There was a vulnerability for PHP announced recently. I didn't take much notice because it was Windows, but I'm reasonably sure it was specific to IIS, not Apache. XAMPP runs Apache. In which case, no vulnerability.
EDIT:
I'm talking rubbish again. It WAS Apache on Windows 
