Symfony
26 known vulnerabilities
Top Products
Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, the Stimulus controller in symfony/
Symfony UX is a JavaScript ecosystem for Symfony. From 2.22.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\EventList
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\Liv
Symfony UX is a JavaScript ecosystem for Symfony. From 2.2.0 until 2.36.0 and 3.1.0, Symfony\UX\Autocomplete\Doctrine\En
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\Child
Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as Date
Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is c
Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable val
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerc
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forw
Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a
Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplat
Twig is a template language for PHP. From 3.15.0 until 3.26.0, _self.(<string>) and import-alias dynamic attribute synta
Twig is a template language for PHP. From 3.24.0 until 3.26.0, object-destructuring assignment compiles CoreExtension::g
Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previou
Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra a
Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), whic
Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template n
Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter ins
Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, ca
Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, m
Symfony UX is a JavaScript ecosystem for Symfony. From 2.17.0 before 2.36.1 and from 3.0.0 before 3.2.0, the ux_icon() T
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface
Frequently Asked Questions
How many CVEs affect Symfony?
Symfony has 26 CVE records in our database, including 5 critical and 7 high severity vulnerabilities.
What are the most severe Symfony vulnerabilities?
Symfony has 5 critical severity (CVSS 9.0+) and 7 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Symfony vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Symfony products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Symfony Vulnerabilities
CyberStrike scans your infrastructure for Symfony vulnerabilities and provides real-time remediation guidance.
Get Started