The Symfony PHP framework
96%
Total Score
100
72
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-47212 symfony/symfony is vulnerable to Missing Authentication for Critical Function in versions 6.4.0 - 6.4.40, 7.0.0 - 7.4.12 and 8.0.0 - 8.0.12. | 6.4.0 - 6.4.407.0.0 - 7.4.128.0.0 - 8.0.12 | Medium |
CVE-2026-45072 symfony/symfony is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 6.4.24 - 6.4.40, 7.2.9 - 7.4.12 and 8.0.0 - 8.0.12. | 6.4.24 - 6.4.407.2.9 - 7.4.128.0.0 - 8.0.12 | Low |
CVE-2024-50343 symfony/symfony is vulnerable to Improper Input Validation in versions 0.0.0 - 5.4.43, 6.0.0 - 6.4.11 and 7.0.0 - 7.1.4. | 0.0.0 - 5.4.436.0.0 - 6.4.117.0.0 - 7.1.4 | Low |
AIKIDO-2024-10380 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. symfony/symfony is vulnerable to Improper Neutralization of Null Byte in versions 2.0.0 - 5.4.37, 6.0.0 - 6.4.5 and 7.0.0 - 7.0.5. | 2.0.0 - 5.4.376.0.0 - 6.4.57.0.0 - 7.0.5 | Low |
CVE-2014-6072 symfony/symfony is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 2.0.0 - 2.3.19, 2.4.0 - 2.4.9 and 2.5.0 - 2.5.4. | 2.0.0 - 2.3.192.4.0 - 2.4.92.5.0 - 2.5.4 | High |
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ^1|^2|^3 | — | — |
psr/link Version ^1.1|^2.0 | — | — |
psr/cache Version ^2.0|^3.0 | — | — |
psr/clock Version ^1.0 | — | — |
twig/twig Version ^3.25 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant