FLAT-UOWS6 (CVE-2026-46644)
Lack of data validation - Path Traversal In php-symfony-polyfill
2.7
Low
Ecosystem: Debian
Component: php-symfony-polyfill
FLAT-CQYN6 (CVE-2026-48784)
Server-side request forgery (SSRF) In symfony
1.2
Low
Ecosystem: Debian
Component: symfony
FLAT-BG1KE (CVE-2026-48747)
Insecure encryption algorithm In symfony
1.7
Low
Ecosystem: Debian
Component: symfony
FLAT-PEHHL (CVE-2026-48760)
Clickjacking In symfony
1.3
Low
Ecosystem: Debian
Component: symfony
FLAT-PECXF (CVE-2026-48761)
Server side cross-site scripting In symfony
1.3
Low
Ecosystem: Debian
Component: symfony
FLAT-LEWBU (CVE-2026-48489)
Authentication mechanism absence or evasion In symfony
6.6
Medium
Ecosystem: Debian
Component: symfony
FLAT-1MMDX (CVE-2026-48736)
Server-side request forgery (SSRF) In symfony
2.5
Low
Ecosystem: Debian
Component: symfony
FLAT-NYA4F (CVE-2026-47212)
Authentication mechanism absence or evasion In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-M421A (CVE-2026-45071)
XML injection (XXE) In symfony
6.6
Medium
Ecosystem: Debian
Component: symfony
FLAT-9UW9M (CVE-2026-45068)
Insecure functionality In symfony
6.6
Medium
Ecosystem: Debian
Component: symfony
FLAT-2D70C (CVE-2026-47767)
Lack of data validation In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-V1Y53 (CVE-2026-45754)
Authentication mechanism absence or evasion In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-B5WP8 (CVE-2026-45753)
Reflected cross-site scripting (XSS) In symfony
0.5
Low
Ecosystem: Debian
Component: symfony
FLAT-OCAF7 (CVE-2026-45304)
Asymmetric denial of service In symfony
6.6
Medium
Ecosystem: Debian
Component: symfony
FLAT-MEUK7 (CVE-2026-45305)
Asymmetric denial of service - ReDoS In symfony
6.6
Medium
Ecosystem: Debian
Component: symfony
FLAT-LVZ32 (CVE-2026-45755)
Insufficient data authenticity validation In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-L3WKP (CVE-2026-45072)
Server side cross-site scripting In symfony
0.4
Low
Ecosystem: Debian
Component: symfony
FLAT-UY8M8 (CVE-2026-45133)
Asymmetric denial of service - ReDoS In symfony
4.6
Medium
Ecosystem: Debian
Component: symfony
FLAT-O05T4 (CVE-2026-45073)
SQL injection In symfony
1.7
Low
Ecosystem: Debian
Component: symfony
FLAT-D8N9B (CVE-2026-45070)
Lack of data validation In symfony
1.7
Low
Ecosystem: Debian
Component: symfony
FLAT-XOJZX (CVE-2026-45075)
Authentication mechanism absence or evasion In symfony
4.8
Medium
Ecosystem: Debian
Component: symfony
FLAT-SUPZD (CVE-2026-45069)
Insufficient data authenticity validation In symfony
6.7
Medium
Ecosystem: Debian
Component: symfony
FLAT-7E7E7 (CVE-2026-45064)
Clickjacking In symfony
0.6
Low
Ecosystem: Debian
Component: symfony
FLAT-0FWDE (CVE-2026-45063)
Spoofing In symfony
6.9
Medium
Ecosystem: Debian
Component: symfony
FLAT-KRBJF (CVE-2026-45756)
Asymmetric denial of service - ReDoS In symfony
4.6
Medium
Ecosystem: Debian
Component: symfony
FLAT-4RD7H (CVE-2026-45077)
Insecure deserialization In symfony
4.9
Medium
Ecosystem: Debian
Component: symfony
FLAT-PJBV7 (CVE-2026-45074)
Spoofing In symfony
4.9
Medium
Ecosystem: Debian
Component: symfony
FLAT-NXWDU (CVE-2026-45066)
Lack of data validation In symfony
0.6
Low
Ecosystem: Debian
Component: symfony
FLAT-Q59ND (CVE-2026-45065)
Asymmetric denial of service - ReDoS In symfony
0.6
Low
Ecosystem: Debian
Component: symfony
FLAT-V57PE (CVE-2025-64500)
Authentication mechanism absence or evasion In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-Q3AA9 (DLA-4200-1)
Insecure service configuration In symfony
0.6
Low
Ecosystem: Debian
Component: symfony
FLAT-BNZ0Y (DSA-5813-1)
Improper authorization control for web services In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-MFF9X (DSA-5809-1)
Improper authorization control for web services In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-IF7O0 (CVE-2024-50343)
Lack of data validation In symfony
0.6
Low
Ecosystem: Debian
Component: symfony
FLAT-0MAIK (CVE-2024-50345)
Cross-site request forgery In symfony
0.6
Low
Ecosystem: Debian
Component: symfony
FLAT-FHQNL (CVE-2024-50341)
Authentication mechanism absence or evasion In symfony
0.6
Low
Ecosystem: Debian
Component: symfony
FLAT-ZRGKW (CVE-2024-50342)
Business information leak In symfony
0.6
Low
Ecosystem: Debian
Component: symfony
FLAT-406OM (CVE-2024-50340)
Lack of data validation In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-G2CF1 (DLA-3664-1)
Improper authorization control for web services In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-V1IAU (DLA-3493-1)
Improper authorization control for web services In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-0CB0K (CVE-2022-24895)
Session Fixation In symfony
1.3
Low
Ecosystem: Debian
Component: symfony
FLAT-G7U31 (CVE-2022-24894)
Improper authorization control for web services In symfony
6.1
Medium
Ecosystem: Debian
Component: symfony
FLAT-7XPTS (CVE-2020-15094)
Insecurely deleted files In symfony
4.8
Medium
Ecosystem: Debian
Component: symfony
FLAT-SBCDJ (CVE-2020-5274)
Technical information leak In symfony
1.3
Low
Ecosystem: Debian
Component: symfony
FLAT-NYT52 (CVE-2020-5275)
Improper authorization control for web services In symfony
4.7
Medium
Ecosystem: Debian
Component: symfony
FLAT-38XAV (CVE-2020-5255)
Race condition In symfony
0.5
Low
Ecosystem: Debian
Component: symfony
FLAT-2TOP9 (DSA-4573-1)
Improper authorization control for web services In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-ZTR9X (DLA-1999-1)
Improper authorization control for web services In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-5XE76 (DSA-4441-1)
Improper authorization control for web services In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-67PG2 (DLA-1778-1)
Improper authorization control for web services In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-X3GC2 (DLA-1707-1)
Improper authorization control for web services In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-8ZVAL (DSA-4262-1)
Improper authorization control for web services In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-5CEX9 (CVE-2017-18343)
Reflected cross-site scripting (XSS) In symfony
1.3
Low
Ecosystem: Debian
Component: symfony
FLAT-QMRR8 (CVE-2018-12040)
Reflected cross-site scripting (XSS) In symfony
1.2
Low
Ecosystem: Debian
Component: symfony
FLAT-2TBW9 (DSA-3588-1)
Improper authorization control for web services In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-NR2CB (DSA-3402-1)
Improper authorization control for web services In symfony
2.7
Low
Ecosystem: Debian
Component: symfony
FLAT-JZD8X (DSA-3276-1)
Improper authorization control for web services In symfony
2.7
Low
Ecosystem: Debian
Component: symfony