VYPR

Symfony

by Sensiolabs

Source repositories

CVEs (95)

  • CVE-2019-11325CriNov 21, 2019
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.

  • CVE-2016-2403CriFeb 7, 2017
    risk 0.64cvss 9.8epss 0.03

    Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.

  • CVE-2019-18889CriNov 21, 2019
    risk 0.59cvss 9.8epss 0.33

    An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.

  • CVE-2026-47767CriJul 14, 2026
    risk 0.57cvss 9.8epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a…

  • CVE-2017-11365CriMay 23, 2019
    risk 0.57cvss 9.8epss 0.02

    Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.

  • CVE-2019-10913CriMay 16, 2019
    risk 0.57cvss 9.8epss 0.02

    In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is…

  • CVE-2019-10910CriMay 16, 2019
    risk 0.57cvss 9.8epss 0.06

    In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.

  • CVE-2018-11407CriJun 13, 2018
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an…

  • CVE-2013-4751HigNov 1, 2019
    risk 0.53cvss 8.1epss 0.01

    php-symfony2-Validator has loss of information during serialization

  • CVE-2026-45069CriJul 14, 2026
    risk 0.52cvss 9.1epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list…

  • CVE-2026-45063CriJul 14, 2026
    risk 0.52cvss 9.1epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress=…

  • CVE-2018-11406HigJun 13, 2018
    risk 0.50cvss 8.8epss 0.01

    An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is logged out. This behavior can be disabled…

  • CVE-2026-48736HigJul 14, 2026
    risk 0.49cvss 8.6epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and…

  • CVE-2026-45077HigJul 14, 2026
    risk 0.49cvss 8.6epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and processes each received…

  • CVE-2016-4423HigJun 1, 2016
    risk 0.49cvss 7.5epss 0.02

    The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username stored in a session, which…

  • CVE-2026-45075HigJul 14, 2026
    risk 0.46cvss 8.2epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured for GET only, but Symfony routes HEAD requests to…

  • CVE-2026-45074HigJul 14, 2026
    risk 0.46cvss 8.1epss 0.00

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which reflects an attacker-controlled Host header when…

  • CVE-2024-50340HigNov 6, 2024
    risk 0.46cvss 7.3epss 0.63

    symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted query string, they are able to change the…

  • CVE-2022-23601HigFeb 1, 2022
    risk 0.46cvss 8.1epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony form component provides a CSRF protection mechanism by using a random token injected in the form and using the session to store and control the token submitted by the…

  • CVE-2019-18887HigNov 21, 2019
    risk 0.46cvss 8.1epss 0.01

    An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.

Page 1 of 5