mix_php vulnerabilities
CVEs whose affected-version data names the mix_php package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-42475Medium· 6.5SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `on` array to the joinOn function in BuildHelper.php.
SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `on` array to the joinOn function in BuildHelper.php.
▾ Sunlitopenmix · mix_phpEPSS 0.20%via NVD
CVE-2026-37552High· 8.4Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17
Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) receives data from a TCP socket, passes it directly to Opis\Closure\unserialize(), then executes the result via call_use…
▾ Twilightopenmix · mix_phpEPSS 0.25%via NVD