CVE-2026-92692
- EPSS 0.33%
- Veröffentlicht 23.09.2026 18:19:26
- Zuletzt bearbeitet 23.09.2026 20:17:22
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release lines have a Smart Content QueryBuilder in src/Sulu/Component/Content/SmartContent/QueryBuilder.php ...
CVE-2026-82396
- EPSS 0.17%
- Veröffentlicht 31.08.2026 21:23:16
- Zuletzt bearbeitet 08.09.2026 21:11:31
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /media/{id}/download/{slug} route and its administrat...
CVE-2026-82395
- EPSS 0.25%
- Veröffentlicht 31.08.2026 21:20:58
- Zuletzt bearbeitet 08.09.2026 21:11:31
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied collection value instead of the media item's actual...
CVE-2026-82394
- EPSS 0.32%
- Veröffentlicht 31.08.2026 21:17:49
- Zuletzt bearbeitet 08.09.2026 21:11:31
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php do not enforce VIEW permis...
CVE-2026-45701
- EPSS 0.19%
- Veröffentlicht 01.06.2026 17:17:11
- Zuletzt bearbeitet 22.07.2026 07:10:00
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6, the password reset tokenand API key generation uses a weak cryptographical hash algorithm. This issue has been patched in version...
CVE-2026-34372
- EPSS 0.26%
- Veröffentlicht 31.03.2026 20:19:32
- Zuletzt bearbeitet 24.07.2026 20:10:00
Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.22, and 3.0.0 to before 3.0.5, a user which has permission for the Sulu Admin via at least one role could have access to the sub-en...
CVE-2025-47778
- EPSS 0.45%
- Veröffentlicht 14.05.2025 15:29:08
- Zuletzt bearbeitet 15.04.2026 00:35:42
Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5, and 3.0.0-alpha1, an admin user can upload SVG which may load external data via XML DOM library. This can be used for insecure XM...
CVE-2024-47618
- EPSS 0.36%
- Veröffentlicht 03.10.2024 15:15:15
- Zuletzt bearbeitet 08.10.2024 14:31:08
Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the “Media” section can upload an SVG file with a malicious payload. Once uploaded and accessed, the malicious javascript will be exe...
CVE-2024-47617
- EPSS 0.33%
- Veröffentlicht 03.10.2024 15:15:14
- Zuletzt bearbeitet 08.10.2024 14:23:38
Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code through the media download URL in Sulu CMS. It affects the SuluMediaBundle component. The vulnerability is a Reflected Cross-Site ...
CVE-2024-27915
- EPSS 0.45%
- Veröffentlicht 06.03.2024 20:15:47
- Zuletzt bearbeitet 08.01.2025 18:37:37
Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to pages is granted regardless of role permissions for webspaces which have a security system configured and permission check enabled. We...