Vuln
·
Scope
首頁
套件
KEV
Critical
深度報告
同步紀錄
方案
EN
中
Loading…
Packagist/symfony/ux-live-component — 6 CVEs · VulnScope
pkg:Packagist/
symfony/ux-live-component
共 6 筆 CVE
MEDIUM
1
✅ 檢查你的版本
檢查
所有已知漏洞
MEDIUM
6.1
CVE-2025-47946
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
from 0, < 2.25.1
—
CVE-2026-49215
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted
>= 2.22.0, < 2.36.0
—
CVE-2026-49212
symfony/ux-live-component: LiveComponentHydrator HMAC checksum lacks component and slot binding
>= 2.8.0, < 2.36.0
—
CVE-2026-49210
symfony/ux-live-component: XSS via attacker-controlled child component tag
>= 2.8.0, < 2.36.0
—
symfony/ux-live-component: Denial of service via unbounded batch action requests
>= 2.5.0, < 2.36.0
—
ux-live-component: Format-less date LiveProps parsed with the permissive DateTime constructor
>= 2.8.0, < 2.36.0
CVE-2026-49209
CVE-2026-49208