SecAlerts
sensiolabs logo

sensiolabs

Security Risk Profile

46
/100
medium

Security Risk Score

Comprehensive risk assessment based on 90 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 19, 2012 to present

90
Total CVEs
43
Critical+High
0
Exploited
0
Unpatched

Threat Assessment

Avg CVSS
6.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
46/100
medium

Severity Distribution

Critical
9
High
34
Medium
42
Low
5

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
1

Age Distribution

Common Weaknesses (CWE)

1
XSS
10
2
Input Validation
6
3
CSRF
6
4
Code Injection
4
5
SQL Injection
3

Most Affected Products

1. SensioLabs Symfony736
2. composer/symfony/symfony312
3. composer/symfony/security74
4. composer/symfony/security-http61
5. composer/symfony/http-foundation38

Recent Vulnerabilities

See more →
CVE-2026-48784
CVSS 5.1medium

Symfony: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `../` or `./` → Generated URL Collapses Off-Route Under RFC 3986 Normalization

6/15/2026
CVE-2026-48760
CVSS 5.3medium

Symfony: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense

6/15/2026
CVE-2026-48747
CVSS 6.3medium

Symfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade

6/15/2026
CVE-2026-48736
CVSS 6.9medium

Symfony: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient

6/15/2026
CVE-2026-48489
CVSS 8.7high

Symfony: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes

6/15/2026
CVE-2026-48761
CVSS 5.3medium

Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on <object>, <applet>, <iframe>, <img> and the URL Inside <meta http-equiv="refresh"> content

6/15/2026
CVE-2026-47767
CVSS 8.3high

Symfony: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV/APP_DEBUG via parse_str/SAPI Argv Mismatch

6/9/2026
CVE-2026-47212
CVSS 6.9medium

Symfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event Injection

5/29/2026
CVE-2026-45756
CVSS 8.2high

Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS

5/28/2026
CVE-2026-45755
CVSS 6.9medium

Symfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection

5/28/2026

Monitor sensiolabs in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.