t
the php group
Security Risk Profile
53
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 53 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from July 13, 2004 to present
53
Total CVEs
2
Critical+High
1
Exploited
2
Unpatched
Threat Assessment
Avg CVSS
4.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
53/100
medium
⚠️ 1 Active Exploits⚡ 1 Zero-Days🆕 1Fresh (<7d)📈 1 in Last 30 Days
Severity Distribution
Critical
0High
2Medium
7Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
Integer Overflow
3
2
Buffer Overflow
2
3
Use After Free
1
4
Null Pointer Dereference
1
5
SQL Injection
1
Most Affected Products
1. The PHP Group PHP52
2. PHP PHP1
3. The PHP Group Pear Html Quickform Controller1
Recent Vulnerabilities
See more →REDHAT-BUG-2468560
CVSS 7.0high
May 10, 2026🔧 No Patch
REDHAT-BUG-2425627
CVSS 7.0high
Dec 27, 2025🔧 No Patch
EOL-php-8.5
unknown
Nov 20, 2025
https://seclists.org/oss-sec/2025/q2/45
unknown
Security audit of PHP
Apr 12, 2025🔧 No Patch
https://www.bleepingcomputer.com/news/security/critical-php-rce-vulnerability-mass-exploited-in-new-attacks/
unknown
Critical PHP RCE vulnerability mass exploited in new attacks
Mar 11, 2025⚠ Exploited⚡ Zero-Day🔧 No Patch
latest-version-php-8.3
unknown
Dec 19, 2024
EOL-php-8.3
unknown
Dec 19, 2024
EOL-php-8.4
unknown
Dec 19, 2024
latest-version-php-8.4
unknown
Dec 19, 2024
latest-version-php-8.2
unknown
Nov 21, 2024
Monitor the php group in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.