PHP 8.3.x < 8.3.35 Multiple Vulnerabilities

high Nessus Plugin ID 349675

Synopsis

The version PHP running on the remote web server is affected by multiple vulnerabilities.

Description

The version of PHP installed on the remote host is prior to 8.3.35. It is, therefore, affected by multiple vulnerabilities as referenced in the Version 8.3.35 advisory.

- Debian Linux - php8.2 - None php8.4 - None (CVE-2025-1218, CVE-2025-14181, CVE-2026-6103, CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768, CVE-2026-91769, CVE-2026-92842, CVE-2026-93682)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to PHP version 8.3.35 or later.

See Also

http://php.net/ChangeLog-8.php#8.3.35

http://www.nessus.org/u?0f9a7e4b

http://www.nessus.org/u?52e912ef

http://www.nessus.org/u?70510eb2

http://www.nessus.org/u?88de593e

http://www.nessus.org/u?8cbf7297

http://www.nessus.org/u?8e93272b

http://www.nessus.org/u?b72edf39

http://www.nessus.org/u?c18bb54f

http://www.nessus.org/u?c1ce4dc5

http://www.nessus.org/u?d76b6517

http://www.nessus.org/u?f4778a18

Plugin Details

Severity: High

ID: 349675

File Name: php_8_3_35.nasl

Version: 1.1

Type: Remote

Family: CGI abuses

Published: 9/24/2026

Updated: 9/24/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2026-93682

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:php:php

Required KB Items: www/PHP, installed_sw/PHP

Exploit Ease: No known exploits are available

Patch Publication Date: 9/24/2026

Vulnerability Publication Date: 9/24/2026

Reference Information

CVE: CVE-2025-1218, CVE-2025-14181, CVE-2026-17545, CVE-2026-6103, CVE-2026-91765, CVE-2026-91766, CVE-2026-91767, CVE-2026-91768, CVE-2026-91769, CVE-2026-92842, CVE-2026-93682