Sensiolabs Symfony vulnerabilities
89 known vulnerabilities affecting sensiolabs/symfony.
Total CVEs
89
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH34MEDIUM44
Vulnerabilities
Page 1 of 5
CVE-2025-64500P3HIGHCVSS 7.3PoC≥ 2.0.0, < 5.4.50≥ 6.0.0, < 6.4.29+1 more2025-11-12
CVE-2025-64500 [HIGH] CWE-647 CVE-2025-64500: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Sy
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to rep
nvd
CVE-2019-18889P2CRITICALCVSS 9.8≥ 3.4.0, ≤ 3.4.34≥ 4.2.0, ≤ 4.2.11+1 more2019-11-21
CVE-2019-18889 [CRITICAL] CWE-94 CVE-2019-18889: An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3
An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.
nvd
CVE-2018-14773P3MEDIUMCVSS 6.5≤ 2.7.48≥ 2.8.0, ≤ 2.8.43+4 more2018-08-03
CVE-2018-14773 [MEDIUM] CVE-2018-14773: An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.
An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (legacy) IIS header that lets users override the path in the request URL via the X-Original-URL or X-Rewrite-URL HTTP request header. These h
nvd
CVE-2019-10910P2CRITICALCVSS 9.8≥ 2.7.0, < 2.7.51≥ 2.8.0, < 2.8.50+3 more2019-05-16
CVE-2019-10910 [CRITICAL] CWE-89 CVE-2019-10910: In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x befor
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.
nvd
CVE-2016-2403P3CRITICALCVSS 9.8v2.8.0v2.8.1+10 more2017-02-07
CVE-2016-2403 [CRITICAL] CWE-287 CVE-2016-2403: Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by loggin
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
nvd
CVE-2020-15094P3HIGHCVSS 8.8≥ 4.4.0, < 4.4.13≥ 5.1.0, < 5.1.52020-09-02
CVE-2020-15094 [HIGH] CWE-212 CVE-2020-15094: In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony
In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with surrogate caching and ESI support in mind
nvd
CVE-2015-4050P3MEDIUMCVSS 4.3PoCv2.3.19v2.3.20+25 more2015-06-02
CVE-2015-4050 [MEDIUM] CWE-284 CVE-2015-4050: FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10,
FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash i
nvd
CVE-2026-45063P3CRITICALCVSS 9.1fixed in 5.4.52≥ 6.0.0, < 6.4.40+2 more2026-07-14
CVE-2026-45063 [CRITICAL] CWE-290 CVE-2026-45063: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted ce
nvd
CVE-2017-11365P3CRITICALCVSS 9.8v2.7.30v2.8.23+2 more2019-05-23
CVE-2017-11365 [CRITICAL] CWE-284 CVE-2017-11365: Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and
Certain Symfony products are affected by: Incorrect Access Control. This affects Symfony 2.7.30 and Symfony 2.8.23 and Symfony 3.2.10 and Symfony 3.3.3. The type of exploitation is: remote. The component is: Password validator.
nvd
CVE-2026-47767P3CRITICALCVSS 9.8≥ 5.4.46, < 5.4.52≥ 6.4.14, < 6.4.40+2 more2026-07-14
CVE-2026-47767 [CRITICAL] CVE-2026-47767: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Fr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a crafted query string to leave $_GET empty while $_SERVER['argv'] still carries a
nvd
CVE-2026-45077P3HIGHCVSS 8.6fixed in 5.4.52≥ 6.0.0, < 6.4.40+2 more2026-07-14
CVE-2026-45077 [HIGH] CWE-502 CVE-2026-45077: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and processes each received frame with unserialize(base64_decode($message)) without authentication, int
nvd
CVE-2019-11325P3CRITICALCVSS 9.8≥ 4.2.0, < 4.2.12≥ 4.3.0, < 4.3.82019-11-21
CVE-2019-11325 [CRITICAL] CWE-116 CVE-2019-11325: An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component inc
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.
nvd
CVE-2018-11407P3CRITICALCVSS 9.8≥ 2.8.0, < 2.8.37≥ 3.3.0, < 3.3.17+2 more2018-06-13
CVE-2018-11407 [CRITICAL] CVE-2018-11407: An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3
An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an unauthenticated bind. NOTE: this issue exists because of an incomplete fix for CVE-2016
nvd
CVE-2021-41268P3HIGHCVSS 8.8≥ 5.3.0, < 5.3.122021-11-24
CVE-2021-41268 [HIGH] CWE-384 CVE-2021-41268: Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console appli
Symfony/SecurityBundle is the security system for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Since the rework of the Remember me cookie in version 5.3.0, the cookie is not invalidated when the user changes their password. Attackers can therefore maintain their access to the account even if the passw
nvd
CVE-2026-45069P3CRITICALCVSS 9.1≥ 6.3.0, < 6.4.40≥ 7.4.0, < 7.4.12+1 more2026-07-14
CVE-2026-45069 [CRITICAL] CWE-345 CVE-2026-45069: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered audience (aud), issuer (iss), and expiry (exp) checkers but did not pass the mandatory claims list to ClaimCheckerManager::check(), so a validly signed JWT that omitted t
nvd
CVE-2024-51736P3CRITICALCVSS 9.8fixed in 5.4.46≥ 6.0.0, < 6.4.14+1 more2024-11-06
CVE-2024-51736 [CRITICAL] CWE-77 CVE-2024-51736: Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing command arguments, leading to possible hijacking. This issue has been addressed in release versi
nvd
CVE-2021-32693P3HIGHCVSS 8.8≥ 5.3.0, < 5.3.22021-06-17
CVE-2021-32693 [HIGH] CWE-287 CVE-2021-32693: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. A vulnerability related to firewall authentication is in Symfony starting with version 5.3.0 and prior to 5.3.2. When an application defines multiple firewalls, the token authenticated by one of the firewalls was available for all other firewalls. This cou
nvd
CVE-2026-48736P3HIGHCVSS 8.6≥ 5.4.0, < 5.4.43≥ 6.4.0, < 6.4.41+2 more2026-07-14
CVE-2026-48736 [HIGH] CWE-184 CVE-2026-48736: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Fr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and IPv4-compatible IPv6, allowing attacker-supplied URLs to represent private IPv4 tar
nvd
CVE-2019-10913P3CRITICALCVSS 9.8≥ 2.7.0, < 2.7.51≥ 2.8.0, < 2.8.50+3 more2019-05-16
CVE-2019-10913 [CRITICAL] CWE-79 CVE-2019-10913: In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x befor
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.
nvd
CVE-2026-45075P3HIGHCVSS 8.2≥ 7.4.0, < 7.4.12≥ 8.0.0, < 8.0.122026-07-14
CVE-2026-45075 [HIGH] CWE-863 CVE-2026-45075: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured for GET only, but Symfony routes HEAD requests to the GET handler while the attribute check is skipped, allowing protected co
nvd
1 / 5Next →