CVE-2024-34914: PHP-Censor

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

php-censor v2.1.4 and fixed in v.2.1.5 was discovered to utilize a weak hashing algorithm for its remember_key value. This allows attackers to bruteforce to bruteforce the remember_key value to gain access to accounts that have checked "remember me" when logging in.

Affected products

  • PHP-Censor PHP-Censor: from 2.1.4, before 2.1.5 (fixed in 2.1.5)

Published 2024-05-14. Last modified 2026-06-17.