Phpunit Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    1
    Critical Level Threats
    2
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-41570

    PHPUnit: Argument injection via newline in PHP INI values forwarded to child processes

    Last Modified: May 08, 2026
    Published: May 08, 2026

    CVE-2026-24765

    PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling

    Last Modified: Apr 18, 2026
    Published: Jan 27, 2026

    CVE-2017-9841

    Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.

    Last Modified: Apr 21, 2026
    Published: Jun 27, 2017

    CVE-2013-4744

    Cross-site scripting (XSS) vulnerability in the PHPUnit extension before 3.5.15 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Last Modified: Apr 11, 2025
    Published: Jul 01, 2013
    Items Per Page