Sensiolabs Symfony vulnerabilities
89 known vulnerabilities affecting sensiolabs/symfony.
Total CVEs
89
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL11HIGH34MEDIUM44
Vulnerabilities
Page 4 of 5
CVE-2026-45755P4MEDIUMCVSS 5.3≥ 7.2.0, < 7.4.12≥ 8.0.0, < 8.0.122026-07-14
CVE-2026-45755 [MEDIUM] CWE-306 CVE-2026-45755: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::doParse() received the configured webhook secret but ignored the X-Mt-Signature HMAC header, allowing unauthenticated POST requests to inject forged Mailtrap delivery, bounce, open, click, or spam event
nvd
CVE-2013-4752P4MEDIUMCVSS 6.1≥ 2.0.0, < 2.0.24≥ 2.1.0, < 2.1.12+2 more2020-01-02
CVE-2013-4752 [MEDIUM] CWE-79 CVE-2013-4752: Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an
Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generating an absolute URL. A remote attacker could exploit this vulnerability to inject malicious content into the Web application page and c
nvd
CVE-2021-41267P4MEDIUMCVSS 6.5≥ 5.2.0, < 5.3.122021-11-24
CVE-2021-41267 [MEDIUM] CWE-444 CVE-2021-41267: Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console ap
Symfony/Http-Kernel is the HTTP kernel component for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Headers that are not part of the "trusted_headers" allowed list are ignored and protect users from "Cache poisoning" attacks. In Symfony 5.2, maintainers added support for the `X-Forwarded-Prefix` heade
nvd
CVE-2026-45065P4MEDIUMCVSS 6.1fixed in 5.4.52≥ 6.0.0, < 6.4.40+2 more2026-07-14
CVE-2026-45065 [MEDIUM] CWE-185 CVE-2026-45065: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, UrlGenerator validates route parameters against a pattern built as ^ plus the raw requirement plus $; with ungrouped alternations, middle alternatives match as unanchored substrings, allowing a value such as
nvd
CVE-2017-18343P4MEDIUMCVSS 6.1fixed in 2.7.33≥ 2.8.0, < 2.8.26+2 more2018-07-20
CVE-2017-18343 [MEDIUM] CWE-79 CVE-2017-18343: The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x bef
The debug handler in Symfony before v2.7.33, 2.8.x before v2.8.26, 3.x before v3.2.13, and 3.3.x before v3.3.6 has XSS via an array key during exception pretty printing in ExceptionHandler.php, as demonstrated by a /_debugbar/open?op=get URI. NOTE: the vendor's position is that this is not a vulnerability because the debug tools are not intended for
nvd
CVE-2015-8124P4MEDIUMCVSS 6.8v2.3.0v2.3.1+52 more2015-12-07
CVE-2015-8124 [MEDIUM] CVE-2015-8124: Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.
Session fixation vulnerability in the "Remember Me" login feature in Symfony 2.3.x before 2.3.35, 2.6.x before 2.6.12, and 2.7.x before 2.7.7 allows remote attackers to hijack web sessions via a session id.
nvd
CVE-2026-47212P4MEDIUMCVSS 5.3≥ 6.4.0, < 6.4.40≥ 7.0.0, < 7.4.12+1 more2026-07-14
CVE-2026-47212 [MEDIUM] CWE-306 CVE-2026-47212: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestParser::doParse() received the configured webhook secret but ignored the X-Twilio-Signature HMAC header, allowing unauthenticated POST requests to inject forged Twilio status payloads. This issue is fixe
nvd
CVE-2026-24739P4MEDIUMCVSS 6.3fixed in 5.4.51≥ 6.4.0, < 6.4.33+3 more2026-01-28
CVE-2026-24739 [MEDIUM] CWE-88 CVE-2026-24739: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to versions 5.4.51, 6.4.33, 7.3.11, 7.4.5, and 8.0.5, the Symfony Process component did not correctly treat some characters (notably `=`) as “special” when escaping arguments on Windows. When PHP is executed from an MSYS2-based environment (e.g. Gi
nvd
CVE-2026-45753P4MEDIUMCVSS 6.1≥ 6.1.0, < 6.4.40≥ 7.0.0, < 7.4.12+1 more2026-07-14
CVE-2026-45753 [MEDIUM] CWE-79 CVE-2026-45753: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Fr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlAttributeSanitizer::getSupportedAttributes() omits URL-valued attributes including action, formaction, poster, and cite, so configurations that admit those attributes can leave javascript: URIs unsani
nvd
CVE-2026-48761P4MEDIUMCVSS 6.1≥ 6.1.0, < 6.4.41≥ 7.0.0, < 7.4.13+1 more2026-07-14
CVE-2026-48761 [MEDIUM] CWE-79 CVE-2026-48761: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Fr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on , , , and , and URLs inside content bypassed URL sanitization, allowing explicitly enabled elements or attributes to pass javas
nvd
CVE-2026-45072P4MEDIUMCVSS 5.4≥ 6.4.24, < 6.4.40≥ 7.2.9, < 7.4.12+1 more2026-07-14
CVE-2026-45072 [MEDIUM] CWE-79 CVE-2026-45072: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Fr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the development profiler file_excerpt Twig filter escapes PHP files through highlight_string() but interpolates lines from non-PHP files directly into elements, allowing stored XSS against a developer who ope
nvd
CVE-2024-50345P4MEDIUMCVSS 6.1fixed in 5.4.46≥ 6.0.0, < 6.4.14+1 more2024-11-06
CVE-2024-50345 [MEDIUM] CWE-601 CVE-2024-50345: symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented
symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. As a result, an attacker can trick a validator relying on the `Request` class to redirect users to another domain. The `Request:
nvd
CVE-2026-48760P4MEDIUMCVSS 6.1≥ 6.1.0, < 6.4.41≥ 7.0.0, < 7.4.13+1 more2026-07-14
CVE-2026-48760 [MEDIUM] CWE-451 CVE-2026-48760: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Fr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and used an ASCII-only whitespace check, allowing sanitized URLs to retain visual-spoofing characters that downstrea
nvd
CVE-2026-48747P4MEDIUMCVSS 5.3≥ 7.2.0, < 7.4.13≥ 8.0.0, < 8.0.132026-07-14
CVE-2026-48747 [MEDIUM] CWE-347 CVE-2026-48747: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Pr
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.13 and 8.0.13, MailomatRequestParser::validateSignature() parsed X-MOM-Webhook-Signature as algo=signature and passed the request-selected algorithm to hash_hmac(), allowing a signature algorithm downgrade instead of enforcing Mailomat's do
nvd
CVE-2017-16653P4MEDIUMCVSS 5.9≥ 2.7.0, ≤ 2.7.37≥ 3.2.0, ≤ 3.2.13+2 more2018-08-06
CVE-2017-16653 [MEDIUM] CVE-2017-16653: An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5.
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different tokens for HTTP and HTTPS; therefore the token is subject to MITM attacks on HTTP and can then be used in an HTTPS context to do CSRF attacks.
nvd
CVE-2021-21424P4MEDIUMCVSS 5.3≥ 2.8.0, < 3.4.48≥ 4.0.0, < 4.4.23+1 more2021-05-13
CVE-2021-21424 [MEDIUM] CWE-200 CVE-2021-21424: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Th
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or not when attempting to use the switch users functionality. We now ensure that 403s are returned whether the user
nvd
CVE-2019-18886P4MEDIUMCVSS 5.3≥ 4.2.0, ≤ 4.2.11≥ 4.3.0, ≤ 4.3.72019-11-21
CVE-2019-18886 [MEDIUM] CWE-203 CVE-2019-18886: An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate user
An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthorized attempts to use the switch users functionality. This is related to symfony/security.
nvd
CVE-2018-11386P4MEDIUMCVSS 5.9≥ 2.7.0, < 2.7.48≥ 2.8.0, < 2.8.41+3 more2018-06-13
CVE-2018-11386 [MEDIUM] CWE-613 CVE-2018-11386: An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before
An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was possible to do a denial of service o
nvd
CVE-2023-46734P4MEDIUMCVSS 6.1≥ 2.0.0, < 4.4.51≥ 5.0.0, < 5.4.31+1 more2023-11-10
CVE-2023-46734 [MEDIUM] CWE-79 CVE-2023-46734: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. St
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Starting in versions 2.0.0, 5.0.0, and 6.0.0 and prior to versions 4.4.51, 5.4.31, and 6.3.8, some Twig filters in CodeExtension use `is_safe=html` but don't actually ensure their input is safe. As of versions 4.4.51, 5.4.31, and 6.3.8, Symfony now escap
nvd
CVE-2020-5274P4MEDIUMCVSS 5.4≥ 4.4.0, < 4.4.4≥ 5.0.0, < 5.0.42020-03-30
CVE-2020-5274 [MEDIUM] CWE-209 CVE-2020-5274: In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escap
In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace were displayed even in a non-debug configuration. The ErrorHandler now escape alls properties of the exception, and the stacktrace is only display in debug configuration. Thi
nvd