Review reviewHigh

CVE-2026-6735

PHP Group PHP, php

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

CVSS
7.3
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.05.10
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.3

Vulnerability overview

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause the target to execute arbitrary JavaScript code (XSS) on the target's machine when the target is viewing the PHP-FPM status page.

Affected product and versions

Product
PHP Group PHP, php
Affected versions
>= 8.2.* < 8.2.31, >= 8.3.* < 8.3.31, >= 8.4.* < 8.4.21, >= 8.5.* < 8.5.6, >= 8.2.0 < 8.2.31, >= 8.3.0 < 8.3.31, >= 8.4.0 < 8.4.21, >= 8.5.0 < 8.5.6
Fixed versions
8.2.31, 8.3.31, 8.4.21, 8.5.6

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that PHP Group PHP, php and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:L/U:Amber
CWE
CWE-79
CVE-2026-6735 — PHP Group PHP, php | SECUFOCUS NOW