Sylius
Sylius: vulnerabilidades y CVE
Sylius tiene 28 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses14
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-100872 | Alta (8.7) | 0.18% | — | 27 sept 2026 | Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a… |
| CVE-2026-100871 | Alta (8.7) | 0.31% | — | 27 sept 2026 | Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endpoints. Attackers can register a shop customer account… |
| CVE-2026-100870 | Alta (8.7) | 0.31% | — | 27 sept 2026 | Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens… |
| CVE-2026-100869 | Alta (8.2) | 0.26% | — | 27 sept 2026 | Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers to trigger refunds on completed orders. Attackers with order tokens can submit arbitrary… |
| CVE-2026-53639 | Media (6.3) | 0.54% | — | 8 sept 2026 | Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT… |
| CVE-2026-53638 | Media (4.3) | 0.28% | — | 8 sept 2026 | Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an authorization bypass vulnerability exists in the shop account API. The `PATCH… |
| CVE-2026-53637 | Media (6.5) | 0.36% | — | 8 sept 2026 | Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`.… |
| CVE-2026-31825 | Media (5.3) | 0.33% | — | 10 mar 2026 | Sylius is an Open Source eCommerce Framework on Symfony. Sylius API filters ProductPriceOrderFilter and TranslationOrderNameAndLocaleFilter pass user-supplied order direction values directly to Doctrine's orderBy()… |
| CVE-2026-31824 | Media (5.9) | 0.30% | — | 10 mar 2026 | Sylius is an Open Source eCommerce Framework on Symfony. A Time-of-Check To Time-of-Use (TOCTOU) race condition was discovered in the promotion usage limit enforcement. The same class of vulnerability affects the… |
| CVE-2026-31823 | Media (4.8) | 0.24% | — | 10 mar 2026 | Sylius is an Open Source eCommerce Framework on Symfony. An authenticated stored cross-site scripting (XSS) vulnerability exists in multiple places across the shop frontend and admin panel due to unsanitized entity… |
| CVE-2026-31822 | Media (5.3) | 0.29% | — | 10 mar 2026 | Sylius is an Open Source eCommerce Framework on Symfony. A cross-site scripting (XSS) vulnerability exists in the shop checkout login form handled by the ApiLoginController Stimulus controller. When a login attempt… |
| CVE-2026-31821 | Media (6.9) | 0.30% | — | 10 mar 2026 | Sylius is an Open Source eCommerce Framework on Symfony. The POST /api/v2/shop/orders/{tokenValue}/items endpoint does not verify cart ownership. An unauthenticated attacker can add items to other registered customers'… |
| CVE-2026-31820 | Alta (7.1) | 0.34% | — | 10 mar 2026 | Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulnerability exists in multiple shop LiveComponents due to unvalidated resource IDs accepted via… |
| CVE-2026-31819 | Media (6.9) | 0.30% | — | 10 mar 2026 | Sylius is an Open Source eCommerce Framework on Symfony. CurrencySwitchController::switchAction(), ImpersonateUserController::impersonateAction() and StorageBasedLocaleSwitcher::handle() use the HTTP Referer header… |
| CVE-2024-57610 | Alta (7.5) | 1.2% | — | 6 feb 2025 | A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate… |
| CVE-2021-3841 | Media (5.4) | 0.25% | — | 15 nov 2024 | sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability allows attackers to inject malicious scripts that can be executed in… |
| CVE-2024-40633 | Media (5.3) | 0.38% | — | 17 jul 2024 | Sylius is an Open Source eCommerce Framework on Symfony. A security vulnerability was discovered in the `/api/v2/shop/adjustments/{id}` endpoint, which retrieves order adjustments based on incremental integer IDs. The… |
| CVE-2024-34349 | Media (4.8) | 0.44% | — | 14 may 2024 | Sylius is an open source eCommerce platform. Prior to 1.12.16 and 1.13.1, there is a possibility to execute javascript code in the Admin panel. In order to perform an XSS attack input a script into Name field in which… |
| CVE-2024-29376 | Media (6.4) | 0.42% | — | 22 abr 2024 | Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book. |
| CVE-2022-24749 | Media (6.1) | 1.1% | — | 14 mar 2022 | Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-site scripting (XSS) code in the admin panel. In order to perform a… |
| CVE-2022-24743 | Alta (8.2) | 1.3% | — | 14 mar 2022 | Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set to null after the password was changed. The same token could be used several times, which could… |
| CVE-2022-24742 | Media (5.5) | 0.82% | — | 14 mar 2022 | Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains unclosed after log out. The issue is fixed in versions 1.9.10, 1.10.11,… |
| CVE-2022-24733 | Media (6.1) | 0.91% | — | 14 mar 2022 | Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to load the website within an iframe. This will enable a clickjacking… |
| CVE-2021-32720 | Media (5.3) | 0.88% | — | 28 jun 2021 | Sylius is an Open Source eCommerce platform on top of Symfony. In versions of Sylius prior to 1.9.5 and 1.10.0-RC.1, part of the details (order ID, order number, items total, and token value) of all placed orders were… |
| CVE-2020-15245 | Media (4.3) | 0.63% | — | 19 oct 2020 | In Sylius before versions 1.6.9, 1.7.9 and 1.8.3, the user may register in a shop by email mail@example.com, verify it, change it to the mail another@domain.com and stay verified and enabled. This may lead to having… |
| CVE-2020-5218 | Media (4.3) | 0.60% | — | 27 ene 2020 | Affected versions of Sylius give attackers the ability to switch channels via the _channel_code GET parameter in production environments. This was meant to be enabled only when kernel.debug is set to true. However, if… |
| CVE-2019-12186 | Media (4.8) | 0.55% | — | 31 dic 2019 | An issue was discovered in Sylius products. Missing input sanitization in sylius/sylius 1.0.x through 1.0.18, 1.1.x through 1.1.17, 1.2.x through 1.2.16, 1.3.x through 1.3.11, and 1.4.x through 1.4.3 and sylius/grid… |
| CVE-2019-16768 | Media (4.3) | 0.75% | — | 5 dic 2019 | In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Symfony\Component\Security\Core\Exception\AuthenticationServiceException and propagated through the… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.