Skip to content
COOEY

FAIL › dossier

php

VENDOR

· dossier confidence 67%

PHP has a concerning history of critical security vulnerabilities, including remote code execution flaws, demonstrating a pattern of delayed patching and inadequate security practices. The vendor's track record raises significant concerns regarding the security of systems utilizing PHP.

PROFILE
CategoryProgramming Language/Runtime EnvironmentWhat they doPHP is a widely-used, open-source scripting language primarily used for web development. It powers over 75% of all websites worldwide.Founded1994 Websitehttps://www.php.net/ ↗
SECURITY POSTURE

PHP exhibits a history of critical security vulnerabilities, frequently involving remote code execution (RCE). Patching has been inconsistent, with vulnerabilities dating back to 2012 remaining unaddressed for extended periods.

Notable failures
  • CVE-2024-4577: Patch bypass for 2012 command injection flaw
  • CVE-2019-11043: Buffer overflow in FPM leading to RCE
  • CVE-2012-1823: CGI query string handling flaw allowing RCE
  • CVE-2016-10033: PHPMailer command injection vulnerability
  • CVE-2026-6722: Use-after-free RCE in SOAP extension
  • CVE-2025-14179: Command injection vulnerability
Patterns: Recurring RCE vulnerabilities; Delayed patching of critical vulnerabilities; Vulnerabilities in extensions (e.g., SOAP, PHPMailer)
FAILURE HISTORY · 20
DATEEVENTSEVSUMMARY
2024-06-12 CVE-2024-4577 critical A patch bypass for a 2012 PHP-CGI command injection flaw allows remote code execution on Windows systems, proving years of negligence.
2024-06-12 CVE-2024-4577 critical A patch bypass for a 2012 PHP-CGI command injection flaw allows remote code execution on Windows systems, proving years of negligence.
2022-03-25 CVE-2012-1823 high A PHP CGI vulnerability allowed remote attackers to execute arbitrary code via improperly handled query strings.
2022-03-25 CVE-2012-1823 high A PHP CGI vulnerability allowed remote attackers to execute arbitrary code via improperly handled query strings.
2025-07-07 CVE-2016-10033 high PHPMailer command injection allowed arbitrary code execution.
2022-03-25 CVE-2019-11043 critical A buffer overflow vulnerability in PHP's FPM allowed for potential remote code execution and has been actively exploited in ransomware attacks, impacting systems using vulnerable PHP installations.
2026-05-10 CVE-2026-6722 critical In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains
2026-05-10 CVE-2026-6722 critical In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains
2026-07-30 CVE-2026-17544 critical CVE-2026-17544: Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with s
2026-07-30 CVE-2026-17544 critical CVE-2026-17544: Attacker-provided inputs to bccomp() could lead to an out-of-bounds write with s
2026-07-30 CVE-2026-17543 critical CVE-2026-17543: Improper escaping of backslashes in attacker-provided parameters would allow for
2026-07-30 CVE-2026-17543 critical CVE-2026-17543: Improper escaping of backslashes in attacker-provided parameters would allow for
2026-05-10 CVE-2026-6104 critical CVE-2026-6104: In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding nam
2026-05-10 CVE-2025-14179 critical CVE-2025-14179: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a
2026-05-10 CVE-2025-14179 critical CVE-2025-14179: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a
2026-05-10 CVE-2026-6104 critical CVE-2026-6104: In PHP versions 8.4.* before 8.4.21 and 8.5.* before 8.5.6, when an encoding nam
2026-05-10 CVE-2026-7261 critical CVE-2026-7261: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a
2026-05-10 CVE-2026-7261 critical CVE-2026-7261: In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, a
2019-12-23 CVE-2019-11049 medium CVE-2019-11049: In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom h
2019-12-23 CVE-2019-11049 medium CVE-2019-11049: In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom h
Open questions: What is the current state of PHP's vulnerability management process? · What measures are being taken to address the identified patterns of security failures? · What is the extent of the impact from the identified vulnerabilities on DIB systems?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-20 04:34:51.486863+00:00