VendorsSensioLabssymfonyall versions
Vulnerabilities

SensioLabs Symfony

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

89CVEs
CVE-2026-45072
Symfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Published 2026-07-14 · Analyzed
5.4EPSS 0.003
CVE-2018-19789
An issue was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9, and 4.2.x before 4.2.1. When using the scalar type hint `string` in a setter method (e.g. `setName(string $name)`) of a class that's the `data_class` of a form, and when a file upload is submitted to the corresponding field instead of a normal text input, then `UploadedFile::__toString()` is called which will then return and disclose the path of the uploaded file. If combined with a local file inclusion issue in certain circumstances this could escalate it to a Remote Code Execution.
Published 2018-12-18 · Modified
5.3EPSS 0.036
CVE-2021-21424
Prevent user enumeration using Guard or the new Authenticator-based Security
Published 2021-05-13 · Modified
5.3EPSS 0.017
CVE-2019-18886
An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthorized attempts to use the switch users functionality. This is related to symfony/security.
Published 2019-11-21 · Modified
5.3EPSS 0.016
CVE-2012-5574
lib/form/sfForm.class.php in Symfony CMS before 1.4.20 allows remote attackers to read arbitrary files via a crafted upload request.
Published 2012-12-18 · Modified
5.0EPSS 0.035
CVE-2013-5958
The Security component in Symfony 2.0.x before 2.0.25, 2.1.x before 2.1.13, 2.2.x before 2.2.9, and 2.3.x before 2.3.6 allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation, a similar issue to CVE-2013-5750.
Published 2014-12-27 · Modified
5.0EPSS 0.019
CVE-2015-4050
FragmentListener in the HttpKernel component in Symfony 2.3.19 through 2.3.28, 2.4.9 through 2.4.10, 2.5.4 through 2.5.11, and 2.6.0 through 2.6.7, when ESI or SSI support enabled, does not check if the _controller attribute is set, which allows remote attackers to bypass URL signing and security rules by including (1) no hash or (2) an invalid hash in a request to /_fragment.
Published 2015-06-02 · Modified
4.3EPSS 0.082
CVE-2012-2667
Session fixation vulnerability in lib/user/sfBasicSecurityUser.class.php in SensioLabs Symfony before 1.4.18 allows remote attackers to hijack web sessions via vectors related to the regenerate method and unspecified "database backed session classes."
Published 2012-06-07 · Modified
4.3EPSS 0.013
CVE-2020-5255
Prevent cache poisoning via a Response Content-Type header
Published 2020-03-30 · Modified
4.3EPSS 0.013
← Prev3 / 3