{
    "id": "CVE-2015-5161",
    "published": "2015-08-25 17:59:03",
    "last_modified": "2026-06-17 00:28:35",
    "cvss_score": "6.8",
    "cvss_severity": "MEDIUM",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
    "cwe": null,
    "description": "The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x before 2.5.2, when running under PHP-FPM in a threaded environment, allows remote attackers to bypass security checks and conduct XML external entity (XXE) and XML entity expansion (XEE) attacks via multibyte encoded characters.",
    "epss_score": "0.09867",
    "epss_percentile": "0.95413",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-28 18:17:14",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "zend",
            "product": "zend_framework"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "38573",
            "title": "eBay Magento 1.9.2.1 - PHP FPM XML eXternal Entity Injection",
            "date": "2015-10-30",
            "url": "https://www.exploit-db.com/exploits/38573"
        },
        {
            "source": "exploit-db",
            "ref_id": "37765",
            "title": "Zend Framework 2.4.2 - PHP FPM XML eXternal Entity Injection",
            "date": "2015-08-13",
            "url": "https://www.exploit-db.com/exploits/37765"
        }
    ],
    "refs_list": [
        "http://framework.zend.com/security/advisory/ZF2015-06",
        "http://legalhackers.com/advisories/zend-framework-XXE-vuln.txt",
        "http://lists.fedoraproject.org/pipermail/package-announce/2015-August/164409.html",
        "http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165147.html",
        "http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165173.html",
        "http://packetstormsecurity.com/files/133068/Zend-Framework-2.4.2-1.12.13-XXE-Injection.html",
        "http://seclists.org/fulldisclosure/2015/Aug/46",
        "http://www.debian.org/security/2015/dsa-3340",
        "http://www.securityfocus.com/bid/76177",
        "https://www.exploit-db.com/exploits/37765/",
        "http://framework.zend.com/security/advisory/ZF2015-06",
        "http://legalhackers.com/advisories/zend-framework-XXE-vuln.txt",
        "http://lists.fedoraproject.org/pipermail/package-announce/2015-August/164409.html",
        "http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165147.html",
        "http://lists.fedoraproject.org/pipermail/package-announce/2015-August/165173.html",
        "http://packetstormsecurity.com/files/133068/Zend-Framework-2.4.2-1.12.13-XXE-Injection.html",
        "http://seclists.org/fulldisclosure/2015/Aug/46",
        "http://www.debian.org/security/2015/dsa-3340",
        "http://www.securityfocus.com/bid/76177",
        "https://www.exploit-db.com/exploits/37765/"
    ]
}