Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

symfony — Vulnerabilities & Security Advisories 65

Browse all 65 CVE security advisories affecting symfony. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Symfony is an open-source PHP web framework designed to accelerate the development of web applications and APIs. With twenty-six recorded CVEs, its security history reflects typical risks associated with complex server-side logic. Common vulnerability classes include remote code execution, cross-site scripting, and improper access control, often stemming from input validation failures or insecure deserialization practices. The framework’s modular architecture allows developers to integrate security components, yet misconfigurations in routing or session handling have historically led to privilege escalation incidents. Notable security characteristics involve its robust dependency management, which mitigates supply chain risks, though outdated versions remain susceptible to known exploits. Security audits frequently highlight the importance of keeping dependencies updated to prevent exploitation of legacy code paths.

CVE ID Title CVSS Severity Published
CVE-2026-45072 Symfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering — symfony CWE-79 - - 2026-07-14
CVE-2026-45756 Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS — symfony CWE-400 - - 2026-07-14
CVE-2026-45066 Symfony: HtmlSanitizer allowLinkHosts() / allowMediaHosts() Bypass via URL-Parser Differentials and <area> Misclassification — symfony CWE-184 - - 2026-07-14
CVE-2026-45074 Symfony: Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay — symfony CWE-290 - - 2026-07-14
CVE-2026-45077 Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener — symfony CWE-502 - - 2026-07-14
CVE-2026-45065 Symfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection — symfony CWE-185 - - 2026-07-14
CVE-2026-45067 Symfony: Email Header / SMTP Command Injection via CRLF in Symfony\Component\Mime\Address — symfony CWE-93 - - 2026-07-14
CVE-2026-55877 Symfony UX: XSS in symfony/ux-icons via unsanitized SVG content in local files and Iconify on-demand responses — ux CWE-79 6.1 Medium 2026-07-08
CVE-2026-55878 Symfony: Path Traversal in symfony/ux-toolkit Allows Arbitrary File Write and Read via Crafted Recipe Manifest — ux CWE-22 7.8 High 2026-07-08
CVE-2026-24739 Symfony has incorrect argument escaping under MSYS2/Git Bash on Windows that can lead to destructive file operations — symfony CWE-88 6.3 Medium 2026-01-28
CVE-2025-64500 Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass — symfony CWE-647 7.3 High 2025-11-12
CVE-2025-47946 symfony/ux-live-component and symfony/ux-twig-component vulnerable to unsanitized HTML attribute injection via ComponentAttributes — ux CWE-79 6.1 Medium 2025-05-19
CVE-2024-51996 Symphony has an Authentication Bypass via RememberMe — symfony CWE-287 7.5 High 2024-11-13
CVE-2024-50340 Ability to change environment from query in symfony/runtime — symfony CWE-74 7.3 High 2024-11-06
CVE-2024-50341 Security::login does not take into account custom user_checker in symfony/security-bundle — symfony CWE-287 3.1 Low 2024-11-06
CVE-2024-50342 Internal address and port enumeration allowed by NoPrivateNetworkHttpClient in symfony/http-client — symfony CWE-200 3.1 Low 2024-11-06
CVE-2024-50343 Incorrect response from Validator when input ends with `\n` in symfony/validator — symfony CWE-20 3.1 Low 2024-11-06
CVE-2024-50345 Open redirect via browser-sanitized URLs in symfony/http-foundation — symfony CWE-601 3.1 Low 2024-11-06
CVE-2024-51736 Command execution hijack on Windows with Process class in symfony/process — symfony CWE-77 - - 2024-11-06
CVE-2023-46735 Symfony potential Cross-site Scripting in WebhookController — symfony CWE-79 6.1 Medium 2023-11-10
CVE-2023-46734 Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters — symfony CWE-79 6.1 Medium 2023-11-10
CVE-2023-46733 Symfony possible session fixation vulnerability — symfony CWE-384 6.5 Medium 2023-11-10
CVE-2023-41336 Prevent injection of invalid entity ids for "autocomplete" fields in symfony ux-autocomplete — ux-autocomplete CWE-20 6.5 Medium 2023-09-11
CVE-2022-24894 Symfony storing cookie headers in HttpCache — symfony CWE-285 5.9 Medium 2023-02-03
CVE-2022-24895 Symfony vulnerable to Session Fixation of CSRF tokens — symfony CWE-384 6.3 Medium 2023-02-03
CVE-2022-23601 CSRF token missing in Symfony — symfony CWE-352 8.1 High 2022-02-01
CVE-2021-41270 CSV Injection in Symfony — symfony CWE-1236 6.5 Medium 2021-11-24
CVE-2021-41267 Webcache Poisoning in Symfony — symfony CWE-444 6.5 Medium 2021-11-24
CVE-2021-41268 Cookie persistence in Symfony — symfony CWE-384 6.5 Medium 2021-11-24
CVE-2021-32693 Authentication granted with multiple firewalls — symfony CWE-287 6.8 Medium 2021-06-17

This page lists every published CVE security advisory associated with symfony. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.