All 91 CVE vulnerabilities found in PHP, with AI-generated Chinese analysis, references, and POCs.
This page is a comprehensive vulnerability aggregation resource dedicated to the PHP open-source project, focusing on critical weaknesses, CVE entries, and associated security tags. It collects detailed records of security flaws ranging from remote code execution and cross-site scripting to type confusion and memory corruption issues, covering data from the project's inception through recent years to provide a longitudinal view of its security posture. Readers can use this resource to track vendor advisories and release notes from the PHP Group, understand the evolution and impact of specific weakness classes such as improper input validation or unsafe deserialization, and look up the detailed vulnerability history of various PHP versions to assess risk exposure. By centralizing this information, the page serves as a single point of reference for developers, security researchers, and system administrators seeking to audit their PHP deployments, identify legacy risks in older maintained branches, and stay informed about the remediation status of known issues without navigating disparate sources. The structured presentation allows for efficient correlation between specific CWE categories and actual incident reports, facilitating deeper analysis of attack vectors and mitigation strategies relevant to the PHP ecosystem.
Vendor: PHP
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2019-11034 | Heap over-read in PHP EXIF extension CWE-125 | 9.1 | - | 2019-04-18 |
All 91 known CVE vulnerabilities affecting PHP with full Chinese analysis, references, and POCs where available.