Skip to main content

Vendor/product archive

getsymphony / symphony CVEs

Beta · best-effort

18 CVEs tagged to getsymphony / symphony1 Critical, 4 High, 13 Medium, 0 Low, 0 Unrated.

CVE-2020-25912

Published Oct 31, 2021

A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of s…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-25343

Published Oct 7, 2020

Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script or HTML to fields['body'] param via events\event.publish_art…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15071

Published Aug 11, 2020

content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-8876

Published May 10, 2017

Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-7694

Published Apr 11, 2017

Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attackers to execute code and get a webshell…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5542

Published Jan 20, 2017

Cross-site scripting (XSS) vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to inject arbitrary web script or HTML v…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-5541

Published Jan 20, 2017

Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to rename arbitrary files via a .. (dot dot) in…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-4309

Published Jun 30, 2016

Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2015-8766

Published Jan 8, 2016

Multiple cross-site scripting (XSS) vulnerabilities in content/content.systempreferences.php in Symphony CMS before 2.6.4 allow remote attackers to inject arbitrary web script or…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-8376

Published Jan 8, 2016

Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Navigation Group, or…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-4661

Published Jun 18, 2015

Cross-site scripting (XSS) vulnerability in Symphony CMS 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the sort parameter to system/authors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7346

Published Mar 27, 2014

Cross-site request forgery (CSRF) vulnerability in Symphony CMS before 2.3.2 allows remote attackers to hijack the authentication of administrators for requests that conduct SQL i…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2559

Published Mar 27, 2014

SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter to system/authors/. NOTE: this…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3458

Published Sep 17, 2010

SQL injection vulnerability in lib/toolkit/events/event.section.php in Symphony CMS 2.0.7 and 2.1.1 allows remote attackers to execute arbitrary SQL commands via the send-email[re…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2010-3457

Published Sep 17, 2010

Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.0.7 and 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) fields[website] param…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2143

Published Jun 3, 2010

Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1