İçeriğe atla
Noroxi

symfony kayıtları

symfony üreticisine ait 36 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%94,4
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

36 kayıt
  • CVE-2022-23614
    41Planlayın

    Code injection in Twig

    KritikCVSS 9,8Kavram kanıtıEPSS %8

    symfony · twig4 Şub 2022

  • CVE-2018-13818
    41Planlayın

    Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter.

    KritikCVSS 9,8İstismar yokEPSS %7

    symfony · twig10 Tem 2018

  • CVE-2024-45411
    34İzleyin

    Twig has a possible sandbox bypass

    YüksekCVSS 8,6İstismar yokEPSS %1

    symfony · twig9 Eyl 2024

  • CVE-2026-24425
    34İzleyin

    Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface

    YüksekCVSS 8,7İstismar yokEPSS %1

    symfony · twig20 May 2026

  • CVE-2026-46633
    34İzleyin

    Twig: PHP code injection via `{% use %}` template name

    YüksekCVSS 8,7İstismar yokEPSS %1

    symfony · twig14 Tem 2026

  • CVE-2026-46640
    34İzleyin

    Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation

    YüksekCVSS 8,7İstismar yokEPSS %1

    symfony · twig14 Tem 2026

  • CVE-2022-39261
    31İzleyin

    Twig may load a template outside a configured directory when using the filesystem loader

    YüksekCVSS 7,5İstismar yokEPSS %3

    symfony · twig28 Eyl 2022

  • CVE-2001-1537
    30İzleyin

    The default "basic" security setting' in config.php for TWIG webmail 2.7.4 and earlier stores cleartext usernames and passwords in cookies,

    YüksekCVSS 7,5İstismar yokEPSS %1

    symfony · twig31 Ara 2001

  • CVE-2024-36611
    30İzleyin

    In Symfony v7.07, a security vulnerability was identified in the FormLoginAuthenticator component, where it failed to adequately handle case

    YüksekCVSS 7,5İstismar yokEPSS %1

    29 Kas 2024

  • CVE-2026-46634
    30İzleyin

    Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name

    YüksekCVSS 7,7İstismar yokEPSS %1

    symfony · twig14 Tem 2026

  • CVE-2015-7809
    28İzleyin

    The displayBlock function Template.php in Sensio Labs Twig before 1.20.0, when Sandbox mode is enabled, allows remote attackers to execute a

    OrtaCVSS 6,8İstismar yokEPSS %3

    symfony · twig6 Kas 2015

  • CVE-2026-46627
    28İzleyin

    Twig: Sandbox resource exhaustion via unbounded `for` / `range()`

    YüksekCVSS 7,1İstismar yokEPSS %1

    symfony · twig14 Tem 2026

  • CVE-2026-48806
    28İzleyin

    Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys

    YüksekCVSS 7,1İstismar yokEPSS %0

    symfony · twig14 Tem 2026

  • CVE-2026-47732
    28İzleyin

    Twig Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points

    YüksekCVSS 7,1İstismar yokEPSS %0

    symfony · twig14 Tem 2026

  • CVE-2026-46639
    28İzleyin

    Twig: Sandbox property and method bypass via object-destructuring assignment

    YüksekCVSS 7,1İstismar yokEPSS %0

    symfony · twig14 Tem 2026

  • CVE-2026-48807
    28İzleyin

    Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters

    YüksekCVSS 7,1İstismar yokEPSS %0

    symfony · twig14 Tem 2026

  • CVE-2026-49211
    27İzleyin

    Symfony UX: Information exposure via unescaped LIKE wildcards in EntitySearchUtil

    OrtaCVSS 6,9İstismar yokEPSS %1

    symfony · ux17 Tem 2026

  • CVE-2026-49208
    27İzleyin

    Symfony UX: Format-less date LiveProps parsed with the permissive DateTime constructor

    OrtaCVSS 6,9İstismar yokEPSS %0

    symfony · ux17 Tem 2026

  • CVE-2026-49212
    27İzleyin

    Symfony UX: LiveComponentHydrator HMAC checksum lacks component and slot binding

    OrtaCVSS 6,9İstismar yokEPSS %0

    symfony · ux17 Tem 2026

  • CVE-2023-41336
    26İzleyin

    Prevent injection of invalid entity ids for "autocomplete" fields in symfony ux-autocomplete

    OrtaCVSS 6,5İstismar yokEPSS %1

    symfony · ux autocomplete11 Eyl 2023

  • CVE-2023-46734
    24İzleyin

    Symfony potential Cross-site Scripting vulnerabilities in CodeExtension filters

    OrtaCVSS 6,1İstismar yokEPSS %1

    symfony · twig-bridge10 Kas 2023

  • CVE-2026-46638
    24İzleyin

    Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)

    OrtaCVSS 6,0İstismar yokEPSS %0

    symfony · twig14 Tem 2026

  • CVE-2026-48808
    24İzleyin

    Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`

    OrtaCVSS 6,0İstismar yokEPSS %0

    symfony · twig14 Tem 2026

  • CVE-2026-49981
    24İzleyin

    Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`

    OrtaCVSS 6,0İstismar yokEPSS %0

    symfony · twig14 Tem 2026

  • CVE-2026-55877
    24İzleyin

    Symfony UX: XSS in symfony/ux-icons via unsanitized SVG content in local files and Iconify on-demand responses

    OrtaCVSS 6,1İstismar yokEPSS %0

    symfony · ux8 Tem 2026