Exposure of PHP

Programming languages
934
exposure score
4,350,128
sites use
2
exploited
49
critical
Vexday analysis

Com 1.079 CVEs catalogadas e 74 surgidas apenas nos últimos 90 dias, o PHP apresenta um volume de vulnerabilidades que exige monitoramento contínuo. A taxa de exploração ativa — 2 entradas no catálogo KEV, equivalente a 0,19% do total — está abaixo da média geral do catálogo (0,45%), o que não elimina o risco, mas indica que a conversão de vulnerabilidades em exploração confirmada tem sido relativamente contida. Atenção especial merece a CVE-2024-4577, atualmente a falha mais perigosa em exploração ativa, com EPSS de 0,9999 — valor que sinaliza probabilidade altíssima de exploração —, reforçando a necessidade de aplicação imediata de correções em ambientes expostos. O tipo de falha mais recorrente, CWE-89 (injeção de SQL), combinado com 43 vulnerabilidades críticas no histórico, indica que revisão de práticas de codificação segura e atualização de versões continuam sendo controles prioritários para quem opera aplicações baseadas em PHP.

CVEs

1,167 results
CVE-2025-5558MEDIUMPHPGurukul Teacher Subject Allocation Management System changeimage.php sql injectionEPSS 0.4%CVE-2026-2088MEDIUMPHPGurukul Beauty Parlour Management System accepted-appointment.php sql injectionEPSS 0.4%CVE-2025-6911MEDIUMPHPGurukul Student Record System manage-subjects.php sql injectionEPSS 0.4%CVE-2024-5361MEDIUMPHPGurukul Zoo Management System normal-bwdates-reports-details.php sql injectionEPSS 0.4%CVE-2025-6908MEDIUMPHPGurukul Old Age Home Management System edit-services.php sql injectionEPSS 0.4%CVE-2026-40902HIGHPhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row DimensionsEPSS 0.4%CVE-2026-40863HIGHPhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML ReaderEPSS 0.4%CVE-2025-11112MEDIUMPHPGurukul Employee Record Management System myprofile.php cross site scriptingEPSS 0.4%CVE-2026-46639HIGHTwig: Sandbox property and method bypass via object-destructuring assignmentEPSS 0.4%CVE-2023-3474LOWSimplePHPscripts Simple Blog URL Parameter preview.php cross site scriptingEPSS 0.4%CVE-2023-3476LOWSimplePHPscripts GuestBook Script URL Parameter preview.php cross site scriptingEPSS 0.4%CVE-2026-0733MEDIUMPHPGurukul Online Course Registration System manage-students.php sql injectionEPSS 0.4%CVE-2024-10414MEDIUMPHPGurukul Vehicle Record System edit-brand.php cross site scriptingEPSS 0.4%CVE-2022-40295Authenticated sensitive information disclosure in PHP Point of Sale version 19.0, by PHP Point of Sale, LLC.EPSS 0.4%CVE-2025-2607MEDIUMphplaozhang LzCMS-LaoZhangBoKeXiTong HTTP POST Request upimage.html unrestricted uploadEPSS 0.4%CVE-2026-77337CRITICALCakePHP: Potential Authentication bypass with CookieAuthenticatorEPSS 0.4%CVE-2024-10768MEDIUMPHPGurukul Online Shopping Portal two_tables.php cross site scriptingEPSS 0.4%CVE-2024-10192MEDIUMPHPGurukul IFSC Code Finder Project search.php cross site scriptingEPSS 0.4%CVE-2024-10753MEDIUMPHPGurukul Online Shopping Portal dom_data_two_headers.php cross site scriptingEPSS 0.4%CVE-2025-15390MEDIUMPHPGurukul Small CRM edit-user.php authorizationEPSS 0.4%