CVE-2015-5951: Thomsonreuters Fatca

Critical severity, CVSS 9.9. EPSS: 2.7% chance of exploitation in the next 30 days.

A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to upload arbitrary PHP files to the web root and execute system commands.

Affected products

Published 2020-01-06. Last modified 2026-06-17.