Vulnerabilities > Sylius > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-11-15 | CVE-2021-3841 | Cross-site Scripting vulnerability in Sylius sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. | 5.4 |
2022-03-14 | CVE-2022-24749 | Cross-site Scripting vulnerability in Sylius Sylius is an open source eCommerce platform. | 6.1 |
2022-03-14 | CVE-2022-24742 | Exposure of Resource to Wrong Sphere vulnerability in Sylius Sylius is an open source eCommerce platform. | 5.5 |
2022-03-14 | CVE-2022-24733 | Unspecified vulnerability in Sylius Sylius is an open source eCommerce platform. | 6.1 |
2021-06-28 | CVE-2021-32720 | Information Exposure vulnerability in Sylius Sylius is an Open Source eCommerce platform on top of Symfony. | 5.3 |
2020-10-19 | CVE-2020-15245 | Missing Authorization vulnerability in Sylius In Sylius before versions 1.6.9, 1.7.9 and 1.8.3, the user may register in a shop by email [email protected], verify it, change it to the mail [email protected] and stay verified and enabled. | 4.3 |
2020-01-27 | CVE-2020-5220 | Information Exposure vulnerability in Sylius Syliusresourcebundle Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. | 5.3 |
2020-01-27 | CVE-2020-5218 | HTTP Request Smuggling vulnerability in Sylius Affected versions of Sylius give attackers the ability to switch channels via the _channel_code GET parameter in production environments. | 4.3 |
2019-12-31 | CVE-2019-12186 | Cross-site Scripting vulnerability in Sylius Grid and Sylius An issue was discovered in Sylius products. | 4.8 |
2019-12-05 | CVE-2019-16768 | Information Exposure Through an Error Message vulnerability in Sylius In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Symfony\Component\Security\Core\Exception\AuthenticationServiceException and propagated through the system to UI. | 4.3 |