CVE-2022-50807: 
PHP vulnerability analysis and mitigation

Overview

CVE-2022-50807 is a rejected/withdrawn CVE that was originally described as an XPath injection vulnerability in Concrete CMS version 9.1.3. It was initially submitted by VulnCheck on January 13, 2026, and subsequently rejected by the same CNA on January 14, 2026, after further investigation determined it was not a security issue (Github Advisory). The original claim alleged that URL path parameters could be manipulated with XPath injection payloads (CWE-643), but this was not substantiated. Prior to rejection, VulnCheck had assigned a CVSS v3.1 score of 9.8 (Critical) and a CVSS v4.0 score of 6.9 (Medium), both of which were subsequently removed (Github Advisory).

Technical details

The original (now-withdrawn) claim alleged that the URL path parameter in Concrete CMS 9.1.3 was susceptible to XPath injection (CWE-643), where a crafted payload such as 50539478' or 4591=4591-- injected into a URL path segment would trigger a 500 Internal Server Error, potentially leaking internal content paths (nu11secur1ty PoC). The alleged attack vector was network-accessible, requiring no authentication or user interaction. However, the CNA (VulnCheck) formally rejected this CVE after determining the behavior did not constitute a genuine security vulnerability (Github Advisory).

Impact

Because CVE-2022-50807 has been officially rejected and determined not to be a security issue, there is no confirmed security impact. The originally alleged impacts — partial information disclosure of internal paths and availability degradation through request flooding — were not validated by the vendor or CNA (Github Advisory).

Exploitability

CVE-2022-50807 is a rejected CVE with no confirmed exploitability. An Exploit-DB entry (51144) and a researcher PoC were referenced in the original submission, but these were associated with a claim that was subsequently invalidated. The EPSS score is approximately 0.049% (15th percentile), indicating very low predicted exploitation probability (Github Advisory). There is no evidence of in-the-wild exploitation, no CISA KEV listing, and no threat actor attribution.

Mitigation and workarounds

No mitigation is required, as CVE-2022-50807 has been officially rejected and determined not to represent a security vulnerability (Github Advisory). Organizations running Concrete CMS 9.1.3 should still follow general best practices and upgrade to the latest available version for unrelated security improvements. The GitHub Advisory Database lists no patched version for this specific CVE.

Community reactions

The CVE received minimal industry attention. It was originally submitted by VulnCheck and briefly appeared in vulnerability databases before being rejected within 24 hours of publication. The GitHub Advisory Database entry (GHSA-r7vr-wg3f-8hr9) retains the original description but reflects the rejected status (Github Advisory). No significant vendor statements, researcher commentary, or media coverage was identified.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management