Sylius/sylius
This hub aggregates every CVE we track for Sylius/sylius, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
22
CVEs tracked
0
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM18HIGH3LOW1
Monthly trend
1
0
0
0
1
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
7
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting Sylius/sylius.
- CVE-2026-31825Sylius has a DQL Injection via API Order Filters5.3
- CVE-2026-31824Sylius has a Promotion Usage Limit Bypass via Race Condition8.2
- CVE-2026-31823Sylius has Authenticated Stored XSS4.8
- CVE-2026-31822Sylius has a XSS vulnerability in checkout login form6.1
- CVE-2026-31821Sylius is Missing Authorization in API v2 Add Item Endpoint5.3
- CVE-2026-31820Sylius affected by IDOR in Cart and Checkout LiveComponents6.5
- CVE-2026-31819Sylius has an Open Redirect via Referer Header6.1
- CVE-2024-57610A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of s...7.5
- CVE-2021-3841Stored Cross-site Scripting (XSS) in sylius/sylius5.4
- CVE-2024-40633Customer data leak via adjustments API endpoint in Sylius5.3
- CVE-2024-34349Sylius potentially vulnerable to Cross Site Scripting via "Name" field (Taxons, Products, Options, Variants) in Admin Panel4.8
- CVE-2024-29376Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book.6.4
- CVE-2022-24749Basic Cross-site Scripting and Unrestricted Upload of File with Dangerous Type in Sylius6.1
- CVE-2022-24743Insufficient Session Expiration in Sylius7.1
- CVE-2022-24742Exposure of Sensitive Information Due to Incompatible Policies in Sylius5.0
Product normalization is registry-driven with AI assist and human review. How it works