Vulnerabilities > Sensiolabs > Critical

DATE CVE VULNERABILITY TITLE RISK
2019-11-21 CVE-2019-18889 Code Injection vulnerability in multiple products
An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7.
network
low complexity
sensiolabs fedoraproject CWE-94
critical
9.8
2019-11-21 CVE-2019-11325 Improper Encoding or Escaping of Output vulnerability in Sensiolabs Symfony
An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8.
network
low complexity
sensiolabs CWE-116
critical
9.8
2019-05-23 CVE-2017-11365 Improper Access Control vulnerability in Sensiolabs Symfony
Certain Symfony products are affected by: Incorrect Access Control.
network
low complexity
sensiolabs CWE-284
critical
9.8
2019-05-16 CVE-2019-10913 SQL Injection vulnerability in Sensiolabs Symfony
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS.
network
low complexity
sensiolabs CWE-89
critical
9.8
2019-05-16 CVE-2019-10910 SQL Injection vulnerability in multiple products
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution.
network
low complexity
sensiolabs drupal CWE-89
critical
9.8
2018-06-13 CVE-2018-11407 Improper Authentication vulnerability in Sensiolabs Symfony
An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7.
network
low complexity
sensiolabs CWE-287
critical
9.8
2017-02-07 CVE-2016-2403 Improper Authentication vulnerability in Sensiolabs Symfony
Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind.
network
low complexity
sensiolabs CWE-287
critical
9.8