Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sylius sylius 1.5.0 vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv3
CVE-2020-5218
Affected versions of Sylius give attackers the ability to switch channels via the _channel_code GET parameter in production environments. This was meant to be enabled only when kernel.debug is set to true. However, if no sylius_channel.debug is set explicitly in the configuration...
Sylius Sylius
Sylius Sylius 1.5.0
4.8
CVSSv3
CVE-2019-12186
An issue exists in Sylius products. Missing input sanitization in sylius/sylius 1.0.x up to and including 1.0.18, 1.1.x up to and including 1.1.17, 1.2.x up to and including 1.2.16, 1.3.x up to and including 1.3.11, and 1.4.x up to and including 1.4.3 and sylius/grid 1.0.x up to ...
Sylius Grid
Sylius Grid 1.5.0
Sylius Sylius
5.3
CVSSv3
CVE-2020-5220
Sylius ResourceBundle accepts and uses any serialisation groups to be passed via a HTTP header. This might lead to data exposure by using an unintended serialisation group - for example it could make Shop API use a more permissive group from Admin API. Anyone exposing an API with...
Sylius Syliusresourcebundle
Sylius Syliusresourcebundle 1.5.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started