wordpress:7.1.3-php8.5-fpm-alpine

by Docker Official OFFICIAL ← project: Wordpress
SCOUT
F
score 0
Pull →
docker pull wordpress:7.1.3-php8.5-fpm-alpine click to select

Image metadata

PULL COUNT
1.5B
repository-level (not per-tag)
SIZE (COMPRESSED)
118 MB
ARCHITECTURES
7
RUNS AS
root
image config.User
LAST PUSHED
3d ago
2026-10-07 21:52:03
MANIFEST DIGEST
sha256:a98f10983d9e…
from registry manifest

Latest scan

2026-10-10 09:17:12 UTC · today

OPEN CVES BY SEVERITY

8
CRITICAL
23
HIGH
33
MEDIUM
13
LOW/NEG
Grype DB 2026-10-09T06:32:32.000Z · rubric cerodeo-v1

RUBRIC BREAKDOWN (7 signals that moved the score)

-10 · High CVEs (fixable) -3 · Medium CVEs (fixable) -64 · Critical CVEs (no fix) -66 · High CVEs (no fix) +10 · Rebuilt in last 90 days +3 · Multi-arch +2 · readme_has_example

Raw data

Every signal above decomposes to arithmetic from inputs you can verify. Nothing in these downloads is derived or massaged — they're the raw grype matches and the raw snapshot history exactly as our scanner wrote them.

Latest scan JSON (CVE matches) Full scan history JSON (3 snapshots)

Reproduce this score yourself

We don't use judgement to score — every signal is deterministic from the image, the manifest, and a pinned CVE DB. Run the script below on any host with skopeo, syft, grype, cosign, and jq installed — it fetches the versioned rubric spec, computes the same breakdown, and prints the same grade. Pin the Grype DB with --grype-db to reproduce bit-for-bit identical results.

curl -fsSLO https://ce.rodeo/verify-score.sh && chmod +x verify-score.sh ./verify-score.sh wordpress:7.1.3-php8.5-fpm-alpine \ --rubric cerodeo-v1 \ --grype-db 2026-10-09T06:32:32.000Z
verify-score.sh rubric spec (cerodeo-v1.json)

All open CVEs (77)

sorted by severity, then CVSS score
CVE ID SEV CVSS PACKAGE FIX
CVE-2014-9826 CRITICAL 9.8 imagemagick 7.1.2.30-r0 no fix available
CVE-2014-9826 CRITICAL 9.8 imagemagick-heic 7.1.2.30-r0 no fix available
CVE-2014-9826 CRITICAL 9.8 imagemagick-jp2 7.1.2.30-r0 no fix available
CVE-2014-9826 CRITICAL 9.8 imagemagick-jpeg 7.1.2.30-r0 no fix available
CVE-2014-9826 CRITICAL 9.8 imagemagick-libs 7.1.2.30-r0 no fix available
CVE-2014-9826 CRITICAL 9.8 imagemagick-pdf 7.1.2.30-r0 no fix available
CVE-2014-9826 CRITICAL 9.8 imagemagick-tiff 7.1.2.30-r0 no fix available
CVE-2014-9826 CRITICAL 9.8 imagemagick-webp 7.1.2.30-r0 no fix available
CVE-2018-6553 HIGH 8.8 cups-libs 2.4.19-r0 no fix available
CVE-2026-84782 HIGH 8.2 openssl 3.5.8-r0 no fix available
CVE-2026-84782 HIGH 8.2 libcrypto3 3.5.8-r0 no fix available
CVE-2026-84782 HIGH 8.2 libssl3 3.5.8-r0 no fix available
CVE-2017-5506 HIGH 7.8 imagemagick-webp 7.1.2.30-r0 no fix available
CVE-2017-5506 HIGH 7.8 imagemagick-jp2 7.1.2.30-r0 no fix available
CVE-2017-5506 HIGH 7.8 imagemagick-jpeg 7.1.2.30-r0 no fix available
CVE-2017-5506 HIGH 7.8 imagemagick-libs 7.1.2.30-r0 no fix available
CVE-2017-5506 HIGH 7.8 imagemagick-pdf 7.1.2.30-r0 no fix available
CVE-2017-5506 HIGH 7.8 imagemagick-tiff 7.1.2.30-r0 no fix available
CVE-2017-5506 HIGH 7.8 imagemagick 7.1.2.30-r0 no fix available
CVE-2017-5506 HIGH 7.8 imagemagick-heic 7.1.2.30-r0 no fix available
CVE-2026-4775 HIGH 7.8 tiff 4.7.1-r0 fixed in 4.7.2-r0
CVE-2023-52356 HIGH 7.5 tiff 4.7.1-r0 no fix available
CVE-2026-54873 HIGH 7.5 openssl 3.5.8-r0 no fix available
CVE-2026-54873 HIGH 7.5 libssl3 3.5.8-r0 no fix available
CVE-2026-54873 HIGH 7.5 libcrypto3 3.5.8-r0 no fix available
CVE-2026-72897 HIGH 7.5 libcrypto3 3.5.8-r0 no fix available
CVE-2026-72897 HIGH 7.5 libssl3 3.5.8-r0 no fix available
CVE-2026-72897 HIGH 7.5 openssl 3.5.8-r0 no fix available
CVE-2026-84784 HIGH 7.5 libssl3 3.5.8-r0 no fix available
CVE-2026-84784 HIGH 7.5 openssl 3.5.8-r0 no fix available
CVE-2026-84784 HIGH 7.5 libcrypto3 3.5.8-r0 no fix available
CVE-2016-7538 MEDIUM 6.5 imagemagick-jpeg 7.1.2.30-r0 no fix available
CVE-2016-7538 MEDIUM 6.5 imagemagick-jp2 7.1.2.30-r0 no fix available
CVE-2016-7538 MEDIUM 6.5 imagemagick-heic 7.1.2.30-r0 no fix available
CVE-2016-7538 MEDIUM 6.5 imagemagick-tiff 7.1.2.30-r0 no fix available
CVE-2016-7538 MEDIUM 6.5 imagemagick 7.1.2.30-r0 no fix available
CVE-2016-7538 MEDIUM 6.5 imagemagick-webp 7.1.2.30-r0 no fix available
CVE-2016-7538 MEDIUM 6.5 imagemagick-pdf 7.1.2.30-r0 no fix available
CVE-2016-7538 MEDIUM 6.5 imagemagick-libs 7.1.2.30-r0 no fix available
CVE-2023-6277 MEDIUM 6.5 tiff 4.7.1-r0 no fix available
CVE-2025-60876 MEDIUM 6.5 busybox-binsh 1.37.0-r31 no fix available
CVE-2025-60876 MEDIUM 6.5 busybox 1.37.0-r31 no fix available
CVE-2025-60876 MEDIUM 6.5 ssl_client 1.37.0-r31 no fix available
CVE-2026-58055 MEDIUM 6.3 nghttp2-libs 1.69.0-r0 fixed in 1.70.0-r0
CVE-2023-38560 MEDIUM 5.5 ghostscript 10.07.1-r0 no fix available
CVE-2023-6228 MEDIUM 5.5 tiff 4.7.1-r0 no fix available
CVE-2026-5704 MEDIUM 5.5 tar 1.35-r5 no fix available
CVE-2026-35189 MEDIUM 5.3 openssl 3.5.8-r0 no fix available
CVE-2026-35189 MEDIUM 5.3 libcrypto3 3.5.8-r0 no fix available
CVE-2026-35189 MEDIUM 5.3 libssl3 3.5.8-r0 no fix available
CVE-2026-42772 MEDIUM 5.3 libssl3 3.5.8-r0 no fix available
CVE-2026-42772 MEDIUM 5.3 openssl 3.5.8-r0 no fix available
CVE-2026-42772 MEDIUM 5.3 libcrypto3 3.5.8-r0 no fix available
CVE-2026-75804 MEDIUM 5.3 libcrypto3 3.5.8-r0 no fix available
CVE-2026-75804 MEDIUM 5.3 openssl 3.5.8-r0 no fix available
CVE-2026-75804 MEDIUM 5.3 libssl3 3.5.8-r0 no fix available
CVE-2026-75805 MEDIUM 5.3 libcrypto3 3.5.8-r0 no fix available
CVE-2026-75805 MEDIUM 5.3 openssl 3.5.8-r0 no fix available
CVE-2026-75805 MEDIUM 5.3 libssl3 3.5.8-r0 no fix available
CVE-2026-75806 MEDIUM 5.3 libssl3 3.5.8-r0 no fix available
CVE-2026-75806 MEDIUM 5.3 libcrypto3 3.5.8-r0 no fix available
CVE-2026-75806 MEDIUM 5.3 openssl 3.5.8-r0 no fix available
CVE-2026-18477 MEDIUM 4.4 tar 1.35-r5 no fix available
CVE-2026-18508 MEDIUM 4.4 tar 1.35-r5 no fix available
CVE-2026-35191 LOW 3.7 openssl 3.5.8-r0 no fix available
CVE-2026-35191 LOW 3.7 libssl3 3.5.8-r0 no fix available
CVE-2026-35191 LOW 3.7 libcrypto3 3.5.8-r0 no fix available
CVE-2026-54872 LOW 3.7 openssl 3.5.8-r0 no fix available
CVE-2026-54872 LOW 3.7 libcrypto3 3.5.8-r0 no fix available
CVE-2026-54872 LOW 3.7 libssl3 3.5.8-r0 no fix available
CVE-2026-54875 LOW 3.7 openssl 3.5.8-r0 no fix available
CVE-2026-54875 LOW 3.7 libssl3 3.5.8-r0 no fix available
CVE-2026-54875 LOW 3.7 libcrypto3 3.5.8-r0 no fix available
CVE-2026-77696 LOW 3.7 openssl 3.5.8-r0 no fix available
CVE-2026-77696 LOW 3.7 libcrypto3 3.5.8-r0 no fix available
CVE-2026-77696 LOW 3.7 libssl3 3.5.8-r0 no fix available
CVE-2026-6192 LOW 1.9 openjpeg 2.5.4-r1 fixed in 2.5.4-r2

Scan history

3 total · first today
SCANNED AT GRADE SCORE CRIT HIGH MED GRYPE DB
today F 0 8 23 33 2026-10-09T06:32:32.000Z · (same SBOM)
today F 0 8 23 33 2026-10-09T06:32:32.000Z · (same SBOM)
today F 0 8 23 33 2026-10-09T06:32:32.000Z