slug: php

Explanation

PHPはサーバーサイドで動くプログラミング言語で、Webサイトの裏側を作るのに広く使われています。 WordPress、Laravel、Drupalなど、世界中の多くのサイトの土台になっています。 セキュリティ脆弱性の文脈では「インジェクション系」(攻撃文字列を実行させる) や「ファイルアップロードの不備」が典型的な弱点として知られています。
📌 Example
2017年のEquifax事件 (1.4億人の個人情報流出) は、Apache StrutsというJavaライブラリの脆弱性が原因でしたが、同様にPHPアプリケーションでも脆弱性が悪用された事例は多数あります。

🔖 Related tags

🛡 Vulnerabilities tagged with this 3,748

ID Title
CVE-2026-53992 Cross-Site Scripting (XSS) in CVE-2026-53992 (CVE-2026-53992)
CVE-2026-15979 Path Traversal in wordpress (CVE-2026-15979)
CVE-2026-71294 Unsafe Deserialization in CVE-2026-71294 (CVE-2026-71294)
CVE-2026-71293 Information Disclosure in CVE-2026-71293 (CVE-2026-71293)
CVE-2026-71291 Bolt CMS renders content field values through Twig's full application-level Environment with no...
CVE-2026-71287 Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
CVE-2026-71292 SQL Injection in CVE-2026-71292 (CVE-2026-71292)
CVE-2026-71252 Vulnerability in CVE-2026-71252 (CVE-2026-71252)
CVE-2026-71251 Vulnerability in CVE-2026-71251 (CVE-2026-71251)
CVE-2026-18933 Unrestricted File Upload in wordpress (CVE-2026-18933)
CVE-2026-71245 SQL Injection in CVE-2026-71245 (CVE-2026-71245)
CVE-2026-71248 SQL Injection in sqli (CVE-2026-71248)
CVE-2026-71250 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71250)
CVE-2026-71249 Cross-Site Scripting (XSS) in CVE-2026-71249 (CVE-2026-71249)
CVE-2026-71236 Cross-Site Scripting (XSS) in CVE-2026-71236 (CVE-2026-71236)
CVE-2026-71233 Cross-Site Scripting (XSS) in laravel (CVE-2026-71233)
CVE-2026-71237 SQL Injection in sqli (CVE-2026-71237)
CVE-2026-71231 SQL Injection in sqli (CVE-2026-71231)
CVE-2026-71232 Code Injection in CVE-2026-71232 (CVE-2026-71232)
CVE-2026-7693 Command Injection in wordpress (CVE-2026-7693)
CVE-2026-7444 The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
CVE-2026-7520 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification...
CVE-2026-71207 SQL Injection in CVE-2026-71207 (CVE-2026-71207)
CVE-2026-70376 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-70376)
CVE-2026-6639 Vulnerability in wordpress (CVE-2026-6639)
CVE-2026-6627 The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to...
CVE-2026-6147 The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
CVE-2026-6020 Vulnerability in wordpress (CVE-2026-6020)
CVE-2026-54416 Unrestricted File Upload in CVE-2026-54416 (CVE-2026-54416)
CVE-2026-17532 Cross-Site Scripting (XSS) in wordpress (CVE-2026-17532)

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →