Easyphp
Easyphp Webserver: vulnerabilities and CVEs
Easyphp Webserver has 4 published vulnerabilities, 2 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs4
Last 12 months2
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-53944 | High (7.1) | 0.95% | — | Dec 18, 2025 | EasyPHP Webserver 14.1 contains a path traversal vulnerability that allows remote users with low privileges to access files outside the document root by bypassing SecurityManager restrictions. Attackers can send GET… |
| CVE-2023-53941 | Critical (9.3) | 6.4% | — | Dec 18, 2025 | EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by injecting malicious payloads through the app_service_control parameter.… |
| CVE-2024-11215 | Medium (6.5) | 0.76% | — | Nov 14, 2024 | Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. This vulnerability could allow remote users to bypass SecurityManager… |
| CVE-2023-3767 | Critical (9.8) | 1.8% | — | Sep 27, 2023 | An OS command injection vulnerability has been found on EasyPHP Webserver affecting version 14.1. This vulnerability could allow an attacker to get full access to the system by sending a specially crafted exploit to the… |