FAIL › dossier
php
VENDOR· dossier confidence 67%
PHP has a concerning history of critical security vulnerabilities, including remote code execution flaws, demonstrating a pattern of delayed patching and inadequate security practices. The vendor's track record raises significant concerns regarding the security of systems utilizing PHP.
PROFILE
CategoryProgramming Language/Runtime EnvironmentWhat they doPHP is a widely-used, open-source scripting language primarily used for web development. It powers over 75% of all websites worldwide.Founded1994
Websitehttps://www.php.net/ ↗
SECURITY POSTURE
PHP exhibits a history of critical security vulnerabilities, frequently involving remote code execution (RCE). Patching has been inconsistent, with vulnerabilities dating back to 2012 remaining unaddressed for extended periods.
Notable failures
- CVE-2024-4577: Patch bypass for 2012 command injection flaw
- CVE-2019-11043: Buffer overflow in FPM leading to RCE
- CVE-2012-1823: CGI query string handling flaw allowing RCE
- CVE-2016-10033: PHPMailer command injection vulnerability
- CVE-2026-6722: Use-after-free RCE in SOAP extension
- CVE-2025-14179: Command injection vulnerability
Patterns: Recurring RCE vulnerabilities; Delayed patching of critical vulnerabilities; Vulnerabilities in extensions (e.g., SOAP, PHPMailer)
FAILURE HISTORY · 20
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2024-06-12 | CVE-2024-4577 | critical | A patch bypass for a 2012 PHP-CGI command injection flaw allows remote code execution on Windows systems, proving years of negligence. |
| 2024-06-12 | CVE-2024-4577 | critical | A patch bypass for a 2012 PHP-CGI command injection flaw allows remote code execution on Windows systems, proving years of negligence. |
| 2022-03-25 | CVE-2012-1823 | high | A PHP CGI vulnerability allowed remote attackers to execute arbitrary code via improperly handled query strings. |
| 2022-03-25 | CVE-2012-1823 | high | A PHP CGI vulnerability allowed remote attackers to execute arbitrary code via improperly handled query strings. |
| 2025-07-07 | CVE-2016-10033 | high | PHPMailer command injection allowed arbitrary code execution. |
| 2022-03-25 | CVE-2019-11043 | critical | A buffer overflow vulnerability in PHP's FPM allowed for potential remote code execution and has been actively exploited in ransomware attacks, impacting systems using vulnerable PHP installations. |
| 2026-05-10 | CVE-2026-6722 | critical | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains |
| 2026-05-10 | CVE-2026-6722 | critical | In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains |
| 2026-07-30 | CVE-2026-17544 | critical | CVE-2026-17544: Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with s |
| 2026-07-30 | CVE-2026-17544 | critical | CVE-2026-17544: Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with s |
| 2026-07-30 | CVE-2026-17543 | critical | CVE-2026-17543: Improper escaping of backslashes in attacker-provided parameters would allow for |
| 2026-07-30 | CVE-2026-17543 | critical | CVE-2026-17543: Improper escaping of backslashes in attacker-provided parameters would allow for |
| 2026-05-10 | CVE-2026-6104 | critical | CVE-2026-6104: In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding nam |
| 2026-05-10 | CVE-2025-14179 | critical | CVE-2025-14179: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a |
| 2026-05-10 | CVE-2025-14179 | critical | CVE-2025-14179: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a |
| 2026-05-10 | CVE-2026-6104 | critical | CVE-2026-6104: In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding nam |
| 2026-05-10 | CVE-2026-7261 | critical | CVE-2026-7261: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a |
| 2026-05-10 | CVE-2026-7261 | critical | CVE-2026-7261: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a |
| 2019-12-23 | CVE-2019-11049 | medium | CVE-2019-11049: In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom h |
| 2019-12-23 | CVE-2019-11049 | medium | CVE-2019-11049: In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom h |
DOSSIER SOURCES
- History of PHP - Developing PHP · developingphp.com
- HP Inc. - Wikipedia · en.wikipedia.org
- PHP Security Advisories · phpadvisories.app
- PHP vulnerability CVE-2026-6722 · my.f5.com
- Critical Security Flaws in Composer Put PHP Applications at Risk · dailysecurityreview.com
- PHP SOAP Extension RCE CVE-2026-6722 Patched Across All Branches · dailysecurityreview.com
- PHP Security Advisories · phpadvisories.app
- Critical Security Flaws in Composer Put PHP Applications at Risk · dailysecurityreview.com
Open questions: What is the current state of PHP's vulnerability management process? · What measures are being taken to address the identified patterns of security failures? · What is the extent of the impact from the identified vulnerabilities on DIB systems?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-20 04:34:51.486863+00:00