PHP
Vulnerabilities in PHP applications and the language runtime.
Published work on this topic
| 2026-08-27 | CVE-2026-77998 | CVE-2026-77998: miniOrange SAML - Joomla Auth Bypass | PoC | |
| 2026-08-24 | CVE-2026-77647 | CVE-2026-77647: SPIP Pre-Auth RCE | PoC | |
| 2026-08-20 | CVE-2026-18051 | CVE-2026-18051: W3 Total Cache - Arbitrary File Write | PoC | |
| 2026-08-20 | CVE-2026-18366 | CVE-2026-18366: Events Manager - Privilege Escalation | PoC | |
| 2026-08-17 | CVE-2026-28185 | CVE-2026-28185: Login with Google Auth Bypass | PoC | |
| 2026-08-13 | CVE-2026-67282 | CVE-2026-67282: Fabrik Unauthenticated RCE | PoC | |
| 2026-08-11 | CVE-2026-66915 | CVE-2026-66915: Fabrik Calc Element RCE | PoC | |
| 2026-08-10 | CVE-2026-13001 | CVE-2026-13001: Podlove Podcast Publisher RCE | PoC | |
| 2026-08-08 | CVE-2026-14364 | CVE-2026-14364: TrueBooker Auth Bypass | PoC | |
| 2026-07-31 | CVE-2026-18363 | CVE-2026-18363: osTicket Auth Bypass | PoC |
Other topics
remote code execution25authentication bypass16authorization bypass9wordpress8java7privilege escalation7heap overflow6sql injection6code injection5denial of service5qemu5apache tomcat4go4information disclosure4path traversal4cross-site scripting4buffer overflow3javascript3joomla3node.js3python3stored xss3
