CVE-2026-6735

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-05-10 05:16

Updated : 2026-07-24 08:10


NVD link : CVE-2026-6735

Mitre link : CVE-2026-6735

CVE.ORG link : CVE-2026-6735


JSON object : View

Products Affected

php

  • php
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')