Sylius
7 known vulnerabilities in Sylius, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-100872 CVSS 8.7 high Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to…
- CVE-2026-100871 CVSS 8.7 high Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by…
- CVE-2026-100870 CVSS 8.7 high Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header…
- CVE-2026-100869 CVSS 8.2 high Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers to trigger…
- CVE-2026-53639 CVSS 6.3 medium Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the…
- CVE-2026-53638 CVSS 4.3 medium Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an…
- CVE-2026-53637 CVSS 6.5 medium Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5…