Vulnerability index

Browse CVEs

84 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Symfony CRITICAL 9.8
CVE-2024-51736

Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.…

Fix: 5.4.46 / 6.4.14+
Fix from $2,300 2024-11-06
Symfony MEDIUM 6.1
CVE-2024-50345

symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` c…

Fix: 5.4.46 / 6.4.14+
Fix from $1,600 2024-11-06
Symfony MEDIUM 6.5
CVE-2023-46733

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 5.4.21 and 6.2.7 and prior to …

Fix: 5.4.31 / 6.3.8+
Fix from $1,600 2023-11-10
Symfony MEDIUM 6.1
CVE-2023-46735

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in version 6.0.0 and prior to version 6.3.…

Fix: 6.3.8+
Fix from $1,600 2023-11-10
Symfony HIGH 8.8
CVE-2022-24895

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regene…

Fix: 4.4.50 / 5.4.20+
Fix from $1,950 2023-02-03
Symfony HIGH 8.8
CVE-2022-24894

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse pr…

Fix: 4.4.50 / 5.4.2+
Fix from $1,950 2023-02-03
Symfony HIGH 8.8
CVE-2022-23601

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony form component provides a CSRF protecti…

Fix: 5.3.15 / 5.4.4+
Fix from $1,950 2022-02-01
Symfony HIGH 8.8
CVE-2021-41268

Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Sin…

Fix: 5.3.12+
Fix from $1,950 2021-11-24
Symfony MEDIUM 6.5
CVE-2021-41267

Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. …

Fix: 5.3.12+
Fix from $1,600 2021-11-24
Symfony MEDIUM 6.5
CVE-2021-41270

Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and console applications and a set of r…

Fix: 4.4.35 / 5.3.12+
Fix from $1,600 2021-11-24
Symfony HIGH 8.8
CVE-2021-32693

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication …

Fix: 5.3.2+
Fix from $1,950 2021-06-17
Symfony MEDIUM 5.3
CVE-2021-21424

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without…

Fix: 3.4.48 / 4.4.23+
Fix from $1,600 2021-05-13
Symfony HIGH 8.8
CVE-2020-15094

In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handl…

Fix: 4.4.13 / 5.1.5+
Fix from $1,950 2020-09-02
Symfony HIGH 8.1
CVE-2020-5275

In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and s…

Fix: 4.4.7 / 5.0.7+
Fix from $1,950 2020-03-30
Symfony MEDIUM 5.4
CVE-2020-5274

In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace…

Fix: 4.4.4 / 5.0.4+
Fix from $1,600 2020-03-30
Symfony MEDIUM 6.1
CVE-2013-4752

Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host …

Fix: 2.0.24 / 2.1.12+
Fix from $1,600 2020-01-02
Symfony CRITICAL 9.8
CVE-2019-11325

An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially…

Fix: 4.2.12 / 4.3.8+
Fix from $2,300 2019-11-21
Symfony CRITICAL 9.8
CVE-2019-18889EPSS 33%

An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces …

Fix: after 4.3.7
Fix from $2,300 2019-11-21
Symfony HIGH 8.1
CVE-2019-18887

An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subje…

Fix: after 4.3.7
Fix from $1,950 2019-11-21
Symfony HIGH 7.5
CVE-2019-18888

An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passe…

Fix: after 4.3.7
Fix from $1,950 2019-11-21
Symfony MEDIUM 5.3
CVE-2019-18886

An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling dependin…

Fix: after 4.3.7
Fix from $1,600 2019-11-21
Symfony HIGH 8.1
CVE-2013-4751

php-symfony2-Validator has loss of information during serialization

Fix: 2.0.24 / 2.1.12+
Fix from $1,950 2019-11-01
Symfony CRITICAL 9.8
CVE-2017-11365

Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3…

Patch available
Fix from $2,300 2019-05-23
Symfony CRITICAL 9.8
CVE-2019-10910EPSS 6%

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this …

Fix: 2.7.51 / 2.8.50+
Fix from $2,300 2019-05-16
Symfony CRITICAL 9.8
CVE-2019-10913

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using …

Fix: 2.7.51 / 2.8.50+
Fix from $2,300 2019-05-16
Symfony HIGH 7.5
CVE-2019-10911

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker …

Fix: 2.7.51 / 2.8.50+
Fix from $1,950 2019-05-16
Symfony HIGH 7.1
CVE-2019-10912

In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user inp…

Fix: 2.8.50 / 3.4.26+
Fix from $1,950 2019-05-16
Symfony MEDIUM 5.4
CVE-2019-10909

In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, whi…

Fix: 2.7.51 / 2.8.50+
Fix from $1,600 2019-05-16
Symfony MEDIUM 6.1
CVE-2018-19790

An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4…

Fix: 2.7.50 / 2.8.49+
Fix from $1,600 2018-12-18
Symfony MEDIUM 5.3
CVE-2018-19789

An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x be…

Fix: 2.7.50 / 2.8.49+
Fix from $1,600 2018-12-18