Prestashop 8.1.6
138 vulnérabilités ont été trouvés
3 paquets abandonnés ont été trouvés
Dernière analyse : il y a 19 heures
Vulnérabilités
Paquets concernés : 14
- Critique 6
- Haute 40
- Moyenne 50
- Basse 10
- Non classée 6
-
Composer
95
-
Prestashop/prestashop
5
-
Php
38
Composer
Vulnérabilités
- Critique 2
- Haute 26
- Moyenne 36
- Basse 5
- Non classée 0
-
Haute CVE-2025-31481 Signalée 04/04/2025GraphQL query operations security can be bypassed
- Versions affectées
<4.0.22- Versions patchées
4.0.224.0.22
-
Haute CVE-2025-31485 Signalée 04/04/2025GraphQL grant on a property might be cached with different objects
- Versions affectées
<4.0.22- Versions patchées
4.0.224.0.22
-
Moyenne CVE-2026-49858 Signalée 10/07/2026API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate
- Versions affectées
>=4.3.0,<4.3.8|>=4.2.0,<4.2.25|>=2.6.0,<4.1.29- Versions patchées
4.1.294.2.254.3.84.1.294.2.254.3.84.1.294.2.254.3.8
-
Moyenne CVE-2026-54164 Signalée 07/08/2026API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)
- Versions affectées
>=4.3.0,<4.3.12|>=4.2.0,<4.2.26|<4.1.30- Versions patchées
4.1.304.2.264.3.12
-
Haute CVE-2026-69246 Signalée 03/08/2026Guzzle: Noncanonical host can bypass host-based checks
- Versions affectées
>=8.0.0,<8.0.1|<7.15.2- Versions patchées
7.15.28.0.1
-
Moyenne CVE-2026-55767 Signalée 18/06/2026Dot-only cookie domains match all hosts
- Versions affectées
<7.12.1- Versions patchées
7.12.1
https://github.com/guzzle/guzzle/security/advisories/GHSA-cwxw-98qj-8qjx
-
Moyenne Signalée 20/07/2026Guzzle: Unbounded response cookies risk denial of service
- Versions affectées
<7.15.1- Versions patchées
7.15.1
-
Moyenne CVE-2026-59883 Signalée 20/07/2026Guzzle: Cookie Disclosure and Injection via IP-Address Domains
- Versions affectées
<7.12.3- Versions patchées
7.12.3
-
Moyenne CVE-2026-69245 Signalée 03/08/2026Guzzle: Noncanonical cookie domain keeps subdomain scope
- Versions affectées
>=8.0.0,<8.0.1|<7.15.2- Versions patchées
7.15.28.0.1
-
Moyenne Signalée 20/07/2026Guzzle: URI fragments disclosed in redirect Referer headers
- Versions affectées
<7.15.1- Versions patchées
7.15.1
-
Moyenne CVE-2026-55568 Signalée 18/06/2026Silent HTTPS proxy downgrade to cleartext
- Versions affectées
<7.12.1- Versions patchées
7.12.1
https://github.com/guzzle/guzzle/security/advisories/GHSA-wpwq-4j6v-78m3
-
Moyenne Signalée 20/07/2026Guzzle: Proxy-Authorization headers can be sent to origin servers
- Versions affectées
<7.14.2- Versions patchées
7.14.2
-
Moyenne Signalée 20/07/2026Guzzle: Host-only cookie scope is not preserved
- Versions affectées
<7.15.1- Versions patchées
7.15.1
-
Moyenne CVE-2026-55766 Signalée 18/06/2026CRLF injection in HTTP start-line serialization
- Versions affectées
<2.12.1- Versions patchées
2.12.1
https://github.com/guzzle/psr7/security/advisories/GHSA-vm85-hxw5-5432
-
Moyenne CVE-2026-49214 Signalée 11/06/2026guzzlehttp/psr7 has CRLF Injection via URI Host Component
- Versions affectées
<2.10.2- Versions patchées
2.10.2
-
Moyenne CVE-2026-48998 Signalée 11/06/2026guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation
- Versions affectées
<2.10.2- Versions patchées
2.10.2
-
Moyenne CVE-2026-59882 Signalée 21/07/2026guzzlehttp/psr7: Host Confusion via Weak URI Host Validation
- Versions affectées
<2.12.3- Versions patchées
2.12.3
-
Haute CVE-2023-37260 Signalée 06/07/2023league/oauth2-server key exposed in exception message when passing as a string and providing an invalid pass phrase
- Versions affectées
>=8.5.0,<8.5.3|>=8.3.2,<8.4.2- Versions patchées
8.4.28.5.3
-
Critique CVE-2026-45034 Signalée 08/06/2026PHPSpreadsheet has a patch bypass for CVE-2026-34084
- Versions affectées
<=1.30.4- Versions patchées
1.30.5
-
Haute CVE-2024-56366 Signalée 03/01/2025PhpSpreadsheet allows unauthorized Reflected XSS in the Accounting.php file
- Versions affectées
>=2.2.0,<=2.3.4|>=2.0.0,<=2.1.5|<=1.29.6|>=3.0.0,<3.7.0- Versions patchées
3.7.01.29.72.1.62.3.5
-
Haute CVE-2025-54370 Signalée 25/08/2025PhpSpreadsheet vulnerable to SSRF when reading and displaying a processed HTML document in the browser
- Versions affectées
>=4.0.0,<5.0.0|>=3.0.0,<3.10.0|>=2.2.0,<2.4.0|>=2.0.0,<2.1.12|<1.30.0- Versions patchées
1.30.02.1.122.4.03.10.05.0.0
-
Haute CVE-2026-34084 Signalée 29/04/2026PhpSpreadsheet has SSRF/RCE in IOFactory::load when $filename is user controlled
- Versions affectées
<=1.30.2|>=2.0.0,<=2.1.14|>=2.2.0,<=2.4.3|>=3.3.0,<=3.10.3|>=4.0.0,<=5.5.0- Versions patchées
5.6.03.10.42.4.42.1.151.30.3
-
Haute CVE-2024-56408 Signalée 03/01/2025PhpSpreadsheet allows unauthorized Reflected XSS in `Convert-Online.php` file
- Versions affectées
>=2.2.0,<=2.3.4|>=2.0.0,<=2.1.5|<=1.29.6|>=3.0.0,<3.7.0- Versions patchées
3.7.01.29.72.1.62.3.5
-
Haute CVE-2024-47873 Signalée 18/11/2024XmlScanner bypass leads to XXE
- Versions affectées
>=3.3.0,<3.4.0|>=2.2.0,<2.3.2|>=2.0.0,<2.1.3|<1.29.4- Versions patchées
1.29.42.1.32.3.23.4.0
-
Haute CVE-2026-59931 Signalée 23/07/2026PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist
- Versions affectées
<=1.30.5|>=2.0.0,<=2.1.17|>=2.2.0,<=2.4.6|>=3.3.0,<=3.10.6|>=4.0.0,<=5.8.0- Versions patchées
5.8.13.10.72.4.72.1.181.30.6
-
Haute CVE-2024-48917 Signalée 18/11/2024XXE in PHPSpreadsheet's XLSX reader
- Versions affectées
>=3.3.0,<3.4.0|>=2.2.0,<2.3.2|>=2.0.0,<2.1.3|<1.29.4- Versions patchées
1.29.42.1.32.3.23.4.0
-
Haute CVE-2026-40902 Signalée 29/04/2026PhpSpreadsheet has CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions
- Versions affectées
<=1.30.3|>=2.0.0,<=2.1.15|>=2.2.0,<=2.4.4|>=3.3.0,<=3.10.4|>=4.0.0,<=5.6.0- Versions patchées
5.7.03.10.52.4.52.1.161.30.4
-
Haute CVE-2024-56365 Signalée 03/01/2025PhpSpreadsheet allows unauthorized Reflected XSS in the constructor of the Downloader class
- Versions affectées
>=2.2.0,<=2.3.4|>=2.0.0,<=2.1.5|<=1.29.6|>=3.0.0,<3.7.0- Versions patchées
3.7.01.29.72.1.62.3.5
-
Haute CVE-2026-59932 Signalée 23/07/2026PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion
- Versions affectées
<=1.30.5|>=2.0.0,<=2.1.17|>=2.2.0,<=2.4.6|>=3.3.0,<=3.10.6|>=4.0.0,<=5.8.0- Versions patchées
5.8.13.10.72.4.72.1.181.30.6
-
Haute CVE-2024-45293 Signalée 07/10/2024XXE in PHPSpreadsheet's XLSX reader
- Versions affectées
>=2.0.0,<2.1.1|<1.29.1|>=2.2.0,<2.3.0- Versions patchées
2.3.01.29.12.1.1
-
Haute CVE-2026-59933 Signalée 23/07/2026PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion
- Versions affectées
<=1.30.5|>=2.0.0,<=2.1.17|>=2.2.0,<=2.4.6|>=3.3.0,<=3.10.6|>=4.0.0,<=5.8.0- Versions patchées
5.8.13.10.72.4.72.1.181.30.6
-
Haute CVE-2026-40863 Signalée 29/04/2026PhpSpreadsheet has CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader
- Versions affectées
<=1.30.3|>=2.0.0,<=2.1.15|>=2.2.0,<=2.4.4|>=3.3.0,<=3.10.4|>=4.0.0,<=5.6.0- Versions patchées
5.7.03.10.52.4.52.1.161.30.4
-
Haute CVE-2024-45290 Signalée 07/10/2024PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery when opening XLSX file
- Versions affectées
>=2.0.0,<2.1.1|<1.29.2|>=2.2.0,<2.3.0- Versions patchées
2.3.01.29.22.1.1
-
Haute CVE-2024-45048 Signalée 29/08/2024XXE in PHPSpreadsheet encoding is returned
- Versions affectées
<2.2.1- Versions patchées
2.2.1
-
Haute CVE-2024-56409 Signalée 03/01/2025PhpSpreadsheet allows unauthorized Reflected XSS in Currency.php file
- Versions affectées
>=2.2.0,<=2.3.4|>=2.0.0,<=2.1.5|<=1.29.6|>=3.0.0,<3.7.0- Versions patchées
3.7.01.29.72.1.62.3.5
-
Moyenne CVE-2024-56410 Signalée 03/01/2025PhpSpreadsheet has a Cross-Site Scripting (XSS) vulnerability in custom properties
- Versions affectées
>=2.2.0,<=2.3.4|>=2.0.0,<=2.1.5|<=1.29.6|>=3.0.0,<3.7.0- Versions patchées
3.7.01.29.72.1.62.3.5
-
Moyenne CVE-2024-45291 Signalée 07/10/2024PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled
- Versions affectées
>=2.0.0,<2.1.1|<1.29.2|>=2.2.0,<2.3.0- Versions patchées
2.3.01.29.22.1.1
-
Moyenne CVE-2024-56412 Signalée 03/01/2025PhpSpreadsheet allows bypass XSS sanitizer using the javascript protocol and special characters
- Versions affectées
>=2.2.0,<=2.3.4|>=2.0.0,<=2.1.5|<=1.29.6|>=3.0.0,<3.7.0- Versions patchées
3.7.01.29.72.1.62.3.5
-
Moyenne CVE-2025-23210 Signalée 03/02/2025PhpSpreadsheet allows bypassing of XSS sanitizer using the javascript protocol and special characters
- Versions affectées
>=2.0.0,<2.1.8|>=2.2.0,<2.3.7|<1.29.9|>=3.0.0,<3.9.0- Versions patchées
3.9.01.29.92.3.72.1.8
-
Moyenne CVE-2024-45060 Signalée 07/10/2024PhpSpreadsheet has an Unauthenticated Cross-Site-Scripting (XSS) in sample file
- Versions affectées
>=2.0.0,<2.1.1|<1.29.2|>=2.2.0,<2.3.0- Versions patchées
2.3.01.29.22.1.1
-
Moyenne CVE-2026-40296 Signalée 28/04/2026PhpSpreadsheet has XSS via number format code with @ text placeholder bypasses htmlspecialchars in HTML writer
- Versions affectées
<=1.30.3|>=2.0.0,<=2.1.15|>=2.2.0,<=2.4.4|>=3.3.0,<=3.10.4|>=4.0.0,<=5.6.0- Versions patchées
5.7.03.10.52.4.52.1.161.30.4
-
Moyenne CVE-2026-35453 Signalée 28/04/2026PhpSpreadsheet has XSS via NumberFormat @ Text Substitution in HTML Writer
- Versions affectées
<=1.30.3|>=2.0.0,<=2.1.15|>=2.2.0,<=2.4.4|>=3.3.0,<=3.10.4|>=4.0.0,<=5.6.0- Versions patchées
5.7.03.10.52.4.52.1.161.30.4
-
Moyenne CVE-2024-45046 Signalée 29/08/2024PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via style information
- Versions affectées
<2.1.0- Versions patchées
2.1.0
-
Moyenne CVE-2024-56411 Signalée 03/01/2025PhpSpreadsheet has a Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page header
- Versions affectées
>=2.2.0,<=2.3.4|>=2.0.0,<=2.1.5|<=1.29.6|>=3.0.0,<3.7.0- Versions patchées
3.7.01.29.72.1.62.3.5
-
Moyenne CVE-2024-45292 Signalée 07/10/2024PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinks
- Versions affectées
>=2.0.0,<2.1.1|<1.29.2|>=2.2.0,<2.3.0- Versions patchées
2.3.01.29.22.1.1
-
Moyenne CVE-2025-22131 Signalée 21/01/2025Cross-Site Scripting (XSS) vulnerability in generateNavigation() function in PhpSpreadsheet
- Versions affectées
>=2.2.0,<2.3.6|>=2.0.0,<2.1.7|<1.29.8|>=3.0.0,<3.8.0- Versions patchées
3.8.01.29.82.1.72.3.6
-
Moyenne CVE-2025-24027 Signalée 22/01/2025ps_contactinfo has a potential XSS due to usage of the nofilter tag in template
- Versions affectées
<=3.3.2- Versions patchées
3.3.3
-
Critique CVE-2026-54159 Signalée 10/07/2026prestashop/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE
- Versions affectées
>=3.0.0,<4.0.4- Versions patchées
4.0.4
-
Haute CVE-2024-35226 Signalée 29/05/2024Smarty vulnerable to PHP Code Injection by malicious attribute in extends-tag
- Versions affectées
>=3.0.0,<4.5.3|>=5.0.0,<5.1.1- Versions patchées
5.1.14.5.3
-
Moyenne CVE-2026-62993 Signalée 01/09/2026Smarty: SSRF via redirect bypass of trusted_uri using {fetch}
- Versions affectées
<4.5.7|>=5.0.0,<5.8.2- Versions patchées
5.8.24.5.7
-
Moyenne CVE-2026-62992 Signalée 07/08/2026Smarty: Symlink path traversal out of trusted directories
- Versions affectées
<4.5.7|>=5.0.0,<5.8.2- Versions patchées
5.8.24.5.7
-
Non classée CVE-2026-46644 Signalée 26/05/2026CVE-2026-46644: symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalence
- Versions affectées
>=1.17.1,<1.38.1
-
Haute CVE-2024-51736 Signalée 05/11/2024CVE-2024-51736: Command execution hijack on Windows with Process class
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.46|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.14|>=7.0.0,<7.1.0|>=7.1.0,<7.1.7- Versions patchées
5.4.466.4.147.1.75.4.466.4.147.1.7
-
Haute CVE-2025-64500 Signalée 12/11/2025CVE-2025-64500: Incorrect parsing of PATH_INFO can lead to limited authorization bypass
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.50|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.29|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.3.7- Versions patchées
5.4.506.4.297.3.75.4.506.4.297.3.7
-
Moyenne CVE-2026-24739 Signalée 28/01/2026Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on Windows
- Versions affectées
>=8.0,<8.0.5|>=7.4,<7.4.5|>=7.3,<7.3.11|>=6.4,<6.4.33|<5.4.51- Versions patchées
5.4.516.4.337.3.117.4.58.0.55.4.516.4.337.3.117.4.58.0.5
-
Moyenne CVE-2023-46734 Signalée 10/11/2023CVE-2023-46734: Potential XSS vulnerabilities in CodeExtension filters
- Versions affectées
>=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.4.0|>=2.4.0,<2.5.0|>=2.5.0,<2.6.0|>=2.6.0,<2.7.0|>=2.7.0,<2.8.0|>=2.8.0,<3.0.0|>=3.0.0,<3.1.0|>=3.1.0,<3.2.0|>=3.2.0,<3.3.0|>=3.3.0,<3.4.0|>=3.4.0,<4.0.0|>=4.0.0,<4.1.0|>=4.1.0,<4.2.0|>=4.2.0,<4.3.0|>=4.3.0,<4.4.0|>=4.4.0,<4.4.51|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.31|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.3.8- Versions patchées
4.4.515.4.316.3.84.4.515.4.316.3.8
-
Non classée CVE-2026-45077 Signalée 20/05/2026CVE-2026-45077: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Basse CVE-2024-50343 Signalée 30/08/2024CVE-2024-50343: Incorrect response from Validator when input ends with ` `
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.43|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.11|>=7.0.0,<7.1.0|>=7.1.0,<7.1.4- Versions patchées
5.4.436.4.117.1.45.4.436.4.117.1.4
-
Non classée CVE-2026-45073 Signalée 20/05/2026CVE-2026-45073: SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Non classée CVE-2026-45304 Signalée 20/05/2026CVE-2026-45304: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Non classée CVE-2026-45065 Signalée 20/05/2026CVE-2026-45065: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Non classée CVE-2026-45068 Signalée 20/05/2026CVE-2026-45068: Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Non classée CVE-2026-45071 Signalée 20/05/2026CVE-2026-45071: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Non classée CVE-2026-45305 Signalée 20/05/2026CVE-2026-45305: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Non classée CVE-2026-48784 Signalée 26/05/2026CVE-2026-48784: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.53|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.41|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.13|>=8.0.0,<8.0.13
-
Non classée CVE-2026-48489 Signalée 26/05/2026CVE-2026-48489: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.53|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.41|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.13|>=8.0.0,<8.0.13
-
Non classée CVE-2026-45070 Signalée 20/05/2026CVE-2026-45070: Email Header Injection via Non-Token Characters in Mime Parameter Names
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Basse CVE-2024-50345 Signalée 05/11/2024CVE-2024-50345: Open redirect via browser-sanitized URLs
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.46|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.14|>=7.0.0,<7.1.0|>=7.1.0,<7.1.7- Versions patchées
5.4.466.4.147.1.75.4.466.4.147.1.7
-
Basse CVE-2024-50342 Signalée 05/11/2024CVE-2024-50342: Internal address and port enumeration allowed by NoPrivateNetworkHttpClient
- Versions affectées
>=4.3.0,<4.4.0|>=4.4.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.46|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.14|>=7.0.0,<7.1.0|>=7.1.0,<7.1.7- Versions patchées
5.4.466.4.147.1.75.4.466.4.147.1.7
-
Non classée CVE-2026-45133 Signalée 20/05/2026CVE-2026-45133: YAML Parser Stack Exhaustion via Unbounded Recursion in Nested Blocks, Sequences, and Mappings
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Non classée CVE-2026-45063 Signalée 20/05/2026CVE-2026-45063: Identity Spoofing via Unanchored DN Regex in X509Authenticator
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Non classée CVE-2026-45067 Signalée 20/05/2026CVE-2026-45067: Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address
- Versions affectées
>=2.0.0,<3.0.0|>=3.0.0,<4.0.0|>=4.0.0,<5.0.0|>=5.0.0,<5.1.0|>=5.1.0,<5.2.0|>=5.2.0,<5.3.0|>=5.3.0,<5.4.0|>=5.4.0,<5.4.52|>=6.0.0,<6.1.0|>=6.1.0,<6.2.0|>=6.2.0,<6.3.0|>=6.3.0,<6.4.0|>=6.4.0,<6.4.40|>=7.0.0,<7.1.0|>=7.1.0,<7.2.0|>=7.2.0,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12
-
Haute CVE-2024-56521 Signalée 27/12/2024TCPDF missing certificate validation
- Versions affectées
<6.8.0- Versions patchées
6.8.0
-
Moyenne CVE-2024-51058 Signalée 26/11/2024TCPDF Local File Inclusion vulnerability
- Versions affectées
<=6.7.5- Versions patchées
6.7.6
-
Moyenne CVE-2024-32489 Signalée 15/04/2024TCPDF Cross-site Scripting vulnerability
- Versions affectées
<6.7.4- Versions patchées
6.7.4
-
Moyenne CVE-2024-22640 Signalée 19/04/2024TCPDF vulnerable to Regular Expression Denial of Service
- Versions affectées
<=6.7.4
-
Moyenne CVE-2024-56519 Signalée 27/12/2024TCPDF lacks SVG sanitization
- Versions affectées
<6.8.0- Versions patchées
6.8.0
-
Moyenne CVE-2024-56522 Signalée 27/12/2024TCPDF has incorrect comparison
- Versions affectées
<6.8.0- Versions patchées
6.8.0
-
Moyenne CVE-2024-56527 Signalée 27/12/2024TCPDF missing character escape on error messages
- Versions affectées
<6.8.0- Versions patchées
6.8.0
-
Haute CVE-2024-45411 Signalée 09/09/2024Twig has a possible sandbox bypass
- Versions affectées
>=3.0.0,<3.14.0|>=2.0.0,<2.16.1|>=1.0.0,<1.44.8- Versions patchées
1.44.82.16.13.14.0
-
Haute CVE-2026-49981 Signalée 01/07/2026Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
- Versions affectées
<=3.26.0- Versions patchées
3.27.0
-
Non classée CVE-2026-48806 Signalée 27/05/2026Sandbox `__toString()` policy bypass via dynamic mapping keys
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.27.0
https://symfony.com/blog/cve-2026-48806-sandbox-tostring-policy-bypass-via-dynamic-mapping-keys
-
Basse CVE-2024-51755 Signalée 06/11/2024Unguarded calls to __isset() and to array-accesses when the sandbox is enabled
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.11.2|>=3.12.0,<3.14.1- Versions patchées
3.11.23.14.1
-
Non classée CVE-2026-46638 Signalée 20/05/2026`{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.26.0
-
Non classée CVE-2026-47732 Signalée 20/05/2026Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.26.0
-
Non classée CVE-2026-48808 Signalée 27/05/2026Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.27.0
-
Non classée CVE-2026-48805 Signalée 27/05/2026Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.27.0
-
Non classée CVE-2026-46633 Signalée 20/05/2026PHP code injection via `{% use %}` template name
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.26.0
-
Non classée CVE-2026-46627 Signalée 20/05/2026Sandbox does not protect against resource exhaustion
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.26.0
-
Non classée CVE-2026-46635 Signalée 20/05/2026Sandbox property allowlist bypass via the `column` filter (array_column on objects)
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.26.0
-
Non classée CVE-2026-46628 Signalée 20/05/2026The `spaceless` filter implicitly marks its output as safe
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.26.0
-
Non classée CVE-2026-47730 Signalée 20/05/2026XSS in profiler HtmlDumper via unescaped template and profile names
- Versions affectées
>=3.0.0,<3.26.0
-
Non classée CVE-2026-48807 Signalée 27/05/2026Sandbox `__toString()` policy bypass via `Traversable` in `join`/`replace` and `in`/`not in` operators
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.27.0
-
Non classée CVE-2026-46636 Signalée 27/05/2026Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.27.0
-
Basse CVE-2024-51754 Signalée 06/11/2024Unguarded calls to __toString() when nesting an object into an array
- Versions affectées
>=1.0.0,<2.0.0|>=2.0.0,<3.0.0|>=3.0.0,<3.11.2|>=3.12.0,<3.14.1- Versions patchées
3.11.23.14.1
https://symfony.com/blog/unguarded-calls-to-__tostring-when-nesting-an-object-into-an-array
Prestashop/prestashop
Vulnérabilités
- Critique 0
- Haute 1
- Moyenne 3
- Basse 1
- Non classée 0
-
Haute CVE-2024-41651 Signalée 12/08/2024An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able to hijack network requests made by an admin user (who, by design, is allowed to change the code that is running on the server).
* [https://github.com/Fckroun/CVE-2024-41651/tree/main](https://github.com/Fckroun/CVE-2024-41651/tree/main)
-
Moyenne CVE-2026-25597 Signalée 06/02/2026PrestaShop is an open source e-commerce web application. Prior to 8.2.4 and 9.0.3, there is a time-based user enumeration vulnerability in the user authentication functionality of PrestaShop. This vulnerability allows an attacker to determine whether a customer account exists in the system by measuring response times. This vulnerability is fixed in 8.2.4 and 9.0.3.
* [https://github.com/PrestaShop/PrestaShop/releases/tag/8.2.4](https://github.com/PrestaShop/PrestaShop/releases/tag/8.2.4)
* [https://github.com/PrestaShop/PrestaShop/releases/tag/9.0.3](https://github.com/PrestaShop/PrestaShop/releases/tag/9.0.3)
* [https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-67v7-3g49-mxh2](https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-67v7-3g49-mxh2) -
Moyenne CVE-2026-33673 Signalée 26/03/2026PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 are vulnerable to stored Cross-Site Scripting (stored XSS) vulnerabilities in the BO. An attacker who can inject data into the database, via limited back-office access or a previously existing vulnerability, can exploit unprotected variables in back-office templates. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.
* [https://github.com/PrestaShop/PrestaShop/releases/tag/8.2.5](https://github.com/PrestaShop/PrestaShop/releases/tag/8.2.5)
* [https://github.com/PrestaShop/PrestaShop/releases/tag/9.1.0](https://github.com/PrestaShop/PrestaShop/releases/tag/9.1.0)
* [https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-35pf-37c6-jxjv](https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-35pf-37c6-jxjv) -
Moyenne CVE-2026-33674 Signalée 26/03/2026PrestaShop is an open source e-commerce web application. Versions prior to 8.2.5 and 9.1.0 improperly use the validation framework. Versions 8.2.5 and 9.1.0 contain a fix. No known workarounds are available.
* [https://github.com/PrestaShop/PrestaShop/releases/tag/8.2.5](https://github.com/PrestaShop/PrestaShop/releases/tag/8.2.5)
* [https://github.com/PrestaShop/PrestaShop/releases/tag/9.1.0](https://github.com/PrestaShop/PrestaShop/releases/tag/9.1.0)
* [https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-283w-xf3q-788v](https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-283w-xf3q-788v) -
Basse CVE-2025-51586 Signalée 08/09/2025An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.
* [https://github.com/PrestaShop/PrestaShop/releases/tag/8.2.1](https://github.com/PrestaShop/PrestaShop/releases/tag/8.2.1)
* [https://maxime-morel.github.io/advisories/2025/CVE-2025-51586.md](https://maxime-morel.github.io/advisories/2025/CVE-2025-51586.md)
* [https://prestashop.com/](https://prestashop.com/)
Php
Vulnérabilités
- Critique 4
- Haute 13
- Moyenne 11
- Basse 4
- Non classée 6
-
Critique CVE-2024-11236 Signalée 24/11/2024In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
* [https://github.com/php/php-src/security/advisories/GHSA-5hqh-c84r-qjcv](https://github.com/php/php-src/security/advisories/GHSA-5hqh-c84r-qjcv)
-
Critique CVE-2024-4577 Signalée 09/06/2024In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.
* [https://github.com/php/php-src/security/advisories/GHSA-3qgc-jrrr-25jv](https://github.com/php/php-src/security/advisories/GHSA-3qgc-jrrr-25jv)
* [https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html](https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html)
* [https://devco.re/blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability-en/](https://devco.re/blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability-en/)
* [https://arstechnica.com/security/2024/06/php-vulnerability-allows-attackers-to-run-malicious-code-on-windows-servers/](https://arstechnica.com/security/2024/06/php-vulnerability-allows-attackers-to-run-malicious-code-on-windows-servers/)
* [https://www.imperva.com/blog/imperva-protects-against-critical-php-vulnerability-cve-2024-4577/](https://www.imperva.com/blog/imperva-protects-against-critical-php-vulnerability-cve-2024-4577/)
* [https://github.com/11whoami99/CVE-2024-4577](https://github.com/11whoami99/CVE-2024-4577)
* [https://github.com/xcanwin/CVE-2024-4577-PHP-RCE](https://github.com/xcanwin/CVE-2024-4577-PHP-RCE)
* [https://github.com/rapid7/metasploit-framework/pull/19247](https://github.com/rapid7/metasploit-framework/pull/19247)
* [https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/](https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/)
* [https://github.com/watchtowrlabs/CVE-2024-4577](https://github.com/watchtowrlabs/CVE-2024-4577)
* [https://www.php.net/ChangeLog-8.php#8.1.29](https://www.php.net/ChangeLog-8.php#8.1.29)
* [https://www.php.net/ChangeLog-8.php#8.2.20](https://www.php.net/ChangeLog-8.php#8.2.20)
* [https://www.php.net/ChangeLog-8.php#8.3.8](https://www.php.net/ChangeLog-8.php#8.3.8)
* [https://cert.be/en/advisory/warning-php-remote-code-execution-patch-immediately](https://cert.be/en/advisory/warning-php-remote-code-execution-patch-immediately)
* [https://isc.sans.edu/diary/30994](https://isc.sans.edu/diary/30994)
* [http://www.openwall.com/lists/oss-security/2024/06/07/1](http://www.openwall.com/lists/oss-security/2024/06/07/1)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/)
* [https://security.netapp.com/advisory/ntap-20240621-0008/](https://security.netapp.com/advisory/ntap-20240621-0008/) -
Critique CVE-2025-1861 Signalée 30/03/2025In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when parsing HTTP redirect in the response to an HTTP request, there is currently limit on the location value size caused by limited size of the location buffer to 1024. However as per RFC9110, the limit is recommended to be 8000. This may lead to incorrect URL truncation and redirecting to a wrong location.
* [https://github.com/php/php-src/security/advisories/GHSA-52jp-hrpf-2jff](https://github.com/php/php-src/security/advisories/GHSA-52jp-hrpf-2jff)
* [https://security.netapp.com/advisory/ntap-20250523-0005/](https://security.netapp.com/advisory/ntap-20250523-0005/) -
Critique CVE-2026-6722 Signalée 10/05/2026In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in the temporary result map, freeing the original PHP object while its stale pointer remains in the map. A subsequent href reference to the freed node can copy the dangling pointer into the result. As PHP string allocations can reclaim the freed memory region, an attacker with control over the SOAP request body can exploit this use-after-free to achieve remote code execution.
* [https://github.com/php/php-src/security/advisories/GHSA-85c2-q967-79q5](https://github.com/php/php-src/security/advisories/GHSA-85c2-q967-79q5)
-
Haute CVE-2024-11233 Signalée 24/11/2024In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which can in certain circumstances lead to crashes or disclose content of other memory areas.
* [https://github.com/php/php-src/security/advisories/GHSA-r977-prxv-hc43](https://github.com/php/php-src/security/advisories/GHSA-r977-prxv-hc43)
-
Haute CVE-2024-11234 Signalée 24/11/2024In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option, the URI is not properly sanitized which can lead to HTTP request smuggling and allow the attacker to use the proxy to perform arbitrary HTTP requests originating from the server, thus potentially gaining access to resources not normally available to the external user.
* [https://github.com/php/php-src/security/advisories/GHSA-c5f2-jwm7-mmq2](https://github.com/php/php-src/security/advisories/GHSA-c5f2-jwm7-mmq2)
-
Haute CVE-2024-5585 Signalée 09/06/2024In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
* [https://github.com/php/php-src/security/advisories/GHSA-9fcc-425m-g385](https://github.com/php/php-src/security/advisories/GHSA-9fcc-425m-g385)
* [http://www.openwall.com/lists/oss-security/2024/06/07/1](http://www.openwall.com/lists/oss-security/2024/06/07/1)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/) -
Haute CVE-2024-8926 Signalée 08/10/2024In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using a certain non-standard configurations of Windows codepages, the fixes for CVE-2024-4577 https://github.com/advisories/GHSA-vxpp-6299-mxw3 may still be bypassed and the same command injection related to Windows "Best Fit" codepage behavior can be achieved. This may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.
* [https://github.com/php/php-src/security/advisories/GHSA-p99j-rfp4-xqvq](https://github.com/php/php-src/security/advisories/GHSA-p99j-rfp4-xqvq)
-
Haute CVE-2024-8927 Signalée 08/10/2024In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, HTTP_REDIRECT_STATUS variable is used to check whether or not CGI binary is being run by the HTTP server. However, in certain scenarios, the content of this variable can be controlled by the request submitter via HTTP headers, which can lead to cgi.force_redirect option not being correctly applied. In certain configurations this may lead to arbitrary file inclusion in PHP.
* [https://github.com/php/php-src/security/advisories/GHSA-94p6-54jq-9mwp](https://github.com/php/php-src/security/advisories/GHSA-94p6-54jq-9mwp)
-
Haute CVE-2025-14177 Signalée 27/12/2025In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, the getimagesize() function may leak uninitialized heap memory into the APPn segments (e.g., APP1) when reading images in multi-chunk mode (such as via php://filter). This occurs due to a bug in php_read_stream_all_chunks() that overwrites the buffer without advancing the pointer, leaving tail bytes uninitialized. This may lead to information disclosure of sensitive heap data and affect the confidentiality of the target server.
* [https://github.com/php/php-src/security/advisories/GHSA-3237-qqm7-mfv7](https://github.com/php/php-src/security/advisories/GHSA-3237-qqm7-mfv7)
-
Haute CVE-2025-14178 Signalée 27/12/2025In PHP versions:8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1, a heap buffer overflow occurs in array_merge() when the total element count of packed arrays exceeds 32-bit limits or HT_MAX_SIZE, due to an integer overflow in the precomputation of element counts using zend_hash_num_elements(). This may lead to memory corruption or crashes and affect the integrity and availability of the target server.
* [https://github.com/php/php-src/security/advisories/GHSA-h96m-rvf9-jgm2](https://github.com/php/php-src/security/advisories/GHSA-h96m-rvf9-jgm2)
-
Haute CVE-2025-14179 Signalée 10/05/2026In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and causing subsequent SQL tokens to be interpreted as part of the string. This allows SQL injection when attacker-controlled values are quoted via PDO::quote() and embedded in SQL statements.
* [https://github.com/php/php-src/security/advisories/GHSA-w476-322c-wpvm](https://github.com/php/php-src/security/advisories/GHSA-w476-322c-wpvm)
-
Haute CVE-2025-14180 Signalée 27/12/2025In PHP versions 8.1.* before 8.1.34, 8.2.* before 8.2.30, 8.3.* before 8.3.29, 8.4.* before 8.4.16, 8.5.* before 8.5.1 when using the PDO PostgreSQL driver with PDO::ATTR_EMULATE_PREPARES enabled, an invalid character sequence (such as \x99) in a prepared statement parameter may cause the quoting function PQescapeStringConn to return NULL, leading to a null pointer dereference in pdo_parse_params() function. This may lead to crashes (segmentation fault) and affect the availability of the target server.
* [https://github.com/php/php-src/security/advisories/GHSA-8xr5-qppj-gvwj](https://github.com/php/php-src/security/advisories/GHSA-8xr5-qppj-gvwj)
-
Haute CVE-2025-1735 Signalée 13/07/2025In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* pgsql and pdo_pgsql escaping functions do not check if the underlying quoting functions returned errors. This could cause crashes if Postgres server rejects the string as invalid.
* [https://github.com/php/php-src/security/advisories/GHSA-hrwm-9436-5mv3](https://github.com/php/php-src/security/advisories/GHSA-hrwm-9436-5mv3)
-
Haute CVE-2025-1736 Signalée 30/03/2025In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when user-supplied headers are sent, the insufficient validation of the end-of-line characters may prevent certain headers from being sent or lead to certain headers be misinterpreted.
* [https://github.com/php/php-src/security/advisories/GHSA-hgf5-96fm-v528](https://github.com/php/php-src/security/advisories/GHSA-hgf5-96fm-v528)
* [https://security.netapp.com/advisory/ntap-20250523-0006/](https://security.netapp.com/advisory/ntap-20250523-0006/) -
Haute CVE-2026-17543 Signalée 30/07/2026Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
* [https://github.com/php/php-src/security/advisories/GHSA-7qpv-r5mr-78m4](https://github.com/php/php-src/security/advisories/GHSA-7qpv-r5mr-78m4)
-
Haute CVE-2026-6735 Signalée 10/05/2026In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.
* [https://github.com/php/php-src/security/advisories/GHSA-7qg2-v9fj-4mwv](https://github.com/php/php-src/security/advisories/GHSA-7qg2-v9fj-4mwv)
-
Moyenne CVE-2024-2408 Signalée 09/06/2024The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: https://github.com/openssl/openssl/pull/13817 (rsa_pkcs1_implicit_rejection). These changes are part of OpenSSL 3.2 and have also been backported to stable versions of various Linux distributions, as well as to the PHP builds provided for Windows since the previous release. All distributors and builders should ensure that this version is used to prevent PHP from being vulnerable. PHP Windows builds for the versions 8.1.29, 8.2.20 and 8.3.8 and above include OpenSSL patches that fix the vulnerability.
* [https://github.com/php/php-src/security/advisories/GHSA-hh26-4ppw-5864](https://github.com/php/php-src/security/advisories/GHSA-hh26-4ppw-5864)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/) -
Moyenne CVE-2024-5458 Signalée 09/06/2024In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may lead to the downstream code accepting invalid URLs as valid and parsing them incorrectly.
* [https://github.com/php/php-src/security/advisories/GHSA-w8qr-v226-r27w](https://github.com/php/php-src/security/advisories/GHSA-w8qr-v226-r27w)
* [http://www.openwall.com/lists/oss-security/2024/06/07/1](http://www.openwall.com/lists/oss-security/2024/06/07/1)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/)
* [https://lists.debian.org/debian-lts-announce/2024/06/msg00009.html](https://lists.debian.org/debian-lts-announce/2024/06/msg00009.html) -
Moyenne CVE-2024-8925 Signalée 08/10/2024In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, erroneous parsing of multipart form data contained in an HTTP POST request could lead to legitimate data not being processed. This could lead to malicious attacker able to control part of the submitted data being able to exclude portion of other data, potentially leading to erroneous application behavior.
* [https://github.com/php/php-src/security/advisories/GHSA-9pqp-7h25-4f32](https://github.com/php/php-src/security/advisories/GHSA-9pqp-7h25-4f32)
-
Moyenne CVE-2025-1219 Signalée 30/03/2025In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when requesting a HTTP resource using the DOM or SimpleXML extensions, the wrong content-type header is used to determine the charset when the requested resource performs a redirect. This may cause the resulting document to be parsed incorrectly or bypass validations.
- Versions affectées
8.1.0|8.1.31,8.2.0|8.2.27,8.3.0|8.3.18,8.4.0|8.4.4
* [https://github.com/php/php-src/security/advisories/GHSA-p3x9-6h7p-cgfc](https://github.com/php/php-src/security/advisories/GHSA-p3x9-6h7p-cgfc)
* [https://github.com/php/php-src/security/advisories/GHSA-p3x9-6h7p-cgfc](https://github.com/php/php-src/security/advisories/GHSA-p3x9-6h7p-cgfc) -
Moyenne CVE-2025-1220 Signalée 13/07/2025In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 some functions like fsockopen() lack validation that the hostname supplied does not contain null characters. This may lead to other functions like parse_url() treat the hostname in different way, thus opening way to security problems if the user code implements access checks before access using such functions.
* [https://github.com/php/php-src/security/advisories/GHSA-3cr5-j632-f35r](https://github.com/php/php-src/security/advisories/GHSA-3cr5-j632-f35r)
* [https://github.com/php/php-src/security/advisories/GHSA-3cr5-j632-f35r](https://github.com/php/php-src/security/advisories/GHSA-3cr5-j632-f35r) -
Moyenne CVE-2025-1734 Signalée 30/03/2025In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when receiving headers from HTTP server, the headers missing a colon (:) are treated as valid headers even though they are not. This may confuse applications into accepting invalid headers.
* [https://github.com/php/php-src/security/advisories/GHSA-pcmh-g36c-qc44](https://github.com/php/php-src/security/advisories/GHSA-pcmh-g36c-qc44)
* [https://security.netapp.com/advisory/ntap-20250523-0009/](https://security.netapp.com/advisory/ntap-20250523-0009/) -
Moyenne CVE-2026-14355 Signalée 03/07/2026In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.
* [https://github.com/php/php-src/security/advisories/GHSA-7jrw-539f-x6vr](https://github.com/php/php-src/security/advisories/GHSA-7jrw-539f-x6vr)
* [https://lists.debian.org/debian-lts-announce/2026/07/msg00010.html](https://lists.debian.org/debian-lts-announce/2026/07/msg00010.html) -
Moyenne CVE-2026-7258 Signalée 10/05/2026In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On the systems with default signed char and optimized table-lookup ctype functions - such as NetBSD - this can lead to accessing array with negative offset, which can trigger a denial of service.
* [https://github.com/php/php-src/security/advisories/GHSA-m8rr-4c36-8gq4](https://github.com/php/php-src/security/advisories/GHSA-m8rr-4c36-8gq4)
-
Moyenne CVE-2026-7260 Signalée 30/07/2026Circular symbolic links in phar archives could lead to unbounded recursion, exhausting the C stack and crashing the PHP process, in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
* [https://github.com/php/php-src/security/advisories/GHSA-vc5h-9ppw-p5f3](https://github.com/php/php-src/security/advisories/GHSA-vc5h-9ppw-p5f3)
-
Moyenne CVE-2026-7261 Signalée 10/05/2026In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted across requests via session storage. However, in the case SOAP requests results in an error, the persistance is handled incorrectly, resulting in freeing the object while keeping a pointer to it, which may lead to use-after-free. This may lead to memory corruption, information disclosure, or process crashes, with confidentiality, integrity, and availability impact on the vulnerable system.
* [https://github.com/php/php-src/security/advisories/GHSA-m33r-qmcv-p97q](https://github.com/php/php-src/security/advisories/GHSA-m33r-qmcv-p97q)
-
Moyenne CVE-2026-7568 Signalée 10/05/2026In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the metaphone() function in ext/standard/metaphone.c uses a signed int variable to track the current position within the input string. If a string longer than 2,147,483,647 bytes is passed, a signed integer overflow occurs, resulting in undefined behavior. This can lead to an out-of-bounds read, causing a segmentation fault or access to unrelated memory, and may affect the availability of the PHP process.
* [https://github.com/php/php-src/security/advisories/GHSA-96wq-48vp-hh57](https://github.com/php/php-src/security/advisories/GHSA-96wq-48vp-hh57)
-
Basse CVE-2024-9026 Signalée 08/10/2024In PHP versions 8.1.* before 8.1.30, 8.2.* before 8.2.24, 8.3.* before 8.3.12, when using PHP-FPM SAPI and it is configured to catch workers output through catch_workers_output = yes, it may be possible to pollute the final log or remove up to 4 characters from the log messages by manipulating log message content. Additionally, if PHP-FPM is configured to use syslog output, it may be possible to further remove log data using the same vulnerability.
* [https://github.com/php/php-src/security/advisories/GHSA-865w-9rf3-2wh5](https://github.com/php/php-src/security/advisories/GHSA-865w-9rf3-2wh5)
-
Basse CVE-2025-1217 Signalée 29/03/2025In PHP from 8.1.* before 8.1.32, from 8.2.* before 8.2.28, from 8.3.* before 8.3.19, from 8.4.* before 8.4.5, when http request module parses HTTP response obtained from a server, folded headers are parsed incorrectly, which may lead to misinterpreting the response and using incorrect headers, MIME types, etc.
- Versions affectées
8.1.0|8.1.31,8.2.0|8.2.27,8.3.0|8.3.18,8.4.0|8.4.4
* [https://github.com/php/php-src/security/advisories/GHSA-v8xr-gpvj-cx9g](https://github.com/php/php-src/security/advisories/GHSA-v8xr-gpvj-cx9g)
* [https://github.com/php/php-src/security/advisories/GHSA-v8xr-gpvj-cx9g](https://github.com/php/php-src/security/advisories/GHSA-v8xr-gpvj-cx9g) -
Basse CVE-2026-7259 Signalée 10/05/2026In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to a NULL pointer dereference, resulting in a segmentation fault and denial of service. The vulnerability is exploitable when user-controlled input can influence the encoding passed to mb_regex_encoding().
* [https://github.com/php/php-src/security/advisories/GHSA-wm6j-2649-pv75](https://github.com/php/php-src/security/advisories/GHSA-wm6j-2649-pv75)
-
Basse CVE-2026-7262 Signalée 10/05/2026In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when a SOAP server has a typemap configured, the decoding process contains a mistake which checks the wrong variable in case of missing value element. This leads to dereferences a NULL pointer, causing a segmentation fault. This allows a remote unauthenticated attacker to crash the PHP SOAP server process, resulting in denial of service.
* [https://github.com/php/php-src/security/advisories/GHSA-hmxp-6pc4-f3vv](https://github.com/php/php-src/security/advisories/GHSA-hmxp-6pc4-f3vv)
-
Non classée CVE-2024-1874 Signalée 29/04/2024In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
* [http://www.openwall.com/lists/oss-security/2024/04/12/11](http://www.openwall.com/lists/oss-security/2024/04/12/11)
* [http://www.openwall.com/lists/oss-security/2024/04/12/11](http://www.openwall.com/lists/oss-security/2024/04/12/11)
* [http://www.openwall.com/lists/oss-security/2024/06/07/1](http://www.openwall.com/lists/oss-security/2024/06/07/1)
* [http://www.openwall.com/lists/oss-security/2024/06/07/1](http://www.openwall.com/lists/oss-security/2024/06/07/1)
* [https://github.com/php/php-src/security/advisories/GHSA-pc52-254m-w9w7](https://github.com/php/php-src/security/advisories/GHSA-pc52-254m-w9w7)
* [https://github.com/php/php-src/security/advisories/GHSA-pc52-254m-w9w7](https://github.com/php/php-src/security/advisories/GHSA-pc52-254m-w9w7)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/)
* [https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/)
* [https://security.netapp.com/advisory/ntap-20240510-0009/](https://security.netapp.com/advisory/ntap-20240510-0009/)
* [https://security.netapp.com/advisory/ntap-20240510-0009/](https://security.netapp.com/advisory/ntap-20240510-0009/)
* [https://www.vicarius.io/vsociety/posts/command-injection-vulnerability-in-php-on-windows-systems-cve-2024-1874-and-cve-2024-5585](https://www.vicarius.io/vsociety/posts/command-injection-vulnerability-in-php-on-windows-systems-cve-2024-1874-and-cve-2024-5585) -
Non classée CVE-2024-3096 Signalée 29/04/2024In PHP version 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, if a password stored with password_hash() starts with a null byte (\x00), testing a blank string as the password via password_verify() will incorrectly return true.
* [http://www.openwall.com/lists/oss-security/2024/04/12/11](http://www.openwall.com/lists/oss-security/2024/04/12/11)
* [http://www.openwall.com/lists/oss-security/2024/04/12/11](http://www.openwall.com/lists/oss-security/2024/04/12/11)
* [https://github.com/php/php-src/security/advisories/GHSA-h746-cjrr-wfmr](https://github.com/php/php-src/security/advisories/GHSA-h746-cjrr-wfmr)
* [https://github.com/php/php-src/security/advisories/GHSA-h746-cjrr-wfmr](https://github.com/php/php-src/security/advisories/GHSA-h746-cjrr-wfmr)
* [https://lists.debian.org/debian-lts-announce/2024/05/msg00005.html](https://lists.debian.org/debian-lts-announce/2024/05/msg00005.html)
* [https://lists.debian.org/debian-lts-announce/2024/05/msg00005.html](https://lists.debian.org/debian-lts-announce/2024/05/msg00005.html)
* [https://security.netapp.com/advisory/ntap-20240510-0010/](https://security.netapp.com/advisory/ntap-20240510-0010/)
* [https://security.netapp.com/advisory/ntap-20240510-0010/](https://security.netapp.com/advisory/ntap-20240510-0010/) -
Non classée CVE-2024-3566 Signalée 10/04/2024A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied.
* [https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/](https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/)
* [https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/](https://flatt.tech/research/posts/batbadbut-you-cant-securely-execute-commands-on-windows/)
* [https://kb.cert.org/vuls/id/123335](https://kb.cert.org/vuls/id/123335)
* [https://kb.cert.org/vuls/id/123335](https://kb.cert.org/vuls/id/123335)
* [https://learn.microsoft.com/en-us/archive/blogs/twistylittlepassagesallalike/everyone-quotes-command-line-arguments-the-wrong-way](https://learn.microsoft.com/en-us/archive/blogs/twistylittlepassagesallalike/everyone-quotes-command-line-arguments-the-wrong-way)
* [https://learn.microsoft.com/en-us/archive/blogs/twistylittlepassagesallalike/everyone-quotes-command-line-arguments-the-wrong-way](https://learn.microsoft.com/en-us/archive/blogs/twistylittlepassagesallalike/everyone-quotes-command-line-arguments-the-wrong-way)
* [https://www.cve.org/CVERecord?id=CVE-2024-1874](https://www.cve.org/CVERecord?id=CVE-2024-1874)
* [https://www.cve.org/CVERecord?id=CVE-2024-1874](https://www.cve.org/CVERecord?id=CVE-2024-1874)
* [https://www.cve.org/CVERecord?id=CVE-2024-22423](https://www.cve.org/CVERecord?id=CVE-2024-22423)
* [https://www.cve.org/CVERecord?id=CVE-2024-22423](https://www.cve.org/CVERecord?id=CVE-2024-22423)
* [https://www.cve.org/CVERecord?id=CVE-2024-24576](https://www.cve.org/CVERecord?id=CVE-2024-24576)
* [https://www.cve.org/CVERecord?id=CVE-2024-24576](https://www.cve.org/CVERecord?id=CVE-2024-24576)
* [https://www.kb.cert.org/vuls/id/123335](https://www.kb.cert.org/vuls/id/123335)
* [https://www.kb.cert.org/vuls/id/123335](https://www.kb.cert.org/vuls/id/123335) -
Non classée CVE-2024-8929 Signalée 22/11/2024In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, a hostile MySQL server can cause the client to disclose the content of its heap containing data from other SQL requests and possible other data belonging to different users of the same server.
* [https://github.com/php/php-src/security/advisories/GHSA-h35g-vwh6-m678](https://github.com/php/php-src/security/advisories/GHSA-h35g-vwh6-m678)
* [https://security.netapp.com/advisory/ntap-20250110-0008/](https://security.netapp.com/advisory/ntap-20250110-0008/) -
Non classée CVE-2024-8932 Signalée 22/11/2024In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in an out-of-bounds write.
* [https://github.com/php/php-src/security/advisories/GHSA-g665-fm4p-vhff](https://github.com/php/php-src/security/advisories/GHSA-g665-fm4p-vhff)
* [https://security.netapp.com/advisory/ntap-20250110-0009/](https://security.netapp.com/advisory/ntap-20250110-0009/) -
Non classée CVE-2025-6491 Signalée 13/07/2025In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* before 8.3.23, 8.4.* before 8.4.10 when parsing XML data in SOAP extensions, overly large (>2Gb) XML namespace prefix may lead to null pointer dereference. This may lead to crashes and affect the availability of the target server.
* [https://github.com/php/php-src/security/advisories/GHSA-453j-q27h-5p8x](https://github.com/php/php-src/security/advisories/GHSA-453j-q27h-5p8x)
* [https://github.com/php/php-src/security/advisories/GHSA-453j-q27h-5p8x](https://github.com/php/php-src/security/advisories/GHSA-453j-q27h-5p8x)
Paquets abandonnés
à remplacer ou à surveiller
-
1 oct. 2026, 16:09+43 nouvelles138 au total
-
24 sept. 2026, 03:03−44 fermées95 au total
-
2 sept. 2026, 03:03+1 nouvelles139 au total
-
8 août 2026, 03:03+2 nouvelles138 au total
-
7 août 2026, 03:03+2 nouvelles136 au total
-
4 août 2026, 03:03+2 nouvelles134 au total
-
24 juil. 2026, 03:03+3 nouvelles132 au total
-
22 juil. 2026, 03:03+1 nouvelles129 au total
-
21 juil. 2026, 03:03+5 nouvelles128 au total
-
11 juil. 2026, 03:02+2 nouvelles123 au total
-
10 juil. 2026, 03:01+1 nouvelles121 au total
-
7 juil. 2026, 03:02+41 nouvelles120 au total
-
2 juil. 2026, 03:05+1 nouvelles79 au total
-
1 juil. 2026, 03:05−41 fermées78 au total
-
20 juin 2026, 03:02+3 nouvelles119 au total
-
13 juin 2026, 03:03+2 nouvelles116 au total
-
9 juin 2026, 03:02+1 nouvelles114 au total
-
28 mai 2026, 03:02+7 nouvelles113 au total
-
27 mai 2026, 03:03+1 nouvelles106 au total
-
21 mai 2026, 03:03+18 nouvelles105 au total
-
14 mai 2026, 03:03+8 nouvelles87 au total
-
1 mai 2026, 03:03+46 nouvelles +3 abandonnés79 au total
-
30 avr. 2026, 03:02−43 fermées −3 abandonnés33 au total
-
29 avr. 2026, 03:03+2 nouvelles76 au total
-
3 avr. 2026, 03:03+2 nouvelles74 au total
-
21 févr. 2026, 02:04+1 nouvelles72 au total
-
29 janv. 2026, 02:04+1 nouvelles71 au total
-
11 janv. 2026, 02:03+2 nouvelles70 au total
-
10 janv. 2026, 02:03+1 nouvelles68 au total
-
10 déc. 2025, 02:04+27 nouvelles67 au total
-
9 déc. 2025, 02:03−27 fermées40 au total
-
13 nov. 2025, 02:03+1 nouvelles67 au total
-
14 sept. 2025, 03:03+1 nouvelles66 au total
-
9 sept. 2025, 03:05+39 nouvelles +3 abandonnés65 au total
-
7 sept. 2025, 03:06−39 fermées −3 abandonnés26 au total
-
26 août 2025, 03:03+1 nouvelles65 au total
-
21 août 2025, 03:03+4 nouvelles64 au total
-
7 août 2025, 03:04+22 nouvelles60 au total
-
6 août 2025, 03:04−22 fermées38 au total
-
5 août 2025, 03:03+22 nouvelles60 au total
-
31 juil. 2025, 03:06−22 fermées38 au total
-
24 juil. 2025, 03:04+3 nouvelles60 au total
-
7 juil. 2025, 03:03+5 nouvelles57 au total
-
20 juin 2025, 03:01+2 nouvelles52 au total
-
19 juin 2025, 03:01+1 nouvelles50 au total
-
3 mai 2025, 03:01+1 nouvelles49 au total
-
17 avr. 2025, 03:01+1 nouvelles48 au total
-
5 avr. 2025, 03:02+2 nouvelles47 au total
-
28 févr. 2025, 02:01+45 nouvelles +3 abandonnés45 au total
-
21 févr. 2025, 03:32−45 fermées −3 abandonnés0 au total
-
4 févr. 2025, 02:02+1 nouvelles45 au total
-
23 janv. 2025, 02:02+1 nouvelles44 au total
-
22 janv. 2025, 02:02+1 nouvelles43 au total
-
4 janv. 2025, 02:02+7 nouvelles42 au total
-
28 déc. 2024, 02:02+4 nouvelles35 au total
-
28 nov. 2024, 02:01+3 nouvelles31 au total
-
27 nov. 2024, 02:02+1 nouvelles28 au total
-
19 nov. 2024, 02:01+2 nouvelles27 au total
-
9 nov. 2024, 02:02+6 nouvelles25 au total
-
7 nov. 2024, 02:25+6 nouvelles19 au total
-
8 oct. 2024, 03:25+5 nouvelles13 au total
-
10 sept. 2024, 03:25+1 nouvelles8 au total
-
30 août 2024, 03:25+2 nouvelles7 au total
-
24 juil. 2024, 03:27−5 fermées5 au total
-
12 juil. 2024, 08:52+5 nouvelles10 au total
-
30 mai 2024, 03:00+1 nouvelles5 au total
-
17 mai 2024, 11:06+2 nouvelles +2 abandonnés4 au total
Badges
[](https://audit.security.code-rhapsodie.fr/fr/project/018f85c8-261e-7b77-b73b-fcb17e7205d3)
[](https://audit.security.code-rhapsodie.fr/fr/project/018f85c8-261e-7b77-b73b-fcb17e7205d3)
[](https://audit.security.code-rhapsodie.fr/fr/project/018f85c8-261e-7b77-b73b-fcb17e7205d3)
[](https://audit.security.code-rhapsodie.fr/fr/project/018f85c8-261e-7b77-b73b-fcb17e7205d3)