api-platform records
2 published records for vendor api-platform.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Attack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
26Monitor | CVE-2019-1000011No exploit | API Platform version from 2.2.0 to 2.3.5 contains an Incorrect Access Control vulnerability in GraphQL delete mutations that can result in aapi-platform · core | Medium6.5 | — | 1.0% | Feb 4, 2019 |
26Monitor | CVE-2023-25575No exploit | Secured properties in API Platform Core may be accessible within collectionsapi-platform · core · CWE-842 | Medium6.5 | — | 0.6% | Feb 28, 2023 |
- CVE-2019-100001126Monitor
API Platform version from 2.2.0 to 2.3.5 contains an Incorrect Access Control vulnerability in GraphQL delete mutations that can result in a
MediumCVSS 6.5No exploitEPSS 1%api-platform · coreFeb 4, 2019
- CVE-2023-2557526Monitor
Secured properties in API Platform Core may be accessible within collections
MediumCVSS 6.5No exploitEPSS 1%api-platform · coreFeb 28, 2023