Skip to content

language

PHP

Widely used open-source scripting language for server-side web development, powering sites and frameworks like WordPress, Laravel, and Symfony.

Known aliases

  • libphp
  • PHP 7.1.5
  • PHP 8
  • PHP 8.4
  • PHP 8.5
  • PHP 8.5.8
  • PHP 8.6
  • PHP 8.7
  • PHP 8.x
  • php-src

Relationships

No evidence-backed relationships are recorded.

Current stories

build1 publisher

Exploit attempts for WordPress CVE-2026-87902 began the day 7.1.2 shipped

WordPress released 7.1.2 on 22 September 2026 to fix remote file inclusion flaw CVE-2026-87902, and the first exploit attempt was recorded the same day. The fix was back-ported to every maintained branch down to 4.7, so an exposed site has hours before scanners find it.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence40
build1 publisher

Symfony 8 swaps generated DI proxies for PHP 8.4's native lazy objects

Symfony 8 creates its container services as PHP 8.4 native lazy objects, cutting boot time 15-25% for apps with 200+ services, according to a dev.to post. The gain comes from retiring generated proxy classes, so it depends on how much boot time those classes cost you.

Publishers:dev.to

Reality

Evidence30
Adoption
Insufficient
Hype gap+35
Incentives
Insufficient
Confidence35
security5 publishers

Two miniOrange SAML bugs under attack, and 30,000 paid installs were never told

Patchstack says attackers are chaining CVE-2026-61979 and CVE-2026-15981 to mint WordPress admin sessions. Only the free edition got an advisory; Standard needs 17.0.6.

Perspective Coverage

5 publishers
Builder
Builder 32%
Operator
Operator 56%
Investor
Investor 12%

Reality

Evidence70
Adoption30
Hype gap+15
Incentives
Insufficient
Confidence68

Earlier coverage

  1. Three in four VAPID signatures return 401 until the DER wrapper comes off

    Build · September 16, 2026 · 1 publisher

  2. The image proxy fetches 169.254.169.254 as readily as it fetches a cat photo

    Build · September 15, 2026 · 1 publisher

  3. A checked-in snapshot attributes 59 of a Go service's 67 metric records to the platform

    Build · September 14, 2026 · 1 publisher

  4. A build target greps a fake version string out of both binaries to prove the ldflags symbol exists

    Build · September 14, 2026 · 1 publisher

  5. xz refuses to unpack a PHP extension when Docker's seccomp answers Landlock with EACCES

    Build · September 14, 2026 · 1 publisher

  6. A --check run of the env generator exits non-zero when the committed catalog drifts

    Build · September 13, 2026 · 1 publisher

  7. Replacing node objects with integer indexes lifts a PHP LRU to 13.1 million ops/sec

    Build · September 12, 2026 · 1 publisher

  8. An md5 reset token shrinks the attacker's search space to 3,600 guesses an hour

    Build · September 11, 2026 · 1 publisher

  9. Writing the task text before the research encodes a guess

    Build · September 11, 2026 · 1 publisher

  10. A read-only robots.txt dated two years before the domain passed three monitors

    Build · September 10, 2026 · 1 publisher

  11. Adobe's out-of-band Magento hotfix lands after attackers installed backdoors disguised as kworker

    Security · September 10, 2026 · 1 publisher

  12. A WordPress domain migration breaks on the byte count PHP stored beside every string

    Build · September 10, 2026 · 1 publisher

  13. Magento's silent RabbitMQ backlogs, from late order emails to stuck bulk jobs, often trace to missing or stalled consumers

    Build · September 10, 2026 · 1 publisher

  14. Treating MTN's 409 as a failure is what double-charges the customer

    Build · September 9, 2026 · 1 publisher

  15. StyleSmuggler runs its PHP inside Magento's failed-payment email renderer

    Build · September 8, 2026 · 1 publisher

  16. Attacker PHP executes when Magento renders its failed-payment reminder email

    Build · September 8, 2026 · 1 publisher

  17. StyleSmuggler turns a Magento payment-reminder email into unauthenticated code execution

    Security · September 8, 2026 · 1 publisher

  18. Elementor Pro's upload validator returns early when the first array element is empty

    Build · September 4, 2026 · 1 publisher

  19. Two-file iterations burned 350,000 tokens because the executor went looking around the repo first

    Build · September 4, 2026 · 1 publisher

  20. One hardcoded RenderContext(80, 24) hid the height bug from 92 passing tests

    Build · September 3, 2026 · 1 publisher

  21. GOautodial runs an agent's logout parameter through /bin/sh

    Build · September 2, 2026 · 1 publisher

  22. A 100-worker PHP-FPM pool tops out at 500 req/sec on a 200ms endpoint

    Build · September 1, 2026 · 1 publisher

  23. systemctl restart reopens the app port 2.9 seconds after the atomic symlink swap

    Build · August 30, 2026 · 1 publisher

  24. HttpIdempotencyBundle hashes six request fields before it will replay a stored response

    Build · August 30, 2026 · 1 publisher

  25. An AI agent on the buyer's network probed this vendor at four addresses that all returned 404

    Build · August 29, 2026 · 1 publisher

  26. Temporal's determinism rule forces the three-day wait out of your Laravel job class

    Build · August 29, 2026 · 1 publisher

  27. Twenty-four messages on the PHP internals list separate translation from delegated argument

    Build · August 27, 2026 · 1 publisher

  28. All-Line's Fuel-Boss inherits both of its remote code execution bugs from PHP 7.1.5

    Security · August 27, 2026 · 1 publisher

  29. Six bugs, one order of operations: Avada's zero-click chain is a same-day patch

    Security · August 26, 2026 · 1 publisher

  30. Kaltura's unpatched player bugs arrive with a coordinator that could not reach the vendor

    Security · August 26, 2026 · 1 publisher

  31. Shopware concedes @deprecated was the wrong signal, and splits it in 6.7.14.0

    Build · August 25, 2026 · 1 publisher

  32. One slug, seven editions: the miniOrange SAML bug that makes published metadata an admin login

    Build · August 24, 2026 · 1 publisher

  33. One awkward sentence exposed 2,200 fake-bank domains built on a $25 template

    Security · August 24, 2026 · 1 publisher

  34. Rewritten tags beat your pin: what laravel-lang says about Composer trust

    Build · August 22, 2026 · 1 publisher

  35. array_search_range meets the freeze: PHP internals wants a lazy slice, not another array function

    Build · August 21, 2026 · 1 publisher

  36. Six MariaDB versions, one real difference: the only reason to leave 10.6 is the July 2026 clock

    Build · August 21, 2026 · 1 publisher

  37. Stop defending numprocs=10: derive queue workers from a latency promise

    Build · August 21, 2026 · 1 publisher

  38. Once the question needs a cube, you own the parser

    Build · August 20, 2026 · 1 publisher

  39. PHP-FPM's dynamic pool is a one-second idle-worker loop, not a capacity plan

    Build · August 20, 2026 · 1 publisher

  40. The guard that worked in tests and still wrote 2,684 live records

    Build · August 19, 2026 · 1 publisher