Total vulnerabilities in the database
b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header.
CVSS v3:
CVSS v2:
CWEs:
OWASP TOP 10: