Threats Tagged 'php'
View all threats tagged with 'php'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'php'
Click on any threat for detailed analysis and mitigation recommendations
Click2Shell is a cross-site request forgery (CSRF) vulnerability in WordPress Core up to version 7.1.0 that allows unauthenticated attackers to execute arbitrary PHP code on the server by forcing the installation of a theme from the official WordPress.org catalog. The attack requires a logged-in administrator to visit a crafted URL, which triggers the execution of PHP code via an inactive theme during a Customizer preview. This vulnerability was fixed in WordPress version 7.1.1 by escaping the theme slug and restricting jQuery selectors. The flaw enables remote code execution that could lead to file manipulation, data access, and creation of rogue admin accounts. Join the discussion | Bleeping Computer | 09/21/2026, 18:23:11 UTC Added: 09/21/2026, 18:31:40 UTC |
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...] Join the discussion | Bleeping Computer | 09/15/2026, 14:45:10 UTC Added: 09/15/2026, 15:16:37 UTC |
ILIAS versions prior to 9.22, 10.10, and 11.3 have an unauthenticated PHP object injection vulnerability via the LTI authentication endpoint, enabling remote code execution through the Shibboleth back-channel logout endpoint. This allows attackers to write malicious PHP code to a web-accessible location and execute it as the web server user. Join the discussion | CVE Database V5 | 09/11/2026, 00:00:00 UTC Added: 08/26/2026, 15:52:59 UTC |
A Linux rootkit has been identified targeting F5 BIG-IP APM devices. This rootkit intercepts PHP file loading processes and injects a fileless web shell directly into memory, which allows it to avoid writing malicious code to disk. This technique complicates detection and forensic analysis. The rootkit specifically affects F5 BIG-IP APM environments and leverages in-memory injection to maintain persistence and stealth. Join the discussion | Bleeping Computer | 09/08/2026, 20:08:55 UTC Added: 09/08/2026, 20:22:15 UTC |
0 A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. The /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before initiating outbound connections. An authenticated administrator can manipulate the document server parameter to cause the ownCloud server to send arbitrary requests to attacker-controlled destinations, including localhost and internal network hosts. This allows internal network reconnaissance and TCP port scanning based on differences in server responses. Join the discussion | CERT/CC | 09/08/2026, 14:27:08 UTC Added: 09/08/2026, 14:28:25 UTC |
0 Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed. Join the discussion | CVE Database V5 | 09/07/2026, 20:17:16 UTC Added: 09/07/2026, 20:22:50 UTC |
A critical vulnerability chain in the Avada WordPress theme allows an unauthenticated attacker to execute arbitrary PHP code on the server without any user interaction (zero-click). This flaw affects the popular Avada theme and poses a severe risk of remote code execution. Join the discussion | Bleeping Computer | 08/26/2026, 21:33:20 UTC Added: 08/26/2026, 21:37:15 UTC |
0 The Kaltura HTML5 Player Library (mwEmbed / html5lib) versions v2.45, v2.103, and earlier v2.x releases contain two vulnerabilities involving insecure deserialization. These flaws allow remote, unauthenticated attackers to read arbitrary local files and execute arbitrary code as the web-server user via the vulnerable mwEmbedLoader.php endpoint. The vulnerabilities stem from unsafe deserialization of user-controlled input and insufficient sanitization of a path parameter, enabling directory traversal and remote code execution. These issues affect legacy Player V2 versions but not the currently supported Player V7. Until patches are applied, restricting or disabling access to the vulnerable endpoint is advised. Join the discussion | CERT/CC | 08/25/2026, 16:21:05 UTC Added: 08/25/2026, 16:20:37 UTC |
StopAndProtect is a large-scale malware operation abusing thousands of hacked WordPress sites as infrastructure to spread malware, control infected machines, and store stolen data. It uses a multi-stage infection chain initiated by a social engineering ClickFix prompt leading to PowerShell scripts and .NET loaders. The operation includes ransomware, data theft, screen locking, credential stealing, and a chat utility. Operational security failures exposed extensive logs, screenshots, and source code, revealing the scale and tools used. Many compromised WordPress sites are outdated and vulnerable, facilitating the attackers' control. The campaign affects victims globally, with many IPs from the US, Russia, and India. No official patch or fix is applicable as this is a malware campaign leveraging vulnerable third-party sites. Join the discussion | Check Point Research | 08/18/2026, 13:05:44 UTC Added: 08/18/2026, 13:17:41 UTC |
Exploit-DB RSS Feed | 08/17/2026, 00:00:00 UTC Added: 08/17/2026, 22:15:47 UTC |
Showing 1 to 10 of 40 results