slug: php

Explanation

PHPはサーバーサイドで動くプログラミング言語で、Webサイトの裏側を作るのに広く使われています。 WordPress、Laravel、Drupalなど、世界中の多くのサイトの土台になっています。 セキュリティ脆弱性の文脈では「インジェクション系」(攻撃文字列を実行させる) や「ファイルアップロードの不備」が典型的な弱点として知られています。
📌 Example
2017年のEquifax事件 (1.4億人の個人情報流出) は、Apache StrutsというJavaライブラリの脆弱性が原因でしたが、同様にPHPアプリケーションでも脆弱性が悪用された事例は多数あります。

🔖 Related tags

🛡 Vulnerabilities tagged with this 3,771

ID Title
CVE-2021-47979 Path Traversal in c (CVE-2021-47979)
CVE-2021-47981 Cross-Site Scripting (XSS) in csrf (CVE-2021-47981)
CVE-2021-47934 Cross-Site Scripting (XSS) in CVE-2021-47934 (CVE-2021-47934)
CVE-2021-47954 SQL Injection in sqli (CVE-2021-47954)
CVE-2021-47955 Cross-Site Scripting (XSS) in CVE-2021-47955 (CVE-2021-47955)
CVE-2021-47956 SQL Injection in sqli (CVE-2021-47956)
CVE-2020-37246 Vulnerability in path-traversal (CVE-2020-37246)
CVE-2020-37227 Unrestricted File Upload in CVE-2020-37227 (CVE-2020-37227)
CVE-2025-67031 Code Injection in CVE-2025-67031 (CVE-2025-67031)
CVE-2026-46367 Duplicate Advisory: phpMyFAQ: Stored XSS via Utils::parseUrl() in comment rendering
CVE-2026-46408 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id and uses it to enter t...
CVE-2026-46359 phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields
CVE-2026-46361 Cross-Site Scripting (XSS) in thorsten/phpmyfaq (CVE-2026-46361)
CVE-2026-46366 phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query
CVE-2026-45007 Vulnerability in thorsten/phpmyfaq (CVE-2026-45007)
CVE-2021-47964 Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated...
CVE-2021-47966 PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in...
CVE-2021-47967 Cross-Site Scripting (XSS) in c (CVE-2021-47967)
CVE-2021-47959 WordPress Plugin WPGraphQL 1.3.5 contains a denial of service vulnerability that allows...
CVE-2021-47958 SSRF (Server-Side Request Forgery) in CVE-2021-47958 (CVE-2021-47958)
CVE-2026-45619 Vulnerability in WWBN/AVideo (CVE-2026-45619)
CVE-2026-45610 Vulnerability in WWBN/AVideo (CVE-2026-45610)
CVE-2026-45580 Cross-Site Scripting (XSS) in WWBN/AVideo (CVE-2026-45580)
CVE-2026-45578 OS Command Injection in WWBN/AVideo (CVE-2026-45578)
CVE-2026-46491 Path Traversal in simplesamlphp/simplesamlphp-module-casserver (CVE-2026-46491)
CVE-2026-42155 Vulnerability in openmage/magento-lts (CVE-2026-42155)
CVE-2026-45062 Vulnerability in github.com/dunglas/frankenphp (CVE-2026-45062)
CVE-2026-6228 Privilege Escalation in wordpress (CVE-2026-6228)
CVE-2026-4094 The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to...
CVE-2026-6811 Vulnerability in CVE-2026-6811 (CVE-2026-6811)

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →