Safeguard
Tag

php

Safeguard articles tagged "php" — guides, analysis, and best practices for software supply chain and application security.

19 articles

Vulnerability Analysis

CVE-2012-1823: PHP-CGI Query String Parameter Vulnerability

CVE-2012-1823 affects PHP PHP and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-03-25.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2019-11043: PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability

CVE-2019-11043 affects PHP FastCGI Process Manager (FPM) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-03-25.

Sep 17, 20263 min read
Vulnerability Analysis

CVE-2016-10033: PHPMailer Command Injection Vulnerability

CVE-2016-10033 affects PHP PHPMailer and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-07.

Sep 17, 20263 min read
Vulnerability Analysis

Laravel Livewire's Hydration Flaw Let Attackers Skip Authentication Entirely

CVE-2025-54068 lets unauthenticated attackers achieve remote command execution in Laravel Livewire v3 through how component property updates are hydrated, with no known workaround.

Sep 16, 20264 min read
Application Security

A hardening checklist for modern Drupal deployments

Drupal 7's 2025 end-of-life left unsupported sites exposed; here's a concrete checklist for module vetting, access control, and patch cadence on Drupal 10/11.

Jul 11, 20266 min read
Vulnerability Analysis

PHP-CGI Argument Injection RCE on Windows (CVE-2024-4577) Explained

CVE-2024-4577 revived a decade-old PHP-CGI flaw through a Windows Unicode 'best-fit' quirk, yielding unauthenticated RCE. Here's the mechanism and the patched versions.

Jul 8, 20265 min read
Application Security

PHPStan vs. Psalm: setting up PHP static analysis to catch security bugs pre-commit

Psalm ships free taint analysis out of the box; PHPStan doesn't track data flow at all without extensions. Here's how to wire either one into pre-commit.

Jul 8, 20266 min read
Container Security

Building a minimal, multi-stage, non-root Dockerfile for PHP

The official php:fpm image still runs its master process as root — a documented, still-open issue. Here's how to build a PHP Dockerfile that doesn't.

Jul 8, 20267 min read
Vulnerability Management

What PHP's use-after-free bugs teach us about dynamic-runtime memory safety

Check Point disclosed three PHP 7 unserialize zero-days in 2016 alone. A decade of PHP use-after-free CVEs shows memory-safety risk doesn't end at the C/C++ boundary.

Jul 8, 20266 min read
Buyer's Guides

PHP Code Review Tools: An Honest 2026 Buyer's Guide

A balanced 2026 comparison of PHP code review and static-analysis tools — PHPStan, Psalm, PHP_CodeSniffer, progpilot, Semgrep, SonarQube — with honest tradeoffs and where Safeguard fits.

Jul 5, 20266 min read
Security Guides

Auditing PHP Dependencies with composer audit

Composer ships a native security auditor. Learn to run composer audit against your composer.lock, catch abandoned packages, and extend it with continuous SCA.

Jul 5, 20265 min read
Vulnerability Analysis

Drupalgeddon2 (CVE-2018-7600) Explained: Drupal's Form API RCE

CVE-2018-7600, known as Drupalgeddon2, is a CVSS 9.8 unauthenticated remote code execution flaw in Drupal core's Form API. Here is how the renderable-array bug works and which versions to run.

Jul 3, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.