⤷ Title: Four-Way PHP Domino-Fall: Unchecked Input to Full Root Compromise
════════════════════════
𐀪 Author: Xia0checkmate
════════════════════════
ⴵ Time: Fri, 29 May 2026 17:39:38 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #critical_thinking #bug_bounty_writeup #source_code_review #php
════════════════════════
𐀪 Author: Xia0checkmate
════════════════════════
ⴵ Time: Fri, 29 May 2026 17:39:38 GMT
════════════════════════
⌗ Tags: #rce_vulnerability #critical_thinking #bug_bounty_writeup #source_code_review #php
Medium
Four-Way PHP Domino-Fall: Unchecked Input to Full Root Compromise
A single, seemingly innocent HTTP endpoint can form a critical business-impact chain when multiple structural PHP weaknesses are stitched…
⤷ Title: exfiltration using numeric-only outputs
════════════════════════
𐀪 Author: Bartosz
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 07:50:37 GMT
════════════════════════
⌗ Tags: #pentesting #infosec #hacking #php
════════════════════════
𐀪 Author: Bartosz
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 07:50:37 GMT
════════════════════════
⌗ Tags: #pentesting #infosec #hacking #php
Medium
exfiltration using numeric-only outputs
after identifying a code-injection vulnerability, we always want to look around inside the compromised system. most of the time, we can…
⤷ Title: PhpSpreadsheet RCE Vulnerability: PoC Exploit Disclosed for 312 Million Users
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 01:33:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_45034 #cybersecurity #Exploit #php #PhpSpreadsheet #rce
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 11 Jun 2026 01:33:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_45034 #cybersecurity #Exploit #php #PhpSpreadsheet #rce
Daily CyberSecurity
PhpSpreadsheet RCE Vulnerability: PoC Exploit Disclosed for 312 Million Users
A critical PhpSpreadsheet RCE vulnerability impacts 312 million users. Learn how the CVE-2026-45034 exploit bypasses patches and triggers code execution.
⤷ Title: Part 3/3: Exploiting phpinfo() — Turning Information into Compromise
════════════════════════
𐀪 Author: Cybersecplayground
════════════════════════
ⴵ Time: Sun, 14 Jun 2026 19:25:11 GMT
════════════════════════
⌗ Tags: #php #penetration_testing #bug_bounty #information_leak #phpinfo
════════════════════════
𐀪 Author: Cybersecplayground
════════════════════════
ⴵ Time: Sun, 14 Jun 2026 19:25:11 GMT
════════════════════════
⌗ Tags: #php #penetration_testing #bug_bounty #information_leak #phpinfo
Medium
🎓 Part 3/3: Exploiting phpinfo() — Turning Information into Compromise 🎓
Finding a phpinfo() file is just the beginning. The real value comes from analyzing its contents and using that data to advance your…
⤷ Title: CodeIgniter Vulnerability Enables Arbitrary Code Execution (CVSS 9.8)
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 00:54:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CodeIgniter #CVE_2026_48062 #File Upload Vulnerability #PHP Security #rce
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 15 Jun 2026 00:54:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CodeIgniter #CVE_2026_48062 #File Upload Vulnerability #PHP Security #rce
Daily CyberSecurity
CodeIgniter Vulnerability Enables Arbitrary Code Execution (CVSS 9.8)
A serious CodeIgniter vulnerability has put many PHP web applications at risk. Tracked as CVE-2026-48062, the flaw carries a critical CVSS score of 9.8. Moreover, it can hand attackers full arbitr…
⤷ Title: Analysis CVE-2026–48907 — Joomla JCE
════════════════════════
𐀪 Author: xpl0dec
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 13:11:53 GMT
════════════════════════
⌗ Tags: #php #hacking #proof_of_concept #vulnerability #cybersecurity
════════════════════════
𐀪 Author: xpl0dec
════════════════════════
ⴵ Time: Tue, 16 Jun 2026 13:11:53 GMT
════════════════════════
⌗ Tags: #php #hacking #proof_of_concept #vulnerability #cybersecurity
Medium
Analysis CVE-2026–48907 — Joomla JCE
Sekitar beberapa hari lalu, terdapat kerentanan pada extension JCE(Joomla Content Editor) yang digunakan CMS joomla untuk menggantikan…
⤷ Title: Secure by Design: Implementing Advanced Security in Laravel
════════════════════════
𐀪 Author: Hector Canovas
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 06:29:38 GMT
════════════════════════
⌗ Tags: #cybersecurity #sql_injection #php #software_architecture #laravel
════════════════════════
𐀪 Author: Hector Canovas
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 06:29:38 GMT
════════════════════════
⌗ Tags: #cybersecurity #sql_injection #php #software_architecture #laravel
Medium
Secure by Design: Implementing Advanced Security in Laravel
Strengthen Your Laravel Fortress Against Modern Threats
⤷ Title: PHP Patches Remote DoS Flaw CVE-2026-12184 and an OpenSSL Memory Corruption Bug
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 02:41:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12184 #CVE_2026_14355 #Denial of Service #memory corruption #php #PHP_FPM #Remote DoS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 06 Jul 2026 02:41:37 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12184 #CVE_2026_14355 #Denial of Service #memory corruption #php #PHP_FPM #Remote DoS
Daily CyberSecurity
PHP Patches Remote DoS Flaw CVE-2026-12184 and an OpenSSL Memory Corruption Bug
TL;DR The PHP team fixed two flaws, including a PHP remote DoS that can crash a whole PHP-FPM pool. CVE-2026-12184 (CVSS 8.2) triggers on a failed TLS handshake with a remote server. A second bug,…
⤷ Title: CVE-2026-59948: PHP Composer Flaw Lets Packages Execute Code Outside the Project Context
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 13:30:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_59946 #CVE_2026_59947 #CVE_2026_59948 #Path Traversal #PHP Composer #Supply Chain
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 14 Jul 2026 13:30:50 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary File Write #CVE_2026_59946 #CVE_2026_59947 #CVE_2026_59948 #Path Traversal #PHP Composer #Supply Chain
Daily CyberSecurity
CVE-2026-59948: PHP Composer Flaw Lets Packages Execute Code Outside the Project Context
TL;DR PHP Composer, the main dependency manager for the language, patched three security flaws. The most serious, CVE-2026-59948, is an arbitrary file write rated CVSS 7.0. A malicious package can…
⤷ Title: Hwat Hell Machine Hacking | Achieving Reverse Shell and Capturing the Flags
════════════════════════
𐀪 Author: ABDUL AHAD
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 16:39:11 GMT
════════════════════════
⌗ Tags: #hacking #web_enumeration #ctf #php_reverse_shell #sql_injection
════════════════════════
𐀪 Author: ABDUL AHAD
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 16:39:11 GMT
════════════════════════
⌗ Tags: #hacking #web_enumeration #ctf #php_reverse_shell #sql_injection
Medium
Hwat Hell Machine Hacking | Achieving Reverse Shell and Capturing the Flags
hwats hell machine
⤷ Title: A Crypto Zero-Day Huntress
════════════════════════
𐀪 Author: CypherBlush™
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 22:27:29 GMT
════════════════════════
⌗ Tags: #infosec #women_in_tech #php #defi #cryptocurrency
════════════════════════
𐀪 Author: CypherBlush™
════════════════════════
ⴵ Time: Tue, 21 Jul 2026 22:27:29 GMT
════════════════════════
⌗ Tags: #infosec #women_in_tech #php #defi #cryptocurrency
Medium
A Crypto Zero-Day Huntress
Securing Crypto Wallet Architecture
⤷ Title: Source Code Review: PHP | TryHackMe
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 11:01:08 GMT
════════════════════════
⌗ Tags: #tryhackme #php #cybersecurity #red_team
════════════════════════
𐀪 Author: Ryca
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 11:01:08 GMT
════════════════════════
⌗ Tags: #tryhackme #php #cybersecurity #red_team
Medium
Source Code Review: PHP | TryHackMe
Learn the basics of source code review for PHP.
⤷ Title: CVE-2026-45293: Arbitrary Code Execution in WordPress Coding Standards, a Tool With 49M+ Installs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 01:02:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CI/CD security #CVE_2026_45293 #PHP_CodeSniffer #PHPCS #Static Analysis #Supply Chain Security #WordPress Coding Standards #WordPressCS
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 29 Jul 2026 01:02:18 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Arbitrary Code Execution #CI/CD security #CVE_2026_45293 #PHP_CodeSniffer #PHPCS #Static Analysis #Supply Chain Security #WordPress Coding Standards #WordPressCS
Daily CyberSecurity
CVE-2026-45293: Arbitrary Code Execution in WordPress Coding Standards, a Tool With 49M+ Installs
TL;DR A flaw in WordPress Coding Standards lets malicious PHP run code on the machine that lints it. Tracked as CVE-2026-45293, the bug carries a CVSS score of 8.6. The advisory calls it “an…
⤷ Title: PHP SQL Injection Flaw CVE-2026-17543 Patched in Latest Release
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 01:58:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BCMath #CVE_2026_17543 #php #PHP Security #PostgreSQL #sql injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 01:58:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BCMath #CVE_2026_17543 #php #PHP Security #PostgreSQL #sql injection
Daily CyberSecurity
PHP SQL Injection Flaw CVE-2026-17543 Patched in Latest Release
TL;DR The PHP project fixed three flaws in its latest releases. The headline bug is a PHP SQL injection flaw, CVE-2026-17543, in the PostgreSQL extension. Two memory-safety bugs round out the set.…
⤷ Title: CVE-2026-63223: CodeIgniter4 RCE Vulnerability Rated CVSS 9.8
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 09:19:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CodeIgniter4 #CVE_2026_63223 #File Upload Vulnerability #Path Traversal #PHP Framework #Remote Code Execution #sql injection #Web Security
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 31 Jul 2026 09:19:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CodeIgniter4 #CVE_2026_63223 #File Upload Vulnerability #Path Traversal #PHP Framework #Remote Code Execution #sql injection #Web Security
Daily CyberSecurity
CVE-2026-63223: CodeIgniter4 RCE Vulnerability Rated CVSS 9.8
TL;DR: The CodeIgniter4 team patched four security flaws in release v4.7.4. The most severe, a CodeIgniter4 RCE vulnerability tracked as CVE-2026-63223, scores CVSS 9.8. It can lead to remote code…
⤷ Title: The Debug Flag That Opened the Door: A Journey From Django Debug Mode to Critical RCE
════════════════════════
𐀪 Author: Forhad Parvez
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 17:39:17 GMT
════════════════════════
⌗ Tags: #django #vulnerability_assessment #rce #bug_bounty #php
════════════════════════
𐀪 Author: Forhad Parvez
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 17:39:17 GMT
════════════════════════
⌗ Tags: #django #vulnerability_assessment #rce #bug_bounty #php
Medium
The Debug Flag That Opened the Door: A Journey From Django Debug Mode to Critical RCE
About Me
⤷ Title: Top 5 PHP Frameworks for Web Development in 2025
════════════════════════
𐀪 Author: Sahil Khurana
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 05:18:03 GMT
════════════════════════
⌗ Tags: #web_development #backend_development #scalable_solutions #application_security #php_frameworks
════════════════════════
𐀪 Author: Sahil Khurana
════════════════════════
ⴵ Time: Fri, 14 Aug 2026 05:18:03 GMT
════════════════════════
⌗ Tags: #web_development #backend_development #scalable_solutions #application_security #php_frameworks
Medium
Top 5 PHP Frameworks for Web Development in 2025
Originally published on the Innostax Engineering Blog
⤷ Title: File Upload Security: Polyglots, Content-Type Confusion, and Storage Risks
════════════════════════
𐀪 Author: CYBER MIND SPACE
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:46:24 GMT
════════════════════════
⌗ Tags: #ethical_hacking #file_upload_security #cybersecurity #cybermindspace #php
════════════════════════
𐀪 Author: CYBER MIND SPACE
════════════════════════
ⴵ Time: Wed, 19 Aug 2026 03:46:24 GMT
════════════════════════
⌗ Tags: #ethical_hacking #file_upload_security #cybersecurity #cybermindspace #php
Medium
File Upload Security: Polyglots, Content-Type Confusion, and Storage Risks
The file passed image validation. It was also PHP. That’s the whole attack.