Ibexa User bundle
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2025-10958 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. ibexa/user is vulnerable to Cross-site Scripting (XSS) in versions 4.6.0 - 4.6.25 and 5.0.0 - 5.0.3. | 4.6.0 - 4.6.255.0.0 - 5.0.3 | Medium |
CVE-2025-67719 ibexa/user is vulnerable to Unverified Password Change in versions 5.0.0-beta1 - 5.0.4. | 5.0.0-beta1 - 5.0.4 | Critical |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ^3.0 | — | — |
ibexa/core Version ~5.0 | — | — |
symfony/form Version ^7.4 | — | — |
symfony/intl Version ^7.4 | — | — |
symfony/config Version ^7.4 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant