Phpunit/phpunit
This hub aggregates every CVE we track for Phpunit/phpunit, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
1
Critical
1
High
1
In CISA KEV
Severity distribution
HIGH1CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
2
0
0
0
0
0
2024-102026-09
Latest CVEs
The 4 most recently published vulnerabilities affecting Phpunit/phpunit.
- GHSA-mh6w-vxff-9wqpPHPUnit: Argument injection via newline in PHP INI values forwarded to child processes
- GHSA-qrr6-mg7r-m243PHPUnit has Argument injection via newline in PHP INI values that are forwarded to child processes
- CVE-2026-24765PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling7.8
- CVE-2017-9841Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated b...KEV9.8
Product normalization is registry-driven with AI assist and human review. How it works