[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2016-7131":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T14:55:33.319Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":30,"duplicate_of":9,"upstream":31,"downstream":32,"duplicates":53,"related":54,"reserved_at":9,"published_at":60,"modified_at":61,"state":62,"summary":63,"references_raw":71,"kevs":130,"epss":131,"epss_history":134,"metrics":379,"affected":389},"CVE-2016-7131","ext/wddx/wddx.c in PHP before 5.6.25 and 7.x before 7.0.10 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or possibly have unspecified other impact via a malformed wddxPacket XML document that is mishandled in a wddx_deserialize call, as demonstrated by a tag that lacks a \u003C (less than) character.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-476","NULL Pointer Dereference","The product dereferences a pointer that it expects to be valid but is NULL.","weakness","Stable","Base","Medium",[],[21],{"_key":22,"name":23,"source":24,"url":25,"maturity":26,"reliability_score":27,"verified":28,"type":9,"platforms":29,"requires_auth":9,"exploitdb":9,"metasploit":9},"REF_67BAECCF2D1D403A","Exploit Reference (bugs.php.net)","reference","https://bugs.php.net/bug.php?id=72790","unknown",0.2,false,[],[],[],[33,35,37,39,41,43,45,47,49,51],{"_key":34},"SUSE-SU-2016:2328-1",{"_key":36},"SUSE-SU-2016:2408-1",{"_key":38},"SUSE-SU-2016:2459-1",{"_key":40},"SUSE-SU-2016:2460-1",{"_key":42},"SUSE-SU-2016:2460-2",{"_key":44},"DLA-749-1",{"_key":46},"DSA-3689-1",{"_key":48},"UBUNTU-CVE-2016-7131",{"_key":50},"USN-3095-1",{"_key":52},"RHSA-2016:2750",[],[55,56,57,58,59],{"_key":34},{"_key":36},{"_key":38},{"_key":40},{"_key":42},"2016-09-12T01:00:00.000Z","2024-08-06T01:50:47.580Z","Modified",{"cisa_kev":28,"cisa_ransomware":28,"cisa_vendor":9,"epss_severity":64,"epss_score":65,"severity":66,"severity_score":67,"severity_version":68,"severity_source":69,"severity_vector":70,"severity_status":62},"low",0.06375,"high",7.5,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",[72,79,85,92,98,103,107,111,115,120,126],{"url":73,"sources":74,"tags":76},"http://www.php.net/ChangeLog-7.php",[75,69],"cve.org",[77,78],"X Refsource CONFIRM","Release Notes",{"url":80,"sources":81,"tags":82},"https://github.com/php/php-src/commit/a14fdb9746262549bbbb96abb87338bacd147e1b?w=1",[75,69],[77,83,84],"Issue Tracking","Patch",{"url":86,"sources":87,"tags":88},"https://security.gentoo.org/glsa/201611-22",[75,69],[89,90,91],"Vendor Advisory","X Refsource GENTOO","Third Party Advisory",{"url":93,"sources":94,"tags":95},"http://www.securitytracker.com/id/1036680",[75,69],[96,97,91],"VDB Entry","X Refsource SECTRACK",{"url":99,"sources":100,"tags":101},"http://rhn.redhat.com/errata/RHSA-2016-2750.html",[75,69],[89,102,91],"X Refsource REDHAT",{"url":25,"sources":104,"tags":105},[75,69],[77,106,83],"Exploit",{"url":108,"sources":109,"tags":110},"http://www.php.net/ChangeLog-5.php",[75,69],[77,78],{"url":112,"sources":113,"tags":114},"https://www.tenable.com/security/tns-2016-19",[75,69],[77,91],{"url":116,"sources":117,"tags":118},"http://www.securityfocus.com/bid/92768",[75,69],[96,119,91],"X Refsource BID",{"url":121,"sources":122,"tags":123},"http://openwall.com/lists/oss-security/2016/09/02/9",[75,69],[124,125],"Mailing List","X Refsource MLIST",{"url":127,"sources":128,"tags":129},"https://github.com/php/php-src/commit/0c8a2a2cd1056b7dc403eacb5d2c0eec6ce47c6f",[75,69],[77,84,89],[],{"date":132,"score":65,"percentile":133},"2026-06-04",0.91169,[135,138,140,142,145,148,151,153,155,158,161,164,166,169,172,175,178,181,184,186,189,192,195,198,200,203,206,209,212,214,217,219,222,225,227,229,232,235,238,241,244,247,249,251,253,256,259,261,264,267,270,273,275,278,282,285,288,290,293,296,299,302,305,308,310,313,316,319,322,325,327,330,333,335,338,341,343,345,348,351,354,357,360,362,365,368,370,372,374,376],{"date":136,"score":65,"percentile":137},"2025-11-04",0.90574,{"date":139,"score":65,"percentile":137},"2025-11-05",{"date":141,"score":65,"percentile":137},"2025-11-06",{"date":143,"score":65,"percentile":144},"2025-11-07",0.90583,{"date":146,"score":65,"percentile":147},"2025-11-08",0.90584,{"date":149,"score":65,"percentile":150},"2025-11-09",0.90582,{"date":152,"score":65,"percentile":144},"2025-11-10",{"date":154,"score":65,"percentile":150},"2025-11-11",{"date":156,"score":65,"percentile":157},"2025-11-12",0.90589,{"date":159,"score":65,"percentile":160},"2025-11-13",0.90592,{"date":162,"score":65,"percentile":163},"2025-11-14",0.90595,{"date":165,"score":65,"percentile":160},"2025-11-15",{"date":167,"score":65,"percentile":168},"2025-11-16",0.90596,{"date":170,"score":65,"percentile":171},"2025-11-17",0.90593,{"date":173,"score":65,"percentile":174},"2025-11-18",0.90071,{"date":176,"score":65,"percentile":177},"2025-11-19",0.90075,{"date":179,"score":65,"percentile":180},"2025-11-20",0.90078,{"date":182,"score":65,"percentile":183},"2025-11-21",0.90597,{"date":185,"score":65,"percentile":183},"2025-11-22",{"date":187,"score":65,"percentile":188},"2025-11-23",0.90598,{"date":190,"score":65,"percentile":191},"2025-11-24",0.90599,{"date":193,"score":65,"percentile":194},"2025-11-25",0.90602,{"date":196,"score":65,"percentile":197},"2025-11-26",0.906,{"date":199,"score":65,"percentile":197},"2025-11-27",{"date":201,"score":65,"percentile":202},"2025-11-28",0.9059,{"date":204,"score":65,"percentile":205},"2025-11-29",0.90626,{"date":207,"score":65,"percentile":208},"2025-11-30",0.90625,{"date":210,"score":65,"percentile":211},"2025-12-01",0.90684,{"date":213,"score":65,"percentile":211},"2025-12-02",{"date":215,"score":65,"percentile":216},"2025-12-03",0.90686,{"date":218,"score":65,"percentile":205},"2025-12-04",{"date":220,"score":65,"percentile":221},"2025-12-05",0.90631,{"date":223,"score":65,"percentile":224},"2025-12-06",0.90632,{"date":226,"score":65,"percentile":205},"2025-12-07",{"date":228,"score":65,"percentile":205},"2025-12-08",{"date":230,"score":65,"percentile":231},"2025-12-09",0.90628,{"date":233,"score":65,"percentile":234},"2025-12-10",0.90638,{"date":236,"score":65,"percentile":237},"2025-12-11",0.90645,{"date":239,"score":65,"percentile":240},"2025-12-12",0.90649,{"date":242,"score":65,"percentile":243},"2025-12-13",0.90642,{"date":245,"score":65,"percentile":246},"2025-12-14",0.90641,{"date":248,"score":65,"percentile":246},"2025-12-15",{"date":250,"score":65,"percentile":246},"2025-12-16",{"date":252,"score":65,"percentile":240},"2025-12-17",{"date":254,"score":65,"percentile":255},"2025-12-18",0.90656,{"date":257,"score":65,"percentile":258},"2025-12-19",0.90657,{"date":260,"score":65,"percentile":255},"2025-12-20",{"date":262,"score":65,"percentile":263},"2025-12-21",0.90667,{"date":265,"score":65,"percentile":266},"2025-12-22",0.90663,{"date":268,"score":65,"percentile":269},"2025-12-23",0.90672,{"date":271,"score":65,"percentile":272},"2025-12-24",0.90681,{"date":274,"score":65,"percentile":211},"2025-12-25",{"date":276,"score":65,"percentile":277},"2025-12-26",0.90682,{"date":279,"score":280,"percentile":281},"2025-12-27",0.02944,0.86067,{"date":283,"score":65,"percentile":284},"2025-12-28",0.9068,{"date":286,"score":65,"percentile":287},"2025-12-29",0.90676,{"date":289,"score":65,"percentile":272},"2025-12-30",{"date":291,"score":65,"percentile":292},"2025-12-31",0.90691,{"date":294,"score":65,"percentile":295},"2026-01-01",0.90762,{"date":297,"score":65,"percentile":298},"2026-01-02",0.90756,{"date":300,"score":65,"percentile":301},"2026-01-03",0.90754,{"date":303,"score":65,"percentile":304},"2026-01-04",0.90701,{"date":306,"score":65,"percentile":307},"2026-01-05",0.90699,{"date":309,"score":65,"percentile":304},"2026-01-06",{"date":311,"score":65,"percentile":312},"2026-01-07",0.90705,{"date":314,"score":65,"percentile":315},"2026-01-08",0.90707,{"date":317,"score":65,"percentile":318},"2026-01-09",0.9071,{"date":320,"score":65,"percentile":321},"2026-01-10",0.90711,{"date":323,"score":65,"percentile":324},"2026-01-11",0.90704,{"date":326,"score":65,"percentile":312},"2026-01-12",{"date":328,"score":65,"percentile":329},"2026-01-13",0.90703,{"date":331,"score":65,"percentile":332},"2026-01-14",0.90716,{"date":334,"score":65,"percentile":332},"2026-01-15",{"date":336,"score":65,"percentile":337},"2026-01-16",0.9072,{"date":339,"score":65,"percentile":340},"2026-01-17",0.90721,{"date":342,"score":65,"percentile":337},"2026-01-18",{"date":344,"score":65,"percentile":340},"2026-01-19",{"date":346,"score":65,"percentile":347},"2026-01-20",0.90723,{"date":349,"score":65,"percentile":350},"2026-01-21",0.90728,{"date":352,"score":65,"percentile":353},"2026-01-22",0.90729,{"date":355,"score":65,"percentile":356},"2026-01-23",0.90738,{"date":358,"score":65,"percentile":359},"2026-01-24",0.90746,{"date":361,"score":65,"percentile":359},"2026-01-25",{"date":363,"score":65,"percentile":364},"2026-01-26",0.90748,{"date":366,"score":65,"percentile":367},"2026-01-27",0.90749,{"date":369,"score":65,"percentile":301},"2026-01-28",{"date":371,"score":65,"percentile":301},"2026-01-29",{"date":373,"score":65,"percentile":301},"2026-01-30",{"date":375,"score":65,"percentile":298},"2026-01-31",{"date":377,"score":65,"percentile":378},"2026-02-01",0.90815,[380],{"source":69,"cvss_v2_0":381,"cvss_v3_0":9,"cvss_v3_1":386,"cvss_v4_0":9},{"baseScore":382,"baseSeverity":9,"vectorString":383,"impactScore":384,"exploitabilityScore":385},5,"AV:N/AC:L/Au:N/C:N/I:N/A:P",2.9,10,{"baseScore":67,"baseSeverity":387,"vectorString":70,"impactScore":388,"exploitabilityScore":385},"HIGH",6,[390],{"ecosystem":9,"name":391,"vendor":9,"product":391,"cpe_part":9,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":392},"PHP",[393,396,398,400,402,404,406,408,410,412,414],{"version":394,"is_range":28,"range_type":395,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.0","cpe",{"version":397,"is_range":28,"range_type":395,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.1",{"version":399,"is_range":28,"range_type":395,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.2",{"version":401,"is_range":28,"range_type":395,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.3",{"version":403,"is_range":28,"range_type":395,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.4",{"version":405,"is_range":28,"range_type":395,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.5",{"version":407,"is_range":28,"range_type":395,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.6",{"version":409,"is_range":28,"range_type":395,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.7",{"version":411,"is_range":28,"range_type":395,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.8",{"version":413,"is_range":28,"range_type":395,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"7.0.9",{"version":415,"is_range":416,"range_type":395,"version_start":9,"version_start_type":9,"version_end":417,"version_end_type":418,"fixed_in":9},"lte5.6.24",true,"5.6.24","including"]