php
Safeguard articles tagged "php" — guides, analysis, and best practices for software supply chain and application security.
19 articles
CVE-2012-1823: PHP-CGI Query String Parameter Vulnerability
CVE-2012-1823 affects PHP PHP and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-03-25.
CVE-2019-11043: PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
CVE-2019-11043 affects PHP FastCGI Process Manager (FPM) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2022-03-25.
CVE-2016-10033: PHPMailer Command Injection Vulnerability
CVE-2016-10033 affects PHP PHPMailer and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-07.
Laravel Livewire's Hydration Flaw Let Attackers Skip Authentication Entirely
CVE-2025-54068 lets unauthenticated attackers achieve remote command execution in Laravel Livewire v3 through how component property updates are hydrated, with no known workaround.
A hardening checklist for modern Drupal deployments
Drupal 7's 2025 end-of-life left unsupported sites exposed; here's a concrete checklist for module vetting, access control, and patch cadence on Drupal 10/11.
PHP-CGI Argument Injection RCE on Windows (CVE-2024-4577) Explained
CVE-2024-4577 revived a decade-old PHP-CGI flaw through a Windows Unicode 'best-fit' quirk, yielding unauthenticated RCE. Here's the mechanism and the patched versions.
PHPStan vs. Psalm: setting up PHP static analysis to catch security bugs pre-commit
Psalm ships free taint analysis out of the box; PHPStan doesn't track data flow at all without extensions. Here's how to wire either one into pre-commit.
Building a minimal, multi-stage, non-root Dockerfile for PHP
The official php:fpm image still runs its master process as root — a documented, still-open issue. Here's how to build a PHP Dockerfile that doesn't.
What PHP's use-after-free bugs teach us about dynamic-runtime memory safety
Check Point disclosed three PHP 7 unserialize zero-days in 2016 alone. A decade of PHP use-after-free CVEs shows memory-safety risk doesn't end at the C/C++ boundary.
PHP Code Review Tools: An Honest 2026 Buyer's Guide
A balanced 2026 comparison of PHP code review and static-analysis tools — PHPStan, Psalm, PHP_CodeSniffer, progpilot, Semgrep, SonarQube — with honest tradeoffs and where Safeguard fits.
Auditing PHP Dependencies with composer audit
Composer ships a native security auditor. Learn to run composer audit against your composer.lock, catch abandoned packages, and extend it with continuous SCA.
Drupalgeddon2 (CVE-2018-7600) Explained: Drupal's Form API RCE
CVE-2018-7600, known as Drupalgeddon2, is a CVSS 9.8 unauthenticated remote code execution flaw in Drupal core's Form API. Here is how the renderable-array bug works and which versions to run.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.