← Vulnerability feed

Vulnerability record · CVE-2015-7503 · published 10 October 2017

CVE-2015-7503: Zend framework vulnerability

Zend · Zend Framework

Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private key.

7.5 CVSS 3.0 High EPSS 1.4% · top 29.5% CWE-320 · CWE-320
7.5CVSS 3.0 base score, v2 5.0
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Zend Framework before 2.4.9, zend-framework/zend-crypt 2.4.x before 2.4.9, and 2.5.x before 2.5.2 allows remote attackers to recover the RSA private key.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-7503 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-29312Zend framework deserialization of untrusted data vulnerabilityAn issue found in Zend Framework v.3.1.3 and before allow a remote attacker to execute arbitrary code via the unserialize function. Note: This has be…EPSS 1.3%9.8CVE-2021-3007Laminas-http and Zend Framework PHP deserialization RCELaminas-http before 2.14.2 and Zend Framework 3.0.0 contain a PHP object deserialization flaw tied to the __destruct method of Zend\Http\Response\Str…EPSS 75%analysed9.8CVE-2014-8089Zend framework sql injection vulnerabilitySQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows …EPSS 2.6%9.8CVE-2011-1939Zend framework sql injection vulnerabilitySQL injection vulnerability in Zend Framework 1.10.x before 1.10.9 and 1.11.x before 1.11.6 when using non-ASCII-compatible encodings in conjunction …EPSS 3.9%9.8CVE-2014-4914Zend framework sql injection vulnerabilityThe Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL…EPSS 2.3%9.8CVE-2016-4861Fedoraproject fedora sql injection vulnerabilityThe (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection atta…EPSS 4.1%9.8CVE-2016-6233Fedoraproject fedora sql injection vulnerabilityThe (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection atta…EPSS 2.0%9.8CVE-2016-10034Zend framework command injection vulnerabilityThe setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework befor…EPSS 38%

Source: NIST National Vulnerability Database (record CVE-2015-7503), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.