Pear
Pearweb: vulnerabilidades y CVE
Pearweb tiene 9 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses9
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-25241 | Crítica (9.3) | 0.43% | — | 3 feb 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection in the /get/<package>/<version> endpoint allows remote attackers to execute arbitrary… |
| CVE-2026-25240 | Media (6.9) | 0.28% | — | 3 feb 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability can occur in user::maintains() when role filters are provided as an array and interpolated… |
| CVE-2026-25239 | Alta (8.2) | 0.22% | — | 3 feb 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in apidoc queue insertion can allow query manipulation if an attacker can influence the… |
| CVE-2026-25238 | Crítica (9.2) | 0.28% | — | 3 feb 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in bug subscription deletion may allow attackers to inject SQL via a crafted email value.… |
| CVE-2026-25237 | Crítica (9.2) | 0.41% | — | 3 feb 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() with the /e modifier in bug update email handling can enable PHP code execution if… |
| CVE-2026-25236 | Media (6.9) | 0.28% | — | 3 feb 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in karma queries due to unsafe literal substitution for an IN (...) list. This issue has been… |
| CVE-2026-25235 | Alta (8.2) | 0.26% | — | 3 feb 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable verification hashes may allow attackers to guess verification tokens and potentially verify election account… |
| CVE-2026-25234 | Media (5.3) | 0.26% | — | 3 feb 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in category deletion can allow an attacker with access to the category manager workflow to… |
| CVE-2026-25233 | Alta (7.1) | 0.33% | — | 3 feb 2026 | PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadmap role check allows non-lead maintainers to create, update, or delete roadmaps. This issue has… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.