CVE-2026-6735

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

History

12 May 2026, 17:43

Type Values Removed Values Added
References () https://github.com/php/php-src/security/advisories/GHSA-7qg2-v9fj-4mwv - () https://github.com/php/php-src/security/advisories/GHSA-7qg2-v9fj-4mwv - Vendor Advisory, Exploit
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
CPE cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
First Time Php
Php php

10 May 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-10 05:16

Updated : 2026-05-12 17:43


NVD link : CVE-2026-6735

Mitre link : CVE-2026-6735

CVE.ORG link : CVE-2026-6735


JSON object : View

Products Affected

php

  • php
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')