Vulnerabilities in symfony

65 results
Vexday analysis

O Symfony apresenta um volume significativo de 65 CVEs catalogadas, com 39 publicadas nos últimos 90 dias, indicando vulnerabilidades recentes e contínuas. A fraqueza dominante é XSS (CWE-79), típica de frameworks web, embora apenas 1 seja crítica e nenhuma esteja sob ataque ativo no momento. O risco atual é moderado, mas demanda atenção ao padrão de descobertas recentes para detecção de novos exploits.

CVE-2024-50341LOWSecurity::login does not take into account custom user_checker in symfony/security-bundleEPSS 0.3%CVE-2026-49209MEDIUMSymfony UX: Denial of service in symfony/ux-live-component via unbounded batch action requestsEPSS 0.3%CVE-2026-49211MEDIUMSymfony UX: Information exposure via unescaped LIKE wildcards in EntitySearchUtilEPSS 0.3%CVE-2026-45066LOWSymfony: HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> MisclassificationEPSS 0.3%CVE-2026-45753LOWSymfony: HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite — javascript: URI Survives Sanitization (XSS)EPSS 0.3%CVE-2026-45064LOWSymfony: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href SpoofingEPSS 0.3%CVE-2026-45070MEDIUMSymfony: Email Header Injection via Non-Token Characters in Mime Parameter NamesEPSS 0.3%CVE-2026-48761MEDIUMSymfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet>, <iframe>, <img> and the URL Inside <meta http-equiv="refresh"> contentEPSS 0.3%CVE-2026-48784MEDIUMSymfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 NormalizationEPSS 0.3%CVE-2026-45065LOWSymfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL InjectionEPSS 0.3%CVE-2026-48760MEDIUMSymfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing DefenseEPSS 0.3%CVE-2026-49208MEDIUMSymfony UX: Format-less date LiveProps parsed with the permissive DateTime constructorEPSS 0.2%CVE-2026-45755MEDIUMSymfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event InjectionEPSS 0.2%CVE-2026-47212MEDIUMSymfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event InjectionEPSS 0.2%CVE-2026-45069HIGHSymfony: OidcTokenHandler Accepts JWTs Missing aud/iss/exp ClaimsEPSS 0.2%CVE-2026-45072LOWSymfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File RenderingEPSS 0.2%CVE-2025-47946MEDIUMsymfony/ux-live-component and symfony/ux-twig-component vulnerable to unsanitized HTML attribute injection via ComponentAttributesEPSS 0.2%CVE-2026-24739MEDIUMSymfony has incorrect argument escaping under MSYS2/Git Bash on Windows that can lead to destructive file operationsEPSS 0.2%CVE-2026-48747MEDIUMSymfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm DowngradeEPSS 0.2%CVE-2026-49210LOWSymfony UX: XSS in symfony/ux-live-component via attacker-controlled child component tagEPSS 0.2%