PT-2026-39445 · Php+4 · Php+4

·

CVE-2026-6735

·

Published

2026-05-07

·

Updated

2026-09-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PHP versions 8.2.0 through 8.2.30 PHP versions 8.3.0 through 8.3.30 PHP versions 8.4.0 through 8.4.20 PHP versions 8.5.0 through 8.5.5
Description Improper sanitation of user data allows an attacker to compose a URL that executes arbitrary JavaScript code (Cross-Site Scripting) on a user's machine when viewing the PHP-FPM status page.
Recommendations Update to version 8.2.31 Update to version 8.3.31 Update to version 8.4.21 Update to version 8.5.6

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:22142
ALSA-2026:22143
ALSA-2026:22305
ALSA-2026:22649
ALSA-2026:23388
ALSA-2026:33449
ALSA-2026:34354
AZL-86352
BDU:2026-09671
BIT-LIBPHP-2026-6735
BIT-PHP-2026-6735
BIT-PHP-MIN-2026-6735
CVE-2026-6735
OESA-2026-2342
OESA-2026-2343
OESA-2026-2344
OESA-2026-2420
OESA-2026-2421
OPENSUSE-SU-2026:10747-1
RHSA-2026:14125
RHSA-2026:22142
RHSA-2026:22143
RHSA-2026:22305
RHSA-2026:23388
RHSA-2026:33449
RHSA-2026:34354
USN-8336-1

Affected Products

Linuxmint
Php
Red Os
Rocky Linux
Ubuntu