Vulnerabilities > Sensiolabs > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-11-21 | CVE-2019-18889 | Code Injection vulnerability in multiple products An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. | 9.8 |
2019-11-21 | CVE-2019-11325 | Improper Encoding or Escaping of Output vulnerability in Sensiolabs Symfony An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. | 9.8 |
2019-05-23 | CVE-2017-11365 | Improper Access Control vulnerability in Sensiolabs Symfony Certain Symfony products are affected by: Incorrect Access Control. | 9.8 |
2019-05-16 | CVE-2019-10913 | SQL Injection vulnerability in Sensiolabs Symfony In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. | 9.8 |
2019-05-16 | CVE-2019-10910 | SQL Injection vulnerability in multiple products In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. | 9.8 |
2018-06-13 | CVE-2018-11407 | Improper Authentication vulnerability in Sensiolabs Symfony An issue was discovered in the Ldap component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. | 9.8 |
2017-02-07 | CVE-2016-2403 | Improper Authentication vulnerability in Sensiolabs Symfony Symfony before 2.8.6 and 3.x before 3.0.6 allows remote attackers to bypass authentication by logging in with an empty password and valid username, which triggers an unauthenticated bind. | 9.8 |