Vulnerability Name |
CVE
CWE
|
CWE |
Severity |
PHP Out-of-bounds Write Vulnerability (CVE-2016-5399)
|
CVE-2016-5399
CWE-787
|
CWE-787
|
High
|
PHP Out-of-bounds Write Vulnerability (CVE-2019-6977)
|
CVE-2019-6977
CWE-787
|
CWE-787
|
High
|
PHP Out-of-bounds Write Vulnerability (CVE-2020-7065)
|
CVE-2020-7065
CWE-787
|
CWE-787
|
High
|
PHP Out-of-bounds Write Vulnerability (CVE-2021-21703)
|
CVE-2021-21703
CWE-787
|
CWE-787
|
High
|
PHP Out-of-bounds Write Vulnerability (CVE-2024-11233)
|
CVE-2024-11233
CWE-787
|
CWE-787
|
High
|
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-1461)
|
CVE-2007-1461
CWE-264
|
CWE-264
|
High
|
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2007-3997)
|
CVE-2007-3997
CWE-264
|
CWE-264
|
High
|
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-0145)
|
CVE-2008-0145
CWE-264
|
CWE-264
|
High
|
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-5624)
|
CVE-2008-5624
CWE-264
|
CWE-264
|
High
|
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-5625)
|
CVE-2008-5625
CWE-264
|
CWE-264
|
High
|
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-7002)
|
CVE-2008-7002
CWE-264
|
CWE-264
|
High
|
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-4018)
|
CVE-2009-4018
CWE-264
|
CWE-264
|
High
|
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-2335)
|
CVE-2012-2335
CWE-264
|
CWE-264
|
High
|
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-1635)
|
CVE-2013-1635
CWE-264
|
CWE-264
|
High
|
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0185)
|
CVE-2014-0185
CWE-264
|
CWE-264
|
High
|
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-8994)
|
CVE-2015-8994
CWE-264
|
CWE-264
|
High
|
PHP Permissions, Privileges, and Access Controls Vulnerability (CVE-2019-9637)
|
CVE-2019-9637
CWE-264
|
CWE-264
|
High
|
PHP POST file upload buffer overflow vulnerabilities
|
CVE-2002-0081
CWE-119
|
CWE-119
|
High
|
PHP Release of Invalid Pointer or Reference Vulnerability (CVE-2022-31625)
|
CVE-2022-31625
CWE-763
|
CWE-763
|
High
|
PHP Resource Management Errors Vulnerability (CVE-2002-2309)
|
CVE-2002-2309
|
|
High
|
PHP Resource Management Errors Vulnerability (CVE-2007-4660)
|
CVE-2007-4660
|
|
High
|
PHP Resource Management Errors Vulnerability (CVE-2010-2225)
|
CVE-2010-2225
|
|
High
|
PHP Resource Management Errors Vulnerability (CVE-2011-1148)
|
CVE-2011-1148
|
|
High
|
PHP Resource Management Errors Vulnerability (CVE-2012-0830)
|
CVE-2012-0830
|
|
High
|
PHP Resource Management Errors Vulnerability (CVE-2015-8877)
|
CVE-2015-8877
|
|
High
|
PHP Safedir restriction bypass vulnerabilities
|
CWE-20
|
CWE-20
|
High
|
PHP Server-Side Request Forgery (SSRF) Vulnerability (CVE-2017-7272)
|
CVE-2017-7272
CWE-918
|
CWE-918
|
High
|
phpThumb() fltr[] parameter command injection vulnerability
|
CVE-2010-1598
CWE-20
|
CWE-20
|
High
|
PHP Uncontrolled Resource Consumption Vulnerability (CVE-2011-3336)
|
CVE-2011-3336
CWE-400
|
CWE-400
|
High
|
PHP Uncontrolled Resource Consumption Vulnerability (CVE-2017-11142)
|
CVE-2017-11142
CWE-400
|
CWE-400
|
High
|
PHP Uncontrolled Resource Consumption Vulnerability (CVE-2023-0662)
|
CVE-2023-0662
CWE-400
|
CWE-400
|
High
|
PHPUnit Remote Code Execution
|
CVE-2017-9841
CWE-94
|
CWE-94
|
High
|
PHP Use After Free Vulnerability (CVE-2015-1351)
|
CVE-2015-1351
CWE-416
|
CWE-416
|
High
|
PHP Use After Free Vulnerability (CVE-2015-6831)
|
CVE-2015-6831
CWE-416
|
CWE-416
|
High
|
PHP Use After Free Vulnerability (CVE-2017-12934)
|
CVE-2017-12934
CWE-416
|
CWE-416
|
High
|
PHP Use of Externally-Controlled Format String Vulnerability (CVE-2011-1153)
|
CVE-2011-1153
CWE-134
|
CWE-134
|
High
|
PHP Use of Uninitialized Resource Vulnerability (CVE-2015-3414)
|
CVE-2015-3414
CWE-908
|
CWE-908
|
High
|
PHP version older than 4.4.1
|
CVE-2005-3388
CVE-2006-0097
CWE-1104
|
CWE-1104
|
High
|
PHP version older than 5.2.1
|
CVE-2007-1376
CVE-2007-1380
CVE-2007-1453
CVE-2007-1454
CWE-1104
|
CWE-1104
|
High
|
PHP version older than 5.2.3
|
CVE-2007-1900
CVE-2007-2756
CVE-2007-2872
CWE-1104
|
CWE-1104
|
High
|
PHP version older than 5.2.5
|
CVE-2007-4840
CVE-2007-4887
CVE-2007-5898
CVE-2007-5899
CVE-2007-5900
CWE-1104
|
CWE-1104
|
High
|
PHP version older than 5.2.6
|
CVE-2007-4850
CVE-2008-0599
CVE-2008-0674
CVE-2008-1384
CVE-2008-2050
CVE-2008-2051
CWE-1104
|
CWE-1104
|
High
|
PHP version older than 5.2.8
|
CVE-2008-2371
CVE-2008-2665
CVE-2008-2666
CVE-2008-2829
CVE-2008-3658
CVE-2008-3659
CVE-2008-3660
CWE-1104
|
CWE-1104
|
High
|
PHP Zend_Hash_Del_Key_Or_Index vulnerability
|
CVE-2006-3017
CWE-702
|
CWE-702
|
High
|
Phusion Passenger Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Vulnerability (CVE-2018-12029)
|
CVE-2018-12029
CWE-362
|
CWE-362
|
High
|
Phusion Passenger Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-12027)
|
CVE-2018-12027
CWE-200
|
CWE-200
|
High
|
Phusion Passenger Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2018-12028)
|
CVE-2018-12028
CWE-732
|
CWE-732
|
High
|
Phusion Passenger Permissions, Privileges, and Access Controls Vulnerability (CVE-2016-10345)
|
CVE-2016-10345
CWE-264
|
CWE-264
|
High
|
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2013-1468)
|
CVE-2013-1468
CWE-352
|
CWE-352
|
High
|
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-10678)
|
CVE-2017-10678
CWE-352
|
CWE-352
|
High
|
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-10680)
|
CVE-2017-10680
CWE-352
|
CWE-352
|
High
|
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-10681)
|
CVE-2017-10681
CWE-352
|
CWE-352
|
High
|
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-17774)
|
CVE-2017-17774
CWE-352
|
CWE-352
|
High
|
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-17827)
|
CVE-2017-17827
CWE-352
|
CWE-352
|
High
|
Piwigo Exposure of Resource to Wrong Sphere Vulnerability (CVE-2022-26267)
|
CVE-2022-26267
CWE-668
|
CWE-668
|
High
|
Piwigo Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-10679)
|
CVE-2017-10679
CWE-200
|
CWE-200
|
High
|
Piwigo Improper Access Control Vulnerability (CVE-2016-10084)
|
CVE-2016-10084
CWE-284
|
CWE-284
|
High
|
Piwigo Improper Access Control Vulnerability (CVE-2016-10085)
|
CVE-2016-10085
CWE-284
|
CWE-284
|
High
|
Piwigo Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2012-2208)
|
CVE-2012-2208
CWE-22
|
CWE-22
|
High
|
Piwigo Improper Neutralization of Special Elements used in a Command ('Command Injection') Vulnerability (CVE-2021-40553)
|
CVE-2021-40553
CWE-138
|
CWE-138
|
High
|
Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-2933)
|
CVE-2009-2933
CWE-138
|
CWE-138
|
High
|
Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2014-9115)
|
CVE-2014-9115
CWE-138
|
CWE-138
|
High
|
Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-1441)
|
CVE-2015-1441
CWE-138
|
CWE-138
|
High
|
Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2020-19215)
|
CVE-2020-19215
CWE-138
|
CWE-138
|
High
|
Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2020-19216)
|
CVE-2020-19216
CWE-138
|
CWE-138
|
High
|
Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2020-19217)
|
CVE-2020-19217
CWE-138
|
CWE-138
|
High
|
Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2021-27973)
|
CVE-2021-27973
CWE-138
|
CWE-138
|
High
|
Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2021-40313)
|
CVE-2021-40313
CWE-138
|
CWE-138
|
High
|
Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2021-40317)
|
CVE-2021-40317
CWE-138
|
CWE-138
|
High
|
Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-26266)
|
CVE-2022-26266
CWE-138
|
CWE-138
|
High
|
Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-32297)
|
CVE-2022-32297
CWE-138
|
CWE-138
|
High
|
Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-26876)
|
CVE-2023-26876
CWE-138
|
CWE-138
|
High
|
Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-27233)
|
CVE-2023-27233
CWE-138
|
CWE-138
|
High
|
Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-37270)
|
CVE-2023-37270
CWE-138
|
CWE-138
|
High
|
Piwigo Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) Vulnerability (CVE-2016-3735)
|
CVE-2016-3735
CWE-335
|
CWE-335
|
High
|