CVE-2025-32709 · PHP
PHP CGI Argument Injection
- Severity:
- Medium
- CVSS:
- 6.5
- Published:
- May 9, 2025
Summary
Query strings are passed to the PHP binary as command-line arguments under specific CGI configurations.
Affected products
PHP running in CGI mode behind affected server configurations.
Impact
Remote code execution on misconfigured hosting environments.
Recommended action
Move to PHP-FPM, patch, and review shared hosting configurations.
Need clarity fast?
Whether you're a website owner, product team, or business leader, we'll expertly help you investigate, assess, and secure what matters most.
- 24/7 secure intake
- Confidential and discreet
- Rapid expert response
We respect your privacy. No spam. Ever. Or email support@techforensiq.com