Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sylius MEDIUM 5.9
CVE-2026-31824

Sylius is an Open Source eCommerce Framework on Symfony. A Time-of-Check To Time-of-Use (TOCTOU) race condition was discovered in the promotion usage…

Fix: 1.9.12 / 1.10.16+
Fix from $1,600 2026-03-10
Sylius MEDIUM 5.3
CVE-2026-31825

Sylius is an Open Source eCommerce Framework on Symfony. Sylius API filters ProductPriceOrderFilter and TranslationOrderNameAndLocaleFilter pass user…

Fix: 1.9.12 / 1.10.16+
Fix from $1,600 2026-03-10
Sylius MEDIUM 6.5
CVE-2026-31820

Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulnerability exists in multiple sh…

Fix: 2.0.16 / 2.1.12+
Fix from $1,600 2026-03-10
Sylius MEDIUM 6.1
CVE-2026-31819

Sylius is an Open Source eCommerce Framework on Symfony. CurrencySwitchController::switchAction(), ImpersonateUserController::impersonateAction() and…

Fix: 1.9.12 / 1.10.16+
Fix from $1,600 2026-03-10
Sylius MEDIUM 6.1
CVE-2026-31822

Sylius is an Open Source eCommerce Framework on Symfony. A cross-site scripting (XSS) vulnerability exists in the shop checkout login form handled by…

Fix: 2.0.16 / 2.1.12+
Fix from $1,600 2026-03-10
Sylius MEDIUM 5.3
CVE-2026-31821

Sylius is an Open Source eCommerce Framework on Symfony. The POST /api/v2/shop/orders/{tokenValue}/items endpoint does not verify cart ownership. An …

Fix: 2.0.16 / 2.1.12+
Fix from $1,600 2026-03-10
Sylius HIGH 7.5
CVE-2024-57610

A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasin…

No fix yet
Fix from $1,950 2025-02-06
Sylius MEDIUM 5.4
CVE-2021-3841

sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability…

Fix: 1.9.10 / 1.10.11+
Fix from $1,600 2024-11-15
Sylius MEDIUM 6.4
CVE-2024-29376

Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book.

No fix yet
Fix from $1,600 2024-04-22
Syliusgridbundle CRITICAL 9.8
CVE-2022-24752

SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query…

Fix: 1.10.1+
Fix from $2,300 2022-03-15
Sylius MEDIUM 6.1
CVE-2022-24749

Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-…

Fix: 1.9.10 / 1.10.11+
Fix from $1,600 2022-03-14
Sylius HIGH 8.2
CVE-2022-24743

Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set to null after the password wa…

Fix: 1.10.11 / 1.11.2+
Fix from $1,950 2022-03-14
Sylius MEDIUM 5.5
CVE-2022-24742

Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains u…

Fix: 1.9.10 / 1.10.11+
Fix from $1,600 2022-03-14
Sylius MEDIUM 6.1
CVE-2022-24733

Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to lo…

Fix: 1.9.10 / 1.10.11+
Fix from $1,600 2022-03-14
Paypal HIGH 7.5
CVE-2021-41120

sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment page done after checkout was…

Fix: 1.2.4 / 1.3.1+
Fix from $1,950 2021-10-05
Sylius MEDIUM 5.3
CVE-2021-32720

Sylius is an Open Source eCommerce platform on top of Symfony. In versions of Sylius prior to 1.9.5 and 1.10.0-RC.1, part of the details (order ID, o…

Fix: 1.9.5+
Fix from $1,600 2021-06-28
Syliusresourcebundle HIGH 8.8
CVE-2020-15146

In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression evaluated by `symfony/expres…

Fix: after 1.6.3
Fix from $1,950 2020-08-20
Syliusresourcebundle HIGH 8.8
CVE-2020-15143

In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expression evaluated by `symfony/expre…

Fix: after 1.6.3
Fix from $1,950 2020-08-20
Syliusresourcebundle MEDIUM 5.3
CVE-2020-5220

Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data exposure by using an unintend…

Fix: after 1.6.2
Fix from $1,600 2020-01-27