LIVE · cybersecurity feed
Live wire
vendor

Php

10 CVEs published in the last four months and 3 stories. Exploited flaws first.

Critical6
High4
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2025-141799.8criticalphpIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Fir119d ago
CVE-2026-67229.8criticalphpIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP ext119d ago
CVE-2026-72619.8criticalphpIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapSer119d ago
CVE-2026-175439.8criticalphpImproper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP vers37d ago
CVE-2026-175449.8criticalphpAttacker-provided inputs to bccomp() could lead to an out-of-bounds write with stack and heap corruption in PHP ve37d ago
CVE-2026-61049.1criticalphpIn PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding name containing an embedded NUL byte i119d ago
CVE-2026-75687.5highphpIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphon119d ago
CVE-2026-72587.5highphpIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functio119d ago
CVE-2026-72637.5highphpIn PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, DOMNode::C14N() method may process the XML data incorre119d ago
CVE-2026-72627.5highphpIn PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP 119d ago

Filter the full tracker by Php

Our coverage of Php

CVE-2026-32475critical

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of unrestricted upload of a file with a dangerous type. "The flaw lives in the Forms module's File

CVE-2026-15748critical

Forminator WordPress Plugin Vulnerable to Remote Code Execution

A critical vulnerability in the Forminator WordPress plugin, used by over 600,000 sites, allows unauthenticated attackers to execute arbitrary code. This is achieved by exploiting a flaw that permits the upload of malicious PHP files. The vulnerability has a high severity rating.

CVE-2026-64638high

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,