pear records
22 published records for vendor pear.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 72.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-337 Predictable Seed in Pseudo-Random Number Generator (PRNG)1
- CWE-624 Executable Regular Expression Error1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-783 Operator Precedence Logic Error1
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2009-4025No exploit | Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows repear · pear · CWE-78 | Critical10.0 | — | 6.1% | Nov 29, 2009 |
42Plan | CVE-2009-4024No exploit | Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to epear · pear · CWE-94 | Critical10.0 | — | 6.1% | Nov 29, 2009 |
40Plan | CVE-2017-5677No exploit | PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer.pear · html ajax | Critical9.8 | — | 4.8% | Feb 6, 2017 |
40Plan | CVE-2005-4730No exploit | Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random nupear · text password | Critical10.0 | — | 1.4% | Dec 31, 2005 |
37Monitor | CVE-2026-25241No exploit | PEAR is Vulnerable to SQL Injection in /get/<package>/<version> Endpointpear · pearweb · CWE-89 | Critical9.3 | — | 0.4% | Feb 3, 2026 |
36Monitor | CVE-2026-25237No exploit | PEAR is Vulnerable to PHP Code Execution via preg_replace /e in Bug Update Emailspear · pearweb · CWE-624 | Critical9.2 | — | 0.4% | Feb 3, 2026 |
36Monitor | CVE-2026-25238No exploit | PEAR is Vulnerable to SQL Injection in Bug Subscription Deletion via Weak Email Validationpear · pearweb · CWE-89 | Critical9.2 | — | 0.3% | Feb 3, 2026 |
32Monitor | CVE-2026-25235No exploit | PEAR Has a Predictable Verification Hash in Election Account Requestspear · pearweb · CWE-337 | High8.2 | — | 0.3% | Feb 3, 2026 |
32Monitor | CVE-2026-25239No exploit | PEAR is Vulnerable to SQL Injection in apidoc_queue Insert via Unescaped Filenamepear · pearweb · CWE-89 | High8.2 | — | 0.2% | Feb 3, 2026 |
31Monitor | CVE-2006-0868No exploit | Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4pear · xml rpc | High7.5 | — | 2.5% | Feb 23, 2006 |
31Monitor | CVE-2009-4023No exploit | Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for pear · pear · CWE-94 | High7.5 | — | 2.4% | Nov 29, 2009 |
28Monitor | CVE-2026-25233No exploit | PEAR Has a Roadmap Authorization Bypass via Operator Precedence Bugpear · pearweb · CWE-783 | High7.1 | — | 0.3% | Feb 3, 2026 |
27Monitor | CVE-2009-4111No exploit | Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remotpear · mail · CWE-94 | Medium6.8 | — | 1.6% | Nov 29, 2009 |
27Monitor | CVE-2026-25240No exploit | PEAR is Vulnerable to SQL Injection in user::maintains() Role IN() Filterpear · pearweb · CWE-89 | Medium6.9 | — | 0.3% | Feb 3, 2026 |
27Monitor | CVE-2026-25236No exploit | PEAR is Vulnerable to SQL Injection in Damblan_Karma IN() Query via Literal Substitutionpear · pearweb · CWE-89 | Medium6.9 | — | 0.3% | Feb 3, 2026 |
26Monitor | CVE-2006-0869Proof of concept | Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0pear · pear liveuser | Medium6.4 | — | 4.0% | Feb 23, 2006 |
21Monitor | CVE-2006-0931No exploit | Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwritepear · pear archive tar · CWE-22 | Medium5.0 | — | 2.4% | Feb 28, 2006 |
21Monitor | CVE-2006-0932No exploit | Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files pear · pear archive zip | Medium5.0 | — | 1.9% | Feb 28, 2006 |
21Monitor | CVE-2022-24953No exploit | The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environmentpear · crypt gpg · CWE-88 | Medium5.3 | — | 0.9% | Feb 17, 2022 |
21Monitor | CVE-2026-25234No exploit | PEAR is Vulnerable to SQL Injection in Category Deletionpear · pearweb · CWE-89 | Medium5.3 | — | 0.3% | Feb 3, 2026 |
20Monitor | CVE-2007-3628No exploit | Unspecified vulnerability in the fetch function in MDB2.php in PEAR Structures-DataGrid-DataSource-MDB2 0.1.9 and earlier allows attackers tpear · structures datagrid datasource mdb2 | Medium5.0 | — | 1.0% | Jul 9, 2007 |
17Monitor | CVE-2007-5934No exploit | The LOB functionality in PEAR MDB2 before 2.5.0a1 interprets a request to store a URL string as a request to retrieve and store the contentspear · structures datagrid datasource mdb2 · CWE-200 | Medium4.3 | — | 1.6% | Nov 13, 2007 |
- CVE-2009-402542Plan
Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows re
CriticalCVSS 10.0No exploitEPSS 6%pear · pearNov 29, 2009
- CVE-2009-402442Plan
Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to e
CriticalCVSS 10.0No exploitEPSS 6%pear · pearNov 29, 2009
- CVE-2017-567740Plan
PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer.
CriticalCVSS 9.8No exploitEPSS 5%pear · html ajaxFeb 6, 2017
- CVE-2005-473040Plan
Unspecified vulnerability in PEAR Text_Password 1.0 has unknown impact and attack vectors, related to "problematic seeding" of the random nu
CriticalCVSS 10.0No exploitEPSS 1%pear · text passwordDec 31, 2005
- CVE-2026-2524137Monitor
PEAR is Vulnerable to SQL Injection in /get/<package>/<version> Endpoint
CriticalCVSS 9.3No exploitEPSS 0%pear · pearwebFeb 3, 2026
- CVE-2026-2523736Monitor
PEAR is Vulnerable to PHP Code Execution via preg_replace /e in Bug Update Emails
CriticalCVSS 9.2No exploitEPSS 0%pear · pearwebFeb 3, 2026
- CVE-2026-2523836Monitor
PEAR is Vulnerable to SQL Injection in Bug Subscription Deletion via Weak Email Validation
CriticalCVSS 9.2No exploitEPSS 0%pear · pearwebFeb 3, 2026
- CVE-2026-2523532Monitor
PEAR Has a Predictable Verification Hash in Election Account Requests
HighCVSS 8.2No exploitEPSS 0%pear · pearwebFeb 3, 2026
- CVE-2026-2523932Monitor
PEAR is Vulnerable to SQL Injection in apidoc_queue Insert via Unescaped Filename
HighCVSS 8.2No exploitEPSS 0%pear · pearwebFeb 3, 2026
- CVE-2006-086831Monitor
Multiple unspecified injection vulnerabilities in unspecified Auth Container back ends for PEAR::Auth before 1.2.4, and 1.3.x before 1.3.0r4
HighCVSS 7.5No exploitEPSS 3%pear · xml rpcFeb 23, 2006
- CVE-2009-402331Monitor
Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for
HighCVSS 7.5No exploitEPSS 2%pear · pearNov 29, 2009
- CVE-2026-2523328Monitor
PEAR Has a Roadmap Authorization Bypass via Operator Precedence Bug
HighCVSS 7.1No exploitEPSS 0%pear · pearwebFeb 3, 2026
- CVE-2009-411127Monitor
Argument injection vulnerability in Mail/sendmail.php in the Mail package 1.1.14, 1.2.0b2, and possibly other versions for PEAR allows remot
MediumCVSS 6.8No exploitEPSS 2%pear · mailNov 29, 2009
- CVE-2026-2524027Monitor
PEAR is Vulnerable to SQL Injection in user::maintains() Role IN() Filter
MediumCVSS 6.9No exploitEPSS 0%pear · pearwebFeb 3, 2026
- CVE-2026-2523627Monitor
PEAR is Vulnerable to SQL Injection in Damblan_Karma IN() Query via Literal Substitution
MediumCVSS 6.9No exploitEPSS 0%pear · pearwebFeb 3, 2026
- CVE-2006-086926Monitor
Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0
MediumCVSS 6.4Proof of conceptEPSS 4%pear · pear liveuserFeb 23, 2006
- CVE-2006-093121Monitor
Directory traversal vulnerability in PEAR::Archive_Tar 1.2, and other versions before 1.3.2, allows remote attackers to create and overwrite
MediumCVSS 5.0No exploitEPSS 2%pear · pear archive tarFeb 28, 2006
- CVE-2006-093221Monitor
Directory traversal vulnerability in zip.lib.php 0.1.1 in PEAR::Archive_Zip allows remote attackers to create and overwrite arbitrary files
MediumCVSS 5.0No exploitEPSS 2%pear · pear archive zipFeb 28, 2006
- CVE-2022-2495321Monitor
The Crypt_GPG extension before 1.6.7 for PHP does not prevent additional options in GPG calls, which presents a risk for certain environment
MediumCVSS 5.3No exploitEPSS 1%pear · crypt gpgFeb 17, 2022
- CVE-2026-2523421Monitor
PEAR is Vulnerable to SQL Injection in Category Deletion
MediumCVSS 5.3No exploitEPSS 0%pear · pearwebFeb 3, 2026
- CVE-2007-362820Monitor
Unspecified vulnerability in the fetch function in MDB2.php in PEAR Structures-DataGrid-DataSource-MDB2 0.1.9 and earlier allows attackers t
MediumCVSS 5.0No exploitEPSS 1%pear · structures datagrid datasource mdb2Jul 9, 2007
- CVE-2007-593417Monitor
The LOB functionality in PEAR MDB2 before 2.5.0a1 interprets a request to store a URL string as a request to retrieve and store the contents
MediumCVSS 4.3No exploitEPSS 2%pear · structures datagrid datasource mdb2Nov 13, 2007