Exposure of Symfony

Web frameworks
82
exposure score
9,704
sites use
0
exploited
1
critical
Vexday analysis

O histórico de vulnerabilidades catalogadas para o framework Symfony soma 24 CVEs, sem registros de exploração ativa confirmada no catálogo CISA KEV e sem entradas de severidade crítica, o que posiciona a tecnologia abaixo da média geral do catálogo em termos de taxa de exploração. Ainda assim, merece atenção o fato de que a CVE mais perigosa atualmente identificada, CVE-2024-50340, apresenta um score EPSS de aproximadamente 0,63, indicando probabilidade relevante de exploração prática em curto prazo. O tipo de falha mais recorrente é CWE-287 (autenticação inadequada), padrão que costuma facilitar acesso não autorizado quando não mitigado adequadamente. Equipes responsáveis por ambientes baseados em Symfony devem priorizar a revisão dos mecanismos de autenticação e acompanhar ativamente a evolução do risco associado a CVE-2024-50340.

CVEs

53 results
CVE-2026-45064LOWSymfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href SpoofingEPSS 0.3%CVE-2026-45753LOWSymfony: HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite — javascript: URI Survives Sanitization (XSS)EPSS 0.3%CVE-2026-45070MEDIUMSymfony: Email Header Injection via Non-Token Characters in Mime Parameter NamesEPSS 0.3%CVE-2026-48761MEDIUMSymfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet>, <iframe>, <img> and the URL Inside <meta http-equiv="refresh"> contentEPSS 0.3%CVE-2026-48784MEDIUMSymfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 NormalizationEPSS 0.3%CVE-2026-45065LOWSymfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL InjectionEPSS 0.3%CVE-2026-48760MEDIUMSymfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing DefenseEPSS 0.3%CVE-2026-45755MEDIUMSymfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event InjectionEPSS 0.2%CVE-2026-47212MEDIUMSymfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event InjectionEPSS 0.2%CVE-2026-45069HIGHSymfony: OidcTokenHandler Accepts JWTs Missing aud/iss/exp ClaimsEPSS 0.2%CVE-2026-45072LOWSymfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File RenderingEPSS 0.2%CVE-2026-24739MEDIUMSymfony has incorrect argument escaping under MSYS2/Git Bash on Windows that can lead to destructive file operationsEPSS 0.2%CVE-2026-48747MEDIUMSymfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm DowngradeEPSS 0.2%