Back to all advisories

Tag: PHP

7 advisories tagged with "PHP".

CVE-2026-62953 High

Path Traversal via Unsanitized Upload Filename

baserCMS plugin and theme upload handlers use the client-supplied filename to build a destination path without calling basename(), so an authenticated user can smuggle traversal sequences and write an arbitrary file, including a PHP payload, before any ZIP validation runs. If the webroot is writable this leads to remote code execution; the issue is fixed in version 5.2.3.

basercms
CVE-2026-62952 High

Arbitrary Binary Execution via Unvalidated PHP Path Parameter

The update_core admin action in baserCMS forwards the attacker-supplied php binary path to exec() through updateCore() and rollbackCore() without an allowlist check. Chained with a file-write primitive this gives authenticated remote code execution.

basercms
CVE-2026-46683 High

SSRF and local file read via the xsl-style-sheet option

This is a Server-Side Request Forgery (SSRF) and local file read vulnerability in KnpLabs Snappy, a PHP library that wraps wkhtmltopdf for HTML-to-PDF generation. The flaw lives in the xsl-style-sheet option, which is passed directly to wkhtmltopdf without any URL scheme validation. If an attacker can influence the value of that option, they can point it at internal network resources or at local files using file:// URIs, causing the server to fetch and embed content it should never expose.

Snappy
CVE-2026-46643 Medium

Binary path is never shell-escaped due to an inverted is_executable check

CVE-2026-46643 is a Moderate severity vulnerability in knplabs/knp-snappy (<= 1.7.0) where the binary path passed to Snappy's constructor is never shell-escaped before being executed, despite code that looks like it should be doing exactly that. The root cause is a logic inversion in the is_executable() check. escapeshellarg() wraps the path in single quotes, but is_executable() then looks for a file whose name literally contains those quote characters, which never exists.

Snappy
GHSA-87qc-37cw-84h4 Low

$temporaryFiles is public, enabling arbitrary file deletion at shutdown

GHSA-87qc-37cw-84h4 is a Low severity vulnerability in knplabs/knp-snappy (<= 1.7.1) where the $temporaryFiles property on AbstractGenerator is declared public instead of private. Snappy uses this array to track temp files it creates during generation, then deletes everything in it automatically when the object is destroyed at shutdown via __destruct().

Snappy
CVE-2026-45016 Medium

Local File Inclusion via file:// URI in Mail Compose

Mail composition handler processes image URLs found in outgoing HTML email bodies without validating their URI scheme

egroupware
CVE-2026-63672 Medium

Unrestricted Identity Provider Selection in SAML Authentication

Unauthenticated users can control the Identity Provider (IdP) selection in SAML authentication due to insufficient validation. This advisory explains the issue in Saml.php, the proof of concept, potential impact, and recommended remediation.

egroupware

Start securing your codebase today

Connect your repositories and let AI agents handle continuous scanning, research, and triage.

Have questions? Get in touch →