cbcvebase.
CVE-2026-45073
published 2026-07-14

CVE-2026-45073: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12…

PriorityP345high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.41%
33.5th percentile
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAdapter::doClear() builds a DELETE statement using a namespace derived from the caller-supplied $prefix without binding or escaping it, allowing a caller able to influence $prefix to break out of the LIKE literal and alter query semantics or deletion scope. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.

Affected

20 ranges
VendorProductVersion rangeFixed in
cachesymfony< 5.4.525.4.52
cachesymfony
cachesymfony
cachesymfony
sensiolabssymfony< 5.4.525.4.52
sensiolabssymfony>= 6.0.0 < 6.4.406.4.40
sensiolabssymfony>= 7.0.0 < 7.4.127.4.12
sensiolabssymfony>= 8.0.0 < 8.0.128.0.12
symfonycache>= 0 < 5.4.525.4.52
symfonycache>= 6.0.0 < 6.4.406.4.40
symfonycache>= 7.0.0 < 7.4.127.4.12
symfonycache>= 8.0.0 < 8.0.128.0.12
symfonysymfony< 5.4.525.4.52
symfonysymfony
symfonysymfony
symfonysymfony
symfonysymfony>= 0 < 5.4.525.4.52
symfonysymfony>= 6.0.0 < 6.4.406.4.40
symfonysymfony>= 7.0.0 < 7.4.127.4.12
symfonysymfony>= 8.0.0 < 8.0.128.0.12

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.