VYPR

UX Autocomplete

by Sensiolabs

CVEs (2)

  • CVE-2023-41336MedSep 11, 2023
    risk 0.35cvss 6.5epss 0.01

    ux-autocomplete is a JavaScript Autocomplete functionality for Symfony. Under certain circumstances, an attacker could successfully submit an entity id for an `EntityType` that is *not* part of the valid choices. The problem has been fixed in `symfony/ux-autocomplete` version…

  • CVE-2026-49216MedJul 17, 2026
    risk 0.28cvss 5.4epss 0.00

    Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-autocomplete renders AJAX response items in _createAutocompleteWithRemoteData() by interpolating the text field into HTML template literals…