploited":false,"published_at":"1997-10-19T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0068-php-mylog-script-arbitrary-file-disclosure"},{"cve":"CVE-2026-91768","cvss":6.5,"slug":"cve-2026-91768-the-ipv6-branch-of-the-fastcgi-client-access-check-compares-only","title":"PHP FastCGI access control bypass in IPv6 address comparison","severity":"medium","exploited":false,"published_at":"2026-09-25T22:18:49.807+00:00","url":"https://junglewise.ai/threats/cve-2026-91768-the-ipv6-branch-of-the-fastcgi-client-access-check-compares-only"},{"cve":"CVE-2026-91767","cvss":6.5,"slug":"cve-2026-91767-php-openssl-matches-wildcard-name-in-ext-openssl-xp-ssl-c","title":"PHP OpenSSL heap-buffer overflow in wildcard certificate name matching","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:24.793+00:00","url":"https://junglewise.ai/threats/cve-2026-91767-php-openssl-matches-wildcard-name-in-ext-openssl-xp-ssl-c"},{"cve":"CVE-2025-14181","cvss":6.5,"slug":"cve-2025-14181-the-soap-http-client-guards-its-response-buffer-growth-with-a","title":"PHP SOAP HTTP client heap buffer overflow in response parsing","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:19.84+00:00","url":"https://junglewise.ai/threats/cve-2025-14181-the-soap-http-client-guards-its-response-buffer-growth-with-a"},{"cve":"CVE-2026-92842","cvss":5.9,"slug":"cve-2026-92842-the-convert-base64-encode-convert-quoted-printable-encode-and","title":"PHP stream filter heap information leak with NUL bytes in line-break-chars","severity":"medium","exploited":false,"published_at":"2026-09-25T22:18:49.943+00:00","url":"https://junglewise.ai/threats/cve-2026-92842-the-convert-base64-encode-convert-quoted-printable-encode-and"},{"cve":"CVE-2026-91766","cvss":5.9,"slug":"cve-2026-91766-when-the-http-stream-wrapper-follows-a-redirect-it-forwards-the","title":"PHP HTTP stream wrapper credential leak on cross-origin redirect","severity":"medium","exploited":false,"published_at":"2026-09-25T21:17:24.673+00:00","url":"https://junglewise.ai/threats/cve-2026-91766-when-the-http-stream-wrapper-follows-a-redirect-it-forwards-the"}],"generated_at":"2026-09-27T03:07:00.185062+00:00","technologies":[{"name":"Php","slug":"php-php","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/php-php"},{"name":"PHPMailer","slug":"phpmailer","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/phpmailer"}]}