Vulnerability Database

With exploit

sensiolabs / symfony

Title Severity Exploit Date Affected Version
CVE-2023-46735 Medium Nov 10, 2023 >= 6.0.0 < 6.3.8
CVE-2023-46734 Medium Nov 10, 2023 >= 6.0.0 < 6.3.8
>= 5.0.0 < 5.4.31
>= 2.0.0 < 4.4.51
CVE-2023-46733 Medium Nov 10, 2023 >= 5.4.21 < 5.4.31
>= 6.2.7 < 6.3.8
CVE-2022-24894 High Feb 3, 2023 >= 6.2.0 < 6.2.6
>= 6.1.0 < 6.1.12
>= 6.0.0 < 6.0.20
>= 2.0.0 < 4.4.50
>= 5.0.0 < 5.4.2
CVE-2022-24895 High Feb 3, 2023 >= 6.2.0 < 6.2.6
>= 6.1.0 < 6.1.12
>= 6.0.0 < 6.0.20
>= 2.0.0 < 4.4.50
>= 5.0.0 < 5.4.20
CVE-2022-23601 High Feb 1, 2022 >= 6.0.0 < 6.0.4
>= 5.4.0 < 5.4.4
< 5.3.15
CVE-2021-41267 Low Nov 24, 2021 >= 5.2.0 < 5.3.12
CVE-2021-41268 High Nov 24, 2021 >= 5.3.0 < 5.3.12
CVE-2021-41270 Low Nov 24, 2021 >= 5.0.0 < 5.3.12
>= 4.1.0 < 4.4.35
CVE-2021-32693 High Jun 18, 2021 >= 5.3.0 < 5.3.2

symfony / symfony

Title Severity Exploit Date Affected Version
CVE-2014-6072 High May 30, 2024 >= 2.0.0 < 2.3.19
>= 2.4.0 < 2.4.9
>= 2.5.0 < 2.5.4
Symfony2 improper IP based access control Medium May 30, 2024 >= 2.0.0 < 2.0.19
>= 2.1.0 < 2.1.4
Symfony XML Entity Expansion security vulnerability High May 30, 2024 >= 2.0.0 < 2.0.17
Symfony XML decoding attack vector through external entities Critical May 30, 2024 >= 2.0.0 < 2.0.11
Symfony may allow a user to switch to using another user's identity Medium May 30, 2024 >= 2.0.0 < 2.0.6
CVE-2014-5245 High May 30, 2024 >= 2.0.0 < 2.3.19
>= 2.4.0 < 2.4.9
>= 2.5.0 < 2.5.4
CVE-2015-2309 Medium May 30, 2024 >= 2.0.0 < 2.3.27
>= 2.4.0 < 2.5.11
>= 2.6.0 < 2.6.6
CVE-2014-6061 Medium May 30, 2024 >= 2.0.0 < 2.3.19
>= 2.4.0 < 2.4.9
>= 2.5.0 < 2.5.4
CVE-2014-5244 High May 30, 2024 >= 2.0.0 < 2.3.19
>= 2.4.0 < 2.4.9
>= 2.5.0 < 2.5.4
Symfony2 security issue when the trust proxy mode is enabled Medium May 30, 2024 >= 2.0.0 < 2.0.19
>= 2.1.0 < 2.1.4

auth0 / symfony

Title Severity Exploit Date Affected Version
Auth0 Symfony SDK Deserialization of Untrusted Data vulnerability Critical Jun 6, 2025 >= 5.0.0-BETA0 < 5.1.0
Auth0 Symfony SDK Vulnerable to Brute Force Authentication Tags of CookieStore Sessions Critical May 17, 2025 < 5.4.0