← Vulnerability feed

Vulnerability record · CVE-2015-1786 · published 8 June 2017

CVE-2015-1786: Zend framework cross-site request forgery vulnerability

Zend · Zend Framework

Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token identifiers.

8.8 CVSS 3.0 High EPSS 0.66% · top 50.6% CWE-352 · Cross-site request forgery
8.8CVSS 3.0 base score, v2 6.8
0.66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token identifiers.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugzilla.redhat.com/show_bug.cgi?id=1207781 Issue TrackingThird Party AdvisoryVDB Entry
https://framework.zend.com/changelog/2.3.6 Release NotesVendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1207781 Issue TrackingThird Party AdvisoryVDB Entry
https://framework.zend.com/changelog/2.3.6 Release NotesVendor Advisory

Track CVE-2015-1786 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-29312Zend framework deserialization of untrusted data vulnerabilityAn issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has be…EPSS 1.3%9.8CVE-2021-3007Laminas-http and Zend Framework PHP deserialization RCELaminas-http before 2.14.2 and Zend Framework 3.0.0 contain a PHP object deserialization flaw tied to the __destruct method of Zend\Http\Response\Str…EPSS 75%analysed9.8CVE-2014-8089Zend framework sql injection vulnerabilitySQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows …EPSS 2.6%9.8CVE-2011-1939Zend framework sql injection vulnerabilitySQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction …EPSS 3.9%9.8CVE-2014-4914Zend framework sql injection vulnerabilityThe Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL…EPSS 2.3%9.8CVE-2016-4861Fedoraproject fedora sql injection vulnerabilityThe (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection atta…EPSS 4.1%9.8CVE-2016-6233Fedoraproject fedora sql injection vulnerabilityThe (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection atta…EPSS 2.0%9.8CVE-2016-10034Zend framework command injection vulnerabilityThe setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework befor…EPSS 38%

Source: NIST National Vulnerability Database (record CVE-2015-1786), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.