CVE-2024-1874

Command injection via array-ish $command parameter of proc_open()

In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.


We have discovered 89,456 live websites that are affected by CVE-2024-1874.

Run a Free Instant Scan




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains89,456 live websites (1.29% of PHP install base)
Vulnerable Versions
  • from 8.1 through 8.1
  • from 8.2 through 8.2
  • from 8.3 through 8.3
Vulnerable Versions Count3 versions ( 0.57% of all versions)


Common Weakness Enumeration

CWE-116 Improper Encoding or Escaping of Output



Details

  • Published - Apr 29, 2024
  • Updated - Nov 4, 2025

Credits

  • RyotaK (reporter)

Website Distribution by Country

Number of websites using CVE-2024-1874
United States2,162 websites



France73,481 websites
Brazil3,714 websites
Poland2,763 websites
Spain1,414 websites
Belgium1,251 websites
Italy1,223 websites
Germany667 websites
Russia373 websites
GB231 websites

Website Distribution by TLD

Number of websites using CVE-2024-1874
.com31,835 websites
.fr31,189 websites
.org3,758 websites
.be3,425 websites
.com.br3,098 websites
.pl2,765 websites
.net2,283 websites
.it1,662 websites
.eu1,293 websites
.es1,167 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-1874

Top websites that are affected by CVE-2024-1874. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.fr France**,***
*************.com United States**,***
**************.net France**,***
*************.com France**,***
*******.com United States**,***
******.de Germany**,***
***.de France**,***
******.co France**,***
**********************.org France**,***
******************.fr France**,***
See full domain list

FAQ

CVE-2024-1874 is Improper Encoding or Escaping of Output in PHP
A total of 89,456 websites have been identified as vulnerable to CVE-2024-1874, based on global website indexing conducted by WebTechSurvey.
The PHP is affected by the CVE-2024-1874 vulnerability.
PHP versions up to and including 8.3 are vulnerable to CVE-2024-1874.