slug: php

解説

PHPはサーバーサイドで動くプログラミング言語で、Webサイトの裏側を作るのに広く使われています。 WordPress、Laravel、Drupalなど、世界中の多くのサイトの土台になっています。 セキュリティ脆弱性の文脈では「インジェクション系」(攻撃文字列を実行させる) や「ファイルアップロードの不備」が典型的な弱点として知られています。
📌 具体例
2017年のEquifax事件 (1.4億人の個人情報流出) は、Apache StrutsというJavaライブラリの脆弱性が原因でしたが、同様にPHPアプリケーションでも脆弱性が悪用された事例は多数あります。

🔖 関連タグ

🛡 このタグに関連する脆弱性 3,748

ID タイトル
CVE-2026-19064 CVE-2026-19064 の脆弱性 (CVE-2026-19064)
CVE-2026-19066 c の脆弱性 (CVE-2026-19066)
CVE-2026-11976 CVE-2026-11976 の脆弱性 (CVE-2026-11976)
CVE-2026-67434 squizlabs/php_codesniffer に OSコマンドインジェクション (CVE-2026-67434)
CVE-2026-71488 league/commonmark の脆弱性 (CVE-2026-71488)
CVE-2026-71478 league/commonmark に クロスサイトスクリプティング (CVE-2026-71478)
CVE-2026-71434 statamic/cms に 危険なファイルアップロード (CVE-2026-71434)
CVE-2026-65578 Unauthenticated PHP Object Injection in Agora <= 1.9 versions.
CVE-2026-65579 Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.
CVE-2026-65577 Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.
CVE-2026-65576 Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.
CVE-2026-65575 Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.
CVE-2026-65581 Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.
CVE-2026-65572 Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.
CVE-2026-65573 Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.
CVE-2026-65571 Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.
CVE-2026-65574 Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.
CVE-2026-65556 Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.
CVE-2026-65552 Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.
CVE-2026-65549 Author PHP Object Injection in Jeg Kit for Elementor <= 3.2.10 versions.
CVE-2026-28139 Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.
CVE-2026-19020 sqli の脆弱性 (CVE-2026-19020)
CVE-2026-19021 sqli の脆弱性 (CVE-2026-19021)
CVE-2026-18325 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is...
CVE-2026-16636 The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP...
CVE-2026-15991 The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
CVE-2026-18968 CVE-2026-18968 に クロスサイトスクリプティング (CVE-2026-18968)
CVE-2026-18959 path-traversal に パストラバーサル (CVE-2026-18959)
CVE-2026-18958 sqli の脆弱性 (CVE-2026-18958)
CVE-2026-18927 CVE-2026-18927 の脆弱性 (CVE-2026-18927)

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →