CVE-2026-34372
- EPSS 0.03%
- Veröffentlicht 31.03.2026 20:19:32
- Zuletzt bearbeitet 10.04.2026 01:40:29
Sulu is an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.22, and 3.0.0 to before 3.0.5, a user which has permission for the Sulu Admin via at least one role could have access to the sub-en...
CVE-2025-47778
- EPSS 0.24%
- Veröffentlicht 14.05.2025 15:29:08
- Zuletzt bearbeitet 15.04.2026 00:35:42
Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5, and 3.0.0-alpha1, an admin user can upload SVG which may load external data via XML DOM library. This can be used for insecure XM...
CVE-2024-47618
- EPSS 1.61%
- Veröffentlicht 03.10.2024 15:15:15
- Zuletzt bearbeitet 08.10.2024 14:31:08
Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the “Media” section can upload an SVG file with a malicious payload. Once uploaded and accessed, the malicious javascript will be exe...
CVE-2024-47617
- EPSS 0.75%
- Veröffentlicht 03.10.2024 15:15:14
- Zuletzt bearbeitet 08.10.2024 14:23:38
Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code through the media download URL in Sulu CMS. It affects the SuluMediaBundle component. The vulnerability is a Reflected Cross-Site ...
CVE-2024-27915
- EPSS 0.16%
- Veröffentlicht 06.03.2024 20:15:47
- Zuletzt bearbeitet 08.01.2025 18:37:37
Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to pages is granted regardless of role permissions for webspaces which have a security system configured and permission check enabled. We...
CVE-2024-24807
- EPSS 0.84%
- Veröffentlicht 05.02.2024 21:15:12
- Zuletzt bearbeitet 21.11.2024 08:59:45
Sulu is a highly extensible open-source PHP content management system based on the Symfony framework. There is an issue when inputting HTML into the Tag name. The HTML is executed when the tag name is listed in the auto complete form. Only admin user...
CVE-2023-39343
- EPSS 0.36%
- Veröffentlicht 04.08.2023 01:15:10
- Zuletzt bearbeitet 21.11.2024 08:15:11
Sulu is an open-source PHP content management system based on the Symfony framework. It allows over the Admin Login form to detect which user (username, email) exists and which one do not exist. Sulu Installation not using the old Symfony 5.4 securit...
CVE-2021-43835
- EPSS 0.32%
- Veröffentlicht 15.12.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:53
Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions Sulu users who have access to any subset of the admin UI are able to elevate their privilege. Over the API it was possible for them to give them...
CVE-2021-43836
- EPSS 4.29%
- Veröffentlicht 15.12.2021 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:29:53
Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions an attacker can read arbitrary local files via a PHP file include. In a default configuration this also leads to remote code execution. The prob...
CVE-2021-41169
- EPSS 0.29%
- Veröffentlicht 21.10.2021 21:15:08
- Zuletzt bearbeitet 21.11.2024 06:25:39
Sulu is an open-source PHP content management system based on the Symfony framework. In versions before 1.6.43 are subject to stored cross site scripting attacks. HTML input into Tag names is not properly sanitized. Only admin users are allowed to cr...