VYPR
Vendor

Sylius

Products
7
CVEs
33
Across products
35
Status
Private

Products

7

Recent CVEs

33
View all 33 CVEs →
  • CVE-2022-24752CriMar 15, 2022
    risk 0.57cvss 9.8epss 0.01

    SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query sorting were passed directly to the database. The maintainers do not know if this could lead to direct SQL injections but took…

  • CVE-2020-15146CriAug 20, 2020
    risk 0.56cvss 9.6epss 0.02

    In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized properly. This allows the attacker to access any public service by manipulating that…

  • CVE-2026-31824HigMar 10, 2026
    risk 0.46cvss 8.2epss 0.00

    Sylius is an Open Source eCommerce Framework on Symfony. A Time-of-Check To Time-of-Use (TOCTOU) race condition was discovered in the promotion usage limit enforcement. The same class of vulnerability affects the promotion usage limit (the global used counter on Promotion…

  • CVE-2022-24743HigMar 14, 2022
    risk 0.46cvss 7.1epss 0.01

    Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set to null after the password was changed. The same token could be used several times, which could result in leak of the existing token and unauthorized password…

  • CVE-2020-15143HigAug 20, 2020
    risk 0.43cvss 7.7epss 0.02

    In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized properly. This allows the attacker to access any public service by manipulating…

  • CVE-2026-68500HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.00

    Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but does not verify that the Mollie…

  • CVE-2024-57610HigFeb 6, 2025
    risk 0.42cvss 7.5epss 0.01

    A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The Supplier's position is that the Sylius core…

  • CVE-2021-41120HigOct 5, 2021
    risk 0.42cvss 7.5epss 0.02

    sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment page done after checkout was created with autoincremented payment id (/pay-with-paypal/{id}) and therefore it was easy to predict. The problem is that the…

  • CVE-2022-24749MedMar 14, 2022
    risk 0.40cvss 6.1epss 0.01

    Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-site scripting (XSS) code in the admin panel. In order to perform a XSS attack, the file itself has to be open in a new card or…

  • CVE-2022-24733MedMar 14, 2022
    risk 0.40cvss 6.1epss 0.01

    Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to load the website within an iframe. This will enable a clickjacking attack, in which the attacker's page overlays the target…

  • CVE-2026-68501MedJul 30, 2026
    risk 0.35cvss 6.5epss 0.00

    Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCodeAction::fetchQrCodeFromOrder endpoints…

  • CVE-2026-31820MedMar 10, 2026
    risk 0.35cvss 6.5epss 0.00

    Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulnerability exists in multiple shop LiveComponents due to unvalidated resource IDs accepted via #[LiveArg] parameters. Unlike props, which are protected by…

  • CVE-2025-30152MedMar 19, 2025
    risk 0.35cvss 6.5epss 0.00

    The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. Prior to 1.6.2, 1.7.2, and 2.0.2, a discovered vulnerability allows users to modify their shopping cart after completing the PayPal Checkout process and payment authorization. If a user…

  • CVE-2025-29788MedMar 17, 2025
    risk 0.35cvss 6.5epss 0.00

    The Syliud PayPal Plugin is the Sylius Core Team’s plugin for the PayPal Commerce Platform. A vulnerability in versions prior to 1.6.1, 1.7.1, and 2.0.1 allows users to manipulate the final payment amount processed by PayPal. If a user modifies the item quantity in their…

  • CVE-2024-29376MedApr 22, 2024
    risk 0.35cvss 6.4epss 0.00

    Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book.

  • CVE-2026-31822MedMar 10, 2026
    risk 0.33cvss 6.1epss 0.00

    Sylius is an Open Source eCommerce Framework on Symfony. A cross-site scripting (XSS) vulnerability exists in the shop checkout login form handled by the ApiLoginController Stimulus controller. When a login attempt fails, AuthenticationFailureHandler returns a JSON response…

  • CVE-2026-31819MedMar 10, 2026
    risk 0.33cvss 6.1epss 0.00

    Sylius is an Open Source eCommerce Framework on Symfony. CurrencySwitchController::switchAction(), ImpersonateUserController::impersonateAction() and StorageBasedLocaleSwitcher::handle() use the HTTP Referer header directly when redirecting. The attack requires the victim to…

  • CVE-2022-24742MedMar 14, 2022
    risk 0.33cvss 5.0epss 0.01

    Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains unclosed after log out. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is available. The application must…

  • CVE-2019-12186MedDec 31, 2019
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in Sylius products. Missing input sanitization in sylius/sylius 1.0.x through 1.0.18, 1.1.x through 1.1.17, 1.2.x through 1.2.16, 1.3.x through 1.3.11, and 1.4.x through 1.4.3 and sylius/grid 1.0.x through 1.0.18, 1.1.x through 1.1.18, 1.2.x through…

  • CVE-2020-5220MedJan 27, 2020
    risk 0.29cvss 4.4epss 0.01

    Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data exposure by using an unintended serialisation group - for example it could make Shop API use a more permissive group from Admin API. Anyone exposing an API…