Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-77939 |
|
Code Injection in symfony (CVE-2026-77939)
code injection in symfony (CVE-2026-77939). Confidential information can be exposed externally. Exploitable via `POST /api/v1/query`.
|
| CVE-2026-72830 |
|
Privilege Escalation in symfony (CVE-2026-72830)
vulnerability in symfony (CVE-2026-72830). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57232 |
|
SSRF (Server-Side Request Forgery) in symfony (CVE-2026-57232)
SSRF in symfony (CVE-2026-57232). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55824 |
|
Information Disclosure in contao/contao (CVE-2026-55824)
vulnerability in contao/contao (CVE-2026-55824). Risk of unauthorized operations or information disclosure. Exploitable via ``Cookie``. Mitigation: upgrade to `5.7.7` or later.
|
| CVE-2026-46627 |
|
Vulnerability in symfony (CVE-2026-46627)
vulnerability in symfony (CVE-2026-46627). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-54164 |
|
Vulnerability in api-platform/core (CVE-2026-54164)
vulnerability in api-platform/core (CVE-2026-54164). Data can be tampered with by attackers. Exploitable via ``AbstractItemNormalizer``. Mitigation: upgrade to `4.3.12` or later.
|
| CVE-2026-49981 |
|
Vulnerability in twig/twig (CVE-2026-49981)
vulnerability in twig/twig (CVE-2026-49981). Confidential information can be exposed externally. Exploitable via ``Template``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-48808 |
|
Vulnerability in twig/twig (CVE-2026-48808)
vulnerability in twig/twig (CVE-2026-48808). Confidential information can be exposed externally. Exploitable via ``SourcePolicyInterface``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-48807 |
|
Vulnerability in twig/twig (CVE-2026-48807)
vulnerability in twig/twig (CVE-2026-48807). Confidential information can be exposed externally. Exploitable via ``Traversable``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-48806 |
|
Vulnerability in twig/twig (CVE-2026-48806)
vulnerability in twig/twig (CVE-2026-48806). Confidential information can be exposed externally. Exploitable via ``CheckToStringNode``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-48805 |
|
Vulnerability in twig/twig (CVE-2026-48805)
vulnerability in twig/twig (CVE-2026-48805). Confidential information can be exposed externally. Exploitable via ``Environment``. Mitigation: upgrade to `3.27.0` or later.
|
| CVE-2026-55878 |
|
Path Traversal in symfony/ux-toolkit (CVE-2026-55878)
path traversal in symfony/ux-toolkit (CVE-2026-55878). Successful exploitation can lead to full system takeover. Exploitable via ``true``. Mitigation: upgrade to `3.2.0` or later.
|
| CVE-2026-55877 |
|
Cross-Site Scripting (XSS) in symfony/ux-icons (CVE-2026-55877)
cross-site scripting in symfony/ux-icons (CVE-2026-55877). Risk of unauthorized operations or information disclosure. Exploitable via ``body``. Mitigation: upgrade to `3.2.0` or later.
|
| CVE-2026-49216 |
|
Cross-Site Scripting (XSS) in symfony/ux-autocomplete (CVE-2026-49216)
cross-site scripting in symfony/ux-autocomplete (CVE-2026-49216). Risk of unauthorized operations or information disclosure. Exploitable via ``text``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-49215 |
|
Cross-Site Request Forgery (CSRF) in symfony/ux-live-component (CVE-2026-49215)
vulnerability in symfony/ux-live-component (CVE-2026-49215). Risk of unauthorized operations or information disclosure. Exploitable via ``Accept``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-49212 |
|
Vulnerability in symfony/ux-live-component (CVE-2026-49212)
vulnerability in symfony/ux-live-component (CVE-2026-49212). Data can be tampered with by attackers. Exploitable via ``propsFromParent``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-49211 |
|
Information Disclosure in symfony/ux-autocomplete (CVE-2026-49211)
vulnerability in symfony/ux-autocomplete (CVE-2026-49211). Confidential information can be exposed externally. Exploitable via ``LIKE``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-49210 |
|
Cross-Site Scripting (XSS) in symfony/ux-live-component (CVE-2026-49210)
cross-site scripting in symfony/ux-live-component (CVE-2026-49210). Risk of unauthorized operations or information disclosure. Exploitable via ``LiveComponentSubscriber``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-49209 |
|
Vulnerability in symfony/ux-live-component (CVE-2026-49209)
vulnerability in symfony/ux-live-component (CVE-2026-49209). Risk of unauthorized operations or information disclosure. Exploitable via ``actions``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-49208 |
|
Vulnerability in symfony/ux-live-component (CVE-2026-49208)
vulnerability in symfony/ux-live-component (CVE-2026-49208). Risk of unauthorized operations or information disclosure. Exploitable via ``DateTimeInterface``. Mitigation: upgrade to `3.1.0` or later.
|
| CVE-2026-49260 |
|
OS Command Injection in pontedilana/php-weasyprint (CVE-2026-49260)
OS command injection in pontedilana/php-weasyprint (CVE-2026-49260). Successful exploitation can lead to full system takeover. Exploitable via ``master``. Mitigation: upgrade to `2.5.1` or later.
|
| CVE-2026-48784 |
|
Vulnerability in symfony/routing (CVE-2026-48784)
vulnerability in symfony/routing (CVE-2026-48784). Risk of unauthorized operations or information disclosure. Exploitable via ``strtr``. Mitigation: upgrade to `8.0.13` or later.
|
| CVE-2026-48760 |
|
Vulnerability in symfony/html-sanitizer (CVE-2026-48760)
vulnerability in symfony/html-sanitizer (CVE-2026-48760). Risk of unauthorized operations or information disclosure. Exploitable via ``href``. Mitigation: upgrade to `8.0.13` or later.
|
| CVE-2026-48747 |
|
Vulnerability in symfony/mailomat-mailer (CVE-2026-48747)
vulnerability in symfony/mailomat-mailer (CVE-2026-48747). Risk of unauthorized operations or information disclosure. Exploitable via ``md4``. Mitigation: upgrade to `8.0.13` or later.
|
| CVE-2026-48736 |
|
Vulnerability in symfony/http-client (CVE-2026-48736)
vulnerability in symfony/http-client (CVE-2026-48736). Confidential information can be exposed externally. Exploitable via ``NoPrivateNetworkHttpClient``. Mitigation: upgrade to `5.4.53` or later.
|
| CVE-2026-48489 |
|
Authorization Flaw in symfony/security-http (CVE-2026-48489)
vulnerability in symfony/security-http (CVE-2026-48489). Confidential information can be exposed externally. Exploitable via ``DefaultAuthenticationFailureHandler``. Mitigation: upgrade to `8.0.13` or later.
|
| CVE-2026-48761 |
|
Vulnerability in symfony/html-sanitizer (CVE-2026-48761)
vulnerability in symfony/html-sanitizer (CVE-2026-48761). Risk of unauthorized operations or information disclosure. Exploitable via ``content``. Mitigation: upgrade to `8.0.13` or later.
|
| CVE-2026-47767 |
|
Vulnerability in symfony/runtime (CVE-2026-47767)
vulnerability in symfony/runtime (CVE-2026-47767). Successful exploitation can lead to full system takeover. Exploitable via ``APP_ENV``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-47732 |
|
Authorization Flaw in twig/twig (CVE-2026-47732)
vulnerability in twig/twig (CVE-2026-47732). Confidential information can be exposed externally. Exploitable via ``SandboxNodeVisitor``. Mitigation: upgrade to `3.26.0` or later.
|
| CVE-2026-47730 |
|
Cross-Site Scripting (XSS) in twig/twig (CVE-2026-47730)
cross-site scripting in twig/twig (CVE-2026-47730). Risk of unauthorized operations or information disclosure. Exploitable via ``ArrayLoader``. Mitigation: upgrade to `3.26.0` or later.
|
| CVE-2026-47212 |
|
Vulnerability in symfony/symfony (CVE-2026-47212)
vulnerability in symfony/symfony (CVE-2026-47212). Risk of unauthorized operations or information disclosure. Exploitable via ``framework.trusted_proxies``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-46644 |
|
Vulnerability in symfony/polyfill (CVE-2026-46644)
vulnerability in symfony/polyfill (CVE-2026-46644). Risk of unauthorized operations or information disclosure. Exploitable via ``intl``. Mitigation: upgrade to `1.38.1` or later.
|
| CVE-2026-45756 |
|
Vulnerability in symfony/json-path (CVE-2026-45756)
vulnerability in symfony/json-path (CVE-2026-45756). Risk of unauthorized operations or information disclosure. Exploitable via ``JsonPath``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45755 |
|
Vulnerability in symfony/mailtrap-mailer (CVE-2026-45755)
vulnerability in symfony/mailtrap-mailer (CVE-2026-45755). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45754 |
|
Authentication Bypass in symfony/lox24-notifier (CVE-2026-45754)
authentication bypass in symfony/lox24-notifier (CVE-2026-45754). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45753 |
|
Cross-Site Scripting (XSS) in symfony/html-sanitizer (CVE-2026-45753)
cross-site scripting in symfony/html-sanitizer (CVE-2026-45753). Risk of unauthorized operations or information disclosure. Exploitable via ``UrlAttributeSanitizer``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45305 |
|
Vulnerability in symfony/yaml (CVE-2026-45305)
vulnerability in symfony/yaml (CVE-2026-45305). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45304 |
|
Vulnerability in symfony/yaml (CVE-2026-45304)
vulnerability in symfony/yaml (CVE-2026-45304). Risk of unauthorized operations or information disclosure. Exploitable via ``stdClass``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45133 |
|
Vulnerability in symfony/yaml (CVE-2026-45133)
vulnerability in symfony/yaml (CVE-2026-45133). Risk of unauthorized operations or information disclosure. Exploitable via ``Parser``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45077 |
|
Unsafe Deserialization in symfony/monolog-bridge (CVE-2026-45077)
vulnerability in symfony/monolog-bridge (CVE-2026-45077). Risk of unauthorized operations or information disclosure. Exploitable via ``allowed_classes``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45075 |
|
Authorization Flaw in symfony/http-kernel (CVE-2026-45075)
vulnerability in symfony/http-kernel (CVE-2026-45075). Data can be tampered with by attackers. Exploitable via ``HEAD``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45074 |
|
Vulnerability in symfony/security-http (CVE-2026-45074)
vulnerability in symfony/security-http (CVE-2026-45074). Confidential information can be exposed externally. Exploitable via `Host header`. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45073 |
|
SQL Injection in symfony/cache (CVE-2026-45073)
SQL injection in symfony/cache (CVE-2026-45073). Risk of unauthorized operations or information disclosure. Exploitable via ``AbstractAdapterTrait``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45072 |
|
Cross-Site Scripting (XSS) in symfony/symfony (CVE-2026-45072)
cross-site scripting in symfony/symfony (CVE-2026-45072). Risk of unauthorized operations or information disclosure. Exploitable via ``file_excerpt``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45071 |
|
XXE (XML External Entity) in symfony/dom-crawler (CVE-2026-45071)
vulnerability in symfony/dom-crawler (CVE-2026-45071). Confidential information can be exposed externally. Exploitable via ``Crawler``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45070 |
|
Vulnerability in symfony/mime (CVE-2026-45070)
vulnerability in symfony/mime (CVE-2026-45070). Risk of unauthorized operations or information disclosure. Exploitable via ``tokens``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45069 |
|
Vulnerability in symfony/security-http (CVE-2026-45069)
vulnerability in symfony/security-http (CVE-2026-45069). Confidential information can be exposed externally. Exploitable via ``OidcTokenHandler``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45068 |
|
Vulnerability in symfony/mailer (CVE-2026-45068)
vulnerability in symfony/mailer (CVE-2026-45068). Data can be tampered with by attackers. Exploitable via ``MAILER_DSN``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45067 |
|
Vulnerability in symfony/mime (CVE-2026-45067)
vulnerability in symfony/mime (CVE-2026-45067). Risk of unauthorized operations or information disclosure. Exploitable via ``SmtpTransport``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-45066 |
|
Vulnerability in symfony/html-sanitizer (CVE-2026-45066)
vulnerability in symfony/html-sanitizer (CVE-2026-45066). Risk of unauthorized operations or information disclosure. Exploitable via ``trusted.com``. Mitigation: upgrade to `8.0.12` or later.
|