Skip to content
Noroxi

getsymphony records

18 published records for vendor getsymphony.

All records

18 records
  • CVE-2017-7694
    36Monitor

    Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attac

    HighCVSS 8.8No exploitEPSS 4%

    getsymphony · symphonyApr 11, 2017

  • A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to a

    CriticalCVSS 9.1No exploitEPSS 1%

    getsymphony · symphonyOct 31, 2021

  • CVE-2016-4309
    33Monitor

    Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessi

    HighCVSS 7.5Proof of conceptEPSS 10%

    getsymphony · symphonyJun 30, 2016

  • CVE-2010-2143
    32Monitor

    Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and possibly have unspe

    HighCVSS 7.5Proof of conceptEPSS 7%

    getsymphony · symphonyJun 3, 2010

  • CVE-2010-3458
    30Monitor

    SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbit

    HighCVSS 7.5Proof of conceptEPSS 1%

    getsymphony · symphonySep 17, 2010

  • CVE-2013-2559
    27Monitor

    SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort pa

    MediumCVSS 6.5Proof of conceptEPSS 2%

    getsymphony · symphonyMar 27, 2014

  • CVE-2013-7346
    27Monitor

    Cross-site request forgery (CSRF) vulnerability in Symphony CMS before 2.3.2 allows remote attackers to hijack the authentication of adminis

    MediumCVSS 6.8Proof of conceptEPSS 1%

    getsymphony · symphonyMar 27, 2014

  • CVE-2015-8766
    25Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in content/content.systempreferences.php in Symphony CMS before 2.6.4 allow remote attac

    MediumCVSS 6.1No exploitEPSS 2%

    getsymphony · symphonyJan 8, 2016

  • CVE-2017-5542
    24Monitor

    Cross-site scripting (XSS) vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers t

    MediumCVSS 6.1No exploitEPSS 1%

    getsymphony · symphonyJan 20, 2017

  • CVE-2015-8376
    24Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web script or HTML via

    MediumCVSS 6.1No exploitEPSS 1%

    getsymphony · symphonyJan 8, 2016

  • content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page.

    MediumCVSS 6.1No exploitEPSS 1%

    getsymphony · symphonyJun 7, 2018

  • CVE-2017-8876
    24Monitor

    Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php.

    MediumCVSS 6.1No exploitEPSS 1%

    getsymphony · symphonyMay 10, 2017

  • CVE-2017-6067
    24Monitor

    Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom form field.

    MediumCVSS 6.1No exploitEPSS 1%

    getsymphony · symphonyMar 26, 2017

  • content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading.

    MediumCVSS 6.1No exploitEPSS 1%

    getsymphony · symphonyAug 11, 2020

  • CVE-2017-5541
    22Monitor

    Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to renam

    MediumCVSS 5.3No exploitEPSS 2%

    getsymphony · symphonyJan 20, 2017

  • Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script or HTML to fields['bo

    MediumCVSS 5.4No exploitEPSS 1%

    getsymphony · symphonyOct 7, 2020

  • CVE-2015-4661
    18Monitor

    Cross-site scripting (XSS) vulnerability in Symphony CMS 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the sort p

    MediumCVSS 4.3No exploitEPSS 2%

    getsymphony · symphonyJun 18, 2015

  • CVE-2010-3457
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.0.7 and 2.1.1 allow remote attackers to inject arbitrary web script or

    MediumCVSS 4.3Proof of conceptEPSS 1%

    getsymphony · symphonySep 17, 2010