Vulnerabilities > Swoole

DATE CVE VULNERABILITY TITLE RISK
2023-07-20 CVE-2020-24275 Injection vulnerability in Swoole 4.5.2
A HTTP response header injection vulnerability in Swoole v4.5.2 allows attackers to execute arbitrary code via supplying a crafted URL.
network
low complexity
swoole CWE-74
6.5
2021-12-03 CVE-2021-43676 Path Traversal vulnerability in Swoole PHP Framework 3.0.5
matyhtf framework v3.0.5 is affected by a path manipulation vulnerability in Smarty.class.php.
network
low complexity
swoole CWE-22
7.5
2019-08-23 CVE-2019-15518 Path Traversal vulnerability in Swoole
Swoole before 4.2.13 allows directory traversal in swPort_http_static_handler.
network
low complexity
swoole CWE-22
5.0
2018-08-18 CVE-2018-15503 Deserialization of Untrusted Data vulnerability in Swoole 4.0.4
The unpack implementation in Swoole version 4.0.4 lacks correct size checks in the deserialization process.
network
low complexity
swoole CWE-502
5.0