Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
php php vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2023-6933
The Better Search Replace plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.4 via deserialization of untrusted input. This makes it possible for unauthenticated malicious users to inject a PHP Object. No POP chain is present in t...
Wpengine Better Search Replace
1 Github repository
9.8
CVSSv3
CVE-2023-6989
The Shield Security – Smart Bot Blocking & Intrusion Prevention Security plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 18.5.9 via the render_action_template parameter. This makes it possible for unauthenticated maliciou...
Getshieldsecurity Shield Security
9.8
CVSSv3
CVE-2024-24754
Bref enable serverless PHP on AWS Lambda. When Bref is used with the Event-Driven Function runtime and the handler is a `RequestHandlerInterface`, then the Lambda event is converted to a PSR7 object. During the conversion process, if the request is a MultiPart, each part is parse...
Mnapoli Bref
9.8
CVSSv3
CVE-2024-22922
An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe malicious user to escalate privileges via a crafted script to the login page in the POST/index.php
Projectworlds Visitor Management System In Php 1.0
9.8
CVSSv3
CVE-2024-22076
MyQ Print Server prior to 8.2 patch 43 allows remote authenticated administrators to execute arbitrary code via PHP scripts that are reached through the administrative interface.
Myq-solution Print Server
Myq-solution Print Server 8.2
9.8
CVSSv3
CVE-2022-1609
The School Management WordPress plugin prior to 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated malicious user to execute arbitrary PHP code on the site.
Weblizar School Management
4 Github repositories
9.8
CVSSv3
CVE-2023-6049
The Estatik Real Estate Plugin WordPress plugin prior to 4.1.1 unserializes user input via some of its cookies, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget chain is present on the blog
Estatik Estatik
9.8
CVSSv3
CVE-2023-52262
outdoorbits little-backup-box (aka Little Backup Box) before f39f91c allows remote malicious users to execute arbitrary code because the PHP extract function is used for untrusted input.
Outdoorbits Little Backup Box
9.8
CVSSv3
CVE-2023-7096
A vulnerability was found in code-projects Faculty Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/php/crud.php. The manipulation of the argument fieldname leads to sql injection. The attack may be laun...
Carmelogarcia Faculty Management System 1.0
9.8
CVSSv3
CVE-2023-6971
The Backup Migration plugin for WordPress is vulnerable to Remote File Inclusion in versions 1.0.8 to 1.3.9 via the 'content-dir' HTTP header. This makes it possible for unauthenticated malicious users to include remote files on the server, resulting in code execution. ...
Backupbliss Backup Migration
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
cross-site request forgery
CVE-2024-34351
CVE-2024-1076
CVE-2024-25522
CVE-2024-34547
CVE-2024-4644
unauthorized
remote
CVE-2024-4671
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »