Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

16 advisories

Loading
Symfony vulnerable to Session Fixation of CSRF tokens Moderate
CVE-2022-24895 was published for symfony/security-bundle (Composer) Feb 1, 2023
nicolas-grekas Credited to nicolas-grekas and lavish lavish lavish
Symfony storing cookie headers in HttpCache Moderate
CVE-2022-24894 was published for symfony/http-kernel (Composer) Feb 1, 2023
nicolas-grekas Credited to nicolas-grekas and shyim shyim shyim
Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters Moderate
CVE-2023-46734 was published for symfony/symfony (Composer) Nov 12, 2023
Rudloff Credited to Rudloff and nicolas-grekas nicolas-grekas nicolas-grekas
Symfony potential Cross-site Scripting in WebhookController Moderate
CVE-2023-46735 was published for symfony/symfony (Composer) Nov 12, 2023
maxime-aknin Credited to maxime-aknin and nicolas-grekas nicolas-grekas nicolas-grekas
Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on Windows Moderate
CVE-2026-24739 was published for symfony/process (Composer) Jan 28, 2026
Seldaek Credited to Seldaek and nicolas-grekas nicolas-grekas nicolas-grekas
Symfony's HtmlSanitizer URL Attributes Pass Through BiDi Override Characters → Visual href Spoofing Moderate
CVE-2026-45064 was published for symfony/html-sanitizer (Composer) May 27, 2026
nicolas-grekas Credited to nicolas-grekas and unknownhad unknownhad unknownhad
Symfony Vulnerable to SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix Moderate
CVE-2026-45073 was published for symfony/cache (Composer) May 27, 2026
FORIMOC Credited to FORIMOC and nicolas-grekas nicolas-grekas nicolas-grekas
Symfony's Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay Moderate
CVE-2026-45074 was published for symfony/security-http (Composer) May 27, 2026
nicolas-grekas Credited to nicolas-grekas
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection Moderate
CVE-2026-45754 was published for symfony/lox24-notifier (Composer) May 28, 2026
alexandre-daubois Credited to alexandre-daubois, nicolas-grekas, and unknownhad nicolas-grekas nicolas-grekas
unknownhad unknownhad
Symfony: Twilio SMS Notifier allows unauthenticated webhook injection due to missing X-Twilio-Signature verification Moderate
CVE-2026-47212 was published for symfony/symfony (Composer) May 29, 2026
nicolas-grekas Credited to nicolas-grekas
nicolas-grekas Credited to nicolas-grekas and 0xEr3n 0xEr3n 0xEr3n
Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes Moderate
CVE-2026-48761 was published for symfony/html-sanitizer (Composer) Jun 15, 2026
tob-scott-a Credited to tob-scott-a and nicolas-grekas nicolas-grekas nicolas-grekas
tonghuaroot Credited to tonghuaroot and nicolas-grekas nicolas-grekas nicolas-grekas
Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade Moderate
CVE-2026-48747 was published for symfony/mailomat-mailer (Composer) Jun 15, 2026
KEJJ0 Credited to KEJJ0, xpw6, Wele44, and nicolas-grekas xpw6 xpw6
Wele44 Wele44 nicolas-grekas nicolas-grekas
tob-scott-a Credited to tob-scott-a and nicolas-grekas nicolas-grekas nicolas-grekas
nicolas-grekas Credited to nicolas-grekas
ProTip! Advisories are also available from the GraphQL API