VYPR

Sylius

by Sylius

Source repositories

CVEs (24)

  • CVE-2026-31823MedMar 10, 2026
    risk 0.24cvss 4.8epss 0.00

    Sylius is an Open Source eCommerce Framework on Symfony. An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple places across the shop frontend and admin panel due to unsanitized entity names being rendered as raw HTML. Shop breadcrumbs…

  • CVE-2024-34349MedMay 14, 2024
    risk 0.24cvss 4.8epss 0.00

    Sylius is an open source eCommerce platform. Prior to 1.12.16 and 1.13.1, there is a possibility to execute javascript code in the Admin panel. In order to perform an XSS attack input a script into Name field in which of the resources: Taxons, Products, Product Options or…

  • CVE-2020-15245MedOct 19, 2020
    risk 0.21cvss 4.3epss 0.01

    In Sylius before versions 1.6.9, 1.7.9 and 1.8.3, the user may register in a shop by email [email protected], verify it, change it to the mail [email protected] and stay verified and enabled. This may lead to having accounts addressed to totally different emails, that were…

  • CVE-2019-16768LowDec 5, 2019
    risk 0.16cvss 3.5epss 0.01

    In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Symfony\Component\Security\Core\Exception\AuthenticationServiceException and propagated through the system to UI. Therefore, some internal system information may…

Page 2 of 2