Skip to content
Noroxi

symphony-cms records

4 published records for vendor symphony-cms.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
25%
Median publish → KEV
No record has entered KEV

Records by year

  1. 24

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

All records

4 records
  • A Cross Site Scripting (XSS) vulnerability in Symphony CMS 2.7.10 allows remote attackers to inject arbitrary web script or HTML by editing

    MediumCVSS 5.4No exploitEPSS 0%

    symphony-cms · symphony cmsAug 13, 2024

  • symphonycms <=2.7.10 is vulnerable to Cross Site Scripting (XSS) in the Comment component for articles.

    MediumCVSS 4.8No exploitEPSS 0%

    symphony-cms · symphony cmsAug 13, 2024

  • CVE-2011-4341
    18Monitor

    Multiple SQL injection vulnerabilities in symphony/content/content.publish.php in Symphony CMS 2.2.3 and possibly other versions before 2.2.

    MediumCVSS 4.3Proof of conceptEPSS 3%

    symphony-cms · symphony cmsFeb 12, 2012

  • CVE-2011-4340
    15Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.2.3 and possibly other versions before 2.2.4 allow remote authenticate

    LowCVSS 3.5Proof of conceptEPSS 2%

    symphony-cms · symphony cmsFeb 12, 2012