CVE-2026-48761
- EPSS 0.27%
- Veröffentlicht 14.07.2026 19:21:26
- Zuletzt bearbeitet 21.07.2026 19:17:10
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on <object>, <applet>, <ifra...
CVE-2026-47767
- EPSS 0.39%
- Veröffentlicht 14.07.2026 19:17:09
- Zuletzt bearbeitet 16.07.2026 15:16:31
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAP...
CVE-2026-45304
- EPSS 0.8%
- Veröffentlicht 14.07.2026 19:17:07
- Zuletzt bearbeitet 15.07.2026 14:55:30
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser resolved YAML collection aliases recursively, allowing a small untrusted YAML...
CVE-2026-45305
- EPSS 0.8%
- Veröffentlicht 14.07.2026 19:17:07
- Zuletzt bearbeitet 15.07.2026 14:57:02
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() used regular expressions with overlapping quantifiers for YAML dir...
CVE-2026-45753
- EPSS 0.29%
- Veröffentlicht 14.07.2026 19:17:07
- Zuletzt bearbeitet 15.07.2026 13:44:21
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlAttributeSanitizer::getSupportedAttributes() omits URL-valued attributes including action, formact...
CVE-2026-45754
- EPSS 0.35%
- Veröffentlicht 14.07.2026 19:17:07
- Zuletzt bearbeitet 21.07.2026 18:16:58
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, the Mailjet mailer bridge and LOX24 notifier bridge webhook parsers received configured webhook secrets but did not...
CVE-2026-45755
- EPSS 0.24%
- Veröffentlicht 14.07.2026 19:17:07
- Zuletzt bearbeitet 15.07.2026 13:42:26
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, MailtrapRequestParser::doParse() received the configured webhook secret but ignored the X-Mt-Signature HMAC header, allowing...
CVE-2026-45072
- EPSS 0.23%
- Veröffentlicht 14.07.2026 19:17:06
- Zuletzt bearbeitet 16.07.2026 03:12:44
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the development profiler file_excerpt Twig filter escapes PHP files through highlight_string() but interpo...
CVE-2026-45073
- EPSS 0.41%
- Veröffentlicht 14.07.2026 19:17:06
- Zuletzt bearbeitet 15.07.2026 14:51:54
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAdapter::doClear() builds a DELETE statement using a namespace derived from the caller-supplied $prefix ...
CVE-2026-45075
- EPSS 0.38%
- Veröffentlicht 14.07.2026 19:17:06
- Zuletzt bearbeitet 16.07.2026 15:16:31
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #[IsCsrfTokenValid] attributes can be configured for GET only, but Symf...