In a critical security alert for the PHP community, Nils Adermann, Co-Creator of Composer, has issued an...
php
For the system administrators and DevOps engineers who maintain the backbone of the internet, PHP is a...
Researchers at Socket have identified a massive new cluster of malicious packages linked to North Korea’s notorious...
Cybersecurity researchers at Synacktiv have uncovered two critical vulnerabilities in Snipe-IT, an open-source IT asset management system,...
A newly disclosed security flaw, tracked as CVE-2025-54370, has been identified in PhpSpreadsheet, a PHP-based library that...
A critical SQL injection vulnerability has been discovered in ADOdb, a widely used PHP database abstraction library....
Developers relying on CodeIgniter, one of the most widely adopted PHP full-stack web frameworks with over 2.9...
A critical remote command execution (RCE) vulnerability has been discovered in Livewire, the popular full-stack framework for...
As one of the most widely used open-source scripting languages in the world, PHP has long faced...
A newly discovered Server-Side Template Injection (SSTI) vulnerability in the widely-used LaRecipe documentation tool has been assigned...
Interlock RAT Gets PHP Makeover: New Variant Uses Steganography & ClickFix for Stealthy Infiltration
Interlock RAT Gets PHP Makeover: New Variant Uses Steganography & ClickFix for Stealthy Infiltration
Researchers from The DFIR Report, in collaboration with Proofpoint, have uncovered a stealthy and resilient variant of...
A recent technical deep-dive by Synacktiv has exposed a serious yet often overlooked risk in Laravel—the popular...
The PHP project has released security patches addressing two vulnerabilities that expose PHP-based applications to SQL injection...
A newly disclosed vulnerability in Convoy, a modern KVM server management panel built for hosting providers, has...
Security researcher Egidio Romano (EgiX) uncovers a fascinating PHP Object Injection (POI) vulnerability in legacy versions of...
A newly disclosed vulnerability in the Auth0 PHP SDK—a widely-used authentication toolkit with over 16 million downloads—poses...
Roundcube Webmail, a widely-used browser-based IMAP client, has patched a critical security vulnerability, tracked as CVE-2025-49113 (CVSS...
A newly disclosed vulnerability in vBulletin, one of the most widely used commercial forum platforms on the...
Okta has issued a critical security advisory warning developers and enterprises using the Auth0-PHP SDK about a...
A critical security vulnerability, tracked as CVE-2024-58136 (CVSS 9.1), has been uncovered in the popular PHP web...