PHP 8.0

Status EOLSupport 2020-11 – 2023-11Latest 8.0.30Vulnerabilities 27← All PHP versions
KEV Unfixed
2024-06-09≤ 8.0.30

Argument Injection in PHP-CGI

Critical 9.8
2017-05-12< 8.0.11

php: Overflowing the length of string causes crash

Critical 9.8
2018-08-02< 8.0.10

php: Integer overflow in mysqli_api.c:mysqli_real_escape_string()

Critical 9.8
2022-10-21< 8.0.25

XKCP: buffer overflow in the SHA-3 reference implementation

Critical 9.4
2023-08-11< 8.0.30

Buffer overflow and overread in phar_dir_read()

Critical 9.1
2025-02-12< 8.0.27

PDO::quote() may return unquoted string

High 8.6
2023-08-11< 8.0.30

Security issue with external entity loading in XML without enabling it

High 8.2
2022-02-27< 8.0.16

UAF due to php_filter_float() failing

High 8.1
2022-06-16< 8.0.20

Freeing unallocated memory in php_pgsql_free_params()

High 7.8
2021-10-25< 8.0.12

PHP-FPM memory access in root process leading to privilege escalation

High 7.7
2023-02-16< 8.0.28

password_verify() always returns true for some invalid hashes

High 7.5
2018-08-02< 8.0.14

php: Out of bounds access in php_pcre.c:php_pcre_replace_impl()

High 7.5
2022-06-16< 8.0.20

mysqlnd/pdo password buffer overflow

High 7.5
2023-02-16< 8.0.28

Array overrun in common path resolve code

High 7.5
2023-02-16< 8.0.28

DoS vulnerability when parsing multipart request body

Medium 6.5
2022-09-28< 8.0.24

$_COOKIE names string replacement (. -> _): cookie integrity vulnerabilities

Medium 6.5
2022-11-14< 8.0.25

OOB read due to insufficient input validation in imageloadfont()

Medium 6.2
2023-11-02< 8.0.22

Potential buffer overflow in php_cli_server_startup_workers

Medium 5.3 Unfixed
2024-06-09≥ 8.0.2 and ≤ 8.0.30

Filter bypass in filter_var (FILTER_VALIDATE_URL)

Medium 5.3
2021-02-15< 8.0.1

FILTER_VALIDATE_URL accepts URLs with invalid userinfo

Medium 5.3
2021-02-15< 8.0.2

Null Dereference in SoapClient

Medium 5.3
2021-10-04< 8.0.11

ZipArchive::extractTo may extract outside of destination dir

Medium 5.3
2021-11-29< 8.0.13

Special characters break path parsing in XML functions

Medium 5.0
2021-10-04< 8.0.8

Multiple vulnerabilities in Firebird client extension

Medium 4.3
2021-10-04< 8.0.8

Incorrect URL validation in FILTER_VALIDATE_URL

Low 2.6
2023-07-22< 8.0.29

Missing error check and insufficient random bytes in HTTP Digest authentication for SOAP

Low 2.3
2022-09-28< 8.0.24

phar wrapper can occur dos when using quine gzip file