slug: php

Explanation

PHPはサーバーサイドで動くプログラミング言語で、Webサイトの裏側を作るのに広く使われています。 WordPress、Laravel、Drupalなど、世界中の多くのサイトの土台になっています。 セキュリティ脆弱性の文脈では「インジェクション系」(攻撃文字列を実行させる) や「ファイルアップロードの不備」が典型的な弱点として知られています。
📌 Example
2017年のEquifax事件 (1.4億人の個人情報流出) は、Apache StrutsというJavaライブラリの脆弱性が原因でしたが、同様にPHPアプリケーションでも脆弱性が悪用された事例は多数あります。

🔖 Related tags

🛡 Vulnerabilities tagged with this 3,765

ID Title
CVE-2026-1233 The Text to Speech for WP (AI Voices by Mementor) plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.9.8. This is due to the plugin containing...
CVE-2026-3445 The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass i...
CVE-2026-4896 The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu...
CVE-2026-34788 SQL Injection in sqli (CVE-2026-34788)
CVE-2026-34787 Vulnerability in csrf (CVE-2026-34787)
CVE-2026-34607 Path Traversal in path-traversal (CVE-2026-34607)
CVE-2026-5484 Vulnerability in CVE-2026-5484 (CVE-2026-5484)
CVE-2026-5472 Vulnerability in CVE-2026-5472 (CVE-2026-5472)
CVE-2026-26477 Vulnerability in dos (CVE-2026-26477)
CVE-2026-4350 The Perfmatters plugin for WordPress is vulnerable to arbitrary file deletion via path traversal in all versions up to, and including, 2.5.9.1. This is due to the `PMCS::action_handler()` method proce...
CVE-2026-30252 Cross-Site Scripting (XSS) in interzen (CVE-2026-30252)
CVE-2026-30251 Cross-Site Scripting (XSS) in interzen (CVE-2026-30251)
CVE-2026-34735 Unrestricted File Upload in CVE-2026-34735 (CVE-2026-34735)
CVE-2026-5368 Vulnerability in sqli (CVE-2026-5368)
CVE-2026-34598 Cross-Site Scripting (XSS) in yeswiki (CVE-2026-34598)
CVE-2026-26895 Vulnerability in enhancesoft (CVE-2026-26895)
CVE-2026-33691 Vulnerability in owasp (CVE-2026-33691)
CVE-2026-5344 Path Traversal in path-traversal (CVE-2026-5344)
CVE-2026-34973 Vulnerability in phpmyfaq (CVE-2026-34973)
CVE-2026-34974 Cross-Site Scripting (XSS) in privilege-escalation (CVE-2026-34974)
CVE-2026-34443 SSRF (Server-Side Request Forgery) in laravel (CVE-2026-34443)
CVE-2026-34442 Vulnerability in laravel (CVE-2026-34442)
CVE-2026-34733 Vulnerability in wwbn (CVE-2026-34733)
CVE-2026-34740 SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-34740)
CVE-2026-34739 Cross-Site Scripting (XSS) in wwbn (CVE-2026-34739)
CVE-2026-34737 Vulnerability in wwbn (CVE-2026-34737)
CVE-2026-34611 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34611)
CVE-2026-34613 Cross-Site Request Forgery (CSRF) in csrf (CVE-2026-34613)
CVE-2026-34732 Vulnerability in wwbn (CVE-2026-34732)
CVE-2026-34731 Vulnerability in wwbn (CVE-2026-34731)

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →