CVE-2015-8562: Joomla!
High severity, CVSS 7.5. EPSS: 98.3% chance of exploitation in the next 30 days.
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the HTTP User-Agent header, as exploited in the wild in December 2015.
Affected products
- Joomla! Joomla!: version 1.5.0 only; version 1.5.1 only; version 1.5.2 only; version 1.5.3 only; version 1.5.4 only; version 1.5.6 only; …
Published 2015-12-16. Last modified 2026-06-17.