CVE-2026-100872
- EPSS 0.18%
- Veröffentlicht 27.09.2026 13:16:38
- Zuletzt bearbeitet 28.09.2026 20:57:50
Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order af...
CVE-2026-100871
- EPSS 0.31%
- Veröffentlicht 27.09.2026 13:16:38
- Zuletzt bearbeitet 30.09.2026 16:17:04
Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endpoints. Attackers can register a shop customer account using an administrator's email a...
CVE-2026-100870
- EPSS 0.31%
- Veröffentlicht 27.09.2026 13:16:38
- Zuletzt bearbeitet 30.09.2026 16:17:04
Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains....
CVE-2026-100869
- EPSS 0.26%
- Veröffentlicht 27.09.2026 13:16:38
- Zuletzt bearbeitet 28.09.2026 20:57:50
Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers to trigger refunds on completed orders. Attackers with order tokens can submit arbitrary payment actions like refunds that p...
CVE-2026-53637
- EPSS 0.3%
- Veröffentlicht 08.09.2026 22:31:39
- Zuletzt bearbeitet 09.09.2026 21:04:42
Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is completed while...
CVE-2026-53638
- EPSS 0.18%
- Veröffentlicht 08.09.2026 22:25:26
- Zuletzt bearbeitet 14.09.2026 13:18:39
Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an authorization bypass vulnerability exists in the shop account API. The `PATCH /api/v2/shop/account/orders/{tokenValu...
CVE-2026-53639
- EPSS 0.54%
- Veröffentlicht 08.09.2026 22:22:24
- Zuletzt bearbeitet 09.09.2026 21:04:42
Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop/payment-requests/{hash}` endpoints look up the pay...
CVE-2026-31825
- EPSS 0.2%
- Veröffentlicht 10.03.2026 21:33:26
- Zuletzt bearbeitet 18.03.2026 19:48:52
Sylius is an Open Source eCommerce Framework on Symfony. Sylius API filters ProductPriceOrderFilter and TranslationOrderNameAndLocaleFilter pass user-supplied order direction values directly to Doctrine's orderBy() without validation. An attacker can...
CVE-2026-31824
- EPSS 0.18%
- Veröffentlicht 10.03.2026 21:32:16
- Zuletzt bearbeitet 11.03.2026 19:30:24
Sylius is an Open Source eCommerce Framework on Symfony. A Time-of-Check To Time-of-Use (TOCTOU) race condition was discovered in the promotion usage limit enforcement. The same class of vulnerability affects the promotion usage limit (the global use...
CVE-2026-31823
- EPSS 0.14%
- Veröffentlicht 10.03.2026 21:29:13
- Zuletzt bearbeitet 11.03.2026 19:31:00
Sylius is an Open Source eCommerce Framework on Symfony. An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple places across the shop frontend and admin panel due to unsanitized entity names being rendered as raw HTML. S...