VYPR

Vendor CVEs

Pear

All CVEs

31 total · sorted by risk
  • CVE-2026-25241CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.00

    PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get// endpoint allows remote attackers to execute arbitrary SQL via a crafted package version. This issue has been patched…

  • CVE-2026-25240CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.00

    PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability can occur in user::maintains() when role filters are provided as an array and interpolated into an IN (...) clause. This issue has been patched in…

  • CVE-2026-25238CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.00

    PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription deletion may allow attackers to inject SQL via a crafted email value. This issue has been patched in version 1.33.0.

  • CVE-2026-25237CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.00

    PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() with the /e modifier in bug update email handling can enable PHP code execution if attacker-controlled content reaches the evaluated replacement. This issue…

  • CVE-2026-25236CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.00

    PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to unsafe literal substitution for an IN (...) list. This issue has been patched in version 1.33.0.

  • CVE-2026-25234CriFeb 3, 2026
    risk 0.64cvss 9.8epss 0.00

    PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in category deletion can allow an attacker with access to the category manager workflow to inject SQL via a category id. This issue has been patched in…

  • CVE-2018-1999022CriJul 23, 2018
    risk 0.64cvss 9.8epss 0.02

    PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue method, HTML_QuickForm's validate method, HTML_QuickForm_hierselect's _setOptions method, HTML_QuickForm_element's _findValue method, HTML_QuickForm_element's…

  • CVE-2017-5677CriFeb 6, 2017
    risk 0.64cvss 9.8epss 0.05

    PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression.

  • CVE-2026-25233CriFeb 3, 2026
    risk 0.59cvss 9.1epss 0.00

    PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadmap role check allows non-lead maintainers to create, update, or delete roadmaps. This issue has been patched in version 1.33.0.

  • CVE-2018-1000888HigDec 28, 2018
    risk 0.55cvss 8.8epss 0.19

    PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When extract is called without a specific…

  • CVE-2026-25239HigFeb 3, 2026
    risk 0.49cvss 7.5epss 0.00

    PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in apidoc queue insertion can allow query manipulation if an attacker can influence the inserted filename value. This issue has been patched in version…

  • CVE-2026-25235HigFeb 3, 2026
    risk 0.49cvss 7.5epss 0.00

    PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable verification hashes may allow attackers to guess verification tokens and potentially verify election account requests without authorization. This issue has been patched…

  • CVE-2022-24953MedFeb 17, 2022
    risk 0.28cvss 5.3epss 0.01

    The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environments and GPG versions.

  • CVE-2005-1921Jul 5, 2005
    risk 0.09cvss —epss 0.79

    Eval injection vulnerability in PEAR XML_RPC 1.3.0 and earlier (aka XML-RPC or xmlrpc) and PHPXMLRPC (aka XML-RPC For PHP or php-xmlrpc) 1.1 and earlier, as used in products such as (1) WordPress, (2) Serendipity, (3) Drupal, (4) egroupware, (5) MailWatch, (6) TikiWiki, (7)…

  • CVE-2007-2519May 22, 2007
    risk 0.04cvss —epss 0.08

    Directory traversal vulnerability in the installer in PEAR 1.0 through 1.5.3 allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in the (1) install-as attribute in the file element in package.xml 1.0 or the (2) as attribute in the…

  • CVE-2006-0869Feb 23, 2006
    risk 0.03cvss —epss 0.04

    Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly…

  • CVE-2005-4154Dec 11, 2005
    risk 0.01cvss —epss 0.07

    Unspecified vulnerability in PEAR installer 1.4.2 and earlier allows user-assisted attackers to execute arbitrary code via a crafted package that can execute code when the pear command is executed or when the Web/Gtk frontend is loaded.

  • CVE-2022-27158CriApr 15, 2022
    risk 0.00cvss 9.8epss 0.01

    pearweb < 1.32 suffers from Deserialization of Untrusted Data.

  • CVE-2022-27157CriApr 15, 2022
    risk 0.00cvss 9.8epss 0.01

    pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.

  • CVE-2011-1144Mar 3, 2011
    risk 0.00cvss —epss 0.00

    The installer in PEAR 1.9.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_dir, (3) tmp_dir, and (4) pear-build-download directories. NOTE: this vulnerability exists because of…

  • CVE-2011-1072Mar 3, 2011
    risk 0.00cvss —epss 0.00

    The installer in PEAR before 1.9.2 allows local users to overwrite arbitrary files via a symlink attack on the package.xml file, related to the (1) download_dir, (2) cache_dir, (3) tmp_dir, and (4) pear-build-download directories, a different vulnerability than CVE-2007-2519.

  • CVE-2009-4111Nov 29, 2009
    risk 0.00cvss —epss 0.02

    Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remote attackers to read and write arbitrary files via a crafted $recipients parameter, and possibly other parameters, a different vulnerability…

  • CVE-2009-4025Nov 29, 2009
    risk 0.00cvss —epss 0.06

    Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: some of these details are obtained from third party…

  • CVE-2009-4024Nov 29, 2009
    risk 0.00cvss —epss 0.06

    Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: this has also been reported as a shell metacharacter problem.

  • CVE-2009-4023Nov 29, 2009
    risk 0.00cvss —epss 0.02

    Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for PEAR allows remote attackers to read and write arbitrary files via a crafted $from parameter, a different vector than CVE-2009-4111.

  • CVE-2007-5934Nov 13, 2007
    risk 0.00cvss —epss 0.02

    The LOB functionality in PEAR MDB2 before 2.5.0a1 interprets a request to store a URL string as a request to retrieve and store the contents of the URL, which might allow remote attackers to use MDB2 as an indirect proxy or obtain sensitive information via a URL into a form…

  • CVE-2007-3628Jul 9, 2007
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in the fetch function in MDB2.php in PEAR Structures-DataGrid-DataSource-MDB2 0.1.9 and earlier allows attackers to "manipulate the generated sorting queries."

  • CVE-2006-0932Feb 28, 2006
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a ZIP archive.

  • CVE-2006-0931Feb 28, 2006
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite arbitrary files via certain crafted pathnames in a TAR archive.

  • CVE-2006-0868Feb 23, 2006
    risk 0.00cvss —epss 0.03

    Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4, allow remote attackers to "falsify authentication credentials," related to the "underlying storage containers."

  • CVE-2005-4730Dec 31, 2005
    risk 0.00cvss —epss 0.01

    Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random number generator, possibly predictable seeds.