Phpunit
This hub aggregates every CVE we track for Phpunit, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
4
CVEs tracked
1
Critical
2
High
1
In CISA KEV
Severity distribution
HIGH2MEDIUM1CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
1
0
0
0
0
2024-102026-09
Latest CVEs
The 4 most recently published vulnerabilities affecting Phpunit.
- CVE-2026-41570PHPUnit: Argument injection via newline in PHP INI values forwarded to child processes7.8
- CVE-2026-24765PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling7.8
- CVE-2017-9841Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated b...KEV9.8
- CVE-2013-4744Cross-site scripting (XSS) vulnerability in the PHPUnit extension before 3.5.15 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.4.3
Product normalization is registry-driven with AI assist and human review. How it works