Vulnerabilities > Sensiolabs > Symfony > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-11-10 CVE-2023-46733 Unspecified vulnerability in Sensiolabs Symfony
Symfony is a PHP framework for web and console applications and a set of reusable PHP components.
network
low complexity
sensiolabs
6.5
2023-11-10 CVE-2023-46734 Unspecified vulnerability in Sensiolabs Symfony
Symfony is a PHP framework for web and console applications and a set of reusable PHP components.
network
low complexity
sensiolabs
6.1
2023-11-10 CVE-2023-46735 Unspecified vulnerability in Sensiolabs Symfony
Symfony is a PHP framework for web and console applications and a set of reusable PHP components.
network
low complexity
sensiolabs
6.1
2021-05-13 CVE-2021-21424 Symfony is a PHP framework for web and console applications and a set of reusable PHP components.
network
low complexity
sensiolabs fedoraproject
5.3
2020-03-30 CVE-2020-5274 Information Exposure Through an Error Message vulnerability in Sensiolabs Symfony
In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace.
network
low complexity
sensiolabs CWE-209
5.4
2020-03-30 CVE-2020-5255 Improper Input Validation vulnerability in Sensiolabs Symfony
In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the request, leading to a possible mismatch between the response's content and `Content-Type` header.
network
low complexity
sensiolabs CWE-20
4.3
2020-01-02 CVE-2013-4752 Cross-site Scripting vulnerability in multiple products
Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component.
network
low complexity
sensiolabs fedoraproject CWE-79
6.1
2019-11-21 CVE-2019-18886 Information Exposure Through Discrepancy vulnerability in Sensiolabs Symfony
An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7.
network
low complexity
sensiolabs CWE-203
5.3
2019-05-16 CVE-2019-10909 Cross-site Scripting vulnerability in multiple products
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included.
network
low complexity
sensiolabs drupal CWE-79
5.4
2018-12-18 CVE-2018-19790 Open Redirect vulnerability in multiple products
An open redirect was discovered in Symfony 2.7.x before 2.7.50, 2.8.x before 2.8.49, 3.x before 3.4.20, 4.0.x before 4.0.15, 4.1.x before 4.1.9 and 4.2.x before 4.2.1.
network
low complexity
sensiolabs fedoraproject debian CWE-601
6.1