CVE-2026-45068
- EPSS 0.41%
- Veröffentlicht 14.07.2026 19:02:10
- Zuletzt bearbeitet 15.07.2026 14:18:10
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SendmailTransport in -t mode appended recipient addresses to the sendmail command line without a -- end-of-...
CVE-2026-47212
- EPSS 0.24%
- Veröffentlicht 14.07.2026 19:00:30
- Zuletzt bearbeitet 15.07.2026 15:03:11
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, TwilioRequestParser::doParse() received the configured webhook secret but ignored the X-Twilio-Signature HMAC heade...
CVE-2026-45071
- EPSS 0.46%
- Veröffentlicht 14.07.2026 18:58:15
- Zuletzt bearbeitet 15.07.2026 15:16:33
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() set DOMDocument::$validateOnParse = true before loadXML(), re-enabling external en...
CVE-2026-45756
- EPSS 0.6%
- Veröffentlicht 14.07.2026 17:57:03
- Zuletzt bearbeitet 21.07.2026 19:17:10
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonPath component compiles attacker-controlled match() and search() filter patterns directly into preg_ma...
CVE-2026-45066
- EPSS 0.3%
- Veröffentlicht 14.07.2026 17:53:49
- Zuletzt bearbeitet 16.07.2026 15:16:31
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, HtmlSanitizer URL sanitization can allow off-allowlist URLs through allowLinkHosts() or allowMediaHos...
CVE-2026-45074
- EPSS 0.41%
- Veröffentlicht 14.07.2026 17:49:24
- Zuletzt bearbeitet 15.07.2026 15:35:14
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which reflects an attacker-contro...
CVE-2026-45077
- EPSS 0.45%
- Veröffentlicht 14.07.2026 17:46:33
- Zuletzt bearbeitet 15.07.2026 15:35:50
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default ...
CVE-2026-45065
- EPSS 0.26%
- Veröffentlicht 14.07.2026 17:43:45
- Zuletzt bearbeitet 15.07.2026 14:14:18
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, UrlGenerator validates route parameters against a pattern built as ^ plus the raw requirement plus $; with ...
CVE-2026-24739
- EPSS 0.2%
- Veröffentlicht 28.01.2026 20:25:21
- Zuletzt bearbeitet 02.02.2026 14:24:27
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to versions 5.4.51, 6.4.33, 7.3.11, 7.4.5, and 8.0.5, the Symfony Process component did not correctly treat some characters (notably `=`) as “spec...
CVE-2025-64500
- EPSS 1.33%
- Veröffentlicht 12.11.2025 21:40:57
- Zuletzt bearbeitet 12.01.2026 17:49:20
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6...