VYPR

Sylius

by Sylius

Source repositories

CVEs (28)

  • CVE-2026-100871HigSep 27, 2026
    risk 0.50cvss 8.8epss 0.00

    Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endpoints. Attackers can register a shop customer account using an administrator's email address and obtain a token…

  • CVE-2026-100870HigSep 27, 2026
    risk 0.50cvss 8.8epss 0.00

    Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can request…

  • CVE-2026-31824HigMar 10, 2026
    risk 0.46cvss 8.2epss 0.00

    Sylius is an Open Source eCommerce Framework on Symfony. A Time-of-Check To Time-of-Use (TOCTOU) race condition was discovered in the promotion usage limit enforcement. The same class of vulnerability affects the promotion usage limit (the global used counter on Promotion…

  • CVE-2022-24743HigMar 14, 2022
    risk 0.46cvss 7.1epss 0.01

    Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set to null after the password was changed. The same token could be used several times, which could result in leak of the existing token and unauthorized password…

  • CVE-2026-100872HigSep 27, 2026
    risk 0.42cvss 7.5epss 0.00

    Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have…

  • CVE-2024-57610HigFeb 6, 2025
    risk 0.42cvss 7.5epss 0.01

    A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The Supplier's position is that the Sylius core…

  • CVE-2022-24749MedMar 14, 2022
    risk 0.40cvss 6.1epss 0.01

    Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-site scripting (XSS) code in the admin panel. In order to perform a XSS attack, the file itself has to be open in a new card or…

  • CVE-2022-24733MedMar 14, 2022
    risk 0.40cvss 6.1epss 0.01

    Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to load the website within an iframe. This will enable a clickjacking attack, in which the attacker's page overlays the target…

  • CVE-2026-53637MedSep 8, 2026
    risk 0.35cvss 6.5epss 0.00

    Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is completed while its cart page remains open,…

  • CVE-2026-31820MedMar 10, 2026
    risk 0.35cvss 6.5epss 0.00

    Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulnerability exists in multiple shop LiveComponents due to unvalidated resource IDs accepted via #[LiveArg] parameters. Unlike props, which are protected by…

  • CVE-2024-29376MedApr 22, 2024
    risk 0.35cvss 6.4epss 0.00

    Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book.

  • CVE-2026-53639MedSep 8, 2026
    risk 0.34cvss —epss 0.01

    Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop/payment-requests/{hash}` endpoints look up the payment request solely by the…

  • CVE-2026-31822MedMar 10, 2026
    risk 0.33cvss 6.1epss 0.00

    Sylius is an Open Source eCommerce Framework on Symfony. A cross-site scripting (XSS) vulnerability exists in the shop checkout login form handled by the ApiLoginController Stimulus controller. When a login attempt fails, AuthenticationFailureHandler returns a JSON response…

  • CVE-2026-31819MedMar 10, 2026
    risk 0.33cvss 6.1epss 0.00

    Sylius is an Open Source eCommerce Framework on Symfony. CurrencySwitchController::switchAction(), ImpersonateUserController::impersonateAction() and StorageBasedLocaleSwitcher::handle() use the HTTP Referer header directly when redirecting. The attack requires the victim to…

  • CVE-2022-24742MedMar 14, 2022
    risk 0.33cvss 5.0epss 0.01

    Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains unclosed after log out. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is available. The application must…

  • CVE-2026-100869MedSep 27, 2026
    risk 0.31cvss 5.9epss 0.00

    Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers to trigger refunds on completed orders. Attackers with order tokens can submit arbitrary payment actions like refunds that payment gateways execute while…

  • CVE-2019-12186MedDec 31, 2019
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in Sylius products. Missing input sanitization in sylius/sylius 1.0.x through 1.0.18, 1.1.x through 1.1.17, 1.2.x through 1.2.16, 1.3.x through 1.3.11, and 1.4.x through 1.4.3 and sylius/grid 1.0.x through 1.0.18, 1.1.x through 1.1.18, 1.2.x through…

  • CVE-2020-5218MedJan 27, 2020
    risk 0.29cvss 4.4epss 0.01

    Affected versions of Sylius give attackers the ability to switch channels via the _channel_code GET parameter in production environments. This was meant to be enabled only when kernel.debug is set to true. However, if no sylius_channel.debug is set explicitly in the…

  • CVE-2021-3841MedNov 15, 2024
    risk 0.28cvss 5.4epss 0.00

    sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of the user's browser.

  • CVE-2021-32720MedJun 28, 2021
    risk 0.28cvss 5.3epss 0.01

    Sylius is an Open Source eCommerce platform on top of Symfony. In versions of Sylius prior to 1.9.5 and 1.10.0-RC.1, part of the details (order ID, order number, items total, and token value) of all placed orders were exposed to unauthorized users. If exploited properly, a few…

Page 1 of 2