Sensiolabs Symfony vulnerabilities
89 known vulnerabilities affecting sensiolabs/symfony.
Total CVEs
89
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH34MEDIUM44
Vulnerabilities
Page 2 of 5
CVE-2026-48489P3HIGHCVSS 7.5fixed in 5.4.53≥ 6.0.0, < 6.4.41+2 more2026-07-14
CVE-2026-48489 [HIGH] CWE-863 CVE-2026-48489: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, DefaultAuthenticationFailureHandler honored the request-supplied _failure_path parameter when failure_forward: true was enabled, allowing an unauthenticated failing login request to dispatch a subrequest to acc
nvd
CVE-2026-45071P3HIGHCVSS 7.5fixed in 5.4.52≥ 6.0.0, < 6.4.40+2 more2026-07-14
CVE-2026-45071 [HIGH] CWE-611 CVE-2026-45071: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() set DOMDocument::$validateOnParse = true before loadXML(), re-enabling external entity resolution and allowing attacker-supplied XML to expand file:// entities such as local files. This
nvd
CVE-2026-45304P3HIGHCVSS 7.5fixed in 5.4.52≥ 6.0.0, < 6.4.40+2 more2026-07-14
CVE-2026-45304 [HIGH] CWE-776 CVE-2026-45304: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser resolved YAML collection aliases recursively, allowing a small untrusted YAML input to expand into a multi-gigabyte structure and exhaust memory. This issue is fixed in versions 5.
nvd
CVE-2026-45305P3HIGHCVSS 7.5fixed in 5.4.52≥ 6.0.0, < 6.4.40+2 more2026-07-14
CVE-2026-45305 [HIGH] CWE-1333 CVE-2026-45305: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() used regular expressions with overlapping quantifiers for YAML directive, comment, and document marker cleanup, allowing crafted input to make parsing hang for an arbit
nvd
CVE-2026-45074P3HIGHCVSS 8.1≥ 7.1.0, < 7.4.12≥ 8.0.0, < 8.0.122026-07-14
CVE-2026-45074 [HIGH] CWE-290 CVE-2026-45074: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Fr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which reflects an attacker-controlled Host header when framework.trusted_hosts is not configured; an attacker controlling another applic
nvd
CVE-2026-45073P3HIGHCVSS 7.3fixed in 5.4.52≥ 6.0.0, < 6.4.40+2 more2026-07-14
CVE-2026-45073 [HIGH] CWE-89 CVE-2026-45073: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAdapter::doClear() builds a DELETE statement using a namespace derived from the caller-supplied $prefix without binding or escaping it, allowing a caller able to influence $prefix to break out of the LIKE lit
nvd
CVE-2020-5275P3HIGHCVSS 8.1≥ 4.4.0, < 4.4.7≥ 5.0.0, < 5.0.72020-03-30
CVE-2020-5275 [HIGH] CWE-285 CVE-2020-5275: In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control ru
In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides to grant access on the attribute, preventing the check of next attributes that should have been take into account in an unanimous strategy. The accessDecisi
nvd
CVE-2019-18888P3HIGHCVSS 7.5≥ 2.8.0, ≤ 2.8.50≥ 3.4.0, ≤ 3.4.34+2 more2019-11-21
CVE-2019-18888 [HIGH] CWE-88 CVE-2019-18888: An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11,
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. This is related to symfony/http-foundation (and symfony
nvd
CVE-2026-45133P3HIGHCVSS 7.5fixed in 5.4.52≥ 6.0.0, < 6.4.40+2 more2026-07-14
CVE-2026-45133 [HIGH] CWE-674 CVE-2026-45133: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attacker-controlled input, deeply nested mappings or sequences cause both the block-level (Parser::parseBlock()) and inline (Inline::parseSequence() / Inline::parseMapping()) parse
nvd
CVE-2026-45068P3HIGHCVSS 7.5fixed in 5.4.52≥ 6.0.0, < 6.4.40+2 more2026-07-14
CVE-2026-45068 [HIGH] CWE-88 CVE-2026-45068: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SendmailTransport in -t mode appended recipient addresses to the sendmail command line without a -- end-of-options separator, allowing an address beginning with - to be interpreted as a sendmail command-line opt
nvd
CVE-2022-23601P3HIGHCVSS 8.8fixed in 5.3.15≥ 5.4.0, < 5.4.4+1 more2022-02-01
CVE-2022-23601 [HIGH] CWE-352 CVE-2022-23601: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Th
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony form component provides a CSRF protection mechanism by using a random token injected in the form and using the session to store and control the token submitted by the user. When using the FrameworkBundle, this protection can be enabled or disa
nvd
CVE-2013-1348P3HIGHCVSS 7.5v2.0.0v2.0.1+20 more2014-06-02
CVE-2013-1348 [HIGH] CWE-94 CVE-2013-1348: The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP co
The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.
nvd
CVE-2026-45756P3HIGHCVSS 7.5≥ 7.3.0, < 7.4.12≥ 8.0.0, < 8.0.122026-07-14
CVE-2026-45756 [HIGH] CWE-400 CVE-2026-45756: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Fr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonPath component compiles attacker-controlled match() and search() filter patterns directly into preg_match() without a length cap, i-regexp restriction, or bounded backtracking, allowing catastrophic-backtr
nvd
CVE-2018-11385P3HIGHCVSS 8.1≥ 2.7.0, < 2.7.48≥ 2.8.0, < 2.8.41+3 more2018-06-13
CVE-2018-11385 [HIGH] CWE-384 CVE-2018-11385: An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.4
An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login feature may allow an attacker to impersonate a victim towards the web application if the session id value was previously know
nvd
CVE-2013-1397P3HIGHCVSS 7.5v2.0.0v2.0.1+38 more2014-06-02
CVE-2013-1397 [HIGH] CVE-2013-1397: Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP
Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml::parse or (2) Yaml\Parser::parse function, a different vulnerability than CVE-2013-1348.
nvd
CVE-2019-10911P3HIGHCVSS 7.5≥ 2.7.0, < 2.7.51≥ 2.8.0, < 2.8.50+3 more2019-05-16
CVE-2019-10911 [HIGH] CWE-287 CVE-2019-10911: In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x befor
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.
nvd
CVE-2022-24894P3HIGHCVSS 8.8≥ 2.0.0, < 4.4.50≥ 5.0.0, < 5.4.2+3 more2023-02-03
CVE-2022-24894 [HIGH] CWE-285 CVE-2022-24894: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Th
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers) and returns them to the clients. In a recent change in the `AbstractSessionListener`, the response might contain a `Set-Cookie` header. If the Symfony H
nvd
CVE-2013-4751P3HIGHCVSS 8.1≥ 2.0.0, < 2.0.24≥ 2.1.0, < 2.1.12+2 more2019-11-01
CVE-2013-4751 [HIGH] CWE-20 CVE-2013-4751: php-symfony2-Validator has loss of information during serialization
php-symfony2-Validator has loss of information during serialization
nvd
CVE-2017-16654P3HIGHCVSS 7.5≥ 2.7.0, ≤ 2.7.37≥ 3.2.0, ≤ 3.2.13+2 more2018-08-06
CVE-2017-16654 [HIGH] CWE-22 CVE-2017-16654: An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5.
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The read() methods of these classes use a path and a locale to determine the language bundle to retrieve. The locale argument value is com
nvd
CVE-2022-24895P3HIGHCVSS 8.8≥ 2.0.0, < 4.4.50≥ 5.0.0, < 5.4.20+3 more2023-02-03
CVE-2022-24895 [HIGH] CWE-384 CVE-2022-24895: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Wh
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. When authenticating users Symfony by default regenerates the session ID upon login, but preserves the rest of session attributes. Because this does not clear CSRF tokens upon login, this might enables same-site attackers to bypass the CSRF protection mech
nvd