Количество 378
Количество 378
GHSA-7hwc-2cq4-6x2w
Symfony Open Redirect
GHSA-79gr-58r3-pwm3
Symfony Unsafe Cache Serialization Could Enable RCE
GHSA-72xp-p242-47p9
Symfony has a UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection
GHSA-72x2-5c85-6wmr
Symfony potential Cross-site Scripting in WebhookController
GHSA-6qh9-h6wf-jgqc
Symfony Vulnerable to SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix
GHSA-6h46-9jf5-q59x
Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes
GHSA-66p6-7p29-55p9
Symfony Host Header Injection
GHSA-64hg-93w9-fc35
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection
GHSA-6439-2f28-8p8q
Symfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]
GHSA-5pv8-ppvj-4h68
Prevent user enumeration using Guard or the new Authenticator-based Security
GHSA-5c58-w9xc-qcj9
Symfony Vulnerable to PHP Eval Injection
GHSA-59f3-vp2f-mp9w
Symfony's Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection
GHSA-55rj-x2vc-4whq
Symfony: Twilio SMS Notifier allows unauthenticated webhook injection due to missing X-Twilio-Signature verification
GHSA-4vpc-5jx4-cfqg
User enumeration leak using switch user functionality in Symfony
GHSA-4qpc-3hr4-r2p4
Symfony's YAML Parser Vulnerable to Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")
GHSA-3gv2-29qc-v67m
Symfony vulnerable to Session Fixation of CSRF tokens
GHSA-38cx-cq6f-5755
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
GHSA-35c5-28pg-2qg4
Symfony Authentication Bypass
GHSA-2xhg-w2g5-w95x
CSV Injection in symfony/serializer
GHSA-2r5h-6r7v-5m7c
Symphony Vulnerable to PHP Code Injection via YAML Parsing
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-7hwc-2cq4-6x2w Symfony Open Redirect | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-79gr-58r3-pwm3 Symfony Unsafe Cache Serialization Could Enable RCE | CVSS3: 9.8 | 33% Средний | больше 6 лет назад | |
GHSA-72xp-p242-47p9 Symfony has a UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection | 0% Низкий | 2 месяца назад | ||
GHSA-72x2-5c85-6wmr Symfony potential Cross-site Scripting in WebhookController | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
GHSA-6qh9-h6wf-jgqc Symfony Vulnerable to SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix | 0% Низкий | 2 месяца назад | ||
GHSA-6h46-9jf5-q59x Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes | 0% Низкий | около 2 месяцев назад | ||
GHSA-66p6-7p29-55p9 Symfony Host Header Injection | CVSS3: 7.2 | 1% Низкий | около 4 лет назад | |
GHSA-64hg-93w9-fc35 Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection | 0% Низкий | 2 месяца назад | ||
GHSA-6439-2f28-8p8q Symfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid] | 0% Низкий | 2 месяца назад | ||
GHSA-5pv8-ppvj-4h68 Prevent user enumeration using Guard or the new Authenticator-based Security | CVSS3: 5.3 | 2% Низкий | около 5 лет назад | |
GHSA-5c58-w9xc-qcj9 Symfony Vulnerable to PHP Eval Injection | 1% Низкий | около 4 лет назад | ||
GHSA-59f3-vp2f-mp9w Symfony's Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection | 0% Низкий | 2 месяца назад | ||
GHSA-55rj-x2vc-4whq Symfony: Twilio SMS Notifier allows unauthenticated webhook injection due to missing X-Twilio-Signature verification | 0% Низкий | 2 месяца назад | ||
GHSA-4vpc-5jx4-cfqg User enumeration leak using switch user functionality in Symfony | CVSS3: 5.3 | 2% Низкий | больше 6 лет назад | |
GHSA-4qpc-3hr4-r2p4 Symfony's YAML Parser Vulnerable to Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs") | 1% Низкий | 2 месяца назад | ||
GHSA-3gv2-29qc-v67m Symfony vulnerable to Session Fixation of CSRF tokens | CVSS3: 6.3 | 1% Низкий | больше 3 лет назад | |
GHSA-38cx-cq6f-5755 Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient | 0% Низкий | около 2 месяцев назад | ||
GHSA-35c5-28pg-2qg4 Symfony Authentication Bypass | CVSS3: 9.8 | 2% Низкий | около 4 лет назад | |
GHSA-2xhg-w2g5-w95x CSV Injection in symfony/serializer | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-2r5h-6r7v-5m7c Symphony Vulnerable to PHP Code Injection via YAML Parsing | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу