PHP 5.x — End of Life

EOL Critical risk
EOL: Dec 31, 20187 releases in this series2 CVEs

PHP 5.x reached end of life on Dec 31, 2018, 2837 days ago, and no longer receives security fixes. The most recent release in this series is 5.6.40. 2 CVEs are tracked for this series, including 1 critical. 2 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is PHP 7. See PHP 7 →

PHP 5.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
5.6Aug 28, 2014Jan 19, 2017Dec 31, 20185.6.40EOL
5.5Jun 20, 2013Jul 10, 2015Jul 21, 20165.5.38EOL
5.4Mar 1, 2012Sep 14, 2014Sep 14, 20155.4.45EOL
5.3Jun 30, 2009Jun 30, 2011Aug 14, 20145.3.29EOL
5.2Nov 2, 2006Nov 2, 2008Jan 6, 20115.2.17EOL
5.1Nov 24, 2005Aug 24, 2006Aug 24, 20065.1.6EOL
5.0Jul 13, 2004Sep 5, 2005Sep 5, 20055.0.5EOL

CVEs affecting PHP 5.x (9)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2024-3566CRITICAL9.86.88%—5.5A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d…Apr 10, 2024
CVE-2024-3566CRITICAL9.86.88%—5.0A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d…Apr 10, 2024
CVE-2024-3566CRITICAL9.86.88%—5.6A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d…Apr 10, 2024
CVE-2024-3566CRITICAL9.86.88%—5.1A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d…Apr 10, 2024
CVE-2024-3566CRITICAL9.86.88%—5.4A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d…Apr 10, 2024
CVE-2024-3566CRITICAL9.86.88%—5.3A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d…Apr 10, 2024
CVE-2024-3566CRITICAL9.86.88%—5.2A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d…Apr 10, 2024
CVE-2006-3011MEDIUM4.61.34%—5.0The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe m…Jun 26, 2006
CVE-2006-3011MEDIUM4.61.34%—5.1The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe m…Jun 26, 2006

PHP 5.x is EOL — migrate to PHP 7.x

PHP 7.x is the next major release. Plan your upgrade before PHP 5.x stops receiving security patches.

See PHP 7.x

Add a PHP 5 EOL badge to your README

Show your users which PHP version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

PHP 5 EOL status
[![PHP 5 EOL status](https://eolcanary.com/badge/php/5.svg)](https://eolcanary.com/explore/php/5)

Frequently asked questions

Is PHP 5 end of life?

Yes. All PHP 5.x releases have reached end of life and no longer receive security patches. There are 2 known CVEs affecting PHP 5.x, including 1 critical. Migrate to PHP 7.x as soon as possible.

What CVEs affect PHP 5?

There are 2 CVEs tracked for PHP 5.x, including 1 critical severity issue. See the full list above with CVSS and EPSS scores.

What is the latest PHP 5 version?

The latest PHP 5.x patch release is 5.6.40, released on January 10, 2019. Always run the latest patch to benefit from all security fixes.

How to migrate from PHP 5 to PHP 7?

To migrate from PHP 5 to PHP 7: (1) review the official PHP 7 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run PHP 5 in production?

No. PHP 5 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA