slug: php

Explanation

PHPはサーバーサイドで動くプログラミング言語で、Webサイトの裏側を作るのに広く使われています。 WordPress、Laravel、Drupalなど、世界中の多くのサイトの土台になっています。 セキュリティ脆弱性の文脈では「インジェクション系」(攻撃文字列を実行させる) や「ファイルアップロードの不備」が典型的な弱点として知られています。
📌 Example
2017年のEquifax事件 (1.4億人の個人情報流出) は、Apache StrutsというJavaライブラリの脆弱性が原因でしたが、同様にPHPアプリケーションでも脆弱性が悪用された事例は多数あります。

🔖 Related tags

🛡 Vulnerabilities tagged with this 3,748

ID Title
CVE-2026-19064 Vulnerability in CVE-2026-19064 (CVE-2026-19064)
CVE-2026-19066 Vulnerability in c (CVE-2026-19066)
CVE-2026-11976 Vulnerability in CVE-2026-11976 (CVE-2026-11976)
CVE-2026-67434 OS Command Injection in squizlabs/php_codesniffer (CVE-2026-67434)
CVE-2026-71488 Vulnerability in league/commonmark (CVE-2026-71488)
CVE-2026-71478 Cross-Site Scripting (XSS) in league/commonmark (CVE-2026-71478)
CVE-2026-71434 Unrestricted File Upload in statamic/cms (CVE-2026-71434)
CVE-2026-65578 Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
CVE-2026-65579 Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
CVE-2026-65577 Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
CVE-2026-65576 Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
CVE-2026-65575 Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
CVE-2026-65581 Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
CVE-2026-65572 Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
CVE-2026-65573 Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
CVE-2026-65571 Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
CVE-2026-65574 Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
CVE-2026-65556 Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
CVE-2026-65552 Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
CVE-2026-65549 Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
CVE-2026-28139 Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
CVE-2026-19020 Vulnerability in sqli (CVE-2026-19020)
CVE-2026-19021 Vulnerability in sqli (CVE-2026-19021)
CVE-2026-18325 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
CVE-2026-16636 The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
CVE-2026-15991 The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
CVE-2026-18968 Cross-Site Scripting (XSS) in CVE-2026-18968 (CVE-2026-18968)
CVE-2026-18959 Path Traversal in path-traversal (CVE-2026-18959)
CVE-2026-18958 Vulnerability in sqli (CVE-2026-18958)
CVE-2026-18927 Vulnerability in CVE-2026-18927 (CVE-2026-18927)

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →