Home/Product/pear pearweb
Product

pear pearweb

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-25241
< 1.33.0
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, an unauthenticated SQL injection
9.8CRITICAL
CVE-2026-25240
< 1.33.0
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability ca
9.8CRITICAL
CVE-2026-25239
< 1.33.0
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in
7.5HIGH
CVE-2026-25238
< 1.33.0
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in
9.8CRITICAL
CVE-2026-25237
< 1.33.0
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, use of preg_replace() with the /
9.8CRITICAL
CVE-2026-25236
< 1.33.0
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection risk exists in k
9.8CRITICAL
CVE-2026-25235
< 1.33.0
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, predictable verification hashes
7.5HIGH
CVE-2026-25234
< 1.33.0
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, a SQL injection vulnerability in
9.8CRITICAL
CVE-2026-25233
< 1.33.0
PEAR is a framework and distribution system for reusable PHP components. Prior to version 1.33.0, logic bug in the roadmap role ch
9.1CRITICAL
CVE-2022-27158
< 1.32.0
pearweb < 1.32 suffers from Deserialization of Untrusted Data.
9.8CRITICAL
CVE-2022-27157
< 1.32.0
pearweb < 1.32 is suffers from a Weak Password Recovery Mechanism via include/users/passwordmanage.php.
9.8CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin