AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2014-9509

HIGH · CVSS 7.5 EPSS 1.50%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2015-01-04 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2014-9509
Severity
HIGH
CVSS
7.5
EPSS
1.50%

Original Filing — NVD Description

The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set to all or cached, allows remote attackers to have an unspecified impact (possibly resource consumption) via a "Cache Poisoning" attack using a URL with arbitrary arguments, which triggers a reload of the page.