CVE-2026-31825
- EPSS 0.05%
- Veröffentlicht 10.03.2026 21:33:26
- Zuletzt bearbeitet 18.03.2026 19:48:52
Sylius is an Open Source eCommerce Framework on Symfony. Sylius API filters ProductPriceOrderFilter and TranslationOrderNameAndLocaleFilter pass user-supplied order direction values directly to Doctrine's orderBy() without validation. An attacker can...
CVE-2026-31824
- EPSS 0.06%
- Veröffentlicht 10.03.2026 21:32:16
- Zuletzt bearbeitet 11.03.2026 19:30:24
Sylius is an Open Source eCommerce Framework on Symfony. A Time-of-Check To Time-of-Use (TOCTOU) race condition was discovered in the promotion usage limit enforcement. The same class of vulnerability affects the promotion usage limit (the global use...
CVE-2026-31823
- EPSS 0.04%
- Veröffentlicht 10.03.2026 21:29:13
- Zuletzt bearbeitet 11.03.2026 19:31:00
Sylius is an Open Source eCommerce Framework on Symfony. An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple places across the shop frontend and admin panel due to unsanitized entity names being rendered as raw HTML. S...
CVE-2026-31822
- EPSS 0.05%
- Veröffentlicht 10.03.2026 21:27:38
- Zuletzt bearbeitet 11.03.2026 19:32:26
Sylius is an Open Source eCommerce Framework on Symfony. A cross-site scripting (XSS) vulnerability exists in the shop checkout login form handled by the ApiLoginController Stimulus controller. When a login attempt fails, AuthenticationFailureHandler...
CVE-2026-31821
- EPSS 0.11%
- Veröffentlicht 10.03.2026 21:25:20
- Zuletzt bearbeitet 11.03.2026 19:33:33
Sylius is an Open Source eCommerce Framework on Symfony. The POST /api/v2/shop/orders/{tokenValue}/items endpoint does not verify cart ownership. An unauthenticated attacker can add items to other registered customers' carts by knowing the cart token...
CVE-2026-31820
- EPSS 0.02%
- Veröffentlicht 10.03.2026 21:22:37
- Zuletzt bearbeitet 11.03.2026 19:34:28
Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulnerability exists in multiple shop LiveComponents due to unvalidated resource IDs accepted via #[LiveArg] parameters. Unlike props, w...
CVE-2026-31819
- EPSS 0.05%
- Veröffentlicht 10.03.2026 21:18:59
- Zuletzt bearbeitet 11.03.2026 20:14:24
Sylius is an Open Source eCommerce Framework on Symfony. CurrencySwitchController::switchAction(), ImpersonateUserController::impersonateAction() and StorageBasedLocaleSwitcher::handle() use the HTTP Referer header directly when redirecting. The atta...
CVE-2024-57610
- EPSS 9.75%
- Veröffentlicht 06.02.2025 18:15:32
- Zuletzt bearbeitet 19.09.2025 19:07:05
A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The Supplier's position ...
CVE-2021-3841
- EPSS 0.15%
- Veröffentlicht 15.11.2024 11:15:05
- Zuletzt bearbeitet 19.11.2024 17:11:49
sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of the user's brows...
CVE-2024-40633
- EPSS 0.24%
- Veröffentlicht 17.07.2024 18:15:04
- Zuletzt bearbeitet 15.04.2026 00:35:42
Sylius is an Open Source eCommerce Framework on Symfony. A security vulnerability was discovered in the `/api/v2/shop/adjustments/{id}` endpoint, which retrieves order adjustments based on incremental integer IDs. The vulnerability allows an attacker...