>= 2.7.30, < 2.7.32
>= 2.8.0, < 2.8.37
>= 2.8.0, < 2.8.6
CRITICAL9.8Improper Input Validation in Symfony
>= 4.2.0, < 4.2.12
CRITICAL9.8Invalid HTTP method overrides allow possible XSS or other attacks in Symfony
>= 2.7.0, < 2.7.51
CRITICAL9.8Symfony Unsafe Cache Serialization Could Enable RCE
>= 3.1.0, < 3.4.35
CRITICAL9.8Symfony Service IDs Allow Injection
>= 2.7.0, < 2.7.51
HIGH8.8Symfony CSRF Token Fixation
>= 2.7.0, < 2.7.48
HIGH8.4Symfony vulnerable to command execution hijack on Windows with Process class
from 0, < 5.4.46
HIGH8.1Symfony Cross-Site Request Forgery vulnerability in the Web Profiler
>= 2.0.0, < 2.3.19
HIGH8.1Symfony Session Fixation Vulnerability
>= 2.7.0, < 2.7.48
HIGH8.1Symfony collectionCascaded and collectionCascadedDeeply fields security bypass
>= 2.0.0, < 2.0.24
HIGH8.1symfony - security update
>= 2.2.0, < 2.8.52
HIGH8.0RCE in Symfony
>= 4.3.0, < 4.4.13
HIGH7.6Firewall configured with unanimous strategy was not actually unanimous in Symfony
>= 4.4.0, < 4.4.7
HIGH7.5Symfony allows direct access of ESI URLs behind a trusted proxy
>= 2.0.0, < 2.3.19
HIGH7.5Symfony vulnerable to denial of service via a malicious HTTP Host header
>= 2.0.0, < 2.3.19
HIGH7.5Code injection in the way Symfony implements translation caching in FrameworkBundle
>= 2.0.0, < 2.3.19
HIGH7.5symfony - security update
>= 2.3.0, < 2.3.37
HIGH7.5Symphony Denial of Service Via Overlong Usernames
>= 2.3.0, < 2.3.41
HIGH7.5Symfony Directory Traversal
>= 2.7.0, < 2.7.38
HIGH7.5Improper authentication in Symfony
>= 2.7.0, < 2.7.51
HIGH7.5Argument injection in a MimeTypeGuesser in Symfony
>= 2.0.0, < 2.8.52
HIGH7.3Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
>= 2.0.0, < 5.4.50
HIGH7.3symfony - security update
>= 5.3.0, < 5.4.46
HIGH7.2Symfony Host Header Injection
>= 2.7.0, < 2.7.49
HIGH7.1Deserialization of untrusted data in Symfony
>= 2.8.0, < 2.8.50
MEDIUM6.8Authentication granted to all firewalls instead of just one
>= 5.3.0, < 5.3.2
MEDIUM6.5Symfony possible session fixation vulnerability
>= 5.4.21, < 5.4.31
MEDIUM6.5Symfony SSRF Vulnerability via Form Component
>= 2.7.0, < 2.7.38
MEDIUM6.5symfony - security update
>= 2.7.0, < 2.7.49
MEDIUM6.5CSV Injection in symfony/serializer
>= 4.1.0, < 4.4.35
MEDIUM6.5Cookie persistence after password changes in symfony/security-bundle
>= 5.3.0, < 5.3.12
MEDIUM6.5Webcache Poisoning in symfony/http-kernel
>= 5.2.0, < 5.3.12
MEDIUM6.3Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on Windows
from 0, < 5.4.51
MEDIUM6.3Symfony vulnerable to Session Fixation of CSRF tokens
>= 2.0.0, < 4.4.50
MEDIUM6.1Symfony potential Cross-site Scripting in WebhookController
>= 6.3.0, < 6.3.8
MEDIUM6.1symfony - security update
>= 2.0.0, < 4.4.51
MEDIUM6.1symfony - security update
>= 2.7.0, < 2.7.38
MEDIUM6.1Symfony Open Redirect
>= 2.7.0, < 2.7.48
MEDIUM6.1Symfony Open Redirect
>= 2.7.38, < 2.7.50
MEDIUM6.1Symfony Host Header Injection vulnerability in the HttpFoundation component
>= 2.0.0, < 2.0.24
MEDIUM5.9Symfony storing cookie headers in HttpCache
>= 2.0.0, < 4.4.50
MEDIUM5.9Symfony DoS
>= 2.7.0, < 2.7.48
MEDIUM5.9Symfony CSRF Vulnerability
>= 2.7.0, < 2.7.38
MEDIUM5.4symfony - security update
>= 2.7.0, < 2.7.51
MEDIUM5.3Symfony has unsafe methods in the Request class
>= 2.0.0, < 2.3.27
MEDIUM5.3Symfony has a security issue when parsing the Authorization header
>= 2.0.0, < 2.3.19
MEDIUM5.3Symfony Path Disclosure
>= 2.7.0, < 2.7.50
MEDIUM5.3symfony - security update
>= 2.8.0, < 3.4.49
MEDIUM5.3symfony - security update
>= 4.1.0, < 4.2.12
MEDIUM4.6Exceptions displayed in non-debug configurations in Symfony
>= 4.4.0, < 4.4.4
LOW3.1symfony - security update
from 0, < 5.4.43
LOW3.1Symfony allows internal address and port enumeration by NoPrivateNetworkHttpClient
>= 4.3.0, < 5.4.47
LOW3.1Symfony's `Security::login` does not take into account custom `user_checker`
>= 6.2.0, < 6.4.10
LOW3.1symfony - security update
>= 2.3.0, < 2.3.35
LOW2.6Prevent cache poisoning via a Response Content-Type header in Symfony
>= 4.4.0, < 4.4.7
—Symfony Access Control Vulnerability
—Symfony Allows URI Restrictions Bypass Via Double-Encoded String
>= 2.0.0, < 2.0.19
—Symfony Denial of Service Via Long Password Hashing
>= 2.0.0, < 2.0.25
—Symfony Vulnerable to PHP Eval Injection
>= 2.0.0, < 2.3.27
—Symfony Vulnerable to Timing Attack
>= 2.3.0, < 2.3.35
—symfony - security update
>= 2.3.19, < 2.3.29
—Symphony Vulnerable to PHP Code Injection via YAML Parsing
>= 2.0.0, < 2.0.22
—Symfony Arbitrary PHP code Execution
>= 2.2.0-BETA1, < 2.2.0-BETA2