An open API service providing security vulnerability metadata for many open source software ecosystems.

Browse Security Advisories

High
about 1 year ago

Symfony Cross-Site Request Forgery vulnerability in the Web Profiler GSA_kwCzR0hTQS12MzVnLTRycnctaDRmd84AA8jj

packagist symfony/web-profiler-bundle, symfony/symfony
Moderate
about 1 year ago

Symfony has unsafe methods in the Request class GSA_kwCzR0hTQS1wNjg0LWY3ZmgtanYyas4AA8jb

packagist symfony/symfony, symfony/http-foundation
Moderate
about 1 year ago

Symfony has a security issue when parsing the Authorization header GSA_kwCzR0hTQS1oN3YyLTJxd2ctaDgyOc4AA8ja

packagist symfony/symfony, symfony/http-foundation
Moderate
about 1 year ago

Symfony2 security issue when the trust proxy mode is enabled GSA_kwCzR0hTQS12Zm02LXIyZ2MtcHd3d84AA8jY

packagist symfony/symfony, symfony/http-foundation
Moderate
over 1 year ago

Symfony potential Cross-site Scripting in WebhookController GSA_kwCzR0hTQS03MngyLTVjODUtNndtcs4AA3Cz

packagist symfony/symfony, symfony/webhook
Moderate
over 1 year ago

Symfony possible session fixation vulnerability GSA_kwCzR0hTQS1tMndqLXI2ZzMtZnhmeM4AA3Cx

packagist symfony/symfony, symfony/security-http
Moderate
over 2 years ago

Symfony storing cookie headers in HttpCache GSA_kwCzR0hTQS1oN3ZmLTV3cnYtOWZods4AAxVO

packagist symfony/symfony, symfony/http-kernel
Moderate
over 2 years ago

Symfony vulnerable to Session Fixation of CSRF tokens GSA_kwCzR0hTQS0zZ3YyLTI5cWMtdjY3bc4AAxVN

packagist symfony/symfony, symfony/security-bundle
Critical
about 3 years ago

Symfony Incorrect Access Control GSA_kwCzR0hTQS1xODd2LXE4ZnctZ21qNc4AAgyh

packagist symfony/symfony, symfony/security, symfony/security-core
Moderate
about 3 years ago

Symfony Access Control Vulnerability GSA_kwCzR0hTQS04OWNwLWZ2Y2MtaHhoN84AAfYj

packagist symfony/symfony
Moderate
about 3 years ago

Symfony Allows URI Restrictions Bypass Via Double-Encoded String GSA_kwCzR0hTQS04M2MzLXF4MjctMnJ3cs4AAfXs

packagist symfony/symfony, symfony/security, symfony/routing, symfony/http-foundation
Moderate
about 3 years ago

Symfony Denial of Service Via Long Password Hashing GSA_kwCzR0hTQS1jcjQ5LWZ4MnYtOXA1N84AAd7g

packagist symfony/security, symfony/polyfill, symfony/symfony
High
about 3 years ago

Symfony Cryptographic Vulnerability GSA_kwCzR0hTQS1qang1LWZxNWctOHhwY84AAdU8

packagist symfony/symfony, symfony/security, symfony/security-core
High
about 3 years ago

Symphony Denial of Service Via Overlong Usernames GSA_kwCzR0hTQS13aGd2LThjZzMtN2hjbc4AAdU9

packagist symfony/symfony, symfony/security, symfony/security-http
Moderate
about 3 years ago

Symfony Vulnerable to PHP Eval Injection GSA_kwCzR0hTQS01YzU4LXc5eGMtcWNqOc4AAc0N

packagist symfony/http-kernel, symfony/symfony
High
about 3 years ago

Symfony Vulnerable to Timing Attack GSA_kwCzR0hTQS1nOTdjLWpmeDYteHZ4aM4AAcl9

packagist symfony/symfony, symfony/security, symfony/security-http, symfony/form
Moderate
about 3 years ago

Symfony Incorrect Access Control GSA_kwCzR0hTQS1xbXF3LW1wcXAtbXI1NM4AAcRE

packagist symfony/http-kernel, symfony/symfony
High
about 3 years ago

Symfony Arbitrary PHP code Execution GSA_kwCzR0hTQS03dzUzLWhmcHctcmczZ84AAZ60

packagist symfony/yaml, symfony/symfony
Critical
about 3 years ago

Symfony Authentication Bypass GSA_kwCzR0hTQS0zNWM1LTI4cGctMnFnNM4AAWke

packagist symfony/symfony, symfony/security, symfony/security-core
Critical
about 3 years ago

Symfony Authentication Bypass GSA_kwCzR0hTQS13dmo1LXI3OHItaGhmcc4AAWjw

packagist symfony/symfony, symfony/security, symfony/security-core
Low
about 3 years ago

Symfony Session Fixation Vulnerability GSA_kwCzR0hTQS1qNWpoLWhwcjQtaDMzMs4AAV_7

packagist symfony/security, symfony/security-http, symfony/symfony
Moderate
about 3 years ago

Symfony SSRF Vulnerability via Form Component GSA_kwCzR0hTQS1jcXFoLTk0cjYtd2pyZ84AAV2m

packagist symfony/symfony, symfony/form
High
about 3 years ago

Symfony Host Header Injection GSA_kwCzR0hTQS02NnA2LTdwMjktNTVwOc4AAVWh

packagist symfony/symfony
High
about 3 years ago

Symfony Session Fixation Vulnerability GSA_kwCzR0hTQS1nNHJnLXJ3NjUtOGhmZ84AAT6-

packagist symfony/security, symfony/security-http, symfony/symfony
Moderate
about 3 years ago

Symfony Open Redirect GSA_kwCzR0hTQS1yN3A3LXFyN3AtMnJyZs4AAT52

packagist symfony/security, symfony/security-http, symfony/symfony
High
about 3 years ago

Symfony Directory Traversal GSA_kwCzR0hTQS1jNDlyLThnajYtNzY4cs4AAT5H

packagist symfony/symfony, symfony/intl
Moderate
about 3 years ago

Symfony Open Redirect GSA_kwCzR0hTQS03aHdjLTJjcTQtNngyd84AAT5V

packagist symfony/security-bundle, symfony/symfony
Moderate
about 3 years ago

Symfony DoS GSA_kwCzR0hTQS1yMnJxLTNoNTYtZnFtNM4AATu7

packagist symfony/http-foundation, symfony/symfony
High
about 3 years ago

Symfony CSRF Token Fixation GSA_kwCzR0hTQS1nNGc3LXE3MjYtdjVoZ84AATux

packagist symfony/security, symfony/security-http, symfony/security-bundle, symfony/symfony
Moderate
about 3 years ago

Symfony Open Redirect GSA_kwCzR0hTQS04OXIyLTVnMzQtMmc0N84AATfR

packagist symfony/symfony, symfony/security, symfony/security-http
Moderate
about 3 years ago

Symfony Path Disclosure GSA_kwCzR0hTQS14M2NmLXc2NHgtNGNwMs4AATfM

packagist symfony/form, symfony/symfony
Moderate
about 3 years ago

Symfony CSRF Vulnerability GSA_kwCzR0hTQS05Mng2LWgyZ3ItOGd4cc4AASJF

packagist symfony/symfony, symfony/security, symfony/security-csrf
Moderate
about 3 years ago

Symfony HTTP Foundation web cache poisoning GSA_kwCzR0hTQS04d2dqLTZ3eDgtaDVocc3r4Q

packagist symfony/symfony, symfony/http-foundation
Moderate
about 3 years ago

Symfony Host Header Injection vulnerability in the HttpFoundation component GSA_kwCzR0hTQS0yMnB2LTd2OWotaHF4cM3grg

packagist symfony/http-foundation, symfony/symfony
Moderate
over 3 years ago

CSV Injection in symfony/serializer GSA_kwCzR0hTQS0yeGhnLXcyZzUtdzk1eM0YGA

packagist symfony/symfony, symfony/serializer
Moderate
over 3 years ago

Cookie persistence after password changes in symfony/security-bundle GSA_kwCzR0hTQS1xdzM2LXA5N3ctdmNxcs0YFw

packagist symfony/symfony, symfony/security-bundle
Moderate
over 3 years ago

Webcache Poisoning in symfony/http-kernel GSA_kwCzR0hTQS1xM2ozLXczN3gtaHEycc0YFQ

packagist symfony/symfony, symfony/http-kernel
Moderate
about 4 years ago

Authentication granted to all firewalls instead of just one MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJmY2YtbTY3bS1qY3Jx

packagist symfony/symfony, symfony/security-http
Low
about 4 years ago

User enumeration in authentication mechanisms MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWcycWotcG14bS05Zjhm

packagist symfony/symfony, symfony/security-http
Moderate
about 4 years ago

Prevent user enumeration using Guard or the new Authenticator-based Security MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVwdjgtcHB2ai00aDY4

packagist symfony/symfony, symfony/security, symfony/security-http, symfony/maker-bundle, lexik/jwt-authentication-bundle, symfony/security-core, symfony/security-guard
High
almost 5 years ago

RCE in Symfony MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTc1NGgtNXIyNy03eDNy

packagist symfony/symfony, symfony/http-kernel
High
over 5 years ago

Improper authentication in Symfony MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNjaHgtbWZyYy1md3Fy

packagist symfony/symfony, symfony/security, symfony/security-http
High
over 5 years ago

Deserialization of untrusted data in Symfony MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXcyZnItNjV2cC1teHcz

packagist typo3/cms, typo3/cms-core, symfony/symfony, symfony/phpunit-bridge, symfony/cache
Critical
over 5 years ago

Improper Input Validation in Symfony MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXc0cmMtcngyNS04bTg2

packagist symfony/var-exporter, symfony/symfony
High
over 5 years ago

Argument injection in a MimeTypeGuesser in Symfony MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXhoaDYtOTU2cS00cTY5

packagist symfony/symfony, symfony/mime, symfony/http-foundation
Critical
over 5 years ago

Symfony Service IDs Allow Injection MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXBnd2otcHJwcS1qcGMy

packagist symfony/symfony, symfony/proxy-manager-bridge, symfony/dependency-injection
Moderate
over 5 years ago

Symfony Cross-site Scripting (XSS) vulnerability MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWc5OTYtcTVyOC13N2cy

packagist drupal/drupal, drupal/core, symfony/symfony, symfony/framework-bundle

Filter by Severity

Filter by Ecosystem

Filter by Package

moodle/moodle 418 magento/community-edition 300 typo3/cms 190 pimcore/pimcore 120 dolibarr/dolibarr 116 typo3/cms-core 111 phpmyadmin/phpmyadmin 107 drupal/core 103 magento/project-community-edition 100 microweber/microweber 99 silverstripe/framework 92 drupal/drupal 83 librenms/librenms 82 thorsten/phpmyfaq 73 symfony/symfony 69 concrete5/concrete5 65 shopware/platform 57 craftcms/cms 51 baserproject/basercms 47 shopware/core 45 mautic/core 44 nilsteampassnet/teampass 42 mantisbt/mantisbt 41 showdoc/showdoc 41 froxlor/froxlor 40 intelliants/subrion 39 snipe/snipe-it 36 zendframework/zendframework1 34 getgrav/grav 30 shopware/shopware 30 mediawiki/core 28 centreon/centreon 27 prestashop/prestashop 26 contao/core-bundle 25 magento/core 24 getkirby/cms 24 pocketmine/pocketmine-mp 24 phpoffice/phpexcel 23 laravel/framework 23 simplesamlphp/simplesamlphp 23 grumpydictator/firefly-iii 23 remdex/livehelperchat 23 zendframework/zendframework 23 tribalsystems/zenario 22 phpoffice/phpspreadsheet 21 funadmin/funadmin 20 cockpit-hq/cockpit 20 topthink/framework 18 contao/contao 18 genix/cms 18 forkcms/forkcms 18 openmage/magento-lts 17 opencart/opencart 17 francoisjacquet/rosariosis 17 ezsystems/ezpublish-kernel 17 symfony/security 17 yetiforce/yetiforce-crm 17 typo3/cms-backend 17 cakephp/cakephp 17 october/system 16 phpbb/phpbb 16 smarty/smarty 15 symfony/security-http 15 silverstripe/cms 15 bolt/bolt 15 ec-cube/ec-cube 15 pimcore/admin-ui-classic-bundle 15 feehi/cms 14 modx/revolution 14 phpmailer/phpmailer 14 codeigniter4/framework 14 dompdf/dompdf 14 admidio/admidio 13 impresscms/impresscms 13 lavalite/cms 13 sylius/sylius 13 yeswiki/yeswiki 13 elefant/cms 13 studio-42/elfinder 13 phpmyfaq/phpmyfaq 13 wallabag/wallabag 12 alextselegidis/easyappointments 12 symfony/http-foundation 12 wwbn/avideo 12 leantime/leantime 11 ezsystems/ezplatform-kernel 11 nukeviet/nukeviet 11 yiisoft/yii2 11 pagekit/pagekit 11 sulu/sulu 11 october/october 11 tinymce/tinymce 11 feehi/feehicms 11 tinymce 11 TinyMCE 11 ssddanbrown/bookstack 10 ezsystems/ezpublish-legacy 10 spatie/browsershot 10 in2code/femanager 9 contao/core 9 twbs/bootstrap 9 croogo/croogo 9 concrete5/core 9 bootstrap 9 ezsystems/ezplatform-admin-ui 9 bootstrap 9 twig/twig 9 in2code/powermail 9 kevinpapst/kimai2 9 pterodactyl/panel 9 bootstrap 9 pimcore/customer-management-framework-bundle 9 org.webjars:bootstrap 9 statamic/cms 9 billz/raspap-webgui 9 flarum/core 8 gilacms/gila 8 silverstripe/admin 8 directmailteam/direct-mail 8 starcitizentools/citizen-skin 8 silverstripe/graphql 8 joomla/joomla-cms 8 tecnickcom/tcpdf 8 facturascripts/facturascripts 8 october/cms 8 composer/composer 8 codiad/codiad 8 shopxo/shopxo 7 wpglobus/wpglobus 7 backdrop/backdrop 7 simplesamlphp/saml2 7 bootstrap.sass 7 october/backend 7 bootstrap-sass 7 redaxo/source 7 yiisoft/yii2-dev 7 passbolt/passbolt_api 7 symfony/http-kernel 7 api-platform/core 6 oro/platform 6 vrana/adminer 6 drupal/core-recommended 6 phpseclib/phpseclib 6 icecoder/icecoder 6 yourls/yourls 6 zoujingli/thinkadmin 6 dweeves/magmi 6 bagisto/bagisto 6 typo3/cms-install 6 bootstrap-sass 6 guzzlehttp/guzzle 6 gleez/cms 6 nystudio107/craft-seomatic 6 pear/archive_tar 6 getformwork/formwork 5 adodb/adodb-php 5 cachethq/cachet 5 ibexa/core 5 neos/flow 5 typo3/flow 5 ibexa/admin-ui 5 thinkcmf/thinkcmf 5 neos/neos 5 mautic/core-lib 5 elgg/elgg 5 silverstripe/assets 5 limesurvey/limesurvey 5 anchorcms/anchor-cms 5 phpxmlrpc/phpxmlrpc 5 tcg/voyager 5 bottelet/flarepoint 5 symfony/security-core 5 phpservermon/phpservermon 5 kimai/kimai 5 woocommerce/woocommerce 5 symfony/security-bundle 5 gugoan/economizzer 5 illuminate/database 5 juzaweb/cms 5 typo3/html-sanitizer 4 codeigniter/framework 4 shopware/storefront 4 bytefury/crater 4 ckeditor4 4 oro/commerce 4 wintercms/winter 4 sylius/resource-bundle 4 ckeditor/ckeditor 4 livewire/livewire 4 friendsofsymfony/user-bundle 4 flarum/framework 4 pixelfed/pixelfed 4 typo3/cms-form 4 appwrite/server-ce 4 elmsln/haxcms 4 froala/wysiwyg-editor 4 reportico-web/reportico 4 sjbr/sr-feuser-register 4 evolutioncms/evolution 4 dcat/laravel-admin 4

Filter by Repository