Skip to content
Multiple CVEs Expose Vulnerabilities in PHP and Collabora CODE

Multiple CVEs Expose Vulnerabilities in PHP and Collabora CODE

First seen 22 Sep 2026, 09:52 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 10:29 UTC
  • CVE-2015-57115 affects PHP applications and allows path traversal exploitation.
  • CVE-2020-12432 in Collabora CODE can lead to stored XSS attacks and data theft.
  • Both vulnerabilities require immediate attention from security professionals.

Two critical vulnerabilities have been reported: CVE-2015-57115, a path traversal vulnerability in PHP applications, and CVE-2020-12432, a stored XSS vulnerability in Collabora CODE versions up to 4.2.2. The CVE-2015-57115 exploit allows attackers to check multiple URLs for vulnerabilities using a Python script, while CVE-2020-12432 enables attackers to exploit the WOPI API to steal user data via XSS. The latter requires a specially crafted HTML document to execute the attack. Both vulnerabilities pose significant risks to affected systems, with the potential for data breaches and unauthorized access. Current status indicates that both vulnerabilities are known, with CVE-2015-57115 having a public proof-of-concept available. Security professionals are advised to assess their systems for these vulnerabilities and apply necessary mitigations.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2015-09-22
CVE-2015-57115 disclosed
Path traversal vulnerability in PHP applications allows unauthorized file access.
Sploitus
2020-09-22
CVE-2020-12432 disclosed
Stored XSS vulnerability in Collabora CODE allows data theft via WOPI API exploitation.
Sploitus
Recent
Public PoC available for CVE-2015-57115
A Python script has been released to check for vulnerabilities related to CVE-2015-57115.
Sploitus

More articles in this cluster (2)

Following this threat?

Track CVE-2015-57115 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed