← Back

CVE-2026-6735

nvd nist
Published: May 10, 2026Modified: Jul 24, 2026

JSON object

Loading...
7.3
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:L/U:Amber
Show more
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:L/U:AmberShow less
Source: security@php.net (Secondary)

Description

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

Affected (4)

Products: Php: Php
1 product
Php
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Php
From 8.2.0 to 8.2.31
From 8.3.0 to 8.3.31
From 8.4.0 to 8.4.21
From 8.5.0 to 8.5.6

References (1)

Timeline

No history available yet.