CVE-2025-32709 · PHP

PHP CGI Argument Injection

Severity:
Medium
CVSS:
6.5
Published:
May 9, 2025

Summary

Query strings are passed to the PHP binary as command-line arguments under specific CGI configurations.

Affected products

PHP running in CGI mode behind affected server configurations.

Impact

Remote code execution on misconfigured hosting environments.

Recommended action

Move to PHP-FPM, patch, and review shared hosting configurations.

Back to vulnerability database

Need clarity fast?

Whether you're a website owner, product team, or business leader, we'll expertly help you investigate, assess, and secure what matters most.

  • 24/7 secure intake
  • Confidential and discreet
  • Rapid expert response

We respect your privacy. No spam. Ever. Or email support@techforensiq.com