CVE-2015-5956

low
Published 2015-09-16 · Modified 2024-12-07
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

TYPO3 cross-site scripting (XSS)

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://typo3.org/teams/security/security-bulletins/typo3-core/typo3-core-sa-2015-009/

Package impact

EcosystemPackageVulnerableFixed
php Packagisttypo3/cms>=6.0,<6.2.156.2.15
php Packagisttypo3/cms>=7.0,<7.4.07.4.0
php Packagisttypo3/cms>=4.0,<=4.5.40

Application impact

VendorProductVersionsFixed
typo3typo3{"endIncluding":"4.5.40"}
typo3typo36.0
typo3typo36.0.1
typo3typo36.0.2
typo3typo36.0.3
typo3typo36.0.4
typo3typo36.0.5
typo3typo36.0.6
typo3typo36.0.7
typo3typo36.0.8
typo3typo36.0.9
typo3typo36.0.10
typo3typo36.0.11
typo3typo36.0.12
typo3typo36.0.13
typo3typo36.0.14
typo3typo36.1
typo3typo36.1.1
typo3typo36.1.2
typo3typo36.1.3
typo3typo36.1.4
typo3typo36.1.5
typo3typo36.1.6
typo3typo36.1.7
typo3typo36.1.8
typo3typo36.1.9
typo3typo36.2
typo3typo36.2.0
typo3typo36.2.1
typo3typo36.2.2
typo3typo36.2.3
typo3typo36.2.4
typo3typo36.2.5
typo3typo36.2.6
typo3typo36.2.7
typo3typo36.2.8
typo3typo36.2.9
typo3typo36.2.10
typo3typo36.2.11
typo3typo36.2.12
typo3typo36.2.13
typo3typo36.2.14
typo3typo37.0.0
typo3typo37.1.0
typo3typo37.2.0
typo3typo37.3.0

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.