Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
PHP Number Of NVD 689 CRITICAL 119 HIGH 257 MEDIUM 287 LOW 26
URL https://www.php.net/
Explanation It is an open source programming language used around the world as a development language for web applications.
It is developed by "The PHP Group" and is used in many open source web applications such as WordPress and Xoops.
Today, it can be used as a general-purpose scripting language for applications other than web applications.
It is a popular language among programming beginners because it is easy to learn.

It has become one of the open source combinations called LAMP (Linux, Apache, MySQL [MariaDB], PHP).

Add Information URL
No Type Name URL
1 https://www.php.net/supported-versions.php
2 https://www.php.net/downloads.php
3 https://www.php.net/eol.php
4 https://github.com/php/php-src

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
1 PHP8.3 8.3.28 Nov. 20, 2025 June 6, 2024 Dec. 31, 2025 Dec. 31, 2027 2 3 2 0
2 PHP8.2 8.2.29 July 3, 2025 Dec. 8, 2022 Dec. 31, 2024 Dec. 31, 2026 3 6 4 0
3 PHP8.1 8.1.33 July 3, 2025 Nov. 25, 2021 Nov. 25, 2023 Nov. 25, 2024 6 10 6 0
4 PHP8.0 8.0.30 Aug. 3, 2023 Nov. 26, 2020 Nov. 26, 2022 Nov. 26, 2023 6 9 11 0
5 PHP7.4 7.4.33 Nov. 3, 2022 Nov. 28, 2019 Nov. 28, 2021 Nov. 28, 2022 9 10 19 1
6 PHP7.3 7.3.33 Nov. 18, 2021 Dec. 6, 2018 Dec. 6, 2020 Dec. 6, 2021 19 17 21 1
7 PHP7.2 7.2.34 Oct. 1, 2020 Nov. 30, 2017 Nov. 30, 2019 Nov. 30, 2020 20 21 21 1
8 PHP7.1 7.1.33 Dec. 1, 2019 Dec. 1, 2016 Dec. 1, 2018 Dec. 1, 2019 30 36 10 0
9 PHP7.0 7.0.33 Dec. 6, 2018 Dec. 3, 2015 Dec. 3, 2017 Dec. 3, 2018 76 60 14 0
10 PHP5.6 5.6.40 Dec. 31, 2018 Aug. 28, 2014 Jan. 19, 2017 Dec. 31, 2018 77 95 41 1
11 PHP6.0 6.0 Jan. 1, 2000 4 8 5 0
12 PHP5.6 5.6.9 Jan. 1, 2000 77 95 41 1
13 PHP5.5 5.5.9 Jan. 1, 2000 72 98 67 3
14 PHP5.4 5.4.9 Jan. 1, 2000 61 103 74 4
15 PHP5.3 5.3.9 Jan. 1, 2000 62 110 134 4
16 PHP5.2 5.2.9 Jan. 1, 2000 63 156 184 7
17 PHP5.1 5.1.6 Jan. 1, 2000 63 150 150 19
18 PHP5.0 5.0.5 Jan. 1, 2000 63 154 157 14
19 PHP4.4 4.4.9 Jan. 1, 2000 62 149 164 20
20 PHP4.3 4.3.9 Jan. 1, 2000 62 158 164 15
21 PHP4.2 4.2.4 Jan. 1, 2000 62 157 166 15
22 PHP4.1 4.1.3 Jan. 1, 2000 62 159 163 15
23 PHP4.0 4.0.7 Jan. 1, 2000 62 161 168 17
24 PHP3.0 3.0.9 Jan. 1, 2000 61 136 140 6
25 PHP2.0b10 2.0b10 Jan. 1, 2000 61 124 132 6
26 PHP2.0 2.0.2 Jan. 1, 2000 61 124 132 6
27 PHP1.5 1.5 Jan. 1, 2000 61 120 131 6
28 PHP1.4 1.4 Jan. 1, 2000 61 120 131 6
29 PHP1.3 1.3.5 Jan. 1, 2000 61 120 131 6
30 PHP1.2 1.2.5 Jan. 1, 2000 61 120 131 6
31 PHP1.1 1.1.1 Jan. 1, 2000 61 120 131 6
32 PHP1.0 1.0.4 Jan. 1, 2000 61 124 132 6
33 PHP0.91 0.91 Jan. 1, 2000 61 120 131 6
34 PHP0.90 0.90 Jan. 1, 2000 61 120 131 6
35 PHP0.9 0.9.4 Jan. 1, 2000 61 120 131 6
36 PHP0.7 0.7 Jan. 1, 2000 61 120 131 6
37 PHP0.6 0.6 Jan. 1, 2000 61 120 131 6
38 PHP0.5 0.5.3 Jan. 1, 2000 61 120 131 6
39 PHP0.4 0.4 Jan. 1, 2000 61 120 131 6
40 PHP0.3 0.3 Jan. 1, 2000 61 120 131 6
41 PHP0.2 0.2.4 Jan. 1, 2000 61 120 131 6
42 PHP0.11 0.11 Jan. 1, 2000 61 120 131 6
43 PHP0.10 0.10 Jan. 1, 2000 61 120 131 6
44 PHP0.1 0.1.1 Jan. 1, 2000 61 120 131 6
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
1 8.2
-
HIGH
Network
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, due to an error in convert.quoted-printable-decode filter certain data can lead to buffer overread by one byte, which ca… CWE-787
 Out-of-bounds Write
CVE-2024-11233 cpe:2.3:a:php:php:*:* 8.3.0
8.2.0
8.1.0




8.3.14
8.2.26
8.1.31
2024-11-27 03:26
2024-11-24
Show GitHub Exploit DB Packet Storm
2 9.8
-
CRITICAL
Network
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, uncontrolled long string inputs to ldap_escape() function on 32-bit systems can cause an integer overflow, resulting in … CWE-190
 Integer Overflow or Wraparound
CVE-2024-11236 cpe:2.3:a:php:php:*:* 8.3.0
8.2.0
8.1.0




8.3.14
8.2.26
8.1.31
2024-11-27 03:29
2024-11-24
Show GitHub Exploit DB Packet Storm
3 7.2
-
HIGH
Network
In PHP versions 8.1.* before 8.1.31, 8.2.* before 8.2.26, 8.3.* before 8.3.14, when using streams with configured proxy and "request_fulluri" option, the URI is not properly sanitized which can lead … CWE-74
Injection
CVE-2024-11234 cpe:2.3:a:php:php:*:* 8.3.0
8.2.0
8.1.0




8.3.14
8.2.26
8.1.31
2024-11-27 04:06
2024-11-24
Show GitHub Exploit DB Packet Storm
4 9.8
-
CRITICAL
Network
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" b… CWE-78
OS Command 
CVE-2024-4577 cpe:2.3:a:php:php:*:* 5.0.0
8.2.0
8.3.0




8.1.29
8.2.20
8.3.8
2024-11-21 18:43
2024-06-10
Show GitHub Exploit DB Packet Storm
5 5.9
-
MEDIUM
Network
The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that … CWE-203
 Information Exposure Through Discrepancy
CVE-2024-2408 cpe:2.3:a:php:php:*:* 8.2.0
8.3.0
8.1.0




8.2.20
8.3.8
8.1.29
2024-11-21 18:09
2024-06-10
Show GitHub Exploit DB Packet Storm
6 5.3
-
MEDIUM
Network
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain … CWE-345
 Insufficient Verification of Data Authenticity
CVE-2024-5458 cpe:2.3:a:php:php:*:* 8.2.0
8.3.0
8.1.0
8.0.2
7.4.15
7.3.27



8.0.30
7.4.33
7.3.33





8.2.20
8.3.8
8.1.29


2024-11-21 18:47
2024-06-10
Show GitHub Exploit DB Packet Storm
7 8.8
-
HIGH
Network
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, the fix for CVE-2024-1874 does not work if the command name includes trailing spaces. Original issue: when using proc_ope… CWE-116
 Improper Encoding or Escaping of Output
CVE-2024-5585 cpe:2.3:a:php:php:*:* 8.2.0
8.3.0
8.1.0




8.2.20
8.3.8
8.1.29
2024-11-21 18:47
2024-06-10
Show GitHub Exploit DB Packet Storm
8 5.5
-
MEDIUM
Local
A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow. CWE-787
 Out-of-bounds Write
CVE-2022-4900 cpe:2.3:a:php:php:*:* 8.0.22 2024-11-21 16:36
2023-11-3
Show GitHub Exploit DB Packet Storm
9 9.8
-
CRITICAL
Network
In PHP version 8.0.* before 8.0.30,  8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer… CWE-119
Incorrect Access of Indexable Resource ('Range Error') 
CVE-2023-3824 cpe:2.3:a:php:php:*:* 8.1.0
8.0.0
8.2.0




8.1.22
8.0.30
8.2.9
2024-11-21 17:18
2023-08-11
Show GitHub Exploit DB Packet Storm
10 7.5
-
HIGH
Network
In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are… CWE-611
XXE
CVE-2023-3823 cpe:2.3:a:php:php:*:* 8.1.0
8.0.0
8.2.0




8.1.22
8.0.30
8.2.9
2024-11-21 17:18
2023-08-11
Show GitHub Exploit DB Packet Storm