Symphony
This hub aggregates every CVE we track for Symphony, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
30
CVEs tracked
3
Critical
8
High
0
In CISA KEV
Severity distribution
MEDIUM19HIGH8CRITICAL3
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
2024-082026-07
Latest CVEs
The 15 most recently published vulnerabilities affecting Symphony.
- CVE-2025-12491Senstar Symphony FetchStoredLicense Information Disclosure Vulnerability7.5
- CVE-2024-23049An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.9.8
- CVE-2020-25912A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).9.1
- CVE-2020-25343Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script or HTML to fields['body'] param via events\event.publish_article.php5.4
- CVE-2020-17405This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Senstar Symphony 7.3.2.2. Authentication is not required to exploit this vulnerability. T...8.8
- CVE-2020-15071content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading.6.1
- CVE-2019-17488b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header.6.1
- CVE-2018-16249In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/poin...4.8
- CVE-2019-9142An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java.6.1
- CVE-2018-12043content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page.6.1
- CVE-2018-10469b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI.9.8
- CVE-2017-16956b3log Symphony (aka Sym) 2.2.0 allows an XSS attack by sending a private letter with a certain /article URI, and a second private letter with a modified title.6.1
- CVE-2017-16881b3log Symphony (aka Sym) 2.2.0 does not properly address XSS in JSON objects, as demonstrated by a crafted userAvatarURL value to /settings/avatar, related to processor/AdminProcessor.java, process...6.1
- CVE-2017-16821b3log Symphony (aka Sym) 2.2.0 has XSS in processor/AdminProcessor.java in the admin console, as demonstrated by a crafted X-Forwarded-For HTTP header that is mishandled during display of a client ...5.4
- CVE-2017-8876Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php.6.1
Product normalization is registry-driven with AI assist and human review. How it works