sensiolabs, symfony community
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting sensiolabs, symfony community.
- CVE-2025-64500Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass7.3
- CVE-2024-36611In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle cases where the username or password field of a login request...7.5
- CVE-2024-51996Symphony has an Authentication Bypass via RememberMe7.5
- CVE-2024-50340Ability to change environment from query in symfony/runtime7.3
- CVE-2024-50342Internal address and port enumeration allowed by NoPrivateNetworkHttpClient in symfony/http-client3.1
- CVE-2024-50343Incorrect response from Validator when input ends with `\n` in symfony/validator3.1
- CVE-2024-50345Open redirect via browser-sanitized URLs in symfony/http-foundation3.1
- CVE-2024-45411Twig has a possible sandbox bypass8.5
- CVE-2023-46734Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters6.1
- CVE-2023-46733Symfony possible session fixation vulnerability6.5
- CVE-2022-24894Symfony storing cookie headers in HttpCache5.9
- CVE-2022-24895Symfony vulnerable to Session Fixation of CSRF tokens6.3
- CVE-2022-23614Code injection in Twig8.8
- CVE-2022-23601CSRF token missing in Symfony8.1
- CVE-2021-32693Authentication granted with multiple firewalls6.8