CVE-2026-49215
- EPSS 0.12%
- Veröffentlicht 17.07.2026 16:16:42
- Zuletzt bearbeitet 20.07.2026 16:54:54
Symfony UX is a JavaScript ecosystem for Symfony. From 2.22.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\EventListener\LiveComponentSubscriber::isLiveComponentRequest() gates #[LiveAction] invocations on Accept: application/vnd.live-component+h...
CVE-2026-49216
- EPSS 0.18%
- Veröffentlicht 17.07.2026 16:15:34
- Zuletzt bearbeitet 21.07.2026 03:16:41
Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/ux-autocomplete renders AJAX response items in _createAutocompleteWithRemoteData() by interpolating the text field into HTML templ...
CVE-2026-49211
- EPSS 0.31%
- Veröffentlicht 17.07.2026 16:14:29
- Zuletzt bearbeitet 20.07.2026 16:56:08
Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, Symfony\UX\Autocomplete\Doctrine\EntitySearchUtil::addSearchClause() builds the LIKE expression used by the autocomplete endpoint by wrapping the client-supplied que...
CVE-2026-49208
- EPSS 0.24%
- Veröffentlicht 17.07.2026 16:10:49
- Zuletzt bearbeitet 21.07.2026 03:16:41
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit format is configured, Symfony\UX\LiveComponent\LiveComponentHydrator::hydrateObjectValue() falls bac...
CVE-2026-49210
- EPSS 0.19%
- Veröffentlicht 17.07.2026 16:09:17
- Zuletzt bearbeitet 20.07.2026 16:56:24
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::createHtml() interpolates the client-controlled children[id].tag value from LiveComponentSubscriber and ...
CVE-2026-49212
- EPSS 0.16%
- Veröffentlicht 17.07.2026 16:03:27
- Zuletzt bearbeitet 20.07.2026 16:55:45
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\LiveComponent\LiveComponentHydrator covered only sorted prop key/value pairs and did not include the component name, the slot identif...
CVE-2026-49209
- EPSS 0.31%
- Veröffentlicht 17.07.2026 16:02:06
- Zuletzt bearbeitet 20.07.2026 16:56:45
Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller\BatchActionController::__invoke() iterates over the client-supplied actions array and issues a full HttpKernel sub-request for ea...
CVE-2026-55877
- EPSS 0.19%
- Veröffentlicht 08.07.2026 21:32:37
- Zuletzt bearbeitet 19.08.2026 19:49:29
Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() Twig function is marked is_safe=['html'] and Icon::toHtml() inlines SVG source verbatim, allowing unsanitized local SVG files or Ic...