VendorsSensioLabssymfonyany version
Vulnerabilities

SensioLabs Symfony any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

77CVEs
CVE-2019-18889
An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.
Published 2019-11-21 · Modified
9.8EPSS 0.332
CVE-2019-10910
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection.
Published 2019-05-16 · Modified
9.8EPSS 0.060
CVE-2019-11325
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.
Published 2019-11-21 · Modified
9.8EPSS 0.034
CVE-2018-11407
An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an unauthenticated bind. NOTE: this issue exists because of an incomplete fix for CVE-2016-2403.
Published 2018-06-13 · Modified
9.8EPSS 0.023
CVE-2019-10913
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation.
Published 2019-05-16 · Modified
9.8EPSS 0.019
CVE-2026-47767
Symfony: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch
Published 2026-07-14 · Analyzed
9.8EPSS 0.007
CVE-2024-51736
Command execution hijack on Windows with Process class in symfony/process
Published 2024-11-06 · Analyzed
9.8EPSS 0.004
CVE-2026-45063
Symfony: Identity Spoofing via Unanchored DN Regex in X509Authenticator
Published 2026-07-14 · Analyzed
9.1EPSS 0.004
CVE-2026-45069
Symfony: OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims
Published 2026-07-14 · Analyzed
9.1EPSS 0.003
CVE-2022-24894
Symfony storing cookie headers in HttpCache
Published 2023-02-03 · Analyzed
8.8EPSS 0.040
CVE-2020-15094
RCE in Symfony
Published 2020-09-02 · Modified
8.8EPSS 0.030
CVE-2021-32693
Authentication granted with multiple firewalls
Published 2021-06-17 · Modified
8.8EPSS 0.014
CVE-2021-41268
Cookie persistence in Symfony
Published 2021-11-24 · Modified
8.8EPSS 0.013
CVE-2022-24895
Symfony vulnerable to Session Fixation of CSRF tokens
Published 2023-02-03 · Modified
8.8EPSS 0.008
CVE-2018-11406
An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. By default, a user's session is invalidated when the user is logged out. This behavior can be disabled through the invalidate_session option. In this case, CSRF tokens were not erased during logout which allowed for CSRF token fixation.
Published 2018-06-13 · Modified
8.8EPSS 0.008
CVE-2022-23601
CSRF token missing in Symfony
Published 2022-02-01 · Modified
8.8EPSS 0.006
CVE-2026-45304
Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")
Published 2026-07-14 · Analyzed
8.7EPSS 0.007
CVE-2026-45305
Symfony: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex
Published 2026-07-14 · Analyzed
8.7EPSS 0.007
CVE-2026-48489
Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes
Published 2026-07-14 · Analyzed
8.7EPSS 0.006
CVE-2026-45071
Symfony: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true
Published 2026-07-14 · Analyzed
8.7EPSS 0.006
CVE-2026-45068
Symfony: Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address
Published 2026-07-14 · Analyzed
8.7EPSS 0.005
CVE-2026-45077
Symfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener
Published 2026-07-14 · Analyzed
8.6EPSS 0.007
CVE-2026-48736
Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient
Published 2026-07-14 · Analyzed
8.6EPSS 0.006
CVE-2026-45075
Symfony: HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]
Published 2026-07-14 · Analyzed
8.3EPSS 0.004
CVE-2026-45133
Symfony: [Yaml] Harden the parser when handling untrusted input
Published 2026-07-14 · Analyzed
8.2EPSS 0.006
CVE-2026-45756
Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Published 2026-07-14 · Analyzed
8.2EPSS 0.006
CVE-2018-11385
An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard" login feature may allow an attacker to impersonate a victim towards the web application if the session id value was previously known to the attacker.
Published 2018-06-13 · Modified
8.1EPSS 0.020
CVE-2013-4751
php-symfony2-Validator has loss of information during serialization
Published 2019-11-01 · Modified
8.1EPSS 0.014
CVE-2019-18887
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel.
Published 2019-11-21 · Modified
8.1EPSS 0.013
CVE-2020-5275
Firewall configured with unanimous strategy was not actually unanimous in symfony/security-http
Published 2020-03-30 · Modified
8.1EPSS 0.011
CVE-2026-45074
Symfony: Cas2Handler Derives CAS service URL from Client Host Header → Cross-Service Ticket Replay
Published 2026-07-14 · Analyzed
8.1EPSS 0.005
CVE-2017-16654
An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The read() methods of these classes use a path and a locale to determine the language bundle to retrieve. The locale argument value is commonly retrieved from untrusted user input (like a URL parameter). An attacker can use this argument to navigate to arbitrary directories via the dot-dot-slash attack, aka Directory Traversal.
Published 2018-08-06 · Modified
7.5EPSS 0.027
CVE-2019-18888
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. This is related to symfony/http-foundation (and symfony/mime in 4.3.x).
Published 2019-11-21 · Modified
7.5EPSS 0.022
CVE-2016-1902
The nextBytes function in the SecureRandom class in Symfony before 2.3.37, 2.6.x before 2.6.13, and 2.7.x before 2.7.9 does not properly generate random numbers when used with PHP 5.x without the paragonie/random_compat library and the openssl_random_pseudo_bytes function fails, which makes it easier for attackers to defeat cryptographic protection mechanisms via unspecified vectors.
Published 2016-06-01 · Modified
7.5EPSS 0.019
CVE-2016-4423
The attemptAuthentication function in Component/Security/Http/Firewall/UsernamePasswordFormAuthenticationListener.php in Symfony before 2.3.41, 2.7.x before 2.7.13, 2.8.x before 2.8.6, and 3.0.x before 3.0.6 does not limit the length of a username stored in a session, which allows remote attackers to cause a denial of service (session storage consumption) via a series of authentication attempts with long, non-existent usernames.
Published 2016-06-01 · Modified
7.5EPSS 0.019
CVE-2019-10911
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with user registration and remember me login functionality enabled. This is related to symfony/security.
Published 2019-05-16 · Modified
7.5EPSS 0.012
CVE-2025-64500
Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
Published 2025-11-12 · Analyzed
7.3EPSS 0.013
CVE-2026-45073
Symfony: SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix
Published 2026-07-14 · Analyzed
7.3EPSS 0.005
CVE-2018-14774
An issue was discovered in HttpKernel in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. When using HttpCache, the values of the X-Forwarded-Host headers are implicitly set as trusted while this should be forbidden, leading to potential host header injection.
Published 2018-08-03 · Modified
7.2EPSS 0.011
CVE-2019-10912
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current user has access to. This is related to symfony/cache and symfony/phpunit-bridge.
Published 2019-05-16 · Modified
7.1EPSS 0.023
1 / 2Next →