CVE-2026-31822
- EPSS 0.18%
- Veröffentlicht 10.03.2026 21:27:38
- Zuletzt bearbeitet 11.03.2026 19:32:26
Sylius is an Open Source eCommerce Framework on Symfony. A cross-site scripting (XSS) vulnerability exists in the shop checkout login form handled by the ApiLoginController Stimulus controller. When a login attempt fails, AuthenticationFailureHandler...
CVE-2026-31821
- EPSS 0.18%
- Veröffentlicht 10.03.2026 21:25:20
- Zuletzt bearbeitet 11.03.2026 19:33:33
Sylius is an Open Source eCommerce Framework on Symfony. The POST /api/v2/shop/orders/{tokenValue}/items endpoint does not verify cart ownership. An unauthenticated attacker can add items to other registered customers' carts by knowing the cart token...
CVE-2026-31820
- EPSS 0.29%
- Veröffentlicht 10.03.2026 21:22:37
- Zuletzt bearbeitet 11.03.2026 19:34:28
Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulnerability exists in multiple shop LiveComponents due to unvalidated resource IDs accepted via #[LiveArg] parameters. Unlike props, w...
CVE-2026-31819
- EPSS 0.17%
- Veröffentlicht 10.03.2026 21:18:59
- Zuletzt bearbeitet 11.03.2026 20:14:24
Sylius is an Open Source eCommerce Framework on Symfony. CurrencySwitchController::switchAction(), ImpersonateUserController::impersonateAction() and StorageBasedLocaleSwitcher::handle() use the HTTP Referer header directly when redirecting. The atta...
CVE-2024-57610
- EPSS 1.2%
- Veröffentlicht 06.02.2025 18:15:32
- Zuletzt bearbeitet 19.09.2025 19:07:05
A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The Supplier's position ...
CVE-2021-3841
- EPSS 0.24%
- Veröffentlicht 15.11.2024 11:15:05
- Zuletzt bearbeitet 19.11.2024 17:11:49
sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of the user's brows...
CVE-2024-40633
- EPSS 0.38%
- Veröffentlicht 17.07.2024 18:15:04
- Zuletzt bearbeitet 15.04.2026 00:35:42
Sylius is an Open Source eCommerce Framework on Symfony. A security vulnerability was discovered in the `/api/v2/shop/adjustments/{id}` endpoint, which retrieves order adjustments based on incremental integer IDs. The vulnerability allows an attacker...
CVE-2024-34349
- EPSS 0.44%
- Veröffentlicht 14.05.2024 15:38:41
- Zuletzt bearbeitet 15.04.2026 00:35:42
Sylius is an open source eCommerce platform. Prior to 1.12.16 and 1.13.1, there is a possibility to execute javascript code in the Admin panel. In order to perform an XSS attack input a script into Name field in which of the resources: Taxons, Produc...
CVE-2024-29376
- EPSS 0.42%
- Veröffentlicht 22.04.2024 19:15:46
- Zuletzt bearbeitet 15.09.2025 15:50:07
Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book.
CVE-2022-24749
- EPSS 1.11%
- Veröffentlicht 14.03.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:00
Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-site scripting (XSS) code in the admin panel. In order to perform a XSS attack, the file itself has t...