In PHP versions 7.4.x below 7.4.30, 8.0.x below 8.0.20, and 8.1.x below 8.1.7, when using Postgres database extension, supplying invalid parameters to the parametrized query may lead to PHP attempting to free memory using uninitialized data as pointers. This could lead to RCE vulnerability or denial of service.
We have discovered 252,271 live websites that are affected by CVE-2022-31625.
| Product | |
| Category | Programming Languages |
| Vulnerable Domains | 252,271 live websites (3.46% of PHP install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 55 versions ( 11% of all versions) |
| 42,222 websites | |
| 112,038 websites | |
| 10,171 websites | |
| 9,000 websites | |
| 6,885 websites | |
| 5,902 websites | |
| 5,643 websites | |
| 5,101 websites | |
| 5,099 websites | |
| 4,987 websites |
| .com | 98,019 websites |
| .fr | 46,872 websites |
| .org | 10,659 websites |
| .ru | 8,897 websites |
| .net | 7,369 websites |
| .be | 5,690 websites |
| .de | 5,371 websites |
| .pl | 5,357 websites |
| .it | 5,049 websites |
| .com.br | 5,034 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.pl | *,*** | ||
| *********.org | *,*** | ||
| **********.org | *,*** | ||
| ******.com | *,*** | ||
| *******.pro | *,*** | ||
| ****.**********.***.uk | *,*** | ||
| ***************.com | *,*** | ||
| ******.at | *,*** | ||
| ******.com | *,*** | ||
| **.***.ca | **,*** |
FAQ