Executive Summary — CRITICAL
251 dependencies scanned
Top 3 most critical (direct production dependencies):
Top 2 end-of-life frameworks:
Everything else: 201 production CVE (critical=8, high=57, medium=99, low=37) · 8 dev/test CVE · 44 vulnerable vendored-JS · 5 EOL frameworks · 12 obsolete · 215 outdated · 24 scan alerts
composer:drupal/core
8.5.0
→ 8.5.1
CWE-20Improper Input Validation
composer:symfony/dependency-injection
3.4.4
→ 3.4.26
CWE-89SQL Injection
composer:onelogin/php-saml
4.2.0
→ 4.3.1
composer:symfony/browser-kit
EOL since 2021-11-01
→ latest 8.1.7
composer:symfony/browser-kit
EOL since 2021-11-01
→ latest 8.1.7
drupal/core/composer.jsondrupal/core/lib/Drupal/Component/Annotation/composer.jsondrupal/core/lib/Drupal/Component/Assertion/composer.jsondrupal/core/lib/Drupal/Component/Bridge/composer.jsondrupal/core/lib/Drupal/Component/ClassFinder/composer.jsondrupal/core/lib/Drupal/Component/Datetime/composer.jsondrupal/core/lib/Drupal/Component/DependencyInjection/composer.jsondrupal/core/lib/Drupal/Component/Diff/composer.jsondrupal/core/lib/Drupal/Component/Discovery/composer.jsondrupal/core/lib/Drupal/Component/EventDispatcher/composer.jsondrupal/core/lib/Drupal/Component/FileCache/composer.jsondrupal/core/lib/Drupal/Component/FileSystem/composer.jsondrupal/core/lib/Drupal/Component/Gettext/composer.jsondrupal/core/lib/Drupal/Component/Graph/composer.jsondrupal/core/lib/Drupal/Component/HttpFoundation/composer.jsondrupal/core/lib/Drupal/Component/PhpStorage/composer.jsondrupal/core/lib/Drupal/Component/Plugin/composer.jsondrupal/core/lib/Drupal/Component/ProxyBuilder/composer.jsondrupal/core/lib/Drupal/Component/Render/composer.jsondrupal/core/lib/Drupal/Component/Serialization/composer.jsondrupal/core/lib/Drupal/Component/Transliteration/composer.jsondrupal/core/lib/Drupal/Component/Utility/composer.jsondrupal/core/lib/Drupal/Component/Uuid/composer.jsonwp/wp-includes/sodium_compat/composer.json| CMS / framework | Instance | Observed version | Direct | Indirect | Unknown origin | Priority | Coverage | Note |
|---|---|---|---|---|---|---|---|---|
| drupal | drupal | 8.5.0 | 16 | 61 | 0 | EXPLOITED · 9.8 | inventory: completed (1/1), advisories (drupal-security-advisories): completed (1/1) | |
| laravel | bookstack | 10.48.22 | 4 | 60 | 0 | CRITICAL | inventory: completed (147/147), advisories (dependency-lanes): completed (147/147) | |
| symfony | symfony-demo | 7.1.1 | 22 | 46 | 0 | HIGH · 8.8 | inventory: completed (118/118), advisories (dependency-lanes): completed (118/118), recipes: completed (110/110) | |
| wordpress | wp | 6.4.2 | 0 | 0 | 0 | — | inventory: completed (15/15), advisories (wordfence-v3): not-run (0/15, 15 not evaluated — CMS_PROVIDER_UNCONFIGURED), integrity (wordpress-checksums): completed (2960/2960) | Evaluation incomplete. |
| Priority / severity | Advisory ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
EXPLOITED 🛑 KEV · ransomware CRITICAL 9.8 |
CVE-2018-7600 probable |
composer: drupal/core 8.5.0 direct defined in: drupal/core/lib/Drupal.php |
CWE-20 Improper Input Validation |
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations. | 8.5.1 | drupal-security-advisoriesnvd | ||
Description
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbitrary code because of an issue affecting multiple subsystems with default or common module configurations. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 (CRITICAL) EXPLOITED · 98.4/100 100.0% prob · 100th pct Known exploited · added 2021-11-03 · due 2022-05-03 · ransomware 8.5.1 2018-03-28 2026-06-17 probable drupal-security-advisories+nvd Highly critical (Drupal) External links (21)
Exploit / PoC5 links
Vendor advisory2 links
Third-party advisory13 links
Affected CPE configurations (7)
Aliases
| ||||||||
EXPLOITED 🛑 KEV · ransomware CRITICAL 9.8 |
CVE-2018-7602 probable |
composer: drupal/core 8.5.0 direct defined in: drupal/core/lib/Drupal.php |
CWE-94 Code Injection |
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. | 8.5.3 | drupal-security-advisoriesnvd | ||
Description
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 (CRITICAL) EXPLOITED · 98.4/100 99.2% prob · 100th pct Known exploited · added 2022-04-13 · due 2022-05-04 · ransomware 8.5.3 2018-04-25 2026-08-13 probable drupal-security-advisories+nvd Highly critical (Drupal) External links (8)
Exploit / PoC3 links
Affected CPE configurations (6)
Aliases
| ||||||||
MEDIUM HIGH 7.5 |
CVE-2024-11941 probable |
composer: drupal/core 8.5.0 direct defined in: drupal/core/lib/Drupal.php |
CWE-835 Loop with Unreachable Exit Condition (Infinite Loop) |
A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8. | 10.1.8 | drupal-security-advisoriesnvd | ||
Description
A vulnerability in Drupal Core allows Excessive Allocation.This issue affects Drupal Core: from 10.2.0 before 10.2.2, from 10.1.0 before 10.1.8. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 7.5 (HIGH) MEDIUM · 68.1/100 0.5% prob · 40th pct 10.1.8 2024-01-17 2026-06-17 probable drupal-security-advisories+nvd Moderately critical (Drupal) External links (1)
Affected CPE configurations (2)
Aliases
| ||||||||
MEDIUM MEDIUM 6.1 |
CVE-2018-9861 probable |
composer: drupal/core 8.5.0 direct defined in: drupal/core/lib/Drupal.php |
CWE-79 Cross-site Scripting (XSS) |
Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote at… | 8.5.2 | drupal-security-advisoriesnvd | ||
Description
Cross-site scripting (XSS) vulnerability in the Enhanced Image (aka image2) plugin for CKEditor (in versions 4.5.10 through 4.9.1; fixed in 4.9.2), as used in Drupal 8 before 8.4.7 and 8.5.x before 8.5.2 and other products, allows remote attackers to inject arbitrary web script through a crafted IMG element. Weaknesses (CWE) (1)
Metadata
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 6.1 (MEDIUM) MEDIUM · 64.2/100 1.8% prob · 77th pct 8.5.2 2018-04-18 2026-06-17 probable drupal-security-advisories+nvd Moderately critical (Drupal) External links (4)
Affected CPE configurations (3)
Aliases
| ||||||||
MEDIUM MEDIUM 6.5 |
CVE-2023-31250 probable |
composer: drupal/core 8.5.0 direct defined in: drupal/core/lib/Drupal.php |
CWE-863 Incorrect Authorization |
The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gaining access to private files that they should not have access to. | 9.4.14 | drupal-security-advisoriesnvd | ||
Description
The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gaining access to private files that they should not have access to. Some sites may require configuration changes following this security release. Review the release notes for your Drupal version if you have issues accessing private files after updating. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N 6.5 (MEDIUM) MEDIUM · 60.9/100 0.5% prob · 44th pct 9.4.14 2023-04-19 2026-06-17 probable drupal-security-advisories+nvd Moderately critical (Drupal) External links (1)
Affected CPE configurations (4)
Aliases
| ||||||||
MEDIUM MEDIUM 5.9 |
CVE-2026-55803 probable |
composer: drupal/core 8.5.0 direct defined in: drupal/core/lib/Drupal.php |
CWE-915 Mass Assignment |
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. | 10.5.12 | drupal-security-advisoriesnvd | ||
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N 5.9 (MEDIUM) MEDIUM · 53/100 0.4% prob · 29th pct 10.5.12 2026-06-17 2026-07-16 probable drupal-security-advisories+nvd Critical (Drupal) External links (1)
Affected CPE configurations (4)
Aliases
| ||||||||
MEDIUM MEDIUM 5.9 |
CVE-2026-55804 probable |
composer: drupal/core 8.5.0 direct defined in: drupal/core/lib/Drupal.php |
CWE-915 Mass Assignment |
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. | 10.5.12 | drupal-security-advisoriesnvd | ||
Description
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal core allows Object Injection. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N 5.9 (MEDIUM) MEDIUM · 53/100 0.4% prob · 29th pct 10.5.12 2026-06-17 2026-07-16 probable drupal-security-advisories+nvd Moderately critical (Drupal) External links (1)
Affected CPE configurations (4)
Aliases
| ||||||||
MEDIUM MEDIUM 5.9 |
CVE-2026-55806 probable |
composer: drupal/core 8.5.0 direct defined in: drupal/core/lib/Drupal.php |
CWE-601 URL Redirection to Untrusted Site (Open Redirect) |
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. | 10.5.12 | drupal-security-advisoriesnvd | ||
Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Drupal Drupal core allows Content Spoofing. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H 5.9 (MEDIUM) MEDIUM · 52.7/100 0.3% prob · 27th pct 10.5.12 2026-06-17 2026-07-16 probable drupal-security-advisories+nvd Less critical (Drupal) External links (1)
Affected CPE configurations (4)
Aliases
| ||||||||
MEDIUM MEDIUM |
SA-CORE-2023-001 probable |
composer: drupal/core 8.5.0 direct defined in: drupal/core/lib/Drupal.php |
— | Drupal core - Moderately critical - Information Disclosure - SA-CORE-2023-001 | 9.4.10 | drupal-security-advisories | ||
Description
Drupal core - Moderately critical - Information Disclosure - SA-CORE-2023-001 Metadata
MEDIUM · 50/100 9.4.10 2023-01-18 probable drupal-security-advisories Moderately critical (Drupal) External links (1)
Aliases
| ||||||||
MEDIUM MEDIUM |
SA-CORE-2023-002 probable |
composer: drupal/core 8.5.0 direct defined in: drupal/core/lib/Drupal.php |
— | Drupal core - Moderately critical - Information Disclosure - SA-CORE-2023-002 | 9.4.12 | drupal-security-advisories | ||
Description
Drupal core - Moderately critical - Information Disclosure - SA-CORE-2023-002 Metadata
MEDIUM · 50/100 9.4.12 2023-03-15 probable drupal-security-advisories Moderately critical (Drupal) External links (1)
Aliases
| ||||||||
MEDIUM MEDIUM |
SA-CORE-2023-003 probable |
composer: drupal/core 8.5.0 direct defined in: drupal/core/lib/Drupal.php |
— | Drupal core - Moderately critical - Information Disclosure - SA-CORE-2023-003 | 9.4.12 | drupal-security-advisories | ||
Description
Drupal core - Moderately critical - Information Disclosure - SA-CORE-2023-003 Metadata
MEDIUM · 50/100 9.4.12 2023-03-15 probable drupal-security-advisories Moderately critical (Drupal) External links (1)
Aliases
| ||||||||
MEDIUM MEDIUM |
SA-CORE-2023-004 probable |
composer: drupal/core 8.5.0 direct defined in: drupal/core/lib/Drupal.php |
— | Drupal core - Moderately critical - Access bypass - SA-CORE-2023-004 | 9.4.12 | drupal-security-advisories | ||
Description
Drupal core - Moderately critical - Access bypass - SA-CORE-2023-004 Metadata
MEDIUM · 50/100 9.4.12 2023-03-15 probable drupal-security-advisories Moderately critical (Drupal) External links (1)
Aliases
| ||||||||
MEDIUM MEDIUM 5.4 |
CVE-2026-55808 probable |
composer: drupal/core 8.5.0 direct defined in: drupal/core/lib/Drupal.php |
CWE-79 Cross-site Scripting (XSS) |
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). | 10.5.12 | drupal-security-advisoriesnvd | ||
Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS). This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 5.4 (MEDIUM) MEDIUM · 47.2/100 0.3% prob · 20th pct 10.5.12 2026-06-17 2026-07-16 probable drupal-security-advisories+nvd Moderately critical (Drupal) External links (1)
Affected CPE configurations (4)
Aliases
| ||||||||
MEDIUM MEDIUM 5.4 |
CVE-2026-55805 probable |
composer: drupal/core 8.5.0 direct defined in: drupal/core/lib/Drupal.php |
CWE-79 Cross-site Scripting (XSS) |
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. | 10.6.13 | drupal-security-advisoriesnvd | ||
Description
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N 5.4 (MEDIUM) MEDIUM · 43.8/100 0.1% prob · 3th pct 10.6.13 2026-07-15 2026-08-28 probable drupal-security-advisories+nvd Moderately critical (Drupal) External links (1)
Aliases
| ||||||||
LOW MEDIUM 4.2 |
CVE-2026-15916 probable |
composer: drupal/core 8.5.0 direct defined in: drupal/core/lib/Drupal.php |
CWE-862 Missing Authorization |
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. | 10.6.13 | drupal-security-advisoriesnvd | ||
Description
Missing Authorization vulnerability in Drupal Drupal core allows Forceful Browsing. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N 4.2 (MEDIUM) LOW · 34.1/100 0.1% prob · 2th pct 10.6.13 2026-07-15 2026-08-28 probable drupal-security-advisories+nvd Moderately critical (Drupal) External links (1)
Aliases
| ||||||||
LOW LOW 3.1 |
CVE-2026-55807 probable |
composer: drupal/core 8.5.0 direct defined in: drupal/core/lib/Drupal.php |
CWE-918 Server-Side Request Forgery (SSRF) |
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. | 10.5.12 | drupal-security-advisoriesnvd | ||
Description
Server-Side Request Forgery (SSRF) vulnerability in Drupal Drupal core allows Server Side Request Forgery. This issue affects Drupal core versions: from 0.0.0 to 10.5.12, from 10.6.0 to 10.6.11, from 11.2.0 to 11.2.14, from 11.3.0 to 11.3.12, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N 3.1 (LOW) LOW · 27.4/100 0.2% prob · 13th pct 10.5.12 2026-06-17 2026-07-16 probable drupal-security-advisories+nvd Moderately critical (Drupal) External links (1)
Affected CPE configurations (4)
Aliases
| ||||||||
| Priority / severity | Advisory ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
CRITICAL CRITICAL 9.8 |
CVE-2019-10910 exact |
composer: symfony/dependency-injection 3.4.4 direct defined in: drupal/drupal |
CWE-89 SQL Injection |
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. | 3.4.26 | nvdosvpackagist | ||
Description
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code execution. This is related to symfony/dependency-injection. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 (CRITICAL) CRITICAL · 97/100 5.9% prob · 93th pct 3.4.26 2019-04-16 2025-05-29 exact nvd+osv+packagist External links (4)
Patch / Commit1 link
Affected CPE configurations (7)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
CRITICAL CRITICAL 9.8 |
CVE-2019-10913 exact |
composer: symfony/http-foundation 3.4.4 direct defined in: drupal/drupal |
CWE-79 Cross-site Scripting (XSS) CWE-89SQL Injection |
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly c… | 3.4.26 | nvdosvpackagist | ||
Description
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted input, but they are not validated, possibly causing SQL injection or XSS. This is related to symfony/http-foundation. Metadata
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 (CRITICAL) CRITICAL · 94.1/100 1.9% prob · 78th pct 3.4.26 2019-04-16 2023-11-08 exact nvd+osv+packagist External links (3)
Patch / Commit1 link
Third-party advisory1 link
Affected CPE configurations (5)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH CRITICAL 8.7 |
CVE-2026-46633 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
CWE-94 Code Injection |
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to termin… | 2.0.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.7 (CRITICAL) HIGH · 79.9/100 0.7% prob · 51th pct 2.0.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (5)
Patch / Commit3 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH LOW 8.7 |
CVE-2026-45304 exact |
composer: symfony/yaml 3.4.5 direct defined in: drupal/drupal |
CWE-776 XML Entity Expansion (XEE / Billion Laughs) |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 4.0.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser resolved YAML collection aliases recursively, allowing a small untrusted YAML input to expand into a multi-gigabyte structure and exhaust memory. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.7 (LOW) HIGH · 79.8/100 0.7% prob · 51th pct 4.0.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit6 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH LOW 8.7 |
CVE-2026-45305 exact |
composer: symfony/yaml 3.4.5 direct defined in: drupal/drupal |
CWE-1333 Inefficient Regular Expression Complexity (ReDoS) |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 4.0.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() used regular expressions with overlapping quantifiers for YAML directive, comment, and document marker cleanup, allowing crafted input to make parsing hang for an arbitrarily long time. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.7 (LOW) HIGH · 79.8/100 0.7% prob · 51th pct 4.0.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit6 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH MEDIUM 8.5 |
CVE-2024-45411 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
CWE-693 Protection Mechanism Failure |
Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0. | 1.44.7 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H 8.5 (MEDIUM) HIGH · 79.3/100 0.8% prob · 57th pct 1.44.7 2024-09-09 2024-10-10 exact nvd+osv+packagist External links (6)
Patch / Commit3 links
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH HIGH 8.1 |
CVE-2019-18887 exact |
composer: symfony/http-kernel 3.4.4 direct defined in: drupal/drupal |
CWE-203 Observable Discrepancy |
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel. | 3.4.35 | nvdosvpackagist | ||
Description
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 8.1 (HIGH) HIGH · 78.8/100 1.3% prob · 70th pct 3.4.35 2019-11-13 2024-02-20 exact nvd+osv+packagist External links (7)
Vendor advisory1 link
Mailing list3 links
Affected CPE configurations (6)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH HIGH 8.0 |
CVE-2022-29248 exact |
composer: guzzlehttp/guzzle 6.3.0 direct defined in: drupal/drupal |
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE-565Reliance on Cookies without Validation and Integrity Checking |
Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. | 6.5.6 | nvdosvpackagist | ||
Description
Guzzle is a PHP HTTP client. Guzzle prior to versions 6.5.6 and 7.4.3 contains a vulnerability with the cookie middleware. The vulnerability is that it is not checked if the cookie domain equals the domain of the server which sets the cookie via the Set-Cookie header, allowing a malicious server to set cookies for unrelated domains. The cookie middleware is disabled by default, so most library consumers will not be affected by this issue. Only those who manually add the cookie middleware to the handler stack or construct the client with ['cookies' => true] are affected. Moreover, those who do not use the same Guzzle client to call multiple domains and have disabled redirect forwarding are not affected by this vulnerability. Guzzle versions 6.5.6 and 7.4.3 contain a patch for this issue. As a workaround, turn off the cookie middleware. Weaknesses (CWE) (2)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N 8.0 (HIGH) HIGH · 78/100 1.3% prob · 70th pct 6.5.6 2022-05-25 2025-12-10 exact nvd+osv+packagist External links (5)
Patch / Commit3 links
Affected CPE configurations (5)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH HIGH 7.7 |
CVE-2022-31090 exact |
composer: guzzlehttp/guzzle 6.3.0 direct defined in: drupal/drupal |
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE-212Improper Removal of Sensitive Information Before Storage or Transfer |
Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. | 6.5.8 | nvdosvpackagist | ||
Description
Guzzle, an extensible PHP HTTP client. `Authorization` headers on requests are sensitive information. In affected versions when using our Curl handler, it is possible to use the `CURLOPT_HTTPAUTH` option to specify an `Authorization` header. On making a request which responds with a redirect to a URI with a different origin (change in host, scheme or port), if we choose to follow it, we should remove the `CURLOPT_HTTPAUTH` option before continuing, stopping curl from appending the `Authorization` header to the new request. Affected Guzzle 7 users should upgrade to Guzzle 7.4.5 as soon as possible. Affected users using any earlier series of Guzzle should upgrade to Guzzle 6.5.8 or 7.4.5. Note that a partial fix was implemented in Guzzle 7.4.2, where a change in host would trigger removal of the curl-added Authorization header, however this earlier fix did not cover change in scheme or change in port. If you do not require or expect redirects to be followed, one should simply disable redirects all together. Alternatively, one can specify to use the Guzzle steam handler backend, rather than curl. Weaknesses (CWE) (2)
Metadata
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N 7.7 (HIGH) HIGH · 77.4/100 1.9% prob · 79th pct 6.5.8 2022-06-20 2024-02-16 exact nvd+osv+packagist External links (4)
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH HIGH 7.5 |
CVE-2022-39261 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
CWE-22 Path Traversal |
Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. | 1.44.7 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Versions 1.x prior to 1.44.7, 2.x prior to 2.15.3, and 3.x prior to 3.4.3 encounter an issue when the filesystem loader loads templates for which the name is a user input. It is possible to use the `source` or `include` statement to read arbitrary files from outside the templates' directory when using a namespace like `@somewhere/../some.file`. In such a case, validation is bypassed. Versions 1.44.7, 2.15.3, and 3.4.3 contain a fix for validation of such template names. There are no known workarounds aside from upgrading. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 7.5 (HIGH) HIGH · 76.9/100 2.6% prob · 84th pct 1.44.7 2022-09-28 2025-12-10 exact nvd+osv+packagist External links (12)
Patch / Commit2 links
Security advisory1 link
Third-party advisory3 links
Mailing list6 links
Affected CPE configurations (10)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH HIGH 7.5 |
CVE-2019-18888 exact |
composer: symfony/http-foundation 3.4.4 direct defined in: drupal/drupal |
CWE-88 Argument Injection |
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. | 3.4.35 | nvdosvpackagist | ||
Description
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. This is related to symfony/http-foundation (and symfony/mime in 4.3.x). Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N 7.5 (HIGH) HIGH · 76.4/100 2.2% prob · 82th pct 3.4.35 2019-11-13 2024-02-20 exact nvd+osv+packagist External links (7)
Vendor advisory1 link
Mailing list3 links
Affected CPE configurations (6)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH HIGH 7.7 |
CVE-2022-31091 exact |
composer: guzzlehttp/guzzle 6.3.0 direct defined in: drupal/drupal |
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor |
Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. | 6.5.8 | nvdosvpackagist | ||
Description
Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In affected versions on making a request which responds with a redirect to a URI with a different port, if we choose to follow it, we should remove the `Authorization` and `Cookie` headers from the request, before containing. Previously, we would only consider a change in host or scheme. Affected Guzzle 7 users should upgrade to Guzzle 7.4.5 as soon as possible. Affected users using any earlier series of Guzzle should upgrade to Guzzle 6.5.8 or 7.4.5. Note that a partial fix was implemented in Guzzle 7.4.2, where a change in host would trigger removal of the curl-added Authorization header, however this earlier fix did not cover change in scheme or change in port. An alternative approach would be to use your own redirect middleware, rather than ours, if you are unable to upgrade. If you do not require or expect redirects to be followed, one should simply disable redirects all together. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N 7.7 (HIGH) HIGH · 76.3/100 1.5% prob · 74th pct 6.5.8 2022-06-20 2023-11-08 exact nvd+osv+packagist External links (4)
Patch / Commit1 link
Third-party advisory2 links
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH HIGH 7.5 |
CVE-2022-31042 exact |
composer: guzzlehttp/guzzle 6.3.0 direct defined in: drupal/drupal |
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE-212Improper Removal of Sensitive Information Before Storage or Transfer |
Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. | 6.5.7 | nvdosvpackagist | ||
Description
Guzzle is an open source PHP HTTP client. In affected versions the `Cookie` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, or on making a request to a server which responds with a redirect to a a URI to a different host, we should not forward the `Cookie` header on. Prior to this fix, only cookies that were managed by our cookie middleware would be safely removed, and any `Cookie` header manually added to the initial request would not be stripped. We now always strip it, and allow the cookie middleware to re-add any cookies that it deems should be there. Affected Guzzle 7 users should upgrade to Guzzle 7.4.4 as soon as possible. Affected users using any earlier series of Guzzle should upgrade to Guzzle 6.5.7 or 7.4.4. Users unable to upgrade may consider an alternative approach to use your own redirect middleware, rather than ours. If you do not require or expect redirects to be followed, one should simply disable redirects all together. Weaknesses (CWE) (2)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 7.5 (HIGH) HIGH · 75.8/100 1.9% prob · 79th pct 6.5.7 2022-06-09 2025-12-10 exact nvd+osv+packagist External links (5)
Patch / Commit2 links
Affected CPE configurations (8)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH HIGH 8.7 |
CVE-2026-46636 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
CWE-1336 | Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. | 2.0.0 | nvdpackagist | ||
Description
Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup is not final, so subclasses inherit the bypass. An application that passes an object of a Markup-derived class into a sandboxed template (typically to mark a chunk of HTML as safe) inadvertently exposes every public method of that subclass to template authors, regardless of the configured allowedMethods list. This issue has been patched in version 3.27.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.7 (HIGH) HIGH · 75.5/100 0.4% prob · 30th pct 2.0.0 2026-05-27 2026-09-08 exact nvd+packagist External links (5)
Vendor advisory2 links
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH LOW 8.2 |
CVE-2026-45133 exact |
composer: symfony/yaml 3.4.5 direct defined in: drupal/drupal |
CWE-674 Uncontrolled Recursion CWE-776XML Entity Expansion (XEE / Billion Laughs) +1 |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 4.0.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attacker-controlled input, deeply nested mappings or sequences cause both the block-level (Parser::parseBlock()) and inline (Inline::parseSequence() / Inline::parseMapping()) parsers to recurse without a depth limit. A crafted document exhausts the PHP stack and crashes the worker. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (3)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.2 (LOW) HIGH · 75.4/100 0.6% prob · 49th pct 4.0.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH HIGH |
GHSA-f6p5-76fp-m248 exact |
composer: zendframework/zend-diactoros 1.4.1 direct defined in: drupal/drupal |
— | URL Rewrite vulnerability in multiple zendframework components zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each co… | 1.8.4 | osvpackagist | ||
Description
URL Rewrite vulnerability in multiple zendframework components
zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL rewrite exploit. In each case, marshaling a request URI includes logic that introspects HTTP request headers that are specific to a given server-side URL rewrite mechanism.
When these headers are present on systems not running the specific URL rewriting mechanism, the logic would still trigger, allowing a malicious client or proxy to emulate the headers to request arbitrary content. Metadata
External links (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH HIGH |
GHSA-f6p5-76fp-m248 exact |
composer: zendframework/zend-feed 2.7.0 direct defined in: drupal/drupal |
— | URL Rewrite vulnerability in multiple zendframework components zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each co… | 2.10.3 | osvpackagist | ||
Description
URL Rewrite vulnerability in multiple zendframework components
zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL rewrite exploit. In each case, marshaling a request URI includes logic that introspects HTTP request headers that are specific to a given server-side URL rewrite mechanism.
When these headers are present on systems not running the specific URL rewriting mechanism, the logic would still trigger, allowing a malicious client or proxy to emulate the headers to request arbitrary content. Metadata
External links (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH HIGH 7.5 |
GHSA-jmmp-vh96-78rm exact |
composer: zendframework/zend-feed 2.7.0 direct defined in: drupal/drupal |
— | Zend-Feed URL Rewrite vulnerability zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL rewri… | 2.10.3 | osvpackagist | ||
Description
Zend-Feed URL Rewrite vulnerability
zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL rewrite exploit. In each case, marshaling a request URI includes logic that introspects HTTP request headers that are specific to a given server-side URL rewrite mechanism.
When these headers are present on systems not running the specific URL rewriting mechanism, the logic would still trigger, allowing a malicious client or proxy to emulate the headers to request arbitrary content. Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N 7.5 (HIGH) HIGH · 75/100 2.10.3 2024-06-07 2024-12-04 exact osv+packagist External links (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH HIGH 8.4 |
CVE-2024-51736 exact |
composer: symfony/process 3.4.4 direct defined in: drupal/drupal |
CWE-77 Command Injection |
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. | 4.0.0 | nvdosvpackagist | ||
Description
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing command arguments, leading to possible hijacking. This issue has been addressed in release versions 5.4.46, 6.4.14, and 7.1.7. Users are advised to upgrade. There are no known workarounds for this vulnerability. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N 8.4 (HIGH) HIGH · 74.5/100 0.4% prob · 36th pct 4.0.0 2024-11-05 2026-09-10 exact nvd+osv+packagist External links (2)
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH HIGH 7.3 |
CVE-2025-64500 exact |
composer: symfony/http-foundation 3.4.4 direct defined in: drupal/drupal |
CWE-647 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. | 4.0.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the `Request` class now ensures that URL paths always start with a `/`. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L 7.3 (HIGH) HIGH · 72.3/100 1.3% prob · 70th pct 4.0.0 2025-11-12 2026-09-10 exact nvd+osv+packagist External links (5)
Patch / Commit1 link
Third-party advisory3 links
Affected CPE configurations (6)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH MEDIUM 6.5 |
CVE-2018-14773 exact |
composer: symfony/http-foundation 3.4.4 direct defined in: drupal/drupal |
— | An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. | 3.4.14 | nvdosvpackagist | ||
Description
An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 through 4.1.2. It arises from support for a (legacy) IIS header that lets users override the path in the request URL via the X-Original-URL or X-Rewrite-URL HTTP request header. These headers are designed for IIS support, but it's not verified that the server is in fact running IIS, which means anybody who can send these requests to an application can trigger this. This affects \Symfony\Component\HttpFoundation\Request::prepareRequestUri() where X-Original-URL and X_REWRITE_URL are both used. The fix drops support for these methods so that they cannot be used as attack vectors such as web cache poisoning. Metadata
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N 6.5 (MEDIUM) HIGH · 71.8/100 58.1% prob · 99th pct 3.4.14 2018-08-01 2024-02-16 exact nvd+osv+packagist External links (8)
Patch / Commit3 links
Affected CPE configurations (9)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM HIGH 7.1 |
CVE-2026-46627 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
CWE-400 Uncontrolled Resource Consumption (DoS) |
Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustio… | 2.0.0 | nvdpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource exhaustion. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.1 (HIGH) MEDIUM · 65.7/100 0.5% prob · 45th pct 2.0.0 2026-05-20 2026-07-16 exact nvd+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 5.9 |
CVE-2022-24894 exact |
composer: symfony/http-kernel 3.4.4 direct defined in: drupal/drupal |
CWE-285 Improper Authorization |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers) and returns them to the clients. | 4.0.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The Symfony HTTP cache system, acts as a reverse proxy: It caches entire responses (including headers) and returns them to the clients. In a recent change in the `AbstractSessionListener`, the response might contain a `Set-Cookie` header. If the Symfony HTTP cache system is enabled, this response might bill stored and return to the next clients. An attacker can use this vulnerability to retrieve the victim's session. This issue has been patched and is available for branch 4.4. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:L 5.9 (MEDIUM) MEDIUM · 65.2/100 4.0% prob · 90th pct 4.0.0 2023-02-01 2025-02-13 exact nvd+osv+packagist External links (4)
Patch / Commit1 link
Third-party advisory1 link
Affected CPE configurations (5)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 7.1 |
CVE-2026-48806 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
CWE-693 Protection Mechanism Failure CWE-863Incorrect Authorization |
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxE… | 2.0.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxExtension::ensureToStringAllowed(). This issue is fixed in version 3.27.0. Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.1 (MEDIUM) MEDIUM · 64/100 0.4% prob · 36th pct 2.0.0 2026-05-27 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Security advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM HIGH 7.1 |
CVE-2026-47732 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
CWE-863 Incorrect Authorization |
Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invo… | 2.0.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in the render context through conditional expressions, comparison operators, tests, template-loading tags, dynamic attribute names, spread arguments, the do tag, and the .. range operator. This issue is fixed in version 3.26.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.1 (HIGH) MEDIUM · 63.6/100 0.4% prob · 34th pct 2.0.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 7.1 |
CVE-2026-48807 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
CWE-693 Protection Mechanism Failure CWE-863Incorrect Authorization |
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringab… | 2.0.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0. Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.1 (MEDIUM) MEDIUM · 62.9/100 0.4% prob · 31th pct 2.0.0 2026-05-27 2026-09-10 exact nvd+osv+packagist External links (3)
Security advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 5.9 |
CVE-2018-11386 exact |
composer: symfony/http-foundation 3.4.4 direct defined in: drupal/drupal |
CWE-613 Insufficient Session Expiration |
An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. | 3.4.11 | nvdosvpackagist | ||
Description
An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. The PDOSessionHandler class allows storing sessions on a PDO connection. Under some configurations and with a well-crafted payload, it was possible to do a denial of service on a Symfony application without too much resources. Weaknesses (CWE) (1)
Metadata
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H 5.9 (MEDIUM) MEDIUM · 62.2/100 1.6% prob · 75th pct 3.4.11 2018-05-25 2024-02-17 exact nvd+osv+packagist External links (6)
Vendor advisory1 link
Mailing list3 links
Affected CPE configurations (6)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM HIGH 7.2 |
CVE-2026-69246 exact |
composer: guzzlehttp/guzzle 6.3.0 direct defined in: drupal/drupal |
CWE-180 CWE-436 Interpretation Conflict +2 |
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. | 7.15.2 | nvdosvpackagist | ||
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same through fopen(). libcurl then parses the authority itself, percent-decoding it and, on an IDN-capable build, applying IDNA mapping, and uses the result to resolve, connect, name the TLS peer and address a proxy CONNECT, while the supplied Host suppresses the aligned one libcurl would have generated. For a URI host written as 127.0.0.%31, filter_var() rejects the host as an IP literal, yet libcurl decodes it to 127.0.0.1 and reaches loopback with no DNS lookup while the server receives Host: 127.0.0.%31. An attacker who influences a fetched URI can therefore reach a host the application's checks excluded and read whatever the host exposes of the response. The same divergence moves Guzzle's own decisions onto a spelling the transport does not use: no_proxy selects proxy routing from the literal host, and RedirectMiddleware decides from it whether to strip Authorization and Cookie. Exploitation requires the application to build a request URI from untrusted input and to make a host decision before handing it to Guzzle. This issue is fixed in versions 7.15.2 and 8.0.1. Weaknesses (CWE) (4)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N 7.2 (HIGH) MEDIUM · 60/100 0.2% prob · 12th pct 7.15.2 2026-08-03 2026-09-10 exact nvd+osv+packagist External links (8)
Patch / Commit6 links
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 5.3 |
CVE-2022-24775 exact |
composer: guzzlehttp/psr7 1.4.2 direct defined in: drupal/drupal |
CWE-20 Improper Input Validation |
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. | 1.8.4 | nvdosvpackagist | ||
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library. Versions prior to 1.8.4 and 2.1.1 are vulnerable to improper header parsing. An attacker could sneak in a new line character and pass untrusted values. The issue is patched in 1.8.4 and 2.1.1. There are currently no known workarounds. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N 5.3 (MEDIUM) MEDIUM · 59.2/100 2.5% prob · 84th pct 1.8.4 2022-03-20 2026-02-04 exact nvd+osv+packagist External links (4)
Patch / Commit3 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 6.0 |
CVE-2026-46638 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
CWE-693 Protection Mechanism Failure |
Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbox without re-invoking checkSecurity(), allowing the cached template to use tags, filters, a… | 2.0.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbox without re-invoking checkSecurity(), allowing the cached template to use tags, filters, and functions that should have been denied by SecurityPolicy::checkSecurity(). This issue is fixed in version 3.26.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.0 (MEDIUM) MEDIUM · 56/100 0.5% prob · 40th pct 2.0.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 5.3 |
CVE-2023-29197 exact |
composer: guzzlehttp/psr7 1.4.2 direct defined in: drupal/drupal |
CWE-436 Interpretation Conflict |
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. | 1.9.1 | nvdosvpackagist | ||
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. While the specification states that \r\n\r\n is used to terminate the header list, many servers in the wild will also accept \n\n. This is a follow-up to CVE-2022-24775 where the fix was incomplete. The issue has been patched in versions 1.9.1 and 2.4.5. There are no known workarounds for this vulnerability. Users are advised to upgrade. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N 5.3 (MEDIUM) MEDIUM · 55.9/100 1.2% prob · 67th pct 1.9.1 2023-04-17 2026-02-04 exact nvd+osv+packagist External links (7)
Third-party advisory2 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 6.0 |
CVE-2026-48808 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
CWE-693 Protection Mechanism Failure CWE-863Incorrect Authorization |
Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are… | 2.0.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read public or magic properties not allowed by the sandbox policy. This issue is fixed in version 3.27.0. Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.0 (MEDIUM) MEDIUM · 54.9/100 0.4% prob · 35th pct 2.0.0 2026-05-27 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Security advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM HIGH 6.0 |
CVE-2026-49981 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
CWE-693 Protection Mechanism Failure CWE-863Incorrect Authorization |
Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allow… | — | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0. Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.0 (HIGH) MEDIUM · 54/100 0.4% prob · 30th pct 2026-07-01 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 6.3 |
CVE-2026-24739 exact |
composer: symfony/process 3.4.4 direct defined in: drupal/drupal |
CWE-88 Argument Injection |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 5.4.51 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to versions 5.4.51, 6.4.33, 7.3.11, 7.4.5, and 8.0.5, the Symfony Process component did not correctly treat some characters (notably `=`) as “special” when escaping arguments on Windows. When PHP is executed from an MSYS2-based environment (e.g. Git Bash) and Symfony Process spawns native Windows executables, MSYS2’s argument/path conversion can mis-handle unquoted arguments containing these characters. This can cause the spawned process to receive corrupted/truncated arguments compared to what Symfony intended. If an application (or tooling such as Composer scripts) uses Symfony Process to invoke file-management commands (e.g. `rmdir`, `del`, etc.) with a path argument containing `=`, the MSYS2 conversion layer may alter the argument at runtime. In affected setups this can result in operations being performed on an unintended path, up to and including deletion of the contents of a broader directory or drive. The issue is particularly relevant when untrusted input can influence process arguments (directly or indirectly, e.g. via repository paths, extracted archive paths, temporary directories, or user-controlled configuration). Versions 5.4.51, 6.4.33, 7.3.11, 7.4.5, and 8.0.5 contains a patch for the issue. Some workarounds are available. Avoid running PHP/one's own tooling from MSYS2-based shells on Windows; prefer cmd.exe or PowerShell for workflows that spawn native executables. Avoid passing paths containing `=` (and similar MSYS2-sensitive characters) to Symfony Process when operating under Git Bash/MSYS2. Where applicable, configure MSYS2 to disable or restrict argument conversion (e.g. via `MSYS2_ARG_CONV_EXCL`), understanding this may affect other tooling behavior. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H 6.3 (MEDIUM) MEDIUM · 52.8/100 0.2% prob · 12th pct 5.4.51 2026-01-28 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Affected CPE configurations (5)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 6.5 |
CVE-2026-69245 exact |
composer: guzzlehttp/guzzle 6.3.0 direct defined in: drupal/drupal |
CWE-180 CWE-346 Origin Validation Error +1 |
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, … | 7.15.2 | nvdosvpackagist | ||
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, and the decision comes from the domain's own text, so two spellings a transport reads as an address keep subdomain scope. Hexadecimal and mixed-base forms such as 0x7f000001 and 0177.0.0.0x1 go unrecognized while libcurl 8.21.0 reads both as 127.0.0.1. A percent-escaped Domain keeps that scope on both branches because percent-decoding sits above numeric parsing, so 192.168.0.%31 and 127.0.0.1%2e are registered names in the URI grammar rather than address literals, and no numeric rule in any base classifies them, while libcurl decodes the host before resolving and reads them as 192.168.0.1 and 127.0.0.1. A cookie stored for Domain=0x7f000001 is placed in the Cookie header of a request to evil.0x7f000001, disclosing a session identifier or token to a host that is not that address, and a response from evil.0x7f000001 setting Domain=0x7f000001 is accepted into the jar and replayed to the address, so a server answering for the look-alike name can fix a session or set application state. Exploitation requires the application to enable cookie support, address an origin by one of these spellings, and contact a host whose name ends in that spelling. This issue is fixed in versions 7.15.2 and 8.0.1. Weaknesses (CWE) (3)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N 6.5 (MEDIUM) MEDIUM · 52.7/100 0.1% prob · 3th pct 7.15.2 2026-08-03 2026-09-10 exact nvd+osv+packagist External links (8)
Patch / Commit6 links
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM LOW 5.3 |
CVE-2026-48805 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
CWE-693 Protection Mechanism Failure |
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such … | 2.0.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such as twig_array_some(), twig_array_every(), and twig_check_arrow_in_sandbox() to bypass sandbox callable restrictions. This issue is fixed in version 3.27.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.3 (LOW) MEDIUM · 50.6/100 0.5% prob · 41th pct 2.0.0 2026-05-27 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Security advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 5.9 |
CVE-2026-67354 exact |
composer: guzzlehttp/guzzle 6.3.0 direct defined in: drupal/drupal |
CWE-201 | guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. | 7.15.1 | nvdosvpackagist | ||
Description
guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generated Referer header when following a same-scheme redirect (e.g., HTTPS to HTTPS). An attacker who controls the redirect destination can read this fragment from the incoming Referer header, potentially disclosing one-time login secrets, access tokens, state values, or other sensitive client data to a server never meant to receive it. The referer setting is disabled by default. Fixed in 7.15.1, which strips the fragment before generating the Referer value. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.9 (MEDIUM) MEDIUM · 50.6/100 0.3% prob · 17th pct 7.15.1 2026-07-20 2026-09-10 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 5.9 |
CVE-2026-67355 exact |
composer: guzzlehttp/guzzle 6.3.0 direct defined in: drupal/drupal |
CWE-201 | guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. | 7.15.1 | nvdosvpackagist | ||
Description
guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.9 (MEDIUM) MEDIUM · 50/100 0.2% prob · 14th pct 7.15.1 2026-07-20 2026-09-10 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 5.8 |
CVE-2026-55767 exact |
composer: guzzlehttp/guzzle 6.3.0 direct defined in: drupal/drupal |
CWE-346 Origin Validation Error CWE-1286 |
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. | 7.12.1 | nvdosvpackagist | ||
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the cookie domain, normalizing dot-only values to the empty string; SetCookie::validate() only rejected a strictly empty domain, so these cookies could be stored and the empty normalized domain was treated as matching any request host. An attacker-controlled origin that an application requests with a shared cookie jar can therefore set a cookie that Guzzle later sends to unrelated hosts using the same jar. This may allow cookie injection or session fixation against downstream services, depending on how those services interpret the injected cookie. This vulnerability is fixed in 7.12.1. Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N 5.8 (MEDIUM) MEDIUM · 48.7/100 0.2% prob · 12th pct 7.12.1 2026-06-18 2026-09-10 exact nvd+osv+packagist External links (5)
Patch / Commit3 links
Security advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 5.9 |
CVE-2026-55568 exact |
composer: guzzlehttp/guzzle 6.3.0 direct defined in: drupal/drupal |
CWE-311 Missing Encryption of Sensitive Data CWE-319Cleartext Transmission of Sensitive Information +1 |
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. | 7.12.1 | nvdosvpackagist | ||
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Proxy authentication credentials (the Proxy-Authorization header, proxy userinfo in the proxy URL, or CURLOPT_PROXYUSERPWD) are sent without encryption, and the CONNECT target host and port for tunneled HTTPS requests are exposed. The built-in cURL handlers (GuzzleHttp\Handler\CurlHandler and GuzzleHttp\Handler\CurlMultiHandler, used by default whenever the PHP cURL extension is available) accept an https:// proxy. libcurl older than 7.50.2 silently treats an https:// proxy as a plaintext http:// proxy. The TLS connection to the proxy is never established, and the proxy leg is cleartext with no error or warning. An application is affected when it sends requests through one of the built-in cURL handlers, configures an https:// proxy expecting the proxy connection itself to be encrypted, and runs with libcurl older than 7.50.2. This vulnerability is fixed in 7.12.1. Weaknesses (CWE) (3)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N 5.9 (MEDIUM) MEDIUM · 48.1/100 0.1% prob · 4th pct 7.12.1 2026-06-18 2026-09-10 exact nvd+osv+packagist External links (1)
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM LOW 5.3 |
CVE-2026-46635 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
CWE-863 Incorrect Authorization |
Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties without reaching CoreExtension::getAttribute() or SandboxExtension::checkPropertyAll… | 2.0.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties without reaching CoreExtension::getAttribute() or SandboxExtension::checkPropertyAllowed(), allowing an untrusted template author with column in allowedFilters to read properties that are not in the sandbox allowlist. This issue is fixed in version 3.26.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.3 (LOW) MEDIUM · 47.7/100 0.3% prob · 26th pct 2.0.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 4.7 |
GHSA-fq4p-86hh-42v9 exact |
composer: zendframework/zend-diactoros 1.4.1 direct defined in: drupal/drupal |
— | Zend-Diactoros URL Rewrite vulnerability zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL … | 1.8.4 | osvpackagist | ||
Description
Zend-Diactoros URL Rewrite vulnerability
zend-diactoros (and, by extension, Expressive), zend-http (and, by extension, Zend Framework MVC projects), and zend-feed (specifically, its PubSubHubbub sub-component) each contain a potential URL rewrite exploit. In each case, marshaling a request URI includes logic that introspects HTTP request headers that are specific to a given server-side URL rewrite mechanism.
When these headers are present on systems not running the specific URL rewriting mechanism, the logic would still trigger, allowing a malicious client or proxy to emulate the headers to request arbitrary content. Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N 4.7 (MEDIUM) MEDIUM · 47/100 1.8.4 2024-06-07 2024-12-04 exact osv+packagist External links (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 5.1 |
CVE-2026-48784 exact |
composer: symfony/routing 3.4.4 direct defined in: drupal/drupal |
CWE-172 CWE-601 URL Redirection to Untrusted Site (Open Redirect) |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 4.0.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing attacker-controlled route parameters to generate URLs that collapse to a different path under RFC 3986 normalization. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13. Weaknesses (CWE) (2)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.1 (MEDIUM) MEDIUM · 46.5/100 0.3% prob · 29th pct 4.0.0 2026-05-26 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 5.3 |
CVE-2026-67353 exact |
composer: guzzlehttp/guzzle 6.3.0 direct defined in: drupal/drupal |
CWE-770 Allocation of Resources Without Limits or Throttling |
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. | 7.15.1 | nvdosvpackagist | ||
Description
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.3 (MEDIUM) MEDIUM · 45.7/100 0.2% prob · 16th pct 7.15.1 2026-07-20 2026-09-10 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM LOW 5.1 |
CVE-2026-46628 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
CWE-116 Improper Encoding or Escaping of Output |
Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. | 2.0.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. This issue is fixed in version 3.26.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.1 (LOW) MEDIUM · 45.3/100 0.3% prob · 22th pct 2.0.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 5.3 |
CVE-2026-67339 exact |
composer: guzzlehttp/guzzle 6.3.0 direct defined in: drupal/drupal |
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor |
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. | 7.14.2 | nvdosvpackagist | ||
Description
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.3 (MEDIUM) MEDIUM · 45.3/100 0.2% prob · 14th pct 7.14.2 2026-07-20 2026-09-10 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 5.3 |
CVE-2026-48998 exact |
composer: guzzlehttp/psr7 1.4.2 direct defined in: drupal/drupal |
CWE-20 Improper Input Validation CWE-918Server-Side Request Forgery (SSRF) |
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server variables. | 2.10.2 | nvdosvpackagist | ||
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server variables. An attacker can provide a malformed Host header containing URI authority delimiters, such as `trusted.example@evil.example`. When the Host value is used to construct a URI, the malformed value can be reinterpreted as URI userinfo and host. This can cause the PSR-7 request URI host to differ from the original Host header value. Applications are affected if they parse attacker-controlled raw HTTP requests with `GuzzleHttp\Psr7\Message::parseRequest()` or the legacy 1.x `GuzzleHttp\Psr7\parse_request()` function, or if they build server requests from attacker-controlled server variables, then rely on the resulting URI host for routing, allow-list checks, or forwarding decisions. In affected forwarding or gateway scenarios, this may cause requests or credentials to be sent to an unintended host. The issue is patched in `2.10.2`. `1.x` is end-of-life and will not receive a patch. Some workarounds are available. Validate the `Host` header as `uri-host [ ":" port ]` before calling `Message::parseRequest()` or legacy `parse_request()` on untrusted HTTP request data, or before deriving routing and forwarding decisions from a parsed request URI. Reject Host values containing userinfo, path, query, or fragment delimiters. Weaknesses (CWE) (2)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N 5.3 (MEDIUM) MEDIUM · 44.4/100 0.2% prob · 10th pct 2.10.2 2026-05-25 2026-09-10 exact nvd+osv+packagist External links (1)
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 5.3 |
CVE-2026-49214 exact |
composer: guzzlehttp/psr7 1.4.2 direct defined in: drupal/drupal |
CWE-20 Improper Input Validation CWE-93CRLF Injection +1 |
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. | 2.10.2 | nvdosvpackagist | ||
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an application accepts a user-controlled URL. Second, the URL is used to construct a PSR-7 `Uri` or `Request`. Third, the host component contains CRLF or another header-unsafe character. Fourth, the host is copied into the PSR-7 `Host` header when no explicit `Host` header is provided. Finally, the request is serialized or sent by an HTTP client that does not independently reject the malformed host. In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing `"\r\nX-Injected: yes"` can cause the generated `Host` header to span multiple HTTP header lines. Applications are affected when they use user-controlled URLs for outbound HTTP requests, URL forwarding, proxying, crawling, webhook delivery, or similar request-dispatch flows. In deployments involving HTTP/1.1 connection reuse, proxies, gateways, or load balancers, this malformed request may also contribute to request smuggling or cache poisoning, depending on how downstream components parse the request. The issue is patched in `2.10.2` and later. `1.x` is end-of-life and will not receive a patch. As a workaround, validate and reject all untrusted URI strings before constructing PSR-7 `Uri` or `Request` instances. Reject input containing ASCII control characters, whitespace, or DEL, including CRLF, tab, space, NUL, or DEL characters. Applications that forward requests should also ensure the final HTTP client or serializer rejects invalid URI and header data before writing requests to the network. Weaknesses (CWE) (3)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N 5.3 (MEDIUM) MEDIUM · 44.2/100 0.2% prob · 9th pct 2.10.2 2026-05-25 2026-09-10 exact nvd+osv+packagist External links (1)
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM LOW 3.7 |
CVE-2019-9942 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
— | A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place. | 1.38.0 | nvdosvpackagist | ||
Description
A sandbox information disclosure exists in Twig before 1.38.0 and 2.x before 2.7.0 because, under some circumstances, it is possible to call the __toString() method on an object even if not allowed by the security policy in place. Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N 3.7 (LOW) MEDIUM · 43.9/100 1.4% prob · 71th pct 1.38.0 2019-03-12 2024-02-16 exact nvd+osv+packagist External links (4)
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM MEDIUM 4.8 |
CVE-2026-55766 exact |
composer: guzzlehttp/psr7 1.4.2 direct defined in: drupal/drupal |
CWE-93 CRLF Injection CWE-113HTTP Response Splitting |
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and response reason… | 2.12.1 | nvdosvpackagist | ||
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and response reason phrase. If an application placed attacker-controlled data into one of those fields and later serialized the PSR-7 message as raw HTTP/1.x, for example with Message::toString() or an equivalent serializer, the serialized message could contain attacker-controlled header lines. The issue can also be reached through Message::parseRequest() or Message::parseResponse() when malformed raw messages are parsed into first-party PSR-7 objects and then serialized again. Creating or modifying a Request, Response, or other PSR-7 object alone is not sufficient. The issue requires the malformed message to be serialized and written to the network, forwarded, replayed, or otherwise processed by software that does not independently reject the malformed start line. This vulnerability is fixed in 2.12.1. Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N 4.8 (MEDIUM) MEDIUM · 41.2/100 0.2% prob · 14th pct 2.12.1 2026-06-18 2026-09-10 exact nvd+osv+packagist External links (1)
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
LOW MEDIUM 4.7 |
CVE-2026-59883 exact |
composer: guzzlehttp/guzzle 6.3.0 direct defined in: drupal/drupal |
CWE-346 Origin Validation Error CWE-384Session Fixation |
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matc… | 7.12.3 | nvdosvpackagist | ||
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3. Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N 4.7 (MEDIUM) LOW · 38.9/100 0.2% prob · 6th pct 7.12.3 2026-07-20 2026-09-10 exact nvd+osv+packagist External links (5)
Patch / Commit3 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
LOW MEDIUM 4.2 |
CVE-2026-59882 exact |
composer: guzzlehttp/psr7 1.4.2 direct defined in: drupal/drupal |
CWE-436 Interpretation Conflict |
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::ge… | 2.12.3 | nvdosvpackagist | ||
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. This issue is fixed in version 2.12.3. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N 4.2 (MEDIUM) LOW · 38.6/100 0.3% prob · 25th pct 2.12.3 2026-07-21 2026-07-21 exact nvd+osv+packagist External links (5)
Patch / Commit3 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
LOW LOW 3.1 |
CVE-2024-50345 exact |
composer: symfony/http-foundation 3.4.4 direct defined in: drupal/drupal |
CWE-601 URL Redirection to Untrusted Site (Open Redirect) |
symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. | 4.0.0 | nvdosvpackagist | ||
Description
symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. As a result, an attacker can trick a validator relying on the `Request` class to redirect users to another domain. The `Request::create` methods now assert the URI does not contain invalid characters as defined by https://url.spec.whatwg.org/. This issue has been patched in versions 5.4.46, 6.4.14, and 7.1.7. Users are advised to upgrade. There are no known workarounds for this vulnerability. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N 3.1 (LOW) LOW · 33.8/100 0.6% prob · 45th pct 4.0.0 2024-11-05 2025-11-03 exact nvd+osv+packagist External links (4)
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
LOW LOW 3.1 |
CVE-2024-50343 exact |
composer: symfony/validator 3.4.4 direct defined in: drupal/drupal |
CWE-20 Improper Input Validation |
symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metacharacters, with an input ending with `\n`. | 4.0.0 | nvdosvpackagist | ||
Description
symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metacharacters, with an input ending with `\n`. Symfony as of versions 5.4.43, 6.4.11, and 7.1.4 now uses the `D` regex modifier to match the entire input. Users are advised to upgrade. There are no known workarounds for this vulnerability. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N 3.1 (LOW) LOW · 32.6/100 0.5% prob · 39th pct 4.0.0 2024-08-30 2025-11-03 exact nvd+osv+packagist External links (4)
Patch / Commit1 link
Security advisory2 links
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
LOW LOW 2.2 |
CVE-2024-51754 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
CWE-668 Exposure of Resource to Wrong Sphere |
Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of an array or an argument list (arguments t… | 2.0.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of an array or an argument list (arguments to a function or a filter for instance). This issue has been patched in versions 3.11.2 and 3.14.1. All users are advised to upgrade. There are no known workarounds for this issue. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N 2.2 (LOW) LOW · 25.1/100 0.4% prob · 37th pct 2.0.0 2024-11-06 2025-05-29 exact nvd+osv+packagist External links (4)
Patch / Commit1 link
Security advisory2 links
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
LOW LOW 2.2 |
CVE-2024-51755 exact |
composer: twig/twig 1.35.0 direct defined in: drupal/drupal |
CWE-668 Exposure of Resource to Wrong Sphere |
Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. | 2.0.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy and the `__isset()` method is now called after the security check. This is a BC break. This issue has been patched in versions 3.11.2 and 3.14.1. All users are advised to upgrade. There are no known workarounds for this issue. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N 2.2 (LOW) LOW · 25/100 0.4% prob · 37th pct 2.0.0 2024-11-06 2024-11-12 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
LOW MEDIUM 2.3 |
CVE-2026-45065 exact |
composer: symfony/routing 3.4.4 direct defined in: drupal/drupal |
CWE-185 Incorrect Regular Expression CWE-601URL Redirection to Untrusted Site (Open Redirect) |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 4.0.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, UrlGenerator validates route parameters against a pattern built as ^ plus the raw requirement plus $; with ungrouped alternations, middle alternatives match as unanchored substrings, allowing a value such as //evil.com to satisfy a common locale requirement and generate a protocol-relative off-site URL. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (2)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 2.3 (MEDIUM) LOW · 24.1/100 0.3% prob · 29th pct 4.0.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
| Priority / severity | Advisory ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
HIGH HIGH 8.7 |
CVE-2024-52301 exact |
composer: laravel/framework 10.48.22 direct defined in: bookstackapp/bookstack |
CWE-88 Argument Injection |
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the req… | 10.48.23 | nvdosvpackagist | ||
Description
Laravel is a web application framework. When the register_argc_argv php directive is set to on , and users call any URL with a special crafted query string, they are able to change the environment used by the framework when handling the request. The vulnerability fixed in 6.20.45, 7.30.7, 8.83.28, 9.52.17, 10.48.23, and 11.31.0. The framework now ignores argv values for environment detection on non-cli SAPIs. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.7 (HIGH) HIGH · 89.3/100 44.8% prob · 99th pct 10.48.23 2024-11-12 2024-12-21 exact nvd+osv+packagist External links (3)
Affected CPE configurations (7)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
HIGH HIGH 8.9 |
CVE-2026-48019 exact |
composer: laravel/framework 10.48.22 direct defined in: bookstackapp/bookstack |
CWE-93 CRLF Injection |
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may all… | 11.0.0 | nvdosvpackagist | ||
Description
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain character sequences, may allow an unauthenticated attacker to interfere with outbound email processing in applications that send mail to user-supplied addresses. This issue has been patched in versions 12.60.0 and 13.10.0. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L 8.9 (HIGH) HIGH · 81.4/100 0.7% prob · 51th pct 11.0.0 2026-05-19 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Security advisory1 link
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 6.9 |
CVE-2025-27515 exact |
composer: laravel/framework 10.48.22 direct defined in: bookstackapp/bookstack |
CWE-155 | Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. | 10.48.29 | nvdosvpackagist | ||
Description
Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*`), a user-crafted malicious request could potentially bypass the validation rules. This vulnerability is fixed in 11.44.1 and 12.1.1. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.9 (MEDIUM) MEDIUM · 65.8/100 0.7% prob · 53th pct 10.48.29 2025-03-05 2026-09-10 exact nvd+osv+packagist External links (3)
Patch / Commit1 link
Affected CPE configurations (2)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 4.2 |
GHSA-crmm-hgp2-wgrp exact |
composer: laravel/framework 10.48.22 direct defined in: bookstackapp/bookstack |
— | Laravel Framework: Temporary Signed URL Path Confusion A vulnerability in Laravel's local filesystem driver allows temporary signed URLs to be parsed ambiguously, potentially misrouting requests and bypassing expiration enforcement. Under… | 12.61.1 | osvpackagist | ||
Description
Laravel Framework: Temporary Signed URL Path Confusion
A vulnerability in Laravel's local filesystem driver allows temporary signed URLs to be parsed ambiguously, potentially misrouting requests and bypassing expiration enforcement.
Under certain conditions, a generated temporary signed URL can be interpreted differently by the server than intended at signing time. This may cause requests to resolve to an unintended resource, and can prevent expiration from being enforced, allowing expired URLs to remain valid indefinitely.
### Impact
- Expired temporary URLs may continue to be accepted
- Requests may resolve to a different resource than the one that was signed
- The upload variant may allow writes to reach an unintended destination Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N 4.2 (MEDIUM) MEDIUM · 42/100 12.61.1 2026-06-17 2026-09-10 exact osv+packagist External links (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
| Priority / severity | Advisory ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
CRITICAL CRITICAL |
GHSA-5j8p-438x-rgg5 exact |
composer: onelogin/php-saml 4.2.0 direct defined in: bookstackapp/bookstack |
— | SAML PHP Toolkit Vulnerability on xmlseclibs CVE-2025-66475 **Summary** There is a critical vulnerability on xmlseclibs [CVE-2025-66475](https://github.com/robrichards/xmlseclibs/security/advisories/GHSA-c4cc-x928-vjw9), a dependency of p… | 4.3.1 | osvpackagist | ||
Description
SAML PHP Toolkit Vulnerability on xmlseclibs CVE-2025-66475
**Summary**
There is a critical vulnerability on xmlseclibs [CVE-2025-66475](https://github.com/robrichards/xmlseclibs/security/advisories/GHSA-c4cc-x928-vjw9), a dependency of php-saml
Update to the following versions of php-saml which forces the use of patched versions of xmlseclibs:
- [2.21.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/2.21.1)
- [3.8.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/3.8.1)
- [4.3.1](https://github.com/SAML-Toolkits/php-saml/releases/tag/4.3.1)
**Impact**
Signature Wrapping Vulnerabilities allows an attacker to impersonate a user. Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CRITICAL · 95/100 4.3.1 2025-12-09 2025-12-09 exact osv+packagist External links (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
HIGH CRITICAL 9.8 |
CVE-2026-54133 exact |
composer: mtdowling/jmespath.php 2.8.0 direct defined in: bookstackapp/bookstack |
CWE-20 Improper Input Validation CWE-94Code Injection +1 |
jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. | 2.9.1 | nvdosvpackagist | ||
Description
jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 can generate and execute attacker-controlled PHP code when `JmesPath\CompilerRuntime` is used with an attacker-controlled JMESPath expression. The compiler emits parsed JMESPath function names into generated PHP source without sufficient escaping. A crafted expression can cause the generated cache file to contain executable attacker-controlled PHP, which is then loaded by the compiler runtime. The issue is patched in `2.9.1` and later. As a workaround, disable `JP_PHP_COMPILE` and do not use `JmesPath\CompilerRuntime` with attacker-controlled expressions. Use the default `AstRuntime` for untrusted expressions. Applications that must continue accepting untrusted JMESPath expressions before upgrading should ensure those expressions are never evaluated by the compiler runtime. Weaknesses (CWE) (3)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 9.8 (CRITICAL) HIGH · 85.5/100 0.4% prob · 36th pct 2.9.1 2026-06-11 2026-08-18 exact nvd+osv+packagist External links (1)
Vendor advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
HIGH HIGH |
GHSA-27qh-8cxx-2cr5 exact |
composer: aws/aws-sdk-php 3.322.6 direct defined in: bookstackapp/bookstack |
— | AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters ### Summary This notification is related to the [CloudFront signing utilities](https://github.com/aws/aws-sdk-php/blob/master/src/CloudFront/Signer.php) in th… | — | osvpackagist | ||
Description
AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters
### Summary
This notification is related to the [CloudFront signing utilities](https://github.com/aws/aws-sdk-php/blob/master/src/CloudFront/Signer.php) in the AWS SDK for PHP, which are used to generate Amazon CloudFront signed URLs and signed cookies. A defense-in-depth enhancement has been implemented to improve handling of special characters, such as double quotes and backslashes, in input values.
### Impact
The CloudFront signing utilities build policy documents that define access restrictions for signed URLs and cookies. If an application passes unsanitized input containing special characters to these utilities, the resulting policy document may not reflect the application's intended access restrictions. While the SDK was functioning safely within the requirements of the shared responsibility model, additional safeguards have been added to support secure customer implementations. Applications that already follow AWS security best practices for input validation are not impacted.
### Impacted versions: 3.11.7 - 3.371.3
### Patches
On 3/3/2026, an enhancement was made to the AWS SDK for PHP version 3.371.4. The enhancement ensures that special characters in input values are correctly handled. It is recommended to upgrade to the latest version.
### Workarounds
No workarounds are needed, but customers should ensure that the application is following security best practices:
- Implement proper input validation in application code before passing values to CloudFront signing utilities
- Update to the latest AWS SDK release on a regular basis
- Follow AWS security best practices for SDK configuration
### References
For any questions or comments about this advisory, it is recommended to contact AWS Security via the [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.co… Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:N/SA:N HIGH · 75/100 2026-03-27 2026-09-10 exact osv+packagist External links (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
HIGH HIGH 7.5 |
GHSA-g2gp-3wwq-f4ph exact |
composer: league/commonmark 2.5.3 direct defined in: bookstackapp/bookstack |
— | league/commonmark: Denial of service via adjacent inline attribute blocks ### Impact With the Attributes extension enabled, `AttributesListener::findTargetAndDirection()` resolves each attribute node's target by walking outward through it… | 2.9.0 | osvpackagist | ||
Description
league/commonmark: Denial of service via adjacent inline attribute blocks
### Impact
With the Attributes extension enabled, `AttributesListener::findTargetAndDirection()` resolves each attribute node's target by walking outward through its siblings. For a run of N adjacent inline attribute blocks placed at the start of a block (with nothing to their left), each node scans the **entire** sibling list to the far-right end before giving up and falling back to the parent. Each resolution is therefore Θ(N) and the whole run is **Θ(N²)**.
Reaching the path requires `AttributesExtension` (opt-in, but first-party: `League\CommonMark\Extension\Attributes\AttributesExtension`). No other configuration matters — the quadratic walk runs unconditionally during parsing and is **not** gated by the `attributes/allow` allow-list, the `on*` hardening added in 2.7.0, or `allow_unsafe_links`. An unauthenticated attacker can submit a **~32 KB** input (`{#a}` repeated 8,000 times) that takes **over 5 seconds** to convert, with time growing quadratically in input length — a cheap denial of service. Availability impact only. **The Attributes extension was introduced in 1.5.0 (May 2020) with this outward-walk resolver present from the first commit, so all releases from 1.5.0 onward (including every 2.x) are affected.**
### Workarounds
There is no library-level configuration that gates the quadratic walk. Integrators who cannot upgrade can only reduce exposure indirectly:
- **Disable the Attributes extension** for untrusted input, or
- **Impose a strict maximum input length before conversion** — noting that because the cost is quadratic, even a modest cap must be small to meaningfully bound worst-case CPU.
Upgrading to a release containing the fix is recommended. Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 7.5 (HIGH) HIGH · 75/100 2.9.0 2026-08-06 2026-08-06 exact osv+packagist External links (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
HIGH HIGH 7.5 |
GHSA-jfm3-95jq-q3rf exact |
composer: league/commonmark 2.5.3 direct defined in: bookstackapp/bookstack |
— | league/commonmark: Denial of service via duplicate footnote definitions ### Impact The Footnote extension records one backref per footnote *reference* and then appends the **entire** backref list for **every** footnote *definition* block… | 2.9.0 | osvpackagist | ||
Description
league/commonmark: Denial of service via duplicate footnote definitions
### Impact
The Footnote extension records one backref per footnote *reference* and then appends the **entire** backref list for **every** footnote *definition* block in the document, without ever de-duplicating or removing repeated definitions of the same label (`GatherFootnotesListener`, populated by `NumberFootnotesListener`). A document that references a single label N times and also supplies N duplicate `[^a]:` definitions of that label therefore produces **N × N** `FootnoteBackref` nodes, so output size, parse time, and peak memory are all **O(N²)**.
Reaching the vulnerable path requires `FootnoteExtension` to be registered on the `Environment`. This is opt-in, but is a commonly enabled GFM-style feature; no other non-default configuration is required. An unauthenticated attacker can expand a **~10 KB** request into a **~62 MB** HTML response, **~3 s** of CPU, and **~440 MB** of peak memory — enough to OOM-kill a default 128 MB PHP worker and deny service. Availability impact only; no confidentiality or integrity effect. **The Footnote extension was introduced in 1.5.0 (May 2020) with this backref logic present from the first commit, so all releases from 1.5.0 onward (including every 2.x through 2.8.x) are affected.**
### Workarounds
There is no library-level option to cap the number of footnotes, references, or definitions, so no configuration switch prevents the amplification. Integrators who cannot upgrade should:
- **Disable the Footnote extension** for untrusted input, or
- **Enforce a strict input-size limit before conversion** — but note this is a weak control here, since the ~10 KB payload that already triggers the 62 MB / ~440 MB blowup is well within typical request-body limits, so any cap must be aggressively small to help.
Upgrading to the patched release is the recommended remediation. Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 7.5 (HIGH) HIGH · 75/100 2.9.0 2026-08-06 2026-08-06 exact osv+packagist External links (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
HIGH HIGH 7.5 |
GHSA-mh25-x5hq-wrqp exact |
composer: league/commonmark 2.5.3 direct defined in: bookstackapp/bookstack |
— | league/commonmark: Denial of service via colliding heading slugs ### Impact `UniqueSlugNormalizer::normalize()` makes each slug document-unique by searching for an unused numeric suffix, but **restarts that search from `1` on every collis… | 2.9.0 | osvpackagist | ||
Description
league/commonmark: Denial of service via colliding heading slugs
### Impact
`UniqueSlugNormalizer::normalize()` makes each slug document-unique by searching for an unused numeric suffix, but **restarts that search from `1` on every collision**. The k-th heading that collapses to the same base slug performs k−1 array lookups, so K colliding slugs cost Σ(k−1) = **O(K²)**. An attacker can force every heading onto a single base slug trivially — many empty ATX headings, identical heading text, or punctuation-only headings that normalize to the empty string.
The path is reached whenever the shared slug normalizer runs over attacker-controlled text. That happens when `HeadingPermalinkExtension` is registered (its `HeadingPermalinkProcessor` normalizes every heading), independently through `FootnoteExtension` (its `AnonymousFootnoteRefParser` normalizes every `^[label]` reference), and on any `TableOfContentsExtension` site (which requires `HeadingPermalinkExtension` to be co-registered). The default `slug_normalizer/unique` setting (`UniqueSlugNormalizerInterface::PER_DOCUMENT`) accumulates collisions across the whole document. No authentication is required — a small document body turns into seconds of CPU and denies service. Availability impact only. **`UniqueSlugNormalizer` was introduced in 2.0.0 (first shipped in 2.0.0-beta1, May 2021); the 1.x heading-permalink slug generator performed no de-duplication and is not affected. All 2.x releases (including 2.8.x) are affected.**
### Workarounds
Integrators who cannot upgrade immediately can:
- **Set `slug_normalizer/unique` to `false` / `UniqueSlugNormalizerInterface::DISABLED`**, which stops the de-duplication scan entirely — at the cost of losing id uniqueness (colliding headings then share an anchor).
- **Disable `HeadingPermalinkExtension`** (and `TableOfContentsExtension`, which depends on it), and `FootnoteExtension` where anonymous footnotes reach the same normalizer, for untrusted Markdown.
- **Cap the accept… Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 7.5 (HIGH) HIGH · 75/100 2.9.0 2026-08-06 2026-08-06 exact osv+packagist External links (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
HIGH HIGH 8.4 |
CVE-2024-51736 exact |
composer: symfony/process 6.4.12 direct defined in: bookstackapp/bookstack |
CWE-77 Command Injection |
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. | 6.4.14 | nvdosvpackagist | ||
Description
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing command arguments, leading to possible hijacking. This issue has been addressed in release versions 5.4.46, 6.4.14, and 7.1.7. Users are advised to upgrade. There are no known workarounds for this vulnerability. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N 8.4 (HIGH) HIGH · 74.5/100 0.4% prob · 36th pct 6.4.14 2024-11-05 2026-09-10 exact nvd+osv+packagist External links (2)
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
HIGH HIGH 7.3 |
CVE-2025-64500 exact |
composer: symfony/http-foundation 6.4.12 direct defined in: bookstackapp/bookstack |
CWE-647 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. | 6.4.29 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the `Request` class now ensures that URL paths always start with a `/`. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L 7.3 (HIGH) HIGH · 72.3/100 1.3% prob · 70th pct 6.4.29 2025-11-12 2026-09-10 exact nvd+osv+packagist External links (5)
Patch / Commit1 link
Third-party advisory3 links
Affected CPE configurations (6)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM HIGH 8.2 |
CVE-2026-32313 exact |
composer: robrichards/xmlseclibs 3.1.1 direct defined in: bookstackapp/bookstack |
CWE-354 Improper Validation of Integrity Check Value |
xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. | 3.1.5 | nvdosvpackagist | ||
Description
xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Prior to 3.1.5, XML nodes encrypted with either aes-128-gcm, aes-192-gcm, or aes-256-gcm lack validation of the authentication tag length. An attacker can use this to brute-force an authentication tag, recover the GHASH key, and decrypt the encrypted nodes. It also allows to forge arbitrary ciphertexts without knowing the encryption key. This vulnerability is fixed in 3.1.5. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N 8.2 (HIGH) MEDIUM · 66.6/100 0.2% prob · 5th pct 3.1.5 2026-03-13 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Exploit / PoC1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM HIGH 7.5 |
CVE-2026-71488 exact |
composer: league/commonmark 2.5.3 direct defined in: bookstackapp/bookstack |
CWE-407 Inefficient Algorithmic Complexity CWE-1050 |
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths… | 2.9.0 | nvdosvpackagist | ||
Description
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeatedly rescan growing portions of a line to translate between character positions and byte positions, and the Autolink extension can also copy and validate the remaining line at every URL-like prefix, allowing an attacker who can submit Markdown for conversion to consume disproportionate CPU time with a comparatively small request. This issue is fixed in 2.9.0. Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 7.5 (HIGH) MEDIUM · 65.6/100 0.3% prob · 28th pct 2.9.0 2026-08-06 2026-08-21 exact nvd+osv+packagist External links (6)
Patch / Commit4 links
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 6.9 |
CVE-2026-48736 exact |
composer: symfony/http-foundation 6.4.12 direct defined in: bookstackapp/bookstack |
CWE-184 Incomplete List of Disallowed Inputs CWE-918Server-Side Request Forgery (SSRF) |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 6.4.41 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and IPv4-compatible IPv6, allowing attacker-supplied URLs to represent private IPv4 targets in forms that IpUtils::isPrivateIp() did not block. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13. Weaknesses (CWE) (2)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.9 (MEDIUM) MEDIUM · 64.4/100 0.6% prob · 46th pct 6.4.41 2026-05-26 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit6 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM HIGH 7.5 |
CVE-2026-86429 exact |
composer: league/commonmark 2.5.3 direct defined in: bookstackapp/bookstack |
CWE-407 Inefficient Algorithmic Complexity |
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. | 2.9.1 | nvdosvpackagist | ||
Description
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default and are excluded from the standard CommonMark and GitHub-Flavored Markdown converters), an unauthenticated attacker can submit small, specially crafted Markdown documents — such as text alternating with unpaired quotes, contiguous runs of block-level attribute blocks, or repeated class attributes — to trigger disproportionate CPU consumption and cause a denial of service. Fixed in 2.9.1. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.5 (HIGH) MEDIUM · 64.4/100 0.3% prob · 22th pct 2.9.1 2026-09-01 2026-09-08 exact nvd+osv+packagist External links (3)
Vendor advisory1 link
Third-party advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM HIGH 7.5 |
CVE-2026-86430 exact |
composer: league/commonmark 2.5.3 direct defined in: bookstackapp/bookstack |
CWE-407 Inefficient Algorithmic Complexity |
league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. | 2.9.1 | nvdosvpackagist | ||
Description
league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can submit specially crafted Markdown with long backtick runs, nested brackets, or delimiter sequences to consume disproportionate CPU time and prevent legitimate requests from completing. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.5 (HIGH) MEDIUM · 64.2/100 0.3% prob · 21th pct 2.9.1 2026-09-01 2026-09-08 exact nvd+osv+packagist External links (3)
Patch / Commit1 link
Third-party advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM HIGH 7.5 |
CVE-2024-58382 exact |
composer: league/commonmark 2.5.3 direct defined in: bookstackapp/bookstack |
CWE-407 Inefficient Algorithmic Complexity |
league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service. | 2.6.0 | nvdosvpackagist | ||
Description
league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service. Attackers can submit carefully crafted Markdown inputs designed to trigger worst-case performance, and sending multiple requests in parallel exhausts CPU resources and PHP-FPM processes. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.5 (HIGH) MEDIUM · 64.1/100 0.3% prob · 21th pct 2.6.0 2024-12-09 2026-09-10 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM HIGH 7.5 |
CVE-2026-86428 exact |
composer: league/commonmark 2.5.3 direct defined in: bookstackapp/bookstack |
CWE-407 Inefficient Algorithmic Complexity |
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. | 2.10.0 | nvdosvpackagist | ||
Description
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-time attribute merging and filtering, consuming disproportionate CPU resources and preventing legitimate requests from completing. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.5 (HIGH) MEDIUM · 64.1/100 0.3% prob · 21th pct 2.10.0 2026-09-01 2026-09-08 exact nvd+osv+packagist External links (3)
Vendor advisory1 link
Third-party advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM LOW 6.9 |
CVE-2026-46644 exact |
composer: symfony/polyfill-intl-idn 1.31.0 direct defined in: bookstackapp/bookstack |
CWE-1289 | Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. | 1.38.1 | nvdosvpackagist | ||
Description
Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to ASCII-only code points because Idn::process() does not enforce the UTS #46 revision 33 requirement that decoded ACE labels contain at least one non-ASCII code point. Originally unequal domain names can be regarded as equal, which can lead to blacklist bypassing, inconsistent URL parsing, and server-side request forgery in applications using the polyfill to canonicalise or compare hostnames. This issue is fixed in version 1.38.1. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.9 (LOW) MEDIUM · 64/100 0.5% prob · 44th pct 1.38.1 2026-05-26 2026-09-10 exact nvd+osv+packagist External links (4)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 6.3 |
CVE-2026-59942 exact |
composer: dompdf/dompdf 3.0.0 direct defined in: bookstackapp/bookstack |
CWE-400 Uncontrolled Resource Consumption (DoS) |
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. | 3.1.6 | nvdosvpackagist | ||
Description
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An attacker can crash the PHP process by providing a specially crafted HTML document containing a single image with massive dimensions (e.g., 30,000x30,000 pixels). While Dompdf implements internal checks to validate image dimensions, these can be bypassed by using a high-entropy image (such as random noise) encoded in Base64 and wrapped in specific CSS containers. The vulnerability exists because the dimension validation happens early, but the resource allocation for calculating the object's bounding box and internal buffers during the rendering phase does not strictly limit the cumulative CPU time or memory usage for a single object that has passed the initial check. An unauthenticated remote attacker can cause a complete Denial of Service on the web server by submitting a crafted HTML string. This affects any application that allows users to provide HTML content or URLs that are subsequently converted to PDF using Dompdf. This issue has been fixed in version 3.16. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.3 (MEDIUM) MEDIUM · 61.1/100 0.7% prob · 53th pct 3.1.6 2026-07-22 2026-07-22 exact nvd+osv+packagist External links (5)
Patch / Commit3 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM HIGH 7.5 |
CVE-2026-46643 exact |
composer: knplabs/knp-snappy 1.5.0 direct defined in: bookstackapp/bookstack |
CWE-78 OS Command Injection |
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. | — | nvdpackagist | ||
Description
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.1, on POSIX, escapeshellarg(‘/usr/bin/wkhtmltopdf’) returns the literal string ‘/usr/bin/wkhtmltopdf’ with the single-quote characters included. is_executable() then looks for a file whose actual name contains those quote characters, which essentially never exists. The safe branch is dead code and $command always falls through to the raw, unescaped value. The rest of the arguments (options, input, output) are escaped correctly, so injection has to land in the binary string itself. That happens whenever the binary path is sourced from configuration that is user-influenced, derived from environment variables that ultimately come from request data, or concatenated with any user-controlled fragment. This issue has been patched in version 1.7.1. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.5 (HIGH) MEDIUM · 61/100 0.2% prob · 5th pct 2026-05-21 2026-06-17 exact nvd+packagist External links (3)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 6.3 |
CVE-2025-22145 exact |
composer: nesbot/carbon 2.72.5 direct defined in: bookstackapp/bookstack |
CWE-98 | Carbon is an international PHP extension for DateTime. Application passing unsanitized user input to Carbon::setLocale are at risk of arbitrary file include, if the application allows users to upload files with .php extension in an folder t… | 2.72.6 | nvdosvpackagist | ||
Description
Carbon is an international PHP extension for DateTime. Application passing unsanitized user input to Carbon::setLocale are at risk of arbitrary file include, if the application allows users to upload files with .php extension in an folder that allows include or require to read it, then they are at risk of arbitrary code ran on their servers. This vulnerability is fixed in 3.8.4 and 2.72.6. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.3 (MEDIUM) MEDIUM · 60.9/100 0.7% prob · 53th pct 2.72.6 2025-01-08 2025-02-25 exact nvd+osv+packagist External links (4)
Patch / Commit1 link
Security advisory2 links
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM HIGH 6.3 |
CVE-2026-45067 exact |
composer: symfony/mime 6.4.12 direct defined in: bookstackapp/bookstack |
CWE-93 CRLF Injection |
### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply-to) flows through; its constructor is documented as validating the address and throwing on invalid input, so developers… | 6.4.40 | nvdosvpackagist | ||
Description
### Description
`Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply-to) flows through; its constructor is documented as validating the address and throwing on invalid input, so developers treat it as a security boundary.
The constructor accepts email addresses whose local-part (the part before `@`) is an RFC-5322 *quoted string* containing raw `\r\n` bytes — e.g. `"x\r\nBcc: attacker@evil"@example.com`. The stored address is later emitted verbatim into (1) the rendered message headers and (2) `SmtpTransport`'s `MAIL FROM:<...>` / `RCPT TO:<...>` protocol lines, turning the embedded CRLF into a new mail header and/or a new SMTP command.
### Resolution
The `Address` constructor now rejects addresses containing line breaks.
The patch for this issue is available [here](https://github.com/symfony/symfony/commit/dc2dbd29211eb4ddc451373fa1374fb926e94604) for branch 5.4.
### Credits
We would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.3 (HIGH) MEDIUM · 59.9/100 0.6% prob · 47th pct 6.4.40 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit5 links
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 6.3 |
CVE-2026-59941 exact |
composer: dompdf/dompdf 3.0.0 direct defined in: bookstackapp/bookstack |
CWE-400 Uncontrolled Resource Consumption (DoS) |
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared header dimensions and never bounds width × height before the image is converted through GD.… | 3.1.6 | nvdosvpackagist | ||
Description
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared header dimensions and never bounds width × height before the image is converted through GD. A 58-byte BMP whose header declares e.g. 6000×6000 is accepted and later drives imagecreatetruecolor($width, $height) (and PHP's native BMP decoder) to allocate the full pixel canvas. A payload can fit in a single HTTP request: the BMP can be inlined as a data:image/bmp;base64,… URI inside attacker-controlled HTML, so no upload, no remote fetch, and no chroot-reachable file is required. I measured a 169-byte request driving a dompdf render to ~412 MB peak RSS and ~4.8 s of CPU/wall time, versus ~34 MB for an identically-sized benign request — roughly a 12× memory amplification per request, repeatable and unauthenticated. This issue has been fixed in version 3.16. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.3 (MEDIUM) MEDIUM · 58.9/100 0.5% prob · 43th pct 3.1.6 2026-07-22 2026-07-22 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 6.9 |
CVE-2026-46683 exact |
composer: knplabs/knp-snappy 1.5.0 direct defined in: bookstackapp/bookstack |
CWE-918 Server-Side Request Forgery (SSRF) |
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0, there is a SSRF and local file read vulnerability via the xsl-style-sheet option. | — | nvdosvpackagist | ||
Description
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0, there is a SSRF and local file read vulnerability via the xsl-style-sheet option. This issue has been patched in version 1.7.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.9 (MEDIUM) MEDIUM · 58.5/100 0.2% prob · 17th pct 2026-05-21 2026-09-10 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 6.4 |
CVE-2025-46734 exact |
composer: league/commonmark 2.5.3 direct defined in: bookstackapp/bookstack |
CWE-79 Cross-site Scripting (XSS) |
league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert malicious JavaScript calls … | 2.7.0 | nvdosvpackagist | ||
Description
league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert malicious JavaScript calls into HTML. The league/commonmark library provides configuration options such as `html_input: 'strip'` and `allow_unsafe_links: false` to mitigate cross-site scripting (XSS) attacks by stripping raw HTML and disallowing unsafe links. However, when the Attributes Extension is enabled, it introduces a way for users to inject arbitrary HTML attributes into elements via Markdown syntax using curly braces. Version 2.7.0 contains three changes to prevent this XSS attack vector: All attributes starting with `on` are considered unsafe and blocked by default; support for an explicit allowlist of allowed HTML attributes; and manually-added `href` and `src` attributes now respect the existing `allow_unsafe_links` configuration option. If upgrading is not feasible, please consider disabling the `AttributesExtension` for untrusted users and/or filtering the rendered HTML through a library like HTMLPurifier. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N 6.4 (MEDIUM) MEDIUM · 57.2/100 0.4% prob · 30th pct 2.7.0 2025-05-05 2026-03-20 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 6.3 |
CVE-2026-45070 exact |
composer: symfony/mime 6.4.12 direct defined in: bookstackapp/bookstack |
CWE-93 CRLF Injection |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 6.4.40 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name from untrusted input to include CRLF or other non-token bytes and inject additional headers into rendered structured mail headers such as Content-Type or Content-Disposition. This issue is reported as fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.3 (MEDIUM) MEDIUM · 57/100 0.4% prob · 33th pct 6.4.40 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit6 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 6.3 |
CVE-2026-56722 exact |
composer: dompdf/dompdf 3.0.0 direct defined in: bookstackapp/bookstack |
CWE-20 Improper Input Validation |
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embedding a target file path inside an SVG image delivered through a data: URI, because dompdf… | 3.1.6 | nvdosvpackagist | ||
Description
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embedding a target file path inside an SVG image delivered through a data: URI, because dompdf processes the SVG twice and the second pass does not enforce the same protections as the first. When rendering, dompdf hands the SVG to the separate php-svg-lib library with external references forced on, and that library has no knowledge of the chroot directory, blocks only the phar:// scheme, and ultimately reads the referenced file with no path or protocol validation. This lets an external, unauthenticated attacker read arbitrary image files from the server's file system in the default configuration. This issue has been fixed in version 3.16. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.3 (MEDIUM) MEDIUM · 55.7/100 0.3% prob · 26th pct 3.1.6 2026-07-22 2026-07-22 exact nvd+osv+packagist External links (5)
Patch / Commit3 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 6.3 |
CVE-2026-59943 exact |
composer: dompdf/dompdf 3.0.0 direct defined in: bookstackapp/bookstack |
CWE-209 Generation of Error Message Containing Sensitive Information |
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rendering functionality to leak filesystem information when render… | 3.1.6 | nvdosvpackagist | ||
Description
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf they can utilize the SVG rendering functionality to leak filesystem information when rendering PDF files using image references within a data-URI encoded SVG document. Using an <image> element inside a data-URI embedded SVG, an attacker can attempt to embed other files via the href or xlink:href attributes. When processing a file that does not exist (e.g. file:///DOESNOTEXIST), dompdf behaves differently than it does when accessing a file or directory that actually exists on the filesystem. This issue has been fixed in version 3.16. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.3 (MEDIUM) MEDIUM · 55/100 0.3% prob · 23th pct 3.1.6 2026-07-22 2026-07-22 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 6.3 |
CVE-2026-33347 exact |
composer: league/commonmark 2.5.3 direct defined in: bookstackapp/bookstack |
CWE-79 Cross-site Scripting (XSS) CWE-185Incorrect Regular Expression +1 |
league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matchi… | — | nvdosvpackagist | ||
Description
league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2. Weaknesses (CWE) (3)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.3 (MEDIUM) MEDIUM · 53.5/100 0.2% prob · 16th pct 2026-03-19 2026-03-27 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Vendor advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 5.3 |
GHSA-mj63-m3rc-8ppr exact |
composer: league/commonmark 2.5.3 direct defined in: bookstackapp/bookstack |
— | league/commonmark: Denial of service via deeply nested XML output ### Impact `XmlRenderer` pretty-prints XML by emitting depth-proportional indentation whitespace for **every** opening and closing tag. | 2.9.0 | osvpackagist | ||
Description
league/commonmark: Denial of service via deeply nested XML output
### Impact
`XmlRenderer` pretty-prints XML by emitting depth-proportional indentation whitespace for **every** opening and closing tag. For a tree of depth n, the indentation alone sums to **O(n²)** bytes of output (and corresponding memory), reachable through `MarkdownToXmlConverter` — e.g. `str_repeat('> ', $depth) . "x\n"`, a single line of nested blockquotes — or through a direct `XmlRenderer::renderDocument()` call on an attacker-influenced AST.
This affects applications that convert untrusted Markdown to XML, which is an **opt-in** output path. The parser's `max_nesting_level` bounds the depth of *parser-created* trees, but its default is high enough to reach damaging sizes, can be raised by the host application, and does not constrain custom or programmatically built ASTs handed straight to the renderer. The result is a memory / output-size amplification rather than a hard crash, which is why this issue is rated **Medium** rather than High. No confidentiality or integrity impact. XML rendering was introduced in 2.0.0 (first shipped in 2.0.0-beta1, June 2021) and has emitted depth-proportional indentation ever since, so all 2.x releases are affected (verified against 2.8.x, clean upstream `1902f60f`). 1.x has no XML renderer and is not affected.
### Workarounds
Applications converting untrusted Markdown to XML should:
- **Lower `max_nesting_level`** to a conservative value appropriate to expected content, so the parser refuses to build extremely deep trees. This is the most direct lever for parser-produced ASTs, but does not protect trees built programmatically and passed straight to `XmlRenderer`.
- **Cap input size before conversion**, since the amplification is driven by input-proportional depth.
- **Constrain XML consumers** with memory / output-size limits (and streaming or size caps on any downstream XML parser or storage) so one request cannot allocate unbounded output.
- **Prefer H… Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L 5.3 (MEDIUM) MEDIUM · 53/100 2.9.0 2026-08-06 2026-08-06 exact osv+packagist External links (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 6.3 |
CVE-2026-24739 exact |
composer: symfony/process 6.4.12 direct defined in: bookstackapp/bookstack |
CWE-88 Argument Injection |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 6.4.33 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to versions 5.4.51, 6.4.33, 7.3.11, 7.4.5, and 8.0.5, the Symfony Process component did not correctly treat some characters (notably `=`) as “special” when escaping arguments on Windows. When PHP is executed from an MSYS2-based environment (e.g. Git Bash) and Symfony Process spawns native Windows executables, MSYS2’s argument/path conversion can mis-handle unquoted arguments containing these characters. This can cause the spawned process to receive corrupted/truncated arguments compared to what Symfony intended. If an application (or tooling such as Composer scripts) uses Symfony Process to invoke file-management commands (e.g. `rmdir`, `del`, etc.) with a path argument containing `=`, the MSYS2 conversion layer may alter the argument at runtime. In affected setups this can result in operations being performed on an unintended path, up to and including deletion of the contents of a broader directory or drive. The issue is particularly relevant when untrusted input can influence process arguments (directly or indirectly, e.g. via repository paths, extracted archive paths, temporary directories, or user-controlled configuration). Versions 5.4.51, 6.4.33, 7.3.11, 7.4.5, and 8.0.5 contains a patch for the issue. Some workarounds are available. Avoid running PHP/one's own tooling from MSYS2-based shells on Windows; prefer cmd.exe or PowerShell for workflows that spawn native executables. Avoid passing paths containing `=` (and similar MSYS2-sensitive characters) to Symfony Process when operating under Git Bash/MSYS2. Where applicable, configure MSYS2 to disable or restrict argument conversion (e.g. via `MSYS2_ARG_CONV_EXCL`), understanding this may affect other tooling behavior. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H 6.3 (MEDIUM) MEDIUM · 52.8/100 0.2% prob · 12th pct 6.4.33 2026-01-28 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Affected CPE configurations (5)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 6.1 |
CVE-2026-71478 exact |
composer: league/commonmark 2.5.3 direct defined in: bookstackapp/bookstack |
CWE-79 Cross-site Scripting (XSS) CWE-86 +1 |
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, … | — | nvdosvpackagist | ||
Description
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, line feed, or leading C0 control character, in a javascript: URL that browsers discard before parsing the scheme, causing the browser to still execute the script even when the unsafe-link filter is enabled. This issue is fixed in 2.9.0. Weaknesses (CWE) (3)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 6.1 (MEDIUM) MEDIUM · 52/100 0.2% prob · 16th pct 2026-08-06 2026-08-21 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 6.0 |
CVE-2025-66578 exact |
composer: robrichards/xmlseclibs 3.1.1 direct defined in: bookstackapp/bookstack |
CWE-248 Uncaught Exception |
xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Versions 3.1.3 contain an authentication bypass vulnerability due to a flaw in the libxml2 canonicalization process during document transformation. | — | nvdosvpackagist | ||
Description
xmlseclibs is a library written in PHP for working with XML Encryption and Signatures. Versions 3.1.3 contain an authentication bypass vulnerability due to a flaw in the libxml2 canonicalization process during document transformation. When libxml2’s canonicalization is invoked on an invalid XML input, it may return an empty string rather than a canonicalized node. xmlseclibs then proceeds to compute the DigestValue over this empty string, treating it as if canonicalization succeeded. This issue is fixed in version 3.1.4. Workarounds include treating canonicalization failures (exceptions or nil/empty outputs) as fatal and aborting validation, and/or adding explicit checks to reject when canonicalize returns nil/empty or raises errors. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L 6.0 (MEDIUM) MEDIUM · 51.1/100 0.2% prob · 16th pct 2025-12-08 2025-12-09 exact nvd+osv+packagist External links (4)
Patch / Commit1 link
Exploit / PoC1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 5.1 |
CVE-2026-48784 exact |
composer: symfony/routing 6.4.12 direct defined in: bookstackapp/bookstack |
CWE-172 CWE-601 URL Redirection to Untrusted Site (Open Redirect) |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 6.4.41 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing attacker-controlled route parameters to generate URLs that collapse to a different path under RFC 3986 normalization. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13. Weaknesses (CWE) (2)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.1 (MEDIUM) MEDIUM · 46.5/100 0.3% prob · 29th pct 6.4.41 2026-05-26 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 5.3 |
CVE-2025-14761 exact |
composer: aws/aws-sdk-php 3.322.6 direct defined in: bookstackapp/bookstack |
CWE-327 Use of a Broken or Risky Cryptographic Algorithm |
Missing cryptographic key commitment in the AWS SDK for PHP may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" inste… | 3.368.0 | nvdosvpackagist | ||
Description
Missing cryptographic key commitment in the AWS SDK for PHP may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record.
To mitigate this issue, upgrade AWS SDK for PHP to version 3.368.0 or later Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.3 (MEDIUM) MEDIUM · 44.7/100 0.2% prob · 12th pct 3.368.0 2025-12-17 2026-09-10 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 5.1 |
CVE-2026-30838 exact |
composer: league/commonmark 2.5.3 direct defined in: bookstackapp/bookstack |
CWE-79 Cross-site Scripting (XSS) |
league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and the closing >. | — | nvdosvpackagist | ||
Description
league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and the closing >. For example, <script\n> would pass through unfiltered and be rendered as a valid HTML tag by browsers. This is a cross-site scripting (XSS) vector for any application that relies on this extension to sanitize untrusted user input. All applications using the DisallowedRawHtml extension to process untrusted markdown are affected. Applications that use a dedicated HTML sanitizer (such as HTML Purifier) on the rendered output are not affected. This issue has been patched in version 2.8.1. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.1 (MEDIUM) MEDIUM · 43.3/100 0.2% prob · 12th pct 2026-03-06 2026-03-20 exact nvd+osv+packagist External links (2)
Vendor advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
LOW LOW 3.1 |
CVE-2024-50345 exact |
composer: symfony/http-foundation 6.4.12 direct defined in: bookstackapp/bookstack |
CWE-601 URL Redirection to Untrusted Site (Open Redirect) |
symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. | 6.4.14 | nvdosvpackagist | ||
Description
symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. As a result, an attacker can trick a validator relying on the `Request` class to redirect users to another domain. The `Request::create` methods now assert the URI does not contain invalid characters as defined by https://url.spec.whatwg.org/. This issue has been patched in versions 5.4.46, 6.4.14, and 7.1.7. Users are advised to upgrade. There are no known workarounds for this vulnerability. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N 3.1 (LOW) LOW · 33.8/100 0.6% prob · 45th pct 6.4.14 2024-11-05 2025-11-03 exact nvd+osv+packagist External links (4)
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
LOW LOW 2.3 |
CVE-2026-55555 exact |
composer: dompdf/dompdf 3.0.0 direct defined in: bookstackapp/bookstack |
CWE-203 Observable Discrepancy |
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of the CSS @font-face directive. | 3.1.6 | nvdosvpackagist | ||
Description
Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a File Existence Oracle attack through the manipulation of the CSS @font-face directive. By providing malicious HTML that references local files via the file:// protocol repeatedly, an attacker can trigger PHP memory exhaustion. Because Dompdf behaves differently depending on whether a referenced local file exists (an existing file is processed repeatedly until it triggers an "Allowed memory size exhausted" crash, whereas a missing file fails fast or is ignored and never hits the memory limit), an attacker can use this observable discrepancy as an oracle to enumerate sensitive files on the server regardless of CHROOT restrictions. Exploitation requires the attacker to supply unrestricted or unsanitized HTML in a request that permits large data, plus a configuration where Dompdf's memory limit is low enough to be exhausted (with $_dompdf_show_warnings=true making the overflow easier to reach). This issue has been fixed in version 3.16. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 2.3 (LOW) LOW · 24.2/100 0.4% prob · 29th pct 3.1.6 2026-07-22 2026-07-22 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
LOW MEDIUM 2.3 |
CVE-2026-45065 exact |
composer: symfony/routing 6.4.12 direct defined in: bookstackapp/bookstack |
CWE-185 Incorrect Regular Expression CWE-601URL Redirection to Untrusted Site (Open Redirect) |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 6.4.40 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, UrlGenerator validates route parameters against a pattern built as ^ plus the raw requirement plus $; with ungrouped alternations, middle alternatives match as unanchored substrings, allowing a value such as //evil.com to satisfy a common locale requirement and generate a protocol-relative off-site URL. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (2)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 2.3 (MEDIUM) LOW · 24.1/100 0.3% prob · 29th pct 6.4.40 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
LOW LOW 2.3 |
CVE-2026-55554 exact |
composer: dompdf/dompdf 3.0.0 direct defined in: bookstackapp/bookstack |
CWE-20 Improper Input Validation |
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() prefix check after normalizing paths with realpath() . | 3.1.6 | nvdosvpackagist | ||
Description
Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, the validateLocalUri() method enforces chroot boundaries with a strpos() prefix check after normalizing paths with realpath() . Because normalization strips the trailing directory separator from $chrootPath , the check only verifies that $chrootPath is a string prefix of $realfile, so a chroot of /var/www also matches sibling directories like /var/www2 , /var/www-admin, or /var/www_backup. An attacker who controls part of the rendered HTML could exploit this to escape the chroot and read sensitive files outside the allowed directory. This issue has been fixed in version 3.16. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 2.3 (LOW) LOW · 23.6/100 0.3% prob · 26th pct 3.1.6 2026-07-22 2026-07-22 exact nvd+osv+packagist External links (3)
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
HIGH HIGH 8.2 |
CVE-2026-32935 exact |
composer: phpseclib/phpseclib 3.0.42 direct defined in: bookstackapp/bookstack |
CWE-208 Observable Timing Discrepancy |
phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. | — | nvdosvpackagist | ||
Description
phpseclib is a PHP secure communications library. Projects using versions 0.1.1 through 1.0.26, 2.0.0 through 2.0.51, and 3.0.0 through 3.0.49 are vulnerable to a to padding oracle timing attack when using AES in CBC mode. This issue has been fixed in versions 1.0.27, 2.0.52 and 3.0.50. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.2 (HIGH) HIGH · 71.9/100 0.4% prob · 31th pct 2026-03-19 2026-09-10 exact nvd+osv+packagist External links (3)
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM HIGH 7.5 |
CVE-2026-44167 exact |
composer: phpseclib/phpseclib 3.0.42 direct defined in: bookstackapp/bookstack |
CWE-400 Uncontrolled Resource Consumption (DoS) |
phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc). This is a bypass of CVE-2024-27355. | — | nvdosvpackagist | ||
Description
phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 files (eg. X509 certificates, RSA PKCS8 private or public keys, etc). This is a bypass of CVE-2024-27355. This vulnerability is fixed in 1.0.29, 2.0.54, and 3.0.52. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 7.5 (HIGH) MEDIUM · 62.1/100 0.2% prob · 10th pct 2026-05-05 2026-09-10 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM HIGH 7.2 |
CVE-2026-69246 exact |
composer: guzzlehttp/guzzle 7.9.2 direct defined in: bookstackapp/bookstack |
CWE-180 CWE-436 Interpretation Conflict +2 |
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. | 7.15.2 | nvdosvpackagist | ||
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header separately. The cURL handlers set CURLOPT_URL to the URI exactly as written and push that Host into CURLOPT_HTTPHEADER; StreamHandler does the same through fopen(). libcurl then parses the authority itself, percent-decoding it and, on an IDN-capable build, applying IDNA mapping, and uses the result to resolve, connect, name the TLS peer and address a proxy CONNECT, while the supplied Host suppresses the aligned one libcurl would have generated. For a URI host written as 127.0.0.%31, filter_var() rejects the host as an IP literal, yet libcurl decodes it to 127.0.0.1 and reaches loopback with no DNS lookup while the server receives Host: 127.0.0.%31. An attacker who influences a fetched URI can therefore reach a host the application's checks excluded and read whatever the host exposes of the response. The same divergence moves Guzzle's own decisions onto a spelling the transport does not use: no_proxy selects proxy routing from the literal host, and RedirectMiddleware decides from it whether to strip Authorization and Cookie. Exploitation requires the application to build a request URI from untrusted input and to make a host decision before handing it to Guzzle. This issue is fixed in versions 7.15.2 and 8.0.1. Weaknesses (CWE) (4)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N 7.2 (HIGH) MEDIUM · 60/100 0.2% prob · 12th pct 7.15.2 2026-08-03 2026-09-10 exact nvd+osv+packagist External links (8)
Patch / Commit6 links
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM LOW 6.5 |
CVE-2025-45769 exact |
composer: firebase/php-jwt 6.10.1 direct defined in: bookstackapp/bookstack |
CWE-326 Inadequate Encryption Strength |
php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. | 7.0.0 | nvdosvpackagist | ||
Description
php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths are expected to be set by an application, not by this library. This dispute is subject to review under CNA rules 4.1.4, 4.1.14, and other rules; the dispute tagging is not meant to recommend an outcome for this CVE Record. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N 6.5 (LOW) MEDIUM · 52.7/100 0.1% prob · 3th pct 7.0.0 2025-07-31 2026-09-10 exact nvd+osv+packagist External links (8)
Patch / Commit3 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 6.5 |
CVE-2026-69245 exact |
composer: guzzlehttp/guzzle 7.9.2 direct defined in: bookstackapp/bookstack |
CWE-180 CWE-346 Origin Validation Error +1 |
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, … | 7.15.2 | nvdosvpackagist | ||
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie unless SetCookie::matchesDomain() recognizes the Domain as an IP literal or a numeric host, and the decision comes from the domain's own text, so two spellings a transport reads as an address keep subdomain scope. Hexadecimal and mixed-base forms such as 0x7f000001 and 0177.0.0.0x1 go unrecognized while libcurl 8.21.0 reads both as 127.0.0.1. A percent-escaped Domain keeps that scope on both branches because percent-decoding sits above numeric parsing, so 192.168.0.%31 and 127.0.0.1%2e are registered names in the URI grammar rather than address literals, and no numeric rule in any base classifies them, while libcurl decodes the host before resolving and reads them as 192.168.0.1 and 127.0.0.1. A cookie stored for Domain=0x7f000001 is placed in the Cookie header of a request to evil.0x7f000001, disclosing a session identifier or token to a host that is not that address, and a response from evil.0x7f000001 setting Domain=0x7f000001 is accepted into the jar and replayed to the address, so a server answering for the look-alike name can fix a session or set application state. Exploitation requires the application to enable cookie support, address an origin by one of these spellings, and contact a host whose name ends in that spelling. This issue is fixed in versions 7.15.2 and 8.0.1. Weaknesses (CWE) (3)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N 6.5 (MEDIUM) MEDIUM · 52.7/100 0.1% prob · 3th pct 7.15.2 2026-08-03 2026-09-10 exact nvd+osv+packagist External links (8)
Patch / Commit6 links
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 5.9 |
CVE-2026-67354 exact |
composer: guzzlehttp/guzzle 7.9.2 direct defined in: bookstackapp/bookstack |
CWE-201 | guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. | 7.15.1 | nvdosvpackagist | ||
Description
guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.referer setting is enabled, the middleware copies the URI fragment (the portion after '#') from the referring request into the generated Referer header when following a same-scheme redirect (e.g., HTTPS to HTTPS). An attacker who controls the redirect destination can read this fragment from the incoming Referer header, potentially disclosing one-time login secrets, access tokens, state values, or other sensitive client data to a server never meant to receive it. The referer setting is disabled by default. Fixed in 7.15.1, which strips the fragment before generating the Referer value. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.9 (MEDIUM) MEDIUM · 50.6/100 0.3% prob · 17th pct 7.15.1 2026-07-20 2026-09-10 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 5.9 |
CVE-2026-67355 exact |
composer: guzzlehttp/guzzle 7.9.2 direct defined in: bookstackapp/bookstack |
CWE-201 | guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. | 7.15.1 | nvdosvpackagist | ||
Description
guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking cookies as host-only. Attackers controlling child hosts can receive host-only cookies intended only for parent hosts, potentially disclosing session identifiers and authorization tokens when the same cookie jar is reused across trust boundaries. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.9 (MEDIUM) MEDIUM · 50/100 0.2% prob · 14th pct 7.15.1 2026-07-20 2026-09-10 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 5.8 |
CVE-2026-55599 exact |
composer: phpseclib/phpseclib 3.0.42 direct defined in: bookstackapp/bookstack |
CWE-918 Server-Side Request Forgery (SSRF) |
phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() reads a URL out of that certificate's Auth… | — | nvdosvpackagist | ||
Description
phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() reads a URL out of that certificate's Authority Information Access (AIA) extension and connects to it. Attacker who supplies certificate fully controls host, port, and path of that connection. URL fetching is enabled by default, and no destination is blocked. An unauthenticated attacker can therefore make a validating server open connections to internal hosts and ports it should never reach, for example loopback 127.0.0.1, cloud metadata address 169.254.169.254, and internal-only services. This is a server-side request forgery (SSRF) caused by an insecure default. This vulnerability is fixed in 1.0.30, 2.0.55, and 3.0.54. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N 5.8 (MEDIUM) MEDIUM · 48.8/100 0.2% prob · 12th pct 2026-06-16 2026-09-10 exact nvd+osv+packagist External links (2)
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 5.8 |
CVE-2026-55767 exact |
composer: guzzlehttp/guzzle 7.9.2 direct defined in: bookstackapp/bookstack |
CWE-346 Origin Validation Error CWE-1286 |
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. | 7.12.1 | nvdosvpackagist | ||
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the cookie domain, normalizing dot-only values to the empty string; SetCookie::validate() only rejected a strictly empty domain, so these cookies could be stored and the empty normalized domain was treated as matching any request host. An attacker-controlled origin that an application requests with a shared cookie jar can therefore set a cookie that Guzzle later sends to unrelated hosts using the same jar. This may allow cookie injection or session fixation against downstream services, depending on how those services interpret the injected cookie. This vulnerability is fixed in 7.12.1. Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N 5.8 (MEDIUM) MEDIUM · 48.7/100 0.2% prob · 12th pct 7.12.1 2026-06-18 2026-09-10 exact nvd+osv+packagist External links (5)
Patch / Commit3 links
Security advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 5.9 |
CVE-2026-55568 exact |
composer: guzzlehttp/guzzle 7.9.2 direct defined in: bookstackapp/bookstack |
CWE-311 Missing Encryption of Sensitive Data CWE-319Cleartext Transmission of Sensitive Information +1 |
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. | 7.12.1 | nvdosvpackagist | ||
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Proxy authentication credentials (the Proxy-Authorization header, proxy userinfo in the proxy URL, or CURLOPT_PROXYUSERPWD) are sent without encryption, and the CONNECT target host and port for tunneled HTTPS requests are exposed. The built-in cURL handlers (GuzzleHttp\Handler\CurlHandler and GuzzleHttp\Handler\CurlMultiHandler, used by default whenever the PHP cURL extension is available) accept an https:// proxy. libcurl older than 7.50.2 silently treats an https:// proxy as a plaintext http:// proxy. The TLS connection to the proxy is never established, and the proxy leg is cleartext with no error or warning. An application is affected when it sends requests through one of the built-in cURL handlers, configures an https:// proxy expecting the proxy connection itself to be encrypted, and runs with libcurl older than 7.50.2. This vulnerability is fixed in 7.12.1. Weaknesses (CWE) (3)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N 5.9 (MEDIUM) MEDIUM · 48.1/100 0.1% prob · 4th pct 7.12.1 2026-06-18 2026-09-10 exact nvd+osv+packagist External links (1)
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 5.3 |
CVE-2026-67353 exact |
composer: guzzlehttp/guzzle 7.9.2 direct defined in: bookstackapp/bookstack |
CWE-770 Allocation of Resources Without Limits or Throttling |
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. | 7.15.1 | nvdosvpackagist | ||
Description
guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields with no size restrictions. Attackers can return many large cookies from a malicious server, causing Guzzle to store excessive data in memory and generate oversized Cookie headers that fail in handlers or destination servers. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.3 (MEDIUM) MEDIUM · 45.7/100 0.2% prob · 16th pct 7.15.1 2026-07-20 2026-09-10 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 5.3 |
CVE-2026-67339 exact |
composer: guzzlehttp/guzzle 7.9.2 direct defined in: bookstackapp/bookstack |
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor |
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. | 7.14.2 | nvdosvpackagist | ||
Description
guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies that Guzzle misclassifies as direct connections. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.3 (MEDIUM) MEDIUM · 45.3/100 0.2% prob · 14th pct 7.14.2 2026-07-20 2026-09-10 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 5.3 |
CVE-2026-48998 exact |
composer: guzzlehttp/psr7 2.7.0 direct defined in: bookstackapp/bookstack |
CWE-20 Improper Input Validation CWE-918Server-Side Request Forgery (SSRF) |
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server variables. | 2.10.2 | nvdosvpackagist | ||
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a server request URI from server variables. An attacker can provide a malformed Host header containing URI authority delimiters, such as `trusted.example@evil.example`. When the Host value is used to construct a URI, the malformed value can be reinterpreted as URI userinfo and host. This can cause the PSR-7 request URI host to differ from the original Host header value. Applications are affected if they parse attacker-controlled raw HTTP requests with `GuzzleHttp\Psr7\Message::parseRequest()` or the legacy 1.x `GuzzleHttp\Psr7\parse_request()` function, or if they build server requests from attacker-controlled server variables, then rely on the resulting URI host for routing, allow-list checks, or forwarding decisions. In affected forwarding or gateway scenarios, this may cause requests or credentials to be sent to an unintended host. The issue is patched in `2.10.2`. `1.x` is end-of-life and will not receive a patch. Some workarounds are available. Validate the `Host` header as `uri-host [ ":" port ]` before calling `Message::parseRequest()` or legacy `parse_request()` on untrusted HTTP request data, or before deriving routing and forwarding decisions from a parsed request URI. Reject Host values containing userinfo, path, query, or fragment delimiters. Weaknesses (CWE) (2)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N 5.3 (MEDIUM) MEDIUM · 44.4/100 0.2% prob · 10th pct 2.10.2 2026-05-25 2026-09-10 exact nvd+osv+packagist External links (1)
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 5.3 |
CVE-2026-49214 exact |
composer: guzzlehttp/psr7 2.7.0 direct defined in: bookstackapp/bookstack |
CWE-20 Improper Input Validation CWE-93CRLF Injection +1 |
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. | 2.10.2 | nvdosvpackagist | ||
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulnerable flow is: First, an application accepts a user-controlled URL. Second, the URL is used to construct a PSR-7 `Uri` or `Request`. Third, the host component contains CRLF or another header-unsafe character. Fourth, the host is copied into the PSR-7 `Host` header when no explicit `Host` header is provided. Finally, the request is serialized or sent by an HTTP client that does not independently reject the malformed host. In that flow, an attacker can cause the serialized request to contain additional attacker-controlled header lines. For example, a host containing `"\r\nX-Injected: yes"` can cause the generated `Host` header to span multiple HTTP header lines. Applications are affected when they use user-controlled URLs for outbound HTTP requests, URL forwarding, proxying, crawling, webhook delivery, or similar request-dispatch flows. In deployments involving HTTP/1.1 connection reuse, proxies, gateways, or load balancers, this malformed request may also contribute to request smuggling or cache poisoning, depending on how downstream components parse the request. The issue is patched in `2.10.2` and later. `1.x` is end-of-life and will not receive a patch. As a workaround, validate and reject all untrusted URI strings before constructing PSR-7 `Uri` or `Request` instances. Reject input containing ASCII control characters, whitespace, or DEL, including CRLF, tab, space, NUL, or DEL characters. Applications that forward requests should also ensure the final HTTP client or serializer rejects invalid URI and header data before writing requests to the network. Weaknesses (CWE) (3)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N 5.3 (MEDIUM) MEDIUM · 44.2/100 0.2% prob · 9th pct 2.10.2 2026-05-25 2026-09-10 exact nvd+osv+packagist External links (1)
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM MEDIUM 4.8 |
CVE-2026-55766 exact |
composer: guzzlehttp/psr7 2.7.0 direct defined in: bookstackapp/bookstack |
CWE-93 CRLF Injection CWE-113HTTP Response Splitting |
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and response reason… | 2.12.1 | nvdosvpackagist | ||
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and response reason phrase. If an application placed attacker-controlled data into one of those fields and later serialized the PSR-7 message as raw HTTP/1.x, for example with Message::toString() or an equivalent serializer, the serialized message could contain attacker-controlled header lines. The issue can also be reached through Message::parseRequest() or Message::parseResponse() when malformed raw messages are parsed into first-party PSR-7 objects and then serialized again. Creating or modifying a Request, Response, or other PSR-7 object alone is not sufficient. The issue requires the malformed message to be serialized and written to the network, forwarded, replayed, or otherwise processed by software that does not independently reject the malformed start line. This vulnerability is fixed in 2.12.1. Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N 4.8 (MEDIUM) MEDIUM · 41.2/100 0.2% prob · 14th pct 2.12.1 2026-06-18 2026-09-10 exact nvd+osv+packagist External links (1)
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
LOW MEDIUM 4.7 |
CVE-2026-59883 exact |
composer: guzzlehttp/guzzle 7.9.2 direct defined in: bookstackapp/bookstack |
CWE-346 Origin Validation Error CWE-384Session Fixation |
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matc… | 7.12.3 | nvdosvpackagist | ||
Description
Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3. Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N 4.7 (MEDIUM) LOW · 38.9/100 0.2% prob · 6th pct 7.12.3 2026-07-20 2026-09-10 exact nvd+osv+packagist External links (5)
Patch / Commit3 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
LOW MEDIUM 4.2 |
CVE-2026-59882 exact |
composer: guzzlehttp/psr7 2.7.0 direct defined in: bookstackapp/bookstack |
CWE-436 Interpretation Conflict |
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::ge… | 2.12.3 | nvdosvpackagist | ||
Description
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. This issue is fixed in version 2.12.3. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N 4.2 (MEDIUM) LOW · 38.6/100 0.3% prob · 25th pct 2.12.3 2026-07-21 2026-07-21 exact nvd+osv+packagist External links (5)
Patch / Commit3 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
LOW LOW 3.7 |
CVE-2026-40194 exact |
composer: phpseclib/phpseclib 3.0.42 direct defined in: bookstackapp/bookstack |
CWE-208 Observable Timing Discrepancy |
phpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\Net\SSH2::get_binary_packet() uses PHP's != operator to compare a received SSH packet HMAC against the locally computed H… | 3.0.51 | nvdosvpackagist | ||
Description
phpseclib is a PHP secure communications library. Starting in 0.1.1 and prior to 3.0.51, 2.0.53, and 1.0.28, phpseclib\Net\SSH2::get_binary_packet() uses PHP's != operator to compare a received SSH packet HMAC against the locally computed HMAC. != on equal-length binary strings in PHP uses memcmp(), which short-circuits on the first differing byte. This is a real variable-time comparison (CWE-208), proven by scaling benchmarks. This vulnerability is fixed in 3.0.51, 2.0.53, and 1.0.28. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N 3.7 (LOW) LOW · 35.6/100 0.4% prob · 30th pct 3.0.51 2026-04-10 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit4 links
Vendor advisory1 link
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
MEDIUM MEDIUM 6.7 |
CVE-2026-25129 exact |
composer: psy/psysh 0.12.4 direct defined in: bookstackapp/bookstack |
CWE-427 Uncontrolled Search Path Element |
PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and executes a `.psysh.php` file from the Current Working Directory (CWD) on startup. | — | nvdosvpackagist | ||
Description
PsySH is a runtime developer console, interactive debugger, and REPL for PHP. Prior to versions 0.11.23 and 0.12.19, PsySH automatically loads and executes a `.psysh.php` file from the Current Working Directory (CWD) on startup. If an attacker can write to a directory that a victim later uses as their CWD when launching PsySH, the attacker can trigger arbitrary code execution in the victim's context. When the victim runs PsySH with elevated privileges (e.g., root), this results in local privilege escalation. This is a CWD configuration poisoning issue leading to arbitrary code execution in the victim user’s context. If a privileged user (e.g., root, a CI runner, or an ops/debug account) launches PsySH with CWD set to an attacker-writable directory containing a malicious `.psysh.php`, the attacker can execute commands with that privileged user’s permissions, resulting in local privilege escalation. Downstream consumers that embed PsySH inherit this risk. For example, Laravel Tinker (`php artisan tinker`) uses PsySH. If a privileged user runs Tinker while their shell is in an attacker-writable directory, the `.psysh.php` auto-load behavior can be abused in the same way to execute attacker-controlled code under the victim’s privileges. Versions 0.11.23 and 0.12.19 patch the issue. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H 6.7 (MEDIUM) MEDIUM · 58.1/100 0.3% prob · 23th pct 2026-01-30 2026-02-03 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (2)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
MEDIUM MEDIUM 6.3 |
CVE-2026-45073 exact |
composer: symfony/cache 7.1.1 direct defined in: symfony/symfony-demo |
CWE-89 SQL Injection |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, PdoAdapter::doClear() builds a DELETE statement using a namespace derived from the caller-supplied $prefix without binding or escaping it, allowing a caller able to influence $prefix to break out of the LIKE literal and alter query semantics or deletion scope. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.3 (MEDIUM) MEDIUM · 58.2/100 0.5% prob · 39th pct 7.2.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit6 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
LOW LOW 3.1 |
CVE-2024-50342 exact |
composer: symfony/http-client 7.1.1 direct defined in: symfony/symfony-demo |
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor |
symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. | 7.1.8 | nvdosvpackagist | ||
Description
symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of versions 5.4.46, 6.4.14, and 7.1.7 the `NoPrivateNetworkHttpClient` now filters blocked IPs earlier to prevent such leaks. All users are advised to upgrade. There are no known workarounds for this vulnerability. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N 3.1 (LOW) LOW · 32.8/100 0.5% prob · 40th pct 7.1.8 2024-11-13 2026-02-03 exact nvd+osv+packagist External links (3)
Patch / Commit1 link
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
| Priority / severity | Advisory ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
HIGH MEDIUM 7.3 |
CVE-2024-50340 exact |
composer: symfony/runtime 7.1.1 direct defined in: symfony/symfony-demo |
CWE-74 Improper Neutralization of Special Elements (Injection) |
symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. | 7.1.7 | nvdosvpackagist | ||
Description
symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any URL with a special crafted query string, they are able to change the environment or debug mode used by the kernel when handling the request. As of versions 5.4.46, 6.4.14, and 7.1.7 the `SymfonyRuntime` now ignores the `argv` values for non-SAPI PHP runtimes. All users are advised to upgrade. There are no known workarounds for this vulnerability. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L 7.3 (MEDIUM) HIGH · 78.2/100 64.8% prob · 99th pct 7.1.7 2024-11-05 2024-11-07 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
HIGH HIGH 7.5 |
GHSA-g2gp-3wwq-f4ph exact |
composer: league/commonmark 2.4.2 direct defined in: symfony/symfony-demo |
— | league/commonmark: Denial of service via adjacent inline attribute blocks ### Impact With the Attributes extension enabled, `AttributesListener::findTargetAndDirection()` resolves each attribute node's target by walking outward through it… | 2.9.0 | osvpackagist | ||
Description
league/commonmark: Denial of service via adjacent inline attribute blocks
### Impact
With the Attributes extension enabled, `AttributesListener::findTargetAndDirection()` resolves each attribute node's target by walking outward through its siblings. For a run of N adjacent inline attribute blocks placed at the start of a block (with nothing to their left), each node scans the **entire** sibling list to the far-right end before giving up and falling back to the parent. Each resolution is therefore Θ(N) and the whole run is **Θ(N²)**.
Reaching the path requires `AttributesExtension` (opt-in, but first-party: `League\CommonMark\Extension\Attributes\AttributesExtension`). No other configuration matters — the quadratic walk runs unconditionally during parsing and is **not** gated by the `attributes/allow` allow-list, the `on*` hardening added in 2.7.0, or `allow_unsafe_links`. An unauthenticated attacker can submit a **~32 KB** input (`{#a}` repeated 8,000 times) that takes **over 5 seconds** to convert, with time growing quadratically in input length — a cheap denial of service. Availability impact only. **The Attributes extension was introduced in 1.5.0 (May 2020) with this outward-walk resolver present from the first commit, so all releases from 1.5.0 onward (including every 2.x) are affected.**
### Workarounds
There is no library-level configuration that gates the quadratic walk. Integrators who cannot upgrade can only reduce exposure indirectly:
- **Disable the Attributes extension** for untrusted input, or
- **Impose a strict maximum input length before conversion** — noting that because the cost is quadratic, even a modest cap must be small to meaningfully bound worst-case CPU.
Upgrading to a release containing the fix is recommended. Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 7.5 (HIGH) HIGH · 75/100 2.9.0 2026-08-06 2026-08-06 exact osv+packagist External links (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
HIGH HIGH 7.5 |
GHSA-jfm3-95jq-q3rf exact |
composer: league/commonmark 2.4.2 direct defined in: symfony/symfony-demo |
— | league/commonmark: Denial of service via duplicate footnote definitions ### Impact The Footnote extension records one backref per footnote *reference* and then appends the **entire** backref list for **every** footnote *definition* block… | 2.9.0 | osvpackagist | ||
Description
league/commonmark: Denial of service via duplicate footnote definitions
### Impact
The Footnote extension records one backref per footnote *reference* and then appends the **entire** backref list for **every** footnote *definition* block in the document, without ever de-duplicating or removing repeated definitions of the same label (`GatherFootnotesListener`, populated by `NumberFootnotesListener`). A document that references a single label N times and also supplies N duplicate `[^a]:` definitions of that label therefore produces **N × N** `FootnoteBackref` nodes, so output size, parse time, and peak memory are all **O(N²)**.
Reaching the vulnerable path requires `FootnoteExtension` to be registered on the `Environment`. This is opt-in, but is a commonly enabled GFM-style feature; no other non-default configuration is required. An unauthenticated attacker can expand a **~10 KB** request into a **~62 MB** HTML response, **~3 s** of CPU, and **~440 MB** of peak memory — enough to OOM-kill a default 128 MB PHP worker and deny service. Availability impact only; no confidentiality or integrity effect. **The Footnote extension was introduced in 1.5.0 (May 2020) with this backref logic present from the first commit, so all releases from 1.5.0 onward (including every 2.x through 2.8.x) are affected.**
### Workarounds
There is no library-level option to cap the number of footnotes, references, or definitions, so no configuration switch prevents the amplification. Integrators who cannot upgrade should:
- **Disable the Footnote extension** for untrusted input, or
- **Enforce a strict input-size limit before conversion** — but note this is a weak control here, since the ~10 KB payload that already triggers the 62 MB / ~440 MB blowup is well within typical request-body limits, so any cap must be aggressively small to help.
Upgrading to the patched release is the recommended remediation. Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 7.5 (HIGH) HIGH · 75/100 2.9.0 2026-08-06 2026-08-06 exact osv+packagist External links (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
HIGH HIGH 7.5 |
GHSA-mh25-x5hq-wrqp exact |
composer: league/commonmark 2.4.2 direct defined in: symfony/symfony-demo |
— | league/commonmark: Denial of service via colliding heading slugs ### Impact `UniqueSlugNormalizer::normalize()` makes each slug document-unique by searching for an unused numeric suffix, but **restarts that search from `1` on every collis… | 2.9.0 | osvpackagist | ||
Description
league/commonmark: Denial of service via colliding heading slugs
### Impact
`UniqueSlugNormalizer::normalize()` makes each slug document-unique by searching for an unused numeric suffix, but **restarts that search from `1` on every collision**. The k-th heading that collapses to the same base slug performs k−1 array lookups, so K colliding slugs cost Σ(k−1) = **O(K²)**. An attacker can force every heading onto a single base slug trivially — many empty ATX headings, identical heading text, or punctuation-only headings that normalize to the empty string.
The path is reached whenever the shared slug normalizer runs over attacker-controlled text. That happens when `HeadingPermalinkExtension` is registered (its `HeadingPermalinkProcessor` normalizes every heading), independently through `FootnoteExtension` (its `AnonymousFootnoteRefParser` normalizes every `^[label]` reference), and on any `TableOfContentsExtension` site (which requires `HeadingPermalinkExtension` to be co-registered). The default `slug_normalizer/unique` setting (`UniqueSlugNormalizerInterface::PER_DOCUMENT`) accumulates collisions across the whole document. No authentication is required — a small document body turns into seconds of CPU and denies service. Availability impact only. **`UniqueSlugNormalizer` was introduced in 2.0.0 (first shipped in 2.0.0-beta1, May 2021); the 1.x heading-permalink slug generator performed no de-duplication and is not affected. All 2.x releases (including 2.8.x) are affected.**
### Workarounds
Integrators who cannot upgrade immediately can:
- **Set `slug_normalizer/unique` to `false` / `UniqueSlugNormalizerInterface::DISABLED`**, which stops the de-duplication scan entirely — at the cost of losing id uniqueness (colliding headings then share an anchor).
- **Disable `HeadingPermalinkExtension`** (and `TableOfContentsExtension`, which depends on it), and `FootnoteExtension` where anonymous footnotes reach the same normalizer, for untrusted Markdown.
- **Cap the accept… Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 7.5 (HIGH) HIGH · 75/100 2.9.0 2026-08-06 2026-08-06 exact osv+packagist External links (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM HIGH 7.5 |
CVE-2026-71488 exact |
composer: league/commonmark 2.4.2 direct defined in: symfony/symfony-demo |
CWE-407 Inefficient Algorithmic Complexity CWE-1050 |
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths… | 2.9.0 | nvdosvpackagist | ||
Description
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause the parser to have quadratic time complexity when converting, because several parsing paths repeatedly rescan growing portions of a line to translate between character positions and byte positions, and the Autolink extension can also copy and validate the remaining line at every URL-like prefix, allowing an attacker who can submit Markdown for conversion to consume disproportionate CPU time with a comparatively small request. This issue is fixed in 2.9.0. Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 7.5 (HIGH) MEDIUM · 65.6/100 0.3% prob · 28th pct 2.9.0 2026-08-06 2026-08-21 exact nvd+osv+packagist External links (6)
Patch / Commit4 links
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM HIGH 7.5 |
CVE-2026-86429 exact |
composer: league/commonmark 2.4.2 direct defined in: symfony/symfony-demo |
CWE-407 Inefficient Algorithmic Complexity |
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. | 2.9.1 | nvdosvpackagist | ||
Description
The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its SmartPunctExtension and AttributesExtension. When either extension is explicitly registered on the Environment (they are not enabled by default and are excluded from the standard CommonMark and GitHub-Flavored Markdown converters), an unauthenticated attacker can submit small, specially crafted Markdown documents — such as text alternating with unpaired quotes, contiguous runs of block-level attribute blocks, or repeated class attributes — to trigger disproportionate CPU consumption and cause a denial of service. Fixed in 2.9.1. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.5 (HIGH) MEDIUM · 64.4/100 0.3% prob · 22th pct 2.9.1 2026-09-01 2026-09-08 exact nvd+osv+packagist External links (3)
Vendor advisory1 link
Third-party advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM HIGH 7.5 |
CVE-2026-86430 exact |
composer: league/commonmark 2.4.2 direct defined in: symfony/symfony-demo |
CWE-407 Inefficient Algorithmic Complexity |
league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. | 2.9.1 | nvdosvpackagist | ||
Description
league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link label lookup, and emphasis delimiter processing that perform super-linear work on crafted input. Attackers can submit specially crafted Markdown with long backtick runs, nested brackets, or delimiter sequences to consume disproportionate CPU time and prevent legitimate requests from completing. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.5 (HIGH) MEDIUM · 64.2/100 0.3% prob · 21th pct 2.9.1 2026-09-01 2026-09-08 exact nvd+osv+packagist External links (3)
Patch / Commit1 link
Third-party advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM HIGH 7.5 |
CVE-2024-58382 exact |
composer: league/commonmark 2.4.2 direct defined in: symfony/symfony-demo |
CWE-407 Inefficient Algorithmic Complexity |
league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service. | 2.6.0 | nvdosvpackagist | ||
Description
league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to cause denial of service. Attackers can submit carefully crafted Markdown inputs designed to trigger worst-case performance, and sending multiple requests in parallel exhausts CPU resources and PHP-FPM processes. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.5 (HIGH) MEDIUM · 64.1/100 0.3% prob · 21th pct 2.6.0 2024-12-09 2026-09-10 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM HIGH 7.5 |
CVE-2026-86428 exact |
composer: league/commonmark 2.4.2 direct defined in: symfony/symfony-demo |
CWE-407 Inefficient Algorithmic Complexity |
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. | 2.10.0 | nvdosvpackagist | ||
Description
commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing distinctly-named attributes. Attackers can submit Markdown with numerous distinct attribute names to cause quadratic-time attribute merging and filtering, consuming disproportionate CPU resources and preventing legitimate requests from completing. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.5 (HIGH) MEDIUM · 64.1/100 0.3% prob · 21th pct 2.10.0 2026-09-01 2026-09-08 exact nvd+osv+packagist External links (3)
Vendor advisory1 link
Third-party advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 6.9 |
CVE-2026-49208 exact |
composer: symfony/ux-live-component 2.17.0 direct defined in: symfony/symfony-demo |
CWE-20 Improper Input Validation |
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit format is configured, Symfony\UX\LiveComponent\LiveComponentHydrator::hydrateObjectValue()… | 2.36.0 | nvdosvpackagist | ||
Description
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit format is configured, Symfony\UX\LiveComponent\LiveComponentHydrator::hydrateObjectValue() falls back to new $className($value), allowing client-supplied relative strings such as now, tomorrow, or +10 years to move a writable, format-less date prop past time-based business logic checks. This issue is fixed in versions 2.36.0 and 3.1.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.9 (MEDIUM) MEDIUM · 62.2/100 0.4% prob · 35th pct 2.36.0 2026-05-29 2026-09-10 exact nvd+osv+packagist External links (4)
Affected CPE configurations (2)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM LOW 6.9 |
CVE-2026-49212 exact |
composer: symfony/ux-live-component 2.17.0 direct defined in: symfony/symfony-demo |
CWE-345 Insufficient Verification of Data Authenticity |
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\LiveComponent\LiveComponentHydrator covered only sorted prop key/value pairs and did not include the component name, the sl… | 2.36.0 | nvdosvpackagist | ||
Description
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, the HMAC computed by Symfony\UX\LiveComponent\LiveComponentHydrator covered only sorted prop key/value pairs and did not include the component name, the slot identifier (props vs propsFromParent), or request context, allowing a signed blob minted for one component or slot to be replayed in another and set a read-only prop on a target component. This issue is fixed in versions 2.36.0 and 3.1.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.9 (LOW) MEDIUM · 58.3/100 0.2% prob · 16th pct 2.36.0 2026-05-29 2026-09-10 exact nvd+osv+packagist External links (4)
Affected CPE configurations (2)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 6.4 |
CVE-2025-46734 exact |
composer: league/commonmark 2.4.2 direct defined in: symfony/symfony-demo |
CWE-79 Cross-site Scripting (XSS) |
league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert malicious JavaScript calls … | 2.7.0 | nvdosvpackagist | ||
Description
league/commonmark is a PHP Markdown parser. A cross-site scripting (XSS) vulnerability in the Attributes extension of the league/commonmark library (versions 1.5.0 through 2.6.x) allows remote attackers to insert malicious JavaScript calls into HTML. The league/commonmark library provides configuration options such as `html_input: 'strip'` and `allow_unsafe_links: false` to mitigate cross-site scripting (XSS) attacks by stripping raw HTML and disallowing unsafe links. However, when the Attributes Extension is enabled, it introduces a way for users to inject arbitrary HTML attributes into elements via Markdown syntax using curly braces. Version 2.7.0 contains three changes to prevent this XSS attack vector: All attributes starting with `on` are considered unsafe and blocked by default; support for an explicit allowlist of allowed HTML attributes; and manually-added `href` and `src` attributes now respect the existing `allow_unsafe_links` configuration option. If upgrading is not feasible, please consider disabling the `AttributesExtension` for untrusted users and/or filtering the rendered HTML through a library like HTMLPurifier. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N 6.4 (MEDIUM) MEDIUM · 57.2/100 0.4% prob · 30th pct 2.7.0 2025-05-05 2026-03-20 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 6.3 |
CVE-2026-33347 exact |
composer: league/commonmark 2.4.2 direct defined in: symfony/symfony-demo |
CWE-79 Cross-site Scripting (XSS) CWE-185Incorrect Regular Expression +1 |
league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matchi… | — | nvdosvpackagist | ||
Description
league/commonmark is a PHP Markdown parser. From version 2.3.0 to before version 2.8.2, the DomainFilteringAdapter in the Embed extension is vulnerable to an allowlist bypass due to a missing hostname boundary assertion in the domain-matching regex. An attacker-controlled domain like youtube.com.evil passes the allowlist check when youtube.com is an allowed domain. This issue has been patched in version 2.8.2. Weaknesses (CWE) (3)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.3 (MEDIUM) MEDIUM · 53.5/100 0.2% prob · 16th pct 2026-03-19 2026-03-27 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Vendor advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 5.3 |
GHSA-mj63-m3rc-8ppr exact |
composer: league/commonmark 2.4.2 direct defined in: symfony/symfony-demo |
— | league/commonmark: Denial of service via deeply nested XML output ### Impact `XmlRenderer` pretty-prints XML by emitting depth-proportional indentation whitespace for **every** opening and closing tag. | 2.9.0 | osvpackagist | ||
Description
league/commonmark: Denial of service via deeply nested XML output
### Impact
`XmlRenderer` pretty-prints XML by emitting depth-proportional indentation whitespace for **every** opening and closing tag. For a tree of depth n, the indentation alone sums to **O(n²)** bytes of output (and corresponding memory), reachable through `MarkdownToXmlConverter` — e.g. `str_repeat('> ', $depth) . "x\n"`, a single line of nested blockquotes — or through a direct `XmlRenderer::renderDocument()` call on an attacker-influenced AST.
This affects applications that convert untrusted Markdown to XML, which is an **opt-in** output path. The parser's `max_nesting_level` bounds the depth of *parser-created* trees, but its default is high enough to reach damaging sizes, can be raised by the host application, and does not constrain custom or programmatically built ASTs handed straight to the renderer. The result is a memory / output-size amplification rather than a hard crash, which is why this issue is rated **Medium** rather than High. No confidentiality or integrity impact. XML rendering was introduced in 2.0.0 (first shipped in 2.0.0-beta1, June 2021) and has emitted depth-proportional indentation ever since, so all 2.x releases are affected (verified against 2.8.x, clean upstream `1902f60f`). 1.x has no XML renderer and is not affected.
### Workarounds
Applications converting untrusted Markdown to XML should:
- **Lower `max_nesting_level`** to a conservative value appropriate to expected content, so the parser refuses to build extremely deep trees. This is the most direct lever for parser-produced ASTs, but does not protect trees built programmatically and passed straight to `XmlRenderer`.
- **Cap input size before conversion**, since the amplification is driven by input-proportional depth.
- **Constrain XML consumers** with memory / output-size limits (and streaming or size caps on any downstream XML parser or storage) so one request cannot allocate unbounded output.
- **Prefer H… Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L 5.3 (MEDIUM) MEDIUM · 53/100 2.9.0 2026-08-06 2026-08-06 exact osv+packagist External links (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 6.1 |
CVE-2026-71478 exact |
composer: league/commonmark 2.4.2 direct defined in: symfony/symfony-demo |
CWE-79 Cross-site Scripting (XSS) CWE-86 +1 |
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, … | — | nvdosvpackagist | ||
Description
league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsafe-link filter can be bypassed by embedding control bytes, such as a tab, carriage return, line feed, or leading C0 control character, in a javascript: URL that browsers discard before parsing the scheme, causing the browser to still execute the script even when the unsafe-link filter is enabled. This issue is fixed in 2.9.0. Weaknesses (CWE) (3)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 6.1 (MEDIUM) MEDIUM · 52/100 0.2% prob · 16th pct 2026-08-06 2026-08-21 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 6.1 |
CVE-2025-47946 exact |
composer: symfony/ux-live-component 2.17.0 direct defined in: symfony/symfony-demo |
CWE-79 Cross-site Scripting (XSS) |
Symfony UX is an initiative and set of libraries to integrate JavaScript tools into applications. Prior to version 2.25.1, rendering `{{ attributes }}` or using any method that returns a `ComponentAttributes` instance (e.g. | 2.25.1 | nvdosvpackagist | ||
Description
Symfony UX is an initiative and set of libraries to integrate JavaScript tools into applications. Prior to version 2.25.1, rendering `{{ attributes }}` or using any method that returns a `ComponentAttributes` instance (e.g. `only()`, `defaults()`, `without()`) ouputs attribute values directly without escaping. If these values are unsafe (e.g. contain user input), this can lead to HTML attribute injection and XSS vulnerabilities. The issue is fixed in version `2.25.1` of `symfony/ux-twig-component` Those who use `symfony/ux-live-component` must also update it to `2.25.1` to benefit from the fix, as it reuses the `ComponentAttributes` class internally. As a workaround, avoid rendering `{{ attributes }}` or derived objects directly if it may contain untrusted values.
Instead, use `{{ attributes.render('name') }}` for safe output of individual attributes. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 6.1 (MEDIUM) MEDIUM · 51.9/100 0.2% prob · 16th pct 2.25.1 2025-05-19 2025-08-29 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 6.1 |
CVE-2025-47946 exact |
composer: symfony/ux-twig-component 2.17.0 direct defined in: symfony/symfony-demo |
CWE-79 Cross-site Scripting (XSS) |
Symfony UX is an initiative and set of libraries to integrate JavaScript tools into applications. Prior to version 2.25.1, rendering `{{ attributes }}` or using any method that returns a `ComponentAttributes` instance (e.g. | 2.25.1 | nvdosvpackagist | ||
Description
Symfony UX is an initiative and set of libraries to integrate JavaScript tools into applications. Prior to version 2.25.1, rendering `{{ attributes }}` or using any method that returns a `ComponentAttributes` instance (e.g. `only()`, `defaults()`, `without()`) ouputs attribute values directly without escaping. If these values are unsafe (e.g. contain user input), this can lead to HTML attribute injection and XSS vulnerabilities. The issue is fixed in version `2.25.1` of `symfony/ux-twig-component` Those who use `symfony/ux-live-component` must also update it to `2.25.1` to benefit from the fix, as it reuses the `ComponentAttributes` class internally. As a workaround, avoid rendering `{{ attributes }}` or derived objects directly if it may contain untrusted values.
Instead, use `{{ attributes.render('name') }}` for safe output of individual attributes. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N 6.1 (MEDIUM) MEDIUM · 51.9/100 0.2% prob · 16th pct 2.25.1 2025-05-19 2025-08-29 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM LOW 5.3 |
CVE-2026-49209 exact |
composer: symfony/ux-live-component 2.17.0 direct defined in: symfony/symfony-demo |
CWE-770 Allocation of Resources Without Limits or Throttling |
Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller\BatchActionController::__invoke() iterates over the client-supplied actions array and issues a full HttpKernel sub-requ… | 2.36.0 | nvdosvpackagist | ||
Description
Symfony UX is a JavaScript ecosystem for Symfony. From 2.5.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Controller\BatchActionController::__invoke() iterates over the client-supplied actions array and issues a full HttpKernel sub-request for each entry; because the array size is never bounded, an authenticated client can submit a single _batch request containing thousands of actions and exhaust CPU, memory, and database connections on the application server. This issue is fixed in versions 2.36.0 and 3.1.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.3 (LOW) MEDIUM · 51.5/100 0.6% prob · 45th pct 2.36.0 2026-05-29 2026-09-10 exact nvd+osv+packagist External links (4)
Affected CPE configurations (2)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM LOW 5.3 |
CVE-2026-46629 exact |
composer: twig/intl-extra 3.10.0 direct defined in: symfony/symfony-demo |
CWE-770 Allocation of Resources Without Limits or Throttling |
Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays keyed by template-controlled filter arguments such as locale, pattern, and attrs, allowing a template t… | 3.26.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.26.0, twig/intl-extra memoises IntlDateFormatter and NumberFormatter instances in arrays keyed by template-controlled filter arguments such as locale, pattern, and attrs, allowing a template to allocate many ICU formatter objects that remain pinned for the lifetime of the Twig\Environment. This issue is fixed in version 3.26.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.3 (LOW) MEDIUM · 51.3/100 0.5% prob · 45th pct 3.26.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 5.3 |
CVE-2026-48761 exact |
composer: symfony/html-sanitizer 7.1.1 direct defined in: symfony/symfony-demo |
CWE-79 Cross-site Scripting (XSS) CWE-1023 |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlAttributeSanitizer::getSupportedAttributes() omitted URL-bearing attributes on <object>, <applet>, <iframe>, and <img>, and <meta http-equiv="refresh"> URLs inside content bypassed URL sanitization, allowing explicitly enabled elements or attributes to pass javascript: and similar payloads into sanitized output. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13. Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.3 (MEDIUM) MEDIUM · 48/100 0.3% prob · 28th pct 7.2.0 2026-05-26 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 5.3 |
CVE-2026-48760 exact |
composer: symfony/html-sanitizer 7.1.1 direct defined in: symfony/symfony-demo |
CWE-451 UI Misrepresentation of Critical Information CWE-1007 |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0 until 6.4.41, 7.4.13, and 8.0.13, UrlSanitizer::parse() rejected raw BiDi formatting characters but not percent-encoded forms and used an ASCII-only whitespace check, allowing sanitized URLs to retain visual-spoofing characters that downstream consumers could decode or display. This issue is fixed in versions 6.4.41, 7.4.13, and 8.0.13. Weaknesses (CWE) (2)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.3 (MEDIUM) MEDIUM · 47.9/100 0.3% prob · 27th pct 7.2.0 2026-05-26 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM LOW 5.1 |
CVE-2026-46637 exact |
composer: twig/markdown-extra 3.10.0 direct defined in: symfony/symfony-demo |
CWE-116 Improper Encoding or Escaping of Output CWE-79Cross-site Scripting (XSS) |
Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, U… | 3.26.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.26.0, several filters in twig/markdown-extra and twig/cssinliner-extra are registered with is_safe => [all], causing Twig to treat plain text or HTML output as safe in HTML, JavaScript, CSS, URL, and other contexts where the output is not properly escaped. This issue is fixed in version 3.26.0. Weaknesses (CWE) (2)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.1 (LOW) MEDIUM · 45.5/100 0.3% prob · 23th pct 3.26.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (5)
Patch / Commit3 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 5.1 |
CVE-2026-30838 exact |
composer: league/commonmark 2.4.2 direct defined in: symfony/symfony-demo |
CWE-79 Cross-site Scripting (XSS) |
league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and the closing >. | — | nvdosvpackagist | ||
Description
league/commonmark is a PHP Markdown parser. Prior to version 2.8.1, the DisallowedRawHtml extension can be bypassed by inserting a newline, tab, or other ASCII whitespace character between a disallowed HTML tag name and the closing >. For example, <script\n> would pass through unfiltered and be rendered as a valid HTML tag by browsers. This is a cross-site scripting (XSS) vector for any application that relies on this extension to sanitize untrusted user input. All applications using the DisallowedRawHtml extension to process untrusted markdown are affected. Applications that use a dedicated HTML sanitizer (such as HTML Purifier) on the rendered output are not affected. This issue has been patched in version 2.8.1. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.1 (MEDIUM) MEDIUM · 43.3/100 0.2% prob · 12th pct 2026-03-06 2026-03-20 exact nvd+osv+packagist External links (2)
Vendor advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
LOW MEDIUM 2.3 |
CVE-2026-45064 exact |
composer: symfony/html-sanitizer 7.1.1 direct defined in: symfony/symfony-demo |
CWE-451 UI Misrepresentation of Critical Information CWE-1007 |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlSanitizer::parse() passes Unicode explicit-direction BiDi formatting characters through into sanitized href and src attributes, allowing sanitized content to display a link destination that visually differs from the actual destination and enabling phishing-style visual spoofing. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (2)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 2.3 (MEDIUM) LOW · 23.9/100 0.3% prob · 27th pct 7.2.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit4 links
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
LOW MEDIUM 2.3 |
CVE-2026-45066 exact |
composer: symfony/html-sanitizer 7.1.1 direct defined in: symfony/symfony-demo |
CWE-184 Incomplete List of Disallowed Inputs CWE-436Interpretation Conflict |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, HtmlSanitizer URL sanitization can allow off-allowlist URLs through allowLinkHosts() or allowMediaHosts() because UrlSanitizer::parse() follows RFC 3986 while browsers follow WHATWG URL parsing, and because <area href> is checked against the media policy rather than the link policy. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (2)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 2.3 (MEDIUM) LOW · 23.9/100 0.3% prob · 27th pct 7.2.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
LOW MEDIUM 2.3 |
CVE-2026-49210 exact |
composer: symfony/ux-live-component 2.17.0 direct defined in: symfony/symfony-demo |
CWE-79 Cross-site Scripting (XSS) |
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::createHtml() interpolates the client-controlled children[id].tag value from LiveComponentSubsc… | 2.36.0 | nvdosvpackagist | ||
Description
Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, Symfony\UX\LiveComponent\Util\ChildComponentPartialRenderer::createHtml() interpolates the client-controlled children[id].tag value from LiveComponentSubscriber and InterceptChildComponentRenderSubscriber directly into HTML as a tag name without escaping or validation, allowing arbitrary HTML, including <script> tags, on any Live Component re-render that contains at least one child component. This issue is fixed in versions 2.36.0 and 3.1.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 2.3 (MEDIUM) LOW · 23.9/100 0.3% prob · 27th pct 2.36.0 2026-05-29 2026-09-10 exact nvd+osv+packagist External links (4)
Affected CPE configurations (2)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
LOW LOW 2.1 |
CVE-2026-45753 exact |
composer: symfony/html-sanitizer 7.1.1 direct defined in: symfony/symfony-demo |
CWE-79 Cross-site Scripting (XSS) CWE-184Incomplete List of Disallowed Inputs |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.1.0-BETA1 until 6.4.40, 7.4.12, and 8.0.12, UrlAttributeSanitizer::getSupportedAttributes() omits URL-valued attributes including action, formaction, poster, and cite, so configurations that admit those attributes can leave javascript: URIs unsanitized and enable XSS when the resulting HTML is rendered or a victim submits a form or clicks a button. This issue is fixed in versions 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (2)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 2.1 (LOW) LOW · 22.3/100 0.3% prob · 27th pct 7.2.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
HIGH HIGH 7.3 |
CVE-2025-64500 exact |
composer: symfony/http-foundation 7.1.1 direct defined in: symfony/symfony-demo |
CWE-647 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Starting in version 2.0.0 and prior to version 5.4.50, 6.4.29, and 7.3.7, the `Request` class improperly interprets some `PATH_INFO` in a way that leads to representing some URLs with a path that doesn't start with a `/`. This can allow bypassing some access control rules that are built with this `/`-prefix assumption. Starting in versions 5.4.50, 6.4.29, and 7.3.7, the `Request` class now ensures that URL paths always start with a `/`. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L 7.3 (HIGH) HIGH · 72.3/100 1.3% prob · 70th pct 7.2.0 2025-11-12 2026-09-10 exact nvd+osv+packagist External links (5)
Patch / Commit1 link
Third-party advisory3 links
Affected CPE configurations (6)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 6.9 |
CVE-2026-48736 exact |
composer: symfony/http-foundation 7.1.1 direct defined in: symfony/symfony-demo |
CWE-184 Incomplete List of Disallowed Inputs CWE-918Server-Side Request Forgery (SSRF) |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and IpUtils::PRIVATE_SUBNETS omitted IPv6 transition prefixes such as 6to4, NAT64, Teredo, and IPv4-compatible IPv6, allowing attacker-supplied URLs to represent private IPv4 targets in forms that IpUtils::isPrivateIp() did not block. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13. Weaknesses (CWE) (2)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.9 (MEDIUM) MEDIUM · 64.4/100 0.6% prob · 46th pct 7.2.0 2026-05-26 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit6 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
LOW LOW 3.1 |
CVE-2024-50345 exact |
composer: symfony/http-foundation 7.1.1 direct defined in: symfony/symfony-demo |
CWE-601 URL Redirection to Untrusted Site (Open Redirect) |
symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. | 7.1.7 | nvdosvpackagist | ||
Description
symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters the same way browsers do. As a result, an attacker can trick a validator relying on the `Request` class to redirect users to another domain. The `Request::create` methods now assert the URI does not contain invalid characters as defined by https://url.spec.whatwg.org/. This issue has been patched in versions 5.4.46, 6.4.14, and 7.1.7. Users are advised to upgrade. There are no known workarounds for this vulnerability. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N 3.1 (LOW) LOW · 33.8/100 0.6% prob · 45th pct 7.1.7 2024-11-05 2025-11-03 exact nvd+osv+packagist External links (4)
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
HIGH MEDIUM 8.7 |
CVE-2026-45068 exact |
composer: symfony/mailer 7.1.1 direct defined in: symfony/symfony-demo |
CWE-88 Argument Injection |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, SendmailTransport in -t mode appended recipient addresses to the sendmail command line without a -- end-of-options separator, allowing an address beginning with - to be interpreted as a sendmail command-line option instead of an address. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.7 (MEDIUM) HIGH · 78.3/100 0.5% prob · 43th pct 7.2.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit6 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
MEDIUM HIGH 6.3 |
CVE-2026-45067 exact |
composer: symfony/mime 7.1.1 direct defined in: symfony/symfony-demo |
CWE-93 CRLF Injection |
### Description `Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply-to) flows through; its constructor is documented as validating the address and throwing on invalid input, so developers… | 7.2.0 | nvdosvpackagist | ||
Description
### Description
`Symfony\Component\Mime\Address` is the value-object every Symfony Mailer address (to/cc/bcc/from/reply-to) flows through; its constructor is documented as validating the address and throwing on invalid input, so developers treat it as a security boundary.
The constructor accepts email addresses whose local-part (the part before `@`) is an RFC-5322 *quoted string* containing raw `\r\n` bytes — e.g. `"x\r\nBcc: attacker@evil"@example.com`. The stored address is later emitted verbatim into (1) the rendered message headers and (2) `SmtpTransport`'s `MAIL FROM:<...>` / `RCPT TO:<...>` protocol lines, turning the embedded CRLF into a new mail header and/or a new SMTP command.
### Resolution
The `Address` constructor now rejects addresses containing line breaks.
The patch for this issue is available [here](https://github.com/symfony/symfony/commit/dc2dbd29211eb4ddc451373fa1374fb926e94604) for branch 5.4.
### Credits
We would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.3 (HIGH) MEDIUM · 59.9/100 0.6% prob · 47th pct 7.2.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit5 links
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 6.3 |
CVE-2026-45070 exact |
composer: symfony/mime 7.1.1 direct defined in: symfony/symfony-demo |
CWE-93 CRLF Injection |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Mime\Header\ParameterizedHeader validates and encodes parameter values but emits parameter names verbatim, allowing a caller that derives a parameter name from untrusted input to include CRLF or other non-token bytes and inject additional headers into rendered structured mail headers such as Content-Type or Content-Disposition. This issue is reported as fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.3 (MEDIUM) MEDIUM · 57/100 0.4% prob · 33th pct 7.2.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit6 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
MEDIUM LOW 6.9 |
CVE-2026-46644 exact |
composer: symfony/polyfill-intl-idn 1.29.0 direct defined in: symfony/symfony-demo |
CWE-1289 | Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. | 1.38.1 | nvdosvpackagist | ||
Description
Symfony Polyfill backports PHP features and provides compatibility layers for extensions and functions. From 1.17.1 until 1.38.1, symfony/polyfill-intl-idn accepts xn-- labels whose Punycode payload is empty or decodes to ASCII-only code points because Idn::process() does not enforce the UTS #46 revision 33 requirement that decoded ACE labels contain at least one non-ASCII code point. Originally unequal domain names can be regarded as equal, which can lead to blacklist bypassing, inconsistent URL parsing, and server-side request forgery in applications using the polyfill to canonicalise or compare hostnames. This issue is fixed in version 1.38.1. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.9 (LOW) MEDIUM · 64/100 0.5% prob · 44th pct 1.38.1 2026-05-26 2026-09-10 exact nvd+osv+packagist External links (4)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
HIGH HIGH 8.3 |
CVE-2026-45077 exact |
composer: symfony/monolog-bridge 7.1.1 direct defined in: symfony/symfony-demo |
CWE-502 Deserialization of Untrusted Data CWE-668Exposure of Resource to Wrong Sphere |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and processes each received frame with unserialize(base64_decode($message)) without authentication, integrity checks, or an allowed_classes allowlist, allowing any reachable host to submit attacker-chosen serialized PHP payloads that can crash the listener and may trigger object-injection gadget effects. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (2)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.3 (HIGH) HIGH · 76.5/100 0.7% prob · 50th pct 7.2.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit6 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
HIGH HIGH 8.4 |
CVE-2024-51736 exact |
composer: symfony/process 7.1.1 direct defined in: symfony/symfony-demo |
CWE-77 Command Injection |
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. | 7.1.7 | nvdosvpackagist | ||
Description
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class when preparing command arguments, leading to possible hijacking. This issue has been addressed in release versions 5.4.46, 6.4.14, and 7.1.7. Users are advised to upgrade. There are no known workarounds for this vulnerability. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N 8.4 (HIGH) HIGH · 74.5/100 0.4% prob · 36th pct 7.1.7 2024-11-05 2026-09-10 exact nvd+osv+packagist External links (2)
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
MEDIUM MEDIUM 5.1 |
CVE-2026-48784 exact |
composer: symfony/routing 7.1.1 direct defined in: symfony/symfony-demo |
CWE-172 CWE-601 URL Redirection to Untrusted Site (Open Redirect) |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, UrlGenerator::doGenerate() used strtr() dot-segment encoding that skipped every other chained ../ or ./ segment, allowing attacker-controlled route parameters to generate URLs that collapse to a different path under RFC 3986 normalization. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13. Weaknesses (CWE) (2)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.1 (MEDIUM) MEDIUM · 46.5/100 0.3% prob · 29th pct 7.2.0 2026-05-26 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
LOW MEDIUM 2.3 |
CVE-2026-45065 exact |
composer: symfony/routing 7.1.1 direct defined in: symfony/symfony-demo |
CWE-185 Incorrect Regular Expression CWE-601URL Redirection to Untrusted Site (Open Redirect) |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, UrlGenerator validates route parameters against a pattern built as ^ plus the raw requirement plus $; with ungrouped alternations, middle alternatives match as unanchored substrings, allowing a value such as //evil.com to satisfy a common locale requirement and generate a protocol-relative off-site URL. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (2)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 2.3 (MEDIUM) LOW · 24.1/100 0.3% prob · 29th pct 7.2.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
LOW LOW 3.1 |
CVE-2024-50341 exact |
composer: symfony/security-bundle 7.1.1 direct defined in: symfony/symfony-demo |
CWE-287 Improper Authentication |
symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. | 7.1.3 | nvdosvpackagist | ||
Description
symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom `user_checker` defined on a firewall is not called when Login Programmaticaly with the `Security::login` method, leading to unwanted login. As of versions 6.4.10, 7.0.10 and 7.1.3 the `Security::login` method now ensure to call the configured `user_checker`. All users are advised to upgrade. There are no known workarounds for this vulnerability. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N 3.1 (LOW) LOW · 29.7/100 0.3% prob · 24th pct 7.1.3 2024-07-17 2024-11-07 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
HIGH HIGH 8.7 |
CVE-2026-48489 exact |
composer: symfony/security-http 7.1.1 direct defined in: symfony/symfony-demo |
CWE-863 Incorrect Authorization |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, DefaultAuthenticationFailureHandler honored the request-supplied _failure_path parameter when failure_forward: true was enabled, allowing an unauthenticated failing login request to dispatch a subrequest to access_control-protected GET routes that skipped firewall listeners. This issue is fixed in versions 5.4.53, 6.4.41, 7.4.13, and 8.0.13. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.7 (HIGH) HIGH · 79/100 0.6% prob · 47th pct 7.2.0 2026-05-26 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
HIGH HIGH 9.1 |
CVE-2026-45063 exact |
composer: symfony/security-http 7.1.1 direct defined in: symfony/symfony-demo |
CWE-290 Authentication Bypass by Spoofing |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user identifier from $_SERVER['SSL_CLIENT_S_DN'] with an unanchored regex that matches emailAddress= anywhere in the distinguished name, allowing an attacker with a trusted certificate containing emailAddress=victim inside another RDN value such as CN to authenticate as the victim. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 9.1 (HIGH) HIGH · 78.9/100 0.4% prob · 31th pct 7.2.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit6 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM HIGH 7.5 |
CVE-2024-51996 exact |
composer: symfony/security-http 7.1.1 direct defined in: symfony/symfony-demo |
CWE-287 Improper Authentication CWE-289 |
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. | 7.1.8 | nvdosvpackagist | ||
Description
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted in the database matches the username attached with the cookie, leading to authentication bypass. This vulnerability is fixed in 5.4.47, 6.4.15, and 7.1.8. Metadata
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 7.5 (HIGH) MEDIUM · 69.7/100 0.6% prob · 48th pct 7.1.8 2024-11-13 2024-11-15 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 7.6 |
CVE-2026-45074 exact |
composer: symfony/security-http 7.1.1 direct defined in: symfony/symfony-demo |
CWE-290 Authentication Bypass by Spoofing |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which reflects an attacker-controlled Host header when framework.trusted_hosts is not configured; an attacker controlling another application registered with the same CAS server can replay a victim ticket against the Symfony application and authenticate as the victim. This issue is fixed in versions 7.4.12 and 8.0.12. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.6 (MEDIUM) MEDIUM · 69/100 0.5% prob · 41th pct 7.2.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (5)
Patch / Commit4 links
Affected CPE configurations (2)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
HIGH HIGH 8.8 |
CVE-2026-24425 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-693 Protection Mechanism Failure |
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and red… | 3.26.0 | nvdosvpackagist | ||
Description
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PHP callables to sort, filter, map, and reduce filters. Attackers can exploit the runtime check that fails to use the current template source to bypass sandbox restrictions and execute arbitrary code when the sandbox is enabled through a source policy rather than globally. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.8 (HIGH) HIGH · 81.2/100 0.8% prob · 54th pct 3.26.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (4)
Third-party advisory1 link
Affected CPE configurations (2)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
HIGH CRITICAL 8.7 |
CVE-2026-46633 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-94 Code Injection |
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to termin… | 3.26.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.26.0, Compiler::string() does not escape single quotes when a template name from a {% use %} tag is placed inside a PHP single-quoted string literal, allowing a crafted template name to terminate the string and inject arbitrary PHP expressions into the compiled cache file. This issue is fixed in version 3.26.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.7 (CRITICAL) HIGH · 79.9/100 0.7% prob · 51th pct 3.26.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (5)
Patch / Commit3 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
HIGH MEDIUM 8.5 |
CVE-2024-45411 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-693 Protection Mechanism Failure |
Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0. | 3.11.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Under some circumstances, the sandbox security checks are not run which allows user-contributed templates to bypass the sandbox restrictions. This vulnerability is fixed in 1.44.8, 2.16.1, and 3.14.0. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H 8.5 (MEDIUM) HIGH · 79.3/100 0.8% prob · 57th pct 3.11.0 2024-09-09 2024-10-10 exact nvd+osv+packagist External links (6)
Patch / Commit3 links
Affected CPE configurations (3)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
HIGH HIGH 8.7 |
CVE-2026-46636 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-1336 | Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. | 3.27.0 | nvdpackagist | ||
Description
Twig is a template language for PHP. From version 1.0.0 to before version 3.27.0, SecurityPolicy::checkMethodAllowed() unconditionally whitelists all method calls on instances of Twig\Markup. Twig\Markup is not final, so subclasses inherit the bypass. An application that passes an object of a Markup-derived class into a sandboxed template (typically to mark a chunk of HTML as safe) inadvertently exposes every public method of that subclass to template authors, regardless of the configured allowedMethods list. This issue has been patched in version 3.27.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.7 (HIGH) HIGH · 75.5/100 0.4% prob · 30th pct 3.27.0 2026-05-27 2026-09-08 exact nvd+packagist External links (5)
Vendor advisory2 links
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
HIGH MEDIUM 7.7 |
CVE-2026-46634 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-693 Protection Mechanism Failure |
Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sa… | 3.26.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__<hash> name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sandboxed template that can call template_from_string and include to render an inner template without security policy enforcement. This issue is fixed in version 3.26.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.7 (MEDIUM) HIGH · 71.2/100 0.6% prob · 48th pct 3.26.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM HIGH 7.1 |
CVE-2026-46627 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-400 Uncontrolled Resource Consumption (DoS) |
Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustio… | 3.26.0 | nvdpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.26.0, the Twig sandbox does not prevent a template from consuming CPU, memory, or wall-clock time, even under the strictest allow-list, allowing untrusted templates to cause resource exhaustion. This issue is addressed in version 3.26.0 by documenting that the sandbox does not protect against resource exhaustion. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.1 (HIGH) MEDIUM · 65.7/100 0.5% prob · 45th pct 3.26.0 2026-05-20 2026-07-16 exact nvd+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 7.1 |
CVE-2026-48806 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-693 Protection Mechanism Failure CWE-863Incorrect Authorization |
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxE… | 3.27.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.27.0, ArrayExpression does not guard dynamic mapping keys that are coerced to strings, allowing PHP to invoke __toString() on a Stringable object used as a mapping key without calling SandboxExtension::ensureToStringAllowed(). This issue is fixed in version 3.27.0. Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.1 (MEDIUM) MEDIUM · 64/100 0.4% prob · 36th pct 3.27.0 2026-05-27 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Security advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM HIGH 7.1 |
CVE-2026-47732 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-863 Incorrect Authorization |
Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invo… | 3.26.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a Stringable operand without consulting SecurityPolicy::checkMethodAllowed(), allowing a sandboxed template author to invoke __toString() on objects reachable in the render context through conditional expressions, comparison operators, tests, template-loading tags, dynamic attribute names, spread arguments, the do tag, and the .. range operator. This issue is fixed in version 3.26.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.1 (HIGH) MEDIUM · 63.6/100 0.4% prob · 34th pct 3.26.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 7.1 |
CVE-2026-48807 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-693 Protection Mechanism Failure CWE-863Incorrect Authorization |
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringab… | 3.27.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.27.0, the sandbox __toString() checks do not fully cover Traversable values passed to join and replace filters or operands evaluated by the in and not in operators, allowing contained Stringable objects to be coerced to strings without consulting the sandbox policy. This issue is fixed in version 3.27.0. Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.1 (MEDIUM) MEDIUM · 62.9/100 0.4% prob · 31th pct 3.27.0 2026-05-27 2026-09-10 exact nvd+osv+packagist External links (3)
Security advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 6.0 |
CVE-2026-46638 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-693 Protection Mechanism Failure |
Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbox without re-invoking checkSecurity(), allowing the cached template to use tags, filters, a… | 3.26.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.26.0, {% sandbox %}{% include %} can include a template that was previously loaded outside the sandbox without re-invoking checkSecurity(), allowing the cached template to use tags, filters, and functions that should have been denied by SecurityPolicy::checkSecurity(). This issue is fixed in version 3.26.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.0 (MEDIUM) MEDIUM · 56/100 0.5% prob · 40th pct 3.26.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM MEDIUM 6.0 |
CVE-2026-48808 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-693 Protection Mechanism Failure CWE-863Incorrect Authorization |
Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are… | 3.27.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but does not forward the current Source to SandboxExtension::checkPropertyAllowed(), so SourcePolicyInterface decisions are lost and a template author can read public or magic properties not allowed by the sandbox policy. This issue is fixed in version 3.27.0. Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.0 (MEDIUM) MEDIUM · 54.9/100 0.4% prob · 35th pct 3.27.0 2026-05-27 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Security advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM HIGH 6.0 |
CVE-2026-49981 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-693 Protection Mechanism Failure CWE-863Incorrect Authorization |
Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allow… | — | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.27.0, the per-template filter, tag, and function allow-list verdict is computed when a Template instance is constructed and can remain cached after sandbox state changes between renders, allowing a later sandboxed render to reuse a template that was originally checked with a different or empty policy. This issue is fixed in version 3.27.0. Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 6.0 (HIGH) MEDIUM · 54/100 0.4% prob · 30th pct 2026-07-01 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM LOW 5.3 |
CVE-2026-48805 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-693 Protection Mechanism Failure |
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such … | 3.27.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.27.0, deprecated internal wrappers in src/Resources/core.php do not forward the current sandbox state to CoreExtension::checkArrow(), arraySome(), and arrayEvery(), allowing legacy calls such as twig_array_some(), twig_array_every(), and twig_check_arrow_in_sandbox() to bypass sandbox callable restrictions. This issue is fixed in version 3.27.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.3 (LOW) MEDIUM · 50.6/100 0.5% prob · 41th pct 3.27.0 2026-05-27 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Security advisory1 link
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM LOW 5.3 |
CVE-2026-46635 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-863 Incorrect Authorization |
Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties without reaching CoreExtension::getAttribute() or SandboxExtension::checkPropertyAll… | 3.26.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.26.0, the column filter passes object arrays to PHP array_column(), which reads public and magic properties without reaching CoreExtension::getAttribute() or SandboxExtension::checkPropertyAllowed(), allowing an untrusted template author with column in allowedFilters to read properties that are not in the sandbox allowlist. This issue is fixed in version 3.26.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.3 (LOW) MEDIUM · 47.7/100 0.3% prob · 26th pct 3.26.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM LOW 5.1 |
CVE-2026-46628 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-116 Improper Encoding or Escaping of Output |
Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. | 3.26.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. Prior to 3.26.0, the deprecated spaceless filter is registered as safe for HTML, causing Twig autoescaping to emit attacker-controlled markup unescaped when spaceless is applied to untrusted input. This issue is fixed in version 3.26.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.1 (LOW) MEDIUM · 45.3/100 0.3% prob · 22th pct 3.26.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
MEDIUM LOW 5.1 |
CVE-2026-47730 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-79 Cross-site Scripting (XSS) |
Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to … | 3.26.0 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplate() and Profile::getName() into HTML output without escaping, allowing attacker-controlled template or profile names to inject arbitrary HTML when a browser renders the profiler dump. This issue is fixed in version 3.26.0. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 5.1 (LOW) MEDIUM · 45.3/100 0.3% prob · 22th pct 3.26.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (4)
Patch / Commit2 links
Affected CPE configurations (1)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
LOW LOW 2.2 |
CVE-2024-51754 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-668 Exposure of Resource to Wrong Sphere |
Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of an array or an argument list (arguments t… | 3.11.2 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of an array or an argument list (arguments to a function or a filter for instance). This issue has been patched in versions 3.11.2 and 3.14.1. All users are advised to upgrade. There are no known workarounds for this issue. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N 2.2 (LOW) LOW · 25.1/100 0.4% prob · 37th pct 3.11.2 2024-11-06 2025-05-29 exact nvd+osv+packagist External links (4)
Patch / Commit1 link
Security advisory2 links
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
LOW LOW 2.2 |
CVE-2024-51755 exact |
composer: twig/twig 3.10.3 direct defined in: symfony/symfony-demo |
CWE-668 Exposure of Resource to Wrong Sphere |
Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. | 3.11.2 | nvdosvpackagist | ||
Description
Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property policy and the `__isset()` method is now called after the security check. This is a BC break. This issue has been patched in versions 3.11.2 and 3.14.1. All users are advised to upgrade. There are no known workarounds for this issue. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N 2.2 (LOW) LOW · 25/100 0.4% prob · 37th pct 3.11.2 2024-11-06 2024-11-12 exact nvd+osv+packagist External links (3)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
LOW LOW 3.1 |
CVE-2024-50343 exact |
composer: symfony/validator 7.1.1 direct defined in: symfony/symfony-demo |
CWE-20 Improper Input Validation |
symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metacharacters, with an input ending with `\n`. | 7.1.4 | nvdosvpackagist | ||
Description
symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metacharacters, with an input ending with `\n`. Symfony as of versions 5.4.43, 6.4.11, and 7.1.4 now uses the `D` regex modifier to match the entire input. Users are advised to upgrade. There are no known workarounds for this vulnerability. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N 3.1 (LOW) LOW · 32.6/100 0.5% prob · 39th pct 7.1.4 2024-08-30 2025-11-03 exact nvd+osv+packagist External links (4)
Patch / Commit1 link
Security advisory2 links
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
HIGH LOW 8.7 |
CVE-2026-45304 exact |
composer: symfony/yaml 7.1.1 direct defined in: symfony/symfony-demo |
CWE-776 XML Entity Expansion (XEE / Billion Laughs) |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser resolved YAML collection aliases recursively, allowing a small untrusted YAML input to expand into a multi-gigabyte structure and exhaust memory. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.7 (LOW) HIGH · 79.8/100 0.7% prob · 51th pct 7.2.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit6 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
HIGH LOW 8.7 |
CVE-2026-45305 exact |
composer: symfony/yaml 7.1.1 direct defined in: symfony/symfony-demo |
CWE-1333 Inefficient Regular Expression Complexity (ReDoS) |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() used regular expressions with overlapping quantifiers for YAML directive, comment, and document marker cleanup, allowing crafted input to make parsing hang for an arbitrarily long time. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.7 (LOW) HIGH · 79.8/100 0.7% prob · 51th pct 7.2.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit6 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
HIGH LOW 8.2 |
CVE-2026-45133 exact |
composer: symfony/yaml 7.1.1 direct defined in: symfony/symfony-demo |
CWE-674 Uncontrolled Recursion CWE-776XML Entity Expansion (XEE / Billion Laughs) +1 |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attacker-controlled input, deeply nested mappings or sequences cause both the block-level (Parser::parseBlock()) and inline (Inline::parseSequence() / Inline::parseMapping()) parsers to recurse without a depth limit. A crafted document exhausts the PHP stack and crashes the worker. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (3)
Metadata
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.2 (LOW) HIGH · 75.4/100 0.6% prob · 49th pct 7.2.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
HIGH LOW 8.7 |
CVE-2026-45071 exact |
composer: symfony/dom-crawler 3.4.4 direct dev defined in: drupal/drupal |
CWE-611 XML External Entity (XXE) |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 4.0.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() set DOMDocument::$validateOnParse = true before loadXML(), re-enabling external entity resolution and allowing attacker-supplied XML to expand file:// entities such as local files. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.7 (LOW) HIGH · 78.8/100 0.6% prob · 46th pct 4.0.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit6 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
HIGH HIGH 7.1 |
CVE-2019-10912 exact |
composer: symfony/phpunit-bridge 3.4.4 direct dev defined in: drupal/drupal |
CWE-502 Deserialization of Untrusted Data |
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. | 3.4.26 | nvdosvpackagist | ||
Description
In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this could result in the deletion of files that the current user has access to. This is related to symfony/cache and symfony/phpunit-bridge. Weaknesses (CWE) (1)
Metadata
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N 7.1 (HIGH) HIGH · 73.2/100 2.3% prob · 82th pct 3.4.26 2019-04-16 2024-03-13 exact nvd+osv+packagist External links (14)
Patch / Commit1 link
Third-party advisory1 link
Mailing list9 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM HIGH 7.3 |
CVE-2026-67434 exact |
composer: squizlabs/php_codesniffer 2.8.1 direct dev defined in: drupal/drupal |
CWE-78 OS Command Injection |
PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. | 3.13.6 | nvdosvpackagist | ||
Description
PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgblame, and Svnblame report formats. As a result, running PHP_CodeSniffer over untrusted files, for example in a continuous integration pipeline that scans pull requests, or on a developer machine reviewing third party code, could result in attacker controlled shell commands being executed when the Gitblame, Hgblame, or Svnblame report processes a file whose name contains shell metacharacters. Users using the default Full report, or any of the other non-blame reports, are not affected. Users on a runtime platform which does not allow filenames to contain shell metacharacters, such as " and ;, are not affected. This issue is fixed in versions 3.13.6 and 4.0.2. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.3 (HIGH) MEDIUM · 68.8/100 0.7% prob · 52th pct 3.13.6 2026-08-05 2026-08-06 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Security advisory1 link
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
MEDIUM HIGH 7.8 |
CVE-2026-24765 exact |
composer: phpunit/phpunit 4.8.36 direct dev defined in: drupal/drupal |
CWE-502 Deserialization of Untrusted Data |
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. | 8.5.52 | nvdosvpackagist | ||
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 7.8 (HIGH) MEDIUM · 68.3/100 0.4% prob · 29th pct 8.5.52 2026-01-27 2026-05-05 exact nvd+osv+packagist External links (8)
Patch / Commit6 links
Vendor advisory1 link
Affected CPE configurations (6)
Aliases
Declared in (1 composer.lock)
drupal/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
HIGH LOW 8.7 |
CVE-2026-45071 exact |
composer: symfony/dom-crawler 6.4.12 direct dev defined in: bookstackapp/bookstack |
CWE-611 XML External Entity (XXE) |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 6.4.40 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() set DOMDocument::$validateOnParse = true before loadXML(), re-enabling external entity resolution and allowing attacker-supplied XML to expand file:// entities such as local files. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.7 (LOW) HIGH · 78.8/100 0.6% prob · 46th pct 6.4.40 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit6 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM HIGH 7.3 |
CVE-2026-67434 exact |
composer: squizlabs/php_codesniffer 3.10.3 direct dev defined in: bookstackapp/bookstack |
CWE-78 OS Command Injection |
PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. | 3.13.6 | nvdosvpackagist | ||
Description
PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer contains a command injection vulnerability in the code that generates the Gitblame, Hgblame, and Svnblame report formats. As a result, running PHP_CodeSniffer over untrusted files, for example in a continuous integration pipeline that scans pull requests, or on a developer machine reviewing third party code, could result in attacker controlled shell commands being executed when the Gitblame, Hgblame, or Svnblame report processes a file whose name contains shell metacharacters. Users using the default Full report, or any of the other non-blame reports, are not affected. Users on a runtime platform which does not allow filenames to contain shell metacharacters, such as " and ;, are not affected. This issue is fixed in versions 3.13.6 and 4.0.2. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 7.3 (HIGH) MEDIUM · 68.8/100 0.7% prob · 52th pct 3.13.6 2026-08-05 2026-08-06 exact nvd+osv+packagist External links (6)
Patch / Commit5 links
Security advisory1 link
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
MEDIUM HIGH 7.8 |
CVE-2026-24765 exact |
composer: phpunit/phpunit 10.5.35 direct dev defined in: bookstackapp/bookstack |
CWE-502 Deserialization of Untrusted Data |
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. | 10.5.62 | nvdosvpackagist | ||
Description
PHPUnit is a testing framework for PHP. A vulnerability has been discovered in versions prior to 12.5.8, 11.5.50, 10.5.62, 9.6.33, and 8.5.52 involving unsafe deserialization of code coverage data in PHPT test execution. The vulnerability exists in the `cleanupForCoverage()` method, which deserializes code coverage files without validation, potentially allowing remote code execution if malicious `.coverage` files are present prior to the execution of the PHPT test. The vulnerability occurs when a `.coverage` file, which should not exist before test execution, is deserialized without the `allowed_classes` parameter restriction. An attacker with local file write access can place a malicious serialized object with a `__wakeup()` method into the file system, leading to arbitrary code execution during test runs with code coverage instrumentation enabled. This vulnerability requires local file write access to the location where PHPUnit stores or expects code coverage files for PHPT tests. This can occur through CI/CD pipeline attacks, the local development environment, and/or compromised dependencies. Rather than just silently sanitizing the input via `['allowed_classes' => false]`, the maintainer has chosen to make the anomalous state explicit by treating pre-existing `.coverage` files for PHPT tests as an error condition. Starting in versions in versions 12.5.8, 11.5.50, 10.5.62, 9.6.33, when a `.coverage` file is detected for a PHPT test prior to execution, PHPUnit will emit a clear error message identifying the anomalous state. Organizations can reduce the effective risk of this vulnerability through proper CI/CD configuration, including ephemeral runners, code review enforcement, branch protection, artifact isolation, and access control. Weaknesses (CWE) (1)
Metadata
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 7.8 (HIGH) MEDIUM · 68.3/100 0.4% prob · 29th pct 10.5.62 2026-01-27 2026-05-05 exact nvd+osv+packagist External links (8)
Patch / Commit6 links
Vendor advisory1 link
Affected CPE configurations (6)
Aliases
Declared in (1 composer.lock)
bookstack/composer.lock | ||||||||
| Priority / severity | CVE ID | Dependency | CWE | Description | Fix Version | Source | ||
|---|---|---|---|---|---|---|---|---|
HIGH LOW 8.7 |
CVE-2026-45071 exact |
composer: symfony/dom-crawler 7.1.1 direct dev defined in: symfony/symfony-demo |
CWE-611 XML External Entity (XXE) |
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. | 7.2.0 | nvdosvpackagist | ||
Description
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawler::addXmlContent() set DOMDocument::$validateOnParse = true before loadXML(), re-enabling external entity resolution and allowing attacker-supplied XML to expand file:// entities such as local files. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12. Weaknesses (CWE) (1)
Metadata
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X 8.7 (LOW) HIGH · 78.8/100 0.6% prob · 46th pct 7.2.0 2026-05-20 2026-09-10 exact nvd+osv+packagist External links (7)
Patch / Commit6 links
Affected CPE configurations (4)
Aliases
Declared in (1 composer.lock)
symfony-demo/composer.lock | ||||||||
| Sev | Library | Files | CVE | CWE | Vulns | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| HIGH | tinyMCE 4.9.11 |
wp/wp-includes/js/tinymce/tinymce.min.jswp/wp-includes/js/tinymce/wp-tinymce.js |
CDATA parsing and sanitization has been improved to address a cross-site scripting (XSS) vulnerabili… media embed content not processing safely in some cases. content in an iframe element parsing as DOM elements instead of text content. Regex denial of service vulnerability in codesample plugin CVE-2024-21911 URLs are not correctly filtered in some cases. CVE-2024-21908 CVE-2024-21910 CVE-2022-23494 CVE-2023-45819 CVE-2023-45818 CVE-2023-48219 CVE-2026-47761 CVE-2024-38356 CVE-2024-38357 CVE-2026-47759 CVE-2026-47762 CVE-2024-29203 CVE-2024-29881 | CWE-79 |
19 vulns | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| HIGH | ua-parser-js 0.7.7 |
wp/wp-includes/js/plupload/moxie.js |
CVE-2020-7733 CVE-2020-7793 | CWE-400 |
2 vulns | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| HIGH | underscore.js 1.13.6 |
wp/wp-includes/js/underscore.js |
CVE-2026-27601 | CWE-770 |
1 vuln | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| MEDIUM | plupload 2.1.9 |
wp/wp-includes/js/plupload/plupload.js |
Fixed security vulnerability by adding die calls to all php files to prevent them from being execute… Fixed a potential security issue with not entity encoding the file names in the html in the queue/ui… CVE-2021-23562 | CWE-434 |
3 vulns | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Library | Version | File | Detection | Status |
|---|---|---|---|---|
| tinyMCE | 4.9.11 | wp/wp-includes/js/tinymce/tinymce.min.js | filecontentreplace | 19 vulns · HIGH |
| tinyMCE | 4.9.11 | wp/wp-includes/js/tinymce/wp-tinymce.js | filecontentreplace | 19 vulns · HIGH |
| ua-parser-js | 0.7.7 | wp/wp-includes/js/plupload/moxie.js | filecontent | 2 vulns · HIGH |
| underscore.js | 1.13.6 | wp/wp-includes/js/underscore.js | filecontent | 1 vuln · HIGH |
| plupload | 2.1.9 | wp/wp-includes/js/plupload/plupload.js | filecontent | 3 vulns · MEDIUM |
| backbone.js | 1.5.0 | wp/wp-includes/js/backbone.js | filecontent | no known vuln |
| jquery | 3.7.1 | wp/wp-includes/js/jquery/jquery.js | filecontent | no known vuln |
| jquery | 3.7.1 | wp/wp-includes/js/jquery/jquery.min.js | filecontent | no known vuln |
| jquery-migrate | 3.4.1 | wp/wp-includes/js/jquery/jquery-migrate.js | filecontent | no known vuln |
| jquery-migrate | 3.4.1 | wp/wp-includes/js/jquery/jquery-migrate.min.js | filecontent | no known vuln |
| jquery-ui | 1.13.2 | wp/wp-includes/js/jquery/ui/core.js | filecontent | no known vuln |
| jquery-ui | 1.13.2 | wp/wp-includes/js/jquery/ui/core.min.js | filecontent | no known vuln |
| jquery-ui-autocomplete | 1.13.2 | wp/wp-includes/js/jquery/ui/autocomplete.js | filecontent | no known vuln |
| jquery-ui-autocomplete | 1.13.2 | wp/wp-includes/js/jquery/ui/autocomplete.min.js | filecontent | no known vuln |
| jquery-ui-dialog | 1.13.2 | wp/wp-includes/js/jquery/ui/dialog.js | filecontent | no known vuln |
| jquery-ui-dialog | 1.13.2 | wp/wp-includes/js/jquery/ui/dialog.min.js | filecontent | no known vuln |
| jquery-ui-tooltip | 1.13.2 | wp/wp-includes/js/jquery/ui/tooltip.js | filecontent | no known vuln |
| jquery-ui-tooltip | 1.13.2 | wp/wp-includes/js/jquery/ui/tooltip.min.js | filecontent | no known vuln |
| swfobject | 2.2 | wp/wp-includes/js/swfobject.js | filecontent | no known vuln |
| File | Type | Algorithm | Details | Findings | SHA-256 |
|---|---|---|---|---|---|
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | EE Certification Centre Root CA ← EE Certification Centre Root CA exp 2030-12-17 (1545d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 1024 | Thawte Server CA ← Thawte Server CA exp 2020-12-31 (-2093d) | weak key EXPIRED weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 1024 | Thawte Premium Server CA ← Thawte Premium Server CA exp 2020-12-31 (-2093d) | weak key EXPIRED weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 1024 | C=US ← C=US exp 2028-08-01 (677d) | weak key weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 1024 | C=US ← C=US exp 2028-08-01 (677d) | weak key weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | America Online Root Certification Authority 1 ← America Online Root Certification Authority 1 exp 2037-11-19 (4074d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | America Online Root Certification Authority 2 ← America Online Root Certification Authority 2 exp 2037-09-29 (4022d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 1024 | C=US ← C=US exp 2028-08-02 (678d) | weak key weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | GlobalSign Root CA ← GlobalSign Root CA exp 2028-01-28 (490d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | GlobalSign ← GlobalSign exp 2021-12-15 (-1745d) | EXPIRED weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | VeriSign Class 3 Public Primary Certification Authority - G3 ← VeriSign Class 3 Public Primary Certification Authority - G3 exp 2036-07-16 (3583d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Entrust.net Certification Authority (2048) ← Entrust.net Certification Authority (2048) exp 2029-07-24 (1033d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Baltimore CyberTrust Root ← Baltimore CyberTrust Root exp 2025-05-12 (-500d) | EXPIRED weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Entrust Root Certification Authority ← Entrust Root Certification Authority exp 2026-11-27 (64d) | expiring soon weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | GeoTrust Global CA ← GeoTrust Global CA exp 2022-05-21 (-1588d) | EXPIRED weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | GeoTrust Universal CA ← GeoTrust Universal CA exp 2029-03-04 (891d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | GeoTrust Universal CA 2 ← GeoTrust Universal CA 2 exp 2029-03-04 (891d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | AAA Certificate Services ← AAA Certificate Services exp 2028-12-31 (829d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | QuoVadis Root Certification Authority ← QuoVadis Root Certification Authority exp 2021-03-17 (-2017d) | EXPIRED weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | QuoVadis Root CA 2 ← QuoVadis Root CA 2 exp 2031-11-24 (1887d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | QuoVadis Root CA 3 ← QuoVadis Root CA 3 exp 2031-11-24 (1887d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | C=JP ← C=JP exp 2023-09-30 (-1091d) | EXPIRED weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Sonera Class2 CA ← Sonera Class2 CA exp 2021-04-06 (-1998d) | EXPIRED weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | XRamp Global Certification Authority ← XRamp Global Certification Authority exp 2035-01-01 (3020d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | C=US ← C=US exp 2034-06-29 (2835d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | C=US ← C=US exp 2034-06-29 (2835d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | C=TW ← C=TW exp 2032-12-05 (2263d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | DigiCert Assured ID Root CA ← DigiCert Assured ID Root CA exp 2031-11-10 (1872d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | DigiCert Global Root CA ← DigiCert Global Root CA exp 2031-11-10 (1872d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | DigiCert High Assurance EV Root CA ← DigiCert High Assurance EV Root CA exp 2031-11-10 (1872d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | SwissSign Gold CA - G2 ← SwissSign Gold CA - G2 exp 2036-10-25 (3683d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | SwissSign Silver CA - G2 ← SwissSign Silver CA - G2 exp 2036-10-25 (3683d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | GeoTrust Primary Certification Authority ← GeoTrust Primary Certification Authority exp 2036-07-16 (3583d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | thawte Primary Root CA ← thawte Primary Root CA exp 2036-07-16 (3583d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | VeriSign Class 3 Public Primary Certification Authority - G5 ← VeriSign Class 3 Public Primary Certification Authority - G5 exp 2036-07-16 (3583d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | SecureTrust CA ← SecureTrust CA exp 2029-12-31 (1194d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Secure Global CA ← Secure Global CA exp 2029-12-31 (1194d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | COMODO Certification Authority ← COMODO Certification Authority exp 2029-12-31 (1194d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Network Solutions Certificate Authority ← Network Solutions Certificate Authority exp 2029-12-31 (1194d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | OISTE WISeKey Global Root GA CA ← OISTE WISeKey Global Root GA CA exp 2037-12-11 (4095d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Certigna ← Certigna exp 2027-06-29 (277d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Cybertrust Global Root ← Cybertrust Global Root exp 2021-12-15 (-1745d) | EXPIRED weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | C=TW ← C=TW exp 2034-12-20 (3008d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | C=RO ← C=RO exp 2031-07-04 (1744d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Hongkong Post Root CA 1 ← Hongkong Post Root CA 1 exp 2023-05-15 (-1229d) | EXPIRED weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | SecureSign RootCA11 ← SecureSign RootCA11 exp 2029-04-08 (926d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | Autoridad de Certificacion Firmaprofesional CIF A62634068 ← Autoridad de Certificacion Firmaprofesional CIF A62634068 exp 2030-12-31 (1558d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | Chambers of Commerce Root - 2008 ← Chambers of Commerce Root - 2008 exp 2038-07-31 (4327d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | Global Chambersign Root - 2008 ← Global Chambersign Root - 2008 exp 2038-07-31 (4327d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | AffirmTrust Networking ← AffirmTrust Networking exp 2030-12-31 (1558d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Certum Trusted Network CA ← Certum Trusted Network CA exp 2029-12-31 (1193d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | TWCA Root Certification Authority ← TWCA Root Certification Authority exp 2030-12-31 (1558d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | EC-ACC ← EC-ACC exp 2031-01-07 (1566d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Hellenic Academic and Research Institutions RootCA 2011 ← Hellenic Academic and Research Institutions RootCA 2011 exp 2031-12-01 (1893d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | C=GB ← C=GB exp 2024-01-21 (-978d) | EXPIRED weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | EE Certification Centre Root CA ← EE Certification Centre Root CA exp 2030-12-17 (1545d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | ACCVRAIZ1 ← ACCVRAIZ1 exp 2030-12-31 (1558d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | TeliaSonera Root CA v1 ← TeliaSonera Root CA v1 exp 2032-10-18 (2215d) | weak signature self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | E-Tugra Certification Authority ← E-Tugra Certification Authority exp 2023-03-03 (-1302d) | EXPIRED self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | Staat der Nederlanden EV Root CA ← Staat der Nederlanden EV Root CA exp 2022-12-08 (-1387d) | EXPIRED self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | COMODO ECC Certification Authority ← COMODO ECC Certification Authority exp 2038-01-18 (4134d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | GeoTrust Primary Certification Authority - G3 ← GeoTrust Primary Certification Authority - G3 exp 2037-12-01 (4086d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | thawte Primary Root CA - G2 ← thawte Primary Root CA - G2 exp 2038-01-18 (4134d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | thawte Primary Root CA - G3 ← thawte Primary Root CA - G3 exp 2037-12-01 (4086d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | GeoTrust Primary Certification Authority - G2 ← GeoTrust Primary Certification Authority - G2 exp 2038-01-18 (4134d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | VeriSign Universal Root Certification Authority ← VeriSign Universal Root Certification Authority exp 2037-12-01 (4086d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | VeriSign Class 3 Public Primary Certification Authority - G4 ← VeriSign Class 3 Public Primary Certification Authority - G4 exp 2038-01-18 (4134d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | NetLock Arany (Class Gold) Főtanúsítvány ← NetLock Arany (Class Gold) Főtanúsítvány exp 2028-12-06 (803d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Microsec e-Szigno Root CA 2009 ← Microsec e-Szigno Root CA 2009 exp 2029-12-30 (1192d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | GlobalSign ← GlobalSign exp 2029-03-18 (905d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | Izenpe.com ← Izenpe.com exp 2037-12-13 (4097d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Go Daddy Root Certificate Authority - G2 ← Go Daddy Root Certificate Authority - G2 exp 2037-12-31 (4116d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Starfield Root Certificate Authority - G2 ← Starfield Root Certificate Authority - G2 exp 2037-12-31 (4116d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Starfield Services Root Certificate Authority - G2 ← Starfield Services Root Certificate Authority - G2 exp 2037-12-31 (4116d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | AffirmTrust Commercial ← AffirmTrust Commercial exp 2030-12-31 (1558d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | AffirmTrust Premium ← AffirmTrust Premium exp 2040-12-31 (5211d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | AffirmTrust Premium ECC ← AffirmTrust Premium ECC exp 2040-12-31 (5211d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | C=JP ← C=JP exp 2029-05-29 (977d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | Actalis Authentication Root CA ← Actalis Authentication Root CA exp 2030-09-22 (1458d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | Buypass Class 2 Root CA ← Buypass Class 2 Root CA exp 2040-10-26 (5145d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | Buypass Class 3 Root CA ← Buypass Class 3 Root CA exp 2040-10-26 (5145d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | T-TeleSec GlobalRoot Class 3 ← T-TeleSec GlobalRoot Class 3 exp 2033-10-01 (2564d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | D-TRUST Root Class 3 CA 2 2009 ← D-TRUST Root Class 3 CA 2 2009 exp 2029-11-05 (1137d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | D-TRUST Root Class 3 CA 2 EV 2009 ← D-TRUST Root Class 3 CA 2 EV 2009 exp 2029-11-05 (1137d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | CA Disig Root R2 ← CA Disig Root R2 exp 2042-07-19 (5776d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | TWCA Global Root CA ← TWCA Global Root CA exp 2030-12-31 (1558d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | T-TeleSec GlobalRoot Class 2 ← T-TeleSec GlobalRoot Class 2 exp 2033-10-01 (2564d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Atos TrustedRoot 2011 ← Atos TrustedRoot 2011 exp 2030-12-31 (1559d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | QuoVadis Root CA 1 G3 ← QuoVadis Root CA 1 G3 exp 2042-01-12 (5589d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | QuoVadis Root CA 2 G3 ← QuoVadis Root CA 2 G3 exp 2042-01-12 (5589d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | QuoVadis Root CA 3 G3 ← QuoVadis Root CA 3 G3 exp 2042-01-12 (5589d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | DigiCert Assured ID Root G2 ← DigiCert Assured ID Root G2 exp 2038-01-15 (4130d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | DigiCert Assured ID Root G3 ← DigiCert Assured ID Root G3 exp 2038-01-15 (4130d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | DigiCert Global Root G2 ← DigiCert Global Root G2 exp 2038-01-15 (4130d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | DigiCert Global Root G3 ← DigiCert Global Root G3 exp 2038-01-15 (4130d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | DigiCert Trusted Root G4 ← DigiCert Trusted Root G4 exp 2038-01-15 (4130d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | COMODO RSA Certification Authority ← COMODO RSA Certification Authority exp 2038-01-18 (4134d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | USERTrust RSA Certification Authority ← USERTrust RSA Certification Authority exp 2038-01-18 (4134d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | USERTrust ECC Certification Authority ← USERTrust ECC Certification Authority exp 2038-01-18 (4134d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC prime256v1 | GlobalSign ← GlobalSign exp 2038-01-19 (4134d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | GlobalSign ← GlobalSign exp 2038-01-19 (4134d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | Staat der Nederlanden Root CA - G3 ← Staat der Nederlanden Root CA - G3 exp 2028-11-13 (781d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | IdenTrust Commercial Root CA 1 ← IdenTrust Commercial Root CA 1 exp 2034-01-16 (2671d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | IdenTrust Public Sector Root CA 1 ← IdenTrust Public Sector Root CA 1 exp 2034-01-16 (2671d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Entrust Root Certification Authority - G2 ← Entrust Root Certification Authority - G2 exp 2030-12-07 (1535d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | Entrust Root Certification Authority - EC1 ← Entrust Root Certification Authority - EC1 exp 2037-12-18 (4102d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | CFCA EV ROOT ← CFCA EV ROOT exp 2029-12-31 (1193d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | OISTE WISeKey Global Root GB CA ← OISTE WISeKey Global Root GB CA exp 2039-12-01 (4815d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | SZAFIR ROOT CA2 ← SZAFIR ROOT CA2 exp 2035-10-19 (3311d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | Certum Trusted Network CA 2 ← Certum Trusted Network CA 2 exp 2046-10-06 (7316d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | Hellenic Academic and Research Institutions RootCA 2015 ← Hellenic Academic and Research Institutions RootCA 2015 exp 2040-06-30 (5027d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | Hellenic Academic and Research Institutions ECC RootCA 2015 ← Hellenic Academic and Research Institutions ECC RootCA 2015 exp 2040-06-30 (5027d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | ISRG Root X1 ← ISRG Root X1 exp 2035-06-04 (3174d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | C=ES ← C=ES exp 2030-01-01 (1194d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | Amazon Root CA 1 ← Amazon Root CA 1 exp 2038-01-17 (4132d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | Amazon Root CA 2 ← Amazon Root CA 2 exp 2040-05-26 (4992d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC prime256v1 | Amazon Root CA 3 ← Amazon Root CA 3 exp 2040-05-26 (4992d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | Amazon Root CA 4 ← Amazon Root CA 4 exp 2040-05-26 (4992d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | TUBITAK Kamu SM SSL Kok Sertifikasi - Surum 1 ← TUBITAK Kamu SM SSL Kok Sertifikasi - Surum 1 exp 2043-10-25 (6239d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | GDCA TrustAUTH R5 ROOT ← GDCA TrustAUTH R5 ROOT exp 2040-12-31 (5211d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | TrustCor RootCert CA-1 ← TrustCor RootCert CA-1 exp 2029-12-31 (1194d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | TrustCor RootCert CA-2 ← TrustCor RootCert CA-2 exp 2034-12-31 (3020d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | TrustCor ECA-1 ← TrustCor ECA-1 exp 2029-12-31 (1194d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | SSL.com Root Certification Authority RSA ← SSL.com Root Certification Authority RSA exp 2041-02-12 (5255d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | SSL.com Root Certification Authority ECC ← SSL.com Root Certification Authority ECC exp 2041-02-12 (5255d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | SSL.com EV Root Certification Authority RSA R2 ← SSL.com EV Root Certification Authority RSA R2 exp 2042-05-30 (5727d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | SSL.com EV Root Certification Authority ECC ← SSL.com EV Root Certification Authority ECC exp 2041-02-12 (5255d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | GlobalSign ← GlobalSign exp 2034-12-10 (2998d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | OISTE WISeKey Global Root GC CA ← OISTE WISeKey Global Root GC CA exp 2042-05-09 (5705d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | GTS Root R1 ← GTS Root R1 exp 2036-06-22 (3558d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | GTS Root R2 ← GTS Root R2 exp 2036-06-22 (3558d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | GTS Root R3 ← GTS Root R3 exp 2036-06-22 (3558d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | GTS Root R4 ← GTS Root R4 exp 2036-06-22 (3558d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | UCA Global G2 Root ← UCA Global G2 Root exp 2040-12-31 (5211d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | UCA Extended Validation Root ← UCA Extended Validation Root exp 2038-12-31 (4480d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | Certigna Root CA ← Certigna Root CA exp 2033-10-01 (2563d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | emSign Root CA - G1 ← emSign Root CA - G1 exp 2043-02-18 (5991d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | emSign ECC Root CA - G3 ← emSign ECC Root CA - G3 exp 2043-02-18 (5991d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 2048 | emSign Root CA - C1 ← emSign Root CA - C1 exp 2043-02-18 (5991d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | emSign ECC Root CA - C3 ← emSign ECC Root CA - C3 exp 2043-02-18 (5991d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | Hongkong Post Root CA 3 ← Hongkong Post Root CA 3 exp 2042-06-03 (5730d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | Entrust Root Certification Authority - G4 ← Entrust Root Certification Authority - G4 exp 2037-12-27 (4111d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC secp384r1 | Microsoft ECC Root Certificate Authority 2017 ← Microsoft ECC Root Certificate Authority 2017 exp 2042-07-18 (5776d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | Microsoft RSA Root Certificate Authority 2017 ← Microsoft RSA Root Certificate Authority 2017 exp 2042-07-18 (5776d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | EC prime256v1 | e-Szigno Root CA 2017 ← e-Szigno Root CA 2017 exp 2042-08-22 (5810d) | self-signed | 95b56bb9f0e8e470… |
wp/wp-includes/certificates/ca-bundle.crt | certificate | RSA 4096 | C=RO ← C=RO exp 2042-02-06 (5613d) | self-signed | 95b56bb9f0e8e470… |
| Product | Dependency | EOL date | Latest | Source | Notes |
|---|---|---|---|---|---|
| Laravel | composer:laravel/framework 10.48.22 defined in: bookstackapp/bookstack |
2025-02-04 | 13.33.0 | endoflife.date/laravel matched via composer-framework = laravel/framework |
The 10 branch ended at 10.50.3. |
| Symfony | composer:symfony/browser-kit 3.4.4 +5 more components at cycle 3.4 defined in: drupal/drupal |
2021-11-01 | 8.1.7 | endoflife.date/symfony matched via composer-framework = symfony/browser-kit |
The 3.4 branch ended at 3.4.49. |
| Symfony | composer:symfony/browser-kit 3.4.4 +3 more components at cycle 3.4 defined in: symfony/symfony-demo |
2021-11-01 | 8.1.7 | endoflife.date/symfony matched via composer-framework = symfony/browser-kit |
The 3.4 branch ended at 3.4.49. |
| Symfony | composer:symfony/framework-bundle 7.1.1 +29 more components at cycle 7.1 defined in: symfony/symfony-demo |
2025-01-31 | 8.1.7 | endoflife.date/symfony matched via composer-framework = symfony/framework-bundle |
The 7.1 branch ended at 7.1.11. |
| PHP | composer:php 8.1 defined in: bookstackapp/bookstack |
2025-12-31 | 8.1.34 | endoflife.date/php matched via composer-platform = lock:platform-overrides |
Constraint "8.1.0" (lock:platform-overrides) allows nothing newer than PHP 8.1 — latest 8.1.34. |
| Severity | Obsolete | Replacement | Why |
|---|---|---|---|
| MEDIUM | composer:doctrine/cache 2.2.0 defined in: bookstackapp/bookstack, drupal/drupal +1 more |
— | Package marked abandoned on Packagist |
| MEDIUM | composer:doctrine/annotations 1.2.7 defined in: drupal/drupal |
— | Package marked abandoned on Packagist |
| MEDIUM | composer:stack/builder 1.0.5 defined in: drupal/drupal |
— | Package marked abandoned on Packagist |
| MEDIUM | composer:symfony/class-loader 3.4.4 defined in: drupal/drupal |
— | Package marked abandoned on Packagist |
| MEDIUM | composer:symfony/debug 3.4.4 defined in: drupal/drupal |
symfony/error-handler | Package marked abandoned on Packagist |
| MEDIUM | composer:zendframework/zend-diactoros 1.4.1 defined in: drupal/drupal |
laminas/laminas-diactoros | Package marked abandoned on Packagist |
| MEDIUM | composer:zendframework/zend-escaper 2.5.2 defined in: drupal/drupal |
laminas/laminas-escaper | Package marked abandoned on Packagist |
| MEDIUM | composer:zendframework/zend-feed 2.7.0 defined in: drupal/drupal |
laminas/laminas-feed | Package marked abandoned on Packagist |
| MEDIUM | composer:zendframework/zend-stdlib 3.0.1 defined in: drupal/drupal |
laminas/laminas-stdlib | Package marked abandoned on Packagist |
| MEDIUM | composer:behat/mink-goutte-driver 1.2.1 defined in: drupal/drupal |
behat/mink-browserkit-driver | Package marked abandoned on Packagist |
| MEDIUM | composer:fabpot/goutte 3.2.1 defined in: drupal/drupal |
symfony/browser-kit | Package marked abandoned on Packagist |
| MEDIUM | composer:phpunit/phpunit-mock-objects 2.3.8 defined in: drupal/drupal |
— | Package marked abandoned on Packagist |
| Jump | Dependency | Current | Latest | Released |
|---|---|---|---|---|
| +1 major | composer:asm89/stack-cors defined in: drupal/drupal |
1.2.0 | 2.4.0 | |
| +1 major | composer:behat/mink-browserkit-driver defined in: drupal/drupal |
1.3.2 | 2.3.0 | |
| +1 major | composer:brick/math defined in: bookstackapp/bookstack |
0.12.1 | 1.0.0 | |
| +1 major | composer:carbonphp/carbon-doctrine-types defined in: bookstackapp/bookstack |
2.1.0 | 3.2.1 | |
| +1 major | composer:composer/installers defined in: drupal/drupal |
1.5.0 | 2.3.0 | |
| +2 major | composer:composer/semver defined in: drupal/drupal, symfony/symfony-demo |
1.4.2 | 3.4.4 | |
| +2 major | composer:doctrine/collections defined in: drupal/drupal, symfony/symfony-demo |
1.3.0 | 3.1.0 | |
| +1 major | composer:doctrine/common defined in: drupal/drupal |
2.6.2 | 3.5.0 | |
| +1 major | composer:doctrine/data-fixtures defined in: symfony/symfony-demo |
1.7.0 | 2.2.1 | |
| +1 major | composer:doctrine/dbal defined in: bookstackapp/bookstack, symfony/symfony-demo |
3.9.1 | 4.4.4 | |
| +1 major | composer:doctrine/doctrine-bundle defined in: symfony/symfony-demo |
2.12.0 | 3.3.2 | |
| +1 major | composer:doctrine/doctrine-fixtures-bundle defined in: symfony/symfony-demo |
3.6.1 | 4.3.1 | |
| +1 major | composer:doctrine/doctrine-migrations-bundle defined in: symfony/symfony-demo |
3.3.1 | 4.0.1 | |
| +1 major | composer:doctrine/persistence defined in: symfony/symfony-demo |
3.3.2 | 4.2.0 | |
| +1 major | composer:drupal/coder defined in: drupal/drupal |
8.2.12 | 9.0.1 | |
| +1 major | composer:easyrdf/easyrdf defined in: drupal/drupal |
0.9.1 | 1.1.1 | |
| +1 major | composer:firebase/php-jwt defined in: bookstackapp/bookstack |
6.10.1 | 7.2.0 | |
| +1 major | composer:guzzlehttp/guzzle defined in: bookstackapp/bookstack, drupal/drupal |
7.9.2 | 8.2.0 | |
| +1 major | composer:guzzlehttp/promises defined in: bookstackapp/bookstack, drupal/drupal |
2.0.3 | 3.0.2 | |
| +1 major | composer:guzzlehttp/psr7 defined in: bookstackapp/bookstack, drupal/drupal |
2.7.0 | 3.1.0 | |
| +1 major | composer:guzzlehttp/uri-template defined in: bookstackapp/bookstack |
1.0.3 | 2.0.1 | |
| +1 major | composer:hamcrest/hamcrest-php defined in: bookstackapp/bookstack |
2.0.1 | 3.0.0 | |
| +1 major | composer:intervention/gif defined in: bookstackapp/bookstack |
4.2.0 | 5.0.1 | |
| +1 major | composer:intervention/image defined in: bookstackapp/bookstack |
3.8.0 | 4.3.2 | |
| +1 major | composer:larastan/larastan defined in: bookstackapp/bookstack |
2.9.8 | 3.12.2 | |
| +1 major | composer:laravel/serializable-closure defined in: bookstackapp/bookstack |
1.3.5 | 2.1.0 | |
| +1 major | composer:laravel/tinker defined in: bookstackapp/bookstack |
2.10.0 | 3.0.2 | |
| +1 major | composer:nesbot/carbon defined in: bookstackapp/bookstack |
2.72.5 | 3.14.0 | |
| +1 major | composer:nunomaduro/collision defined in: bookstackapp/bookstack |
7.10.0 | 8.9.5 | |
| +1 major | composer:nunomaduro/termwind defined in: bookstackapp/bookstack |
1.15.1 | 2.4.0 | |
| +4 major | composer:phpdocumentor/reflection-docblock defined in: drupal/drupal |
2.0.4 | 6.0.3 | |
| +1 major | composer:phpmyadmin/sql-parser defined in: bookstackapp/bookstack |
5.10.0 | 6.0.0 | |
| +1 major | composer:phpseclib/phpseclib defined in: bookstackapp/bookstack |
3.0.42 | 4.0.1 | |
| +1 major | composer:phpstan/phpstan defined in: bookstackapp/bookstack, symfony/symfony-demo |
1.12.5 | 2.2.14 | |
| +1 major | composer:phpstan/phpstan-doctrine defined in: symfony/symfony-demo |
1.4.1 | 2.0.28 | |
| +1 major | composer:phpstan/phpstan-symfony defined in: symfony/symfony-demo |
1.4.3 | 2.0.20 | |
| +4 major | composer:phpunit/php-code-coverage defined in: bookstackapp/bookstack, drupal/drupal |
10.1.16 | 14.3.3 | |
| +3 major | composer:phpunit/php-file-iterator defined in: bookstackapp/bookstack, drupal/drupal |
4.1.0 | 7.0.2 | |
| +3 major | composer:phpunit/php-invoker defined in: bookstackapp/bookstack |
4.0.0 | 7.0.0 | |
| +3 major | composer:phpunit/php-text-template defined in: bookstackapp/bookstack, drupal/drupal |
3.0.1 | 6.0.0 | |
| +3 major | composer:phpunit/php-timer defined in: bookstackapp/bookstack, drupal/drupal |
6.0.0 | 9.0.0 | |
| +3 major | composer:phpunit/php-token-stream defined in: drupal/drupal |
1.4.11 | 4.0.4 | |
| +3 major | composer:phpunit/phpunit defined in: bookstackapp/bookstack, drupal/drupal |
10.5.35 | 13.3.4 | |
| +1 major | composer:pragmarx/google2fa defined in: bookstackapp/bookstack |
8.0.3 | 9.1.0 | |
| +1 major | composer:predis/predis defined in: bookstackapp/bookstack |
2.2.2 | 3.6.1 | |
| +1 major | composer:robrichards/xmlseclibs defined in: bookstackapp/bookstack |
3.1.1 | 4.0.0 | |
| +1 major | composer:sabberworm/php-css-parser defined in: bookstackapp/bookstack |
8.6.0 | 9.5.0 | |
| +3 major | composer:sebastian/cli-parser defined in: bookstackapp/bookstack |
2.0.1 | 5.0.1 | |
| +1 major | composer:sebastian/code-unit defined in: bookstackapp/bookstack |
2.0.0 | 3.0.3 | |
| +1 major | composer:sebastian/code-unit-reverse-lookup defined in: bookstackapp/bookstack |
3.0.0 | 4.0.1 | |
| +3 major | composer:sebastian/comparator defined in: bookstackapp/bookstack, drupal/drupal |
5.0.2 | 8.4.0 | |
| +3 major | composer:sebastian/complexity defined in: bookstackapp/bookstack |
3.2.0 | 6.0.0 | |
| +4 major | composer:sebastian/diff defined in: bookstackapp/bookstack, drupal/drupal |
5.1.1 | 9.0.1 | |
| +3 major | composer:sebastian/environment defined in: bookstackapp/bookstack, drupal/drupal |
6.1.0 | 9.3.2 | |
| +3 major | composer:sebastian/exporter defined in: bookstackapp/bookstack, drupal/drupal |
5.1.2 | 8.2.1 | |
| +3 major | composer:sebastian/global-state defined in: bookstackapp/bookstack, drupal/drupal |
6.0.2 | 9.0.1 | |
| +3 major | composer:sebastian/lines-of-code defined in: bookstackapp/bookstack |
2.0.2 | 5.0.2 | |
| +3 major | composer:sebastian/object-enumerator defined in: bookstackapp/bookstack |
5.0.0 | 8.1.0 | |
| +3 major | composer:sebastian/object-reflector defined in: bookstackapp/bookstack |
3.0.0 | 6.1.0 | |
| +3 major | composer:sebastian/recursion-context defined in: bookstackapp/bookstack, drupal/drupal |
5.0.0 | 8.0.1 | |
| +3 major | composer:sebastian/type defined in: bookstackapp/bookstack |
4.0.0 | 7.0.2 | |
| +3 major | composer:sebastian/version defined in: bookstackapp/bookstack, drupal/drupal |
4.0.1 | 7.0.0 | |
| +1 major | composer:squizlabs/php_codesniffer defined in: bookstackapp/bookstack, drupal/drupal |
3.10.3 | 4.0.4 | |
| +1 major | composer:ssddanbrown/htmldiff defined in: bookstackapp/bookstack |
1.0.3 | 2.0.0 | |
| +2 major | composer:symfony-cmf/routing defined in: drupal/drupal |
1.4.1 | 3.0.5 | |
| +1 major | composer:symfony/asset defined in: symfony/symfony-demo |
7.1.1 | 8.1.0 | |
| +1 major | composer:symfony/asset-mapper defined in: symfony/symfony-demo |
7.1.1 | 8.1.7 | |
| +1 major | composer:symfony/cache defined in: symfony/symfony-demo |
7.1.1 | 8.1.7 | |
| +1 major | composer:symfony/clock defined in: symfony/symfony-demo |
7.1.1 | 8.1.0 | |
| +1 major | composer:symfony/config defined in: symfony/symfony-demo |
7.1.1 | 8.1.5 | |
| +2 major | composer:symfony/console defined in: bookstackapp/bookstack, drupal/drupal +1 more |
6.4.12 | 8.1.7 | |
| +2 major | composer:symfony/css-selector defined in: bookstackapp/bookstack, drupal/drupal +1 more |
6.4.8 | 8.1.6 | |
| +1 major | composer:symfony/debug-bundle defined in: symfony/symfony-demo |
7.1.1 | 8.1.0 | |
| +5 major | composer:symfony/dependency-injection defined in: drupal/drupal, symfony/symfony-demo |
3.4.4 | 8.1.7 | |
| +1 major | composer:symfony/doctrine-bridge defined in: symfony/symfony-demo |
7.1.1 | 8.1.7 | |
| +2 major | composer:symfony/dom-crawler defined in: bookstackapp/bookstack, drupal/drupal +1 more |
6.4.12 | 8.1.5 | |
| +1 major | composer:symfony/dotenv defined in: symfony/symfony-demo |
7.1.1 | 8.1.6 | |
| +2 major | composer:symfony/error-handler defined in: bookstackapp/bookstack, symfony/symfony-demo |
6.4.10 | 8.1.5 | |
| +2 major | composer:symfony/event-dispatcher defined in: bookstackapp/bookstack, drupal/drupal +1 more |
6.4.8 | 8.1.5 | |
| +1 major | composer:symfony/expression-language defined in: symfony/symfony-demo |
7.1.1 | 8.1.6 | |
| +1 major | composer:symfony/filesystem defined in: symfony/symfony-demo |
7.1.1 | 8.1.6 | |
| +2 major | composer:symfony/finder defined in: bookstackapp/bookstack, symfony/symfony-demo |
6.4.11 | 8.1.7 | |
| +1 major | composer:symfony/form defined in: symfony/symfony-demo |
7.1.1 | 8.1.7 | |
| +1 major | composer:symfony/html-sanitizer defined in: symfony/symfony-demo |
7.1.1 | 8.1.7 | |
| +1 major | composer:symfony/http-client defined in: symfony/symfony-demo |
7.1.1 | 8.1.7 | |
| +2 major | composer:symfony/http-foundation defined in: bookstackapp/bookstack, drupal/drupal +1 more |
6.4.12 | 8.1.7 | |
| +2 major | composer:symfony/http-kernel defined in: bookstackapp/bookstack, drupal/drupal +1 more |
6.4.12 | 8.1.7 | |
| +1 major | composer:symfony/intl defined in: symfony/symfony-demo |
7.1.1 | 8.1.5 | |
| +1 major | composer:symfony/mailer defined in: symfony/symfony-demo |
7.1.1 | 8.1.7 | |
| +2 major | composer:symfony/mime defined in: bookstackapp/bookstack, symfony/symfony-demo |
6.4.12 | 8.1.7 | |
| +1 major | composer:symfony/monolog-bridge defined in: symfony/symfony-demo |
7.1.1 | 8.1.6 | |
| +1 major | composer:symfony/monolog-bundle defined in: symfony/symfony-demo |
3.10.0 | 4.1.0 | |
| +1 major | composer:symfony/options-resolver defined in: symfony/symfony-demo |
7.1.1 | 8.1.0 | |
| +1 major | composer:symfony/password-hasher defined in: symfony/symfony-demo |
7.1.1 | 8.1.0 | |
| +5 major | composer:symfony/phpunit-bridge defined in: drupal/drupal, symfony/symfony-demo |
3.4.4 | 8.1.6 | |
| +2 major | composer:symfony/process defined in: bookstackapp/bookstack, drupal/drupal +1 more |
6.4.12 | 8.1.7 | |
| +1 major | composer:symfony/property-access defined in: symfony/symfony-demo |
7.1.1 | 8.1.4 | |
| +1 major | composer:symfony/property-info defined in: symfony/symfony-demo |
7.1.1 | 8.1.7 | |
| +7 major | composer:symfony/psr-http-message-bridge defined in: drupal/drupal |
1.0.2 | 8.1.0 | |
| +2 major | composer:symfony/routing defined in: bookstackapp/bookstack, drupal/drupal +1 more |
6.4.12 | 8.1.6 | |
| +1 major | composer:symfony/runtime defined in: symfony/symfony-demo |
7.1.1 | 8.1.0 | |
| +1 major | composer:symfony/security-bundle defined in: symfony/symfony-demo |
7.1.1 | 8.1.7 | |
| +1 major | composer:symfony/security-core defined in: symfony/symfony-demo |
7.1.1 | 8.1.6 | |
| +1 major | composer:symfony/security-csrf defined in: symfony/symfony-demo |
7.1.1 | 8.1.0 | |
| +1 major | composer:symfony/security-http defined in: symfony/symfony-demo |
7.1.1 | 8.1.7 | |
| +5 major | composer:symfony/serializer defined in: drupal/drupal |
3.4.4 | 8.1.7 | |
| +1 major | composer:symfony/stimulus-bundle defined in: symfony/symfony-demo |
2.17.0 | 3.5.1 | |
| +1 major | composer:symfony/stopwatch defined in: symfony/symfony-demo |
7.1.1 | 8.1.0 | |
| +2 major | composer:symfony/string defined in: bookstackapp/bookstack, symfony/symfony-demo |
6.4.12 | 8.1.7 | |
| +2 major | composer:symfony/translation defined in: bookstackapp/bookstack, drupal/drupal +1 more |
6.4.12 | 8.1.5 | |
| +1 major | composer:symfony/twig-bridge defined in: symfony/symfony-demo |
7.1.1 | 8.1.7 | |
| +1 major | composer:symfony/twig-bundle defined in: symfony/symfony-demo |
7.1.1 | 8.1.7 | |
| +1 major | composer:symfony/type-info defined in: symfony/symfony-demo |
7.1.1 | 8.1.5 | |
| +2 major | composer:symfony/uid defined in: bookstackapp/bookstack |
6.4.12 | 8.1.5 | |
| +1 major | composer:symfony/ux-live-component defined in: symfony/symfony-demo |
2.17.0 | 3.5.1 | |
| +1 major | composer:symfony/ux-twig-component defined in: symfony/symfony-demo |
2.17.0 | 3.5.1 | |
| +5 major | composer:symfony/validator defined in: drupal/drupal, symfony/symfony-demo |
3.4.4 | 8.1.7 | |
| +2 major | composer:symfony/var-dumper defined in: bookstackapp/bookstack, symfony/symfony-demo |
6.4.11 | 8.1.7 | |
| +1 major | composer:symfony/var-exporter defined in: symfony/symfony-demo |
7.1.1 | 8.1.6 | |
| +1 major | composer:symfony/web-profiler-bundle defined in: symfony/symfony-demo |
7.1.1 | 8.1.7 | |
| +5 major | composer:symfony/yaml defined in: drupal/drupal, symfony/symfony-demo |
3.4.5 | 8.1.6 | |
| +1 major | composer:theseer/tokenizer defined in: bookstackapp/bookstack |
1.2.3 | 2.0.1 | |
| +1 major | composer:twbs/bootstrap defined in: symfony/symfony-demo |
4.6.2 | 5.3.8 | |
| +2 major | composer:twig/twig defined in: drupal/drupal, symfony/symfony-demo |
1.35.0 | 3.29.0 | |
| +1 major | composer:webmozart/assert defined in: bookstackapp/bookstack |
1.11.0 | 2.4.1 | |
| +1 major | composer:wikimedia/composer-merge-plugin defined in: drupal/drupal |
1.4.1 | 2.1.0 | |
| +74 minor | composer:aws/aws-sdk-php defined in: bookstackapp/bookstack |
3.322.6 | 3.396.0 | |
| +1 minor | composer:bacon/bacon-qr-code defined in: bookstackapp/bookstack |
3.0.0 | 3.1.1 | |
| +13 minor | composer:behat/mink defined in: drupal/drupal |
dev-master | 1.13.0 | |
| +7 minor | composer:behat/mink-selenium2-driver defined in: drupal/drupal |
dev-master | 1.7.0 | |
| +4 minor | composer:dama/doctrine-test-bundle defined in: symfony/symfony-demo |
8.2.0 | 8.6.0 | |
| +1 minor | composer:doctrine/event-manager defined in: bookstackapp/bookstack, symfony/symfony-demo |
2.0.1 | 2.1.1 | |
| +1 minor | composer:doctrine/inflector defined in: bookstackapp/bookstack, drupal/drupal +1 more |
2.0.10 | 2.1.0 | |
| +1 minor | composer:doctrine/instantiator defined in: drupal/drupal, symfony/symfony-demo |
2.0.0 | 2.1.0 | |
| +2 minor | composer:doctrine/migrations defined in: symfony/symfony-demo |
3.7.4 | 3.9.7 | |
| +5 minor | composer:doctrine/orm defined in: symfony/symfony-demo |
3.2.0 | 3.7.2 | |
| +1 minor | composer:doctrine/sql-formatter defined in: symfony/symfony-demo |
1.4.0 | 1.5.4 | |
| +1 minor | composer:dompdf/dompdf defined in: bookstackapp/bookstack |
3.0.0 | 3.1.6 | |
| +3 minor | composer:dragonmantank/cron-expression defined in: bookstackapp/bookstack |
3.3.3 | 3.6.0 | |
| +1 minor | composer:fakerphp/faker defined in: bookstackapp/bookstack |
1.23.1 | 1.24.1 | |
| +2 minor | composer:filp/whoops defined in: bookstackapp/bookstack |
2.16.0 | 2.18.5 | |
| +1 minor | composer:fruitcake/php-cors defined in: bookstackapp/bookstack |
1.3.0 | 1.4.0 | |
| +1 minor | composer:graham-campbell/result-type defined in: bookstackapp/bookstack |
1.1.3 | 1.2.0 | |
| +1 minor | composer:itsgoingd/clockwork defined in: bookstackapp/bookstack |
5.2.2 | 5.3.5 | |
| +2 minor | composer:jcalderonzumba/gastonjs defined in: drupal/drupal |
1.0.2 | 1.2.0 | |
| +2 minor | composer:knplabs/knp-snappy defined in: bookstackapp/bookstack |
1.5.0 | 1.7.3 | |
| +2 minor | composer:laravel/prompts defined in: bookstackapp/bookstack |
0.1.25 | 0.3.24 | |
| +15 minor | composer:laravel/socialite defined in: bookstackapp/bookstack |
5.16.0 | 5.31.0 | |
| +5 minor | composer:league/commonmark defined in: bookstackapp/bookstack, symfony/symfony-demo |
2.5.3 | 2.10.3 | |
| +8 minor | composer:league/flysystem defined in: bookstackapp/bookstack |
3.28.0 | 3.36.0 | |
| +7 minor | composer:league/flysystem-aws-s3-v3 defined in: bookstackapp/bookstack |
3.28.0 | 3.35.3 | |
| +7 minor | composer:league/flysystem-local defined in: bookstackapp/bookstack |
3.28.0 | 3.35.3 | |
| +1 minor | composer:league/mime-type-detection defined in: bookstackapp/bookstack |
1.16.0 | 1.17.0 | |
| +2 minor | composer:league/oauth1-client defined in: bookstackapp/bookstack |
1.10.1 | 1.12.0 | |
| +2 minor | composer:league/oauth2-client defined in: bookstackapp/bookstack |
2.7.0 | 2.9.1 | |
| +4 minor | composer:league/uri defined in: symfony/symfony-demo |
7.4.1 | 7.8.1 | |
| +4 minor | composer:league/uri-interfaces defined in: symfony/symfony-demo |
7.4.1 | 7.8.1 | |
| +2 minor | composer:masterminds/html5 defined in: bookstackapp/bookstack, drupal/drupal +1 more |
2.9.0 | 2.11.0 | |
| +5 minor | composer:monolog/monolog defined in: bookstackapp/bookstack, symfony/symfony-demo |
3.7.0 | 3.12.0 | |
| +1 minor | composer:mtdowling/jmespath.php defined in: bookstackapp/bookstack |
2.8.0 | 2.9.2 | |
| +2 minor | composer:myclabs/deep-copy defined in: bookstackapp/bookstack |
1.12.0 | 1.14.0 | |
| +1 minor | composer:nette/utils defined in: bookstackapp/bookstack, symfony/symfony-demo |
4.0.5 | 4.1.5 | |
| +7 minor | composer:nikic/php-parser defined in: bookstackapp/bookstack, symfony/symfony-demo |
5.2.0 | 5.9.0 | |
| +1 minor | composer:onelogin/php-saml defined in: bookstackapp/bookstack |
4.2.0 | 4.3.2 | |
| +1 minor | composer:paragonie/constant_time_encoding defined in: bookstackapp/bookstack |
3.0.0 | 3.1.3 | |
| +1 minor | composer:phpoption/phpoption defined in: bookstackapp/bookstack |
1.9.3 | 1.10.0 | |
| +19 minor | composer:phpspec/prophecy defined in: drupal/drupal |
1.7.0 | 1.26.1 | |
| +1 minor | composer:phpstan/extension-installer defined in: symfony/symfony-demo |
1.3.1 | 1.4.3 | |
| +1 minor | composer:ramsey/collection defined in: bookstackapp/bookstack |
2.0.0 | 2.1.1 | |
| +2 minor | composer:ramsey/uuid defined in: bookstackapp/bookstack |
4.7.6 | 4.9.4 | |
| +4 minor | composer:socialiteproviders/manager defined in: bookstackapp/bookstack |
4.6.0 | 4.10.0 | |
| +1 minor | composer:socialiteproviders/okta defined in: bookstackapp/bookstack |
4.4.0 | 4.5.0 | |
| +2 minor | composer:ssddanbrown/asserthtml defined in: bookstackapp/bookstack |
3.0.0 | 3.2.0 | |
| +2 minor | composer:symfony/cache-contracts defined in: symfony/symfony-demo |
3.5.0 | 3.7.1 | |
| +2 minor | composer:symfony/deprecation-contracts defined in: bookstackapp/bookstack, symfony/symfony-demo |
3.5.0 | 3.7.1 | |
| +2 minor | composer:symfony/event-dispatcher-contracts defined in: bookstackapp/bookstack, symfony/symfony-demo |
3.5.0 | 3.7.1 | |
| +7 minor | composer:symfony/flex defined in: symfony/symfony-demo |
2.4.5 | 2.11.0 | |
| +2 minor | composer:symfony/http-client-contracts defined in: symfony/symfony-demo |
3.5.0 | 3.7.3 | |
| +9 minor | composer:symfony/maker-bundle defined in: symfony/symfony-demo |
1.59.1 | 1.68.0 | |
| +6 minor | composer:symfony/polyfill-ctype defined in: bookstackapp/bookstack, symfony/symfony-demo |
1.31.0 | 1.37.0 | |
| +31 minor | composer:symfony/polyfill-iconv defined in: drupal/drupal |
1.6.0 | 1.37.0 | |
| +10 minor | composer:symfony/polyfill-intl-grapheme defined in: bookstackapp/bookstack, symfony/symfony-demo |
1.31.0 | 1.41.0 | |
| +9 minor | composer:symfony/polyfill-intl-icu defined in: symfony/symfony-demo |
1.29.0 | 1.38.0 | |
| +11 minor | composer:symfony/polyfill-intl-idn defined in: bookstackapp/bookstack, symfony/symfony-demo |
1.31.0 | 1.42.0 | |
| +9 minor | composer:symfony/polyfill-intl-messageformatter defined in: symfony/symfony-demo |
1.29.0 | 1.38.0 | |
| +11 minor | composer:symfony/polyfill-intl-normalizer defined in: bookstackapp/bookstack, symfony/symfony-demo |
1.31.0 | 1.42.0 | |
| +7 minor | composer:symfony/polyfill-mbstring defined in: bookstackapp/bookstack, drupal/drupal +1 more |
1.31.0 | 1.38.2 | |
| +14 minor | composer:symfony/polyfill-php70 defined in: drupal/drupal |
1.6.0 | 1.20.0 | |
| +6 minor | composer:symfony/polyfill-php80 defined in: bookstackapp/bookstack |
1.31.0 | 1.37.0 | |
| +10 minor | composer:symfony/polyfill-php83 defined in: bookstackapp/bookstack, symfony/symfony-demo |
1.31.0 | 1.41.0 | |
| +6 minor | composer:symfony/polyfill-uuid defined in: bookstackapp/bookstack |
1.31.0 | 1.37.0 | |
| +2 minor | composer:symfony/service-contracts defined in: bookstackapp/bookstack, symfony/symfony-demo |
3.5.0 | 3.7.3 | |
| +2 minor | composer:symfony/translation-contracts defined in: bookstackapp/bookstack, symfony/symfony-demo |
3.5.0 | 3.7.1 | |
| +7 minor | composer:symfonycasts/sass-bundle defined in: symfony/symfony-demo |
0.3.0 | 0.10.0 | |
| +2 minor | composer:tijsverkoyen/css-to-inline-styles defined in: bookstackapp/bookstack |
2.2.7 | 2.4.0 | |
| +19 minor | composer:twig/extra-bundle defined in: symfony/symfony-demo |
3.10.0 | 3.29.0 | |
| +19 minor | composer:twig/intl-extra defined in: symfony/symfony-demo |
3.10.0 | 3.29.0 | |
| +19 minor | composer:twig/markdown-extra defined in: symfony/symfony-demo |
3.10.0 | 3.29.0 | |
| +1 minor | composer:vlucas/phpdotenv defined in: bookstackapp/bookstack |
5.6.1 | 5.7.0 | |
| +1 minor | composer:voku/portable-ascii defined in: bookstackapp/bookstack |
2.0.1 | 2.1.1 | |
| +1 patch | composer:aws/aws-crt-php defined in: bookstackapp/bookstack |
1.2.6 | 1.2.7 | |
| +1 patch | composer:dasprid/enum defined in: bookstackapp/bookstack |
1.0.6 | 1.0.7 | |
| +3 patch | composer:doctrine/deprecations defined in: bookstackapp/bookstack, symfony/symfony-demo |
1.1.3 | 1.1.6 | |
| +1 patch | composer:doctrine/lexer defined in: bookstackapp/bookstack, drupal/drupal +1 more |
3.0.1 | 3.0.2 | |
| +2 patch | composer:dompdf/php-font-lib defined in: bookstackapp/bookstack |
1.0.0 | 1.0.2 | |
| +2 patch | composer:dompdf/php-svg-lib defined in: bookstackapp/bookstack |
1.0.0 | 1.0.2 | |
| +2 patch | composer:egulias/email-validator defined in: bookstackapp/bookstack, drupal/drupal +1 more |
4.0.2 | 4.0.4 | |
| +15 patch | composer:instaclick/php-webdriver defined in: drupal/drupal |
1.4.5 | 1.4.20 | |
| +1 patch | composer:jcalderonzumba/mink-phantomjs-driver defined in: drupal/drupal |
0.3.2 | 0.3.3 | |
| +1 patch | composer:league/html-to-markdown defined in: bookstackapp/bookstack |
5.1.1 | 5.1.2 | |
| +7 patch | composer:mikey179/vfsStream defined in: drupal/drupal |
1.6.5 | 1.6.12 | |
| +3 patch | composer:mockery/mockery defined in: bookstackapp/bookstack |
1.6.12 | 1.6.15 | |
| +6 patch | composer:nette/schema defined in: bookstackapp/bookstack, symfony/symfony-demo |
1.3.0 | 1.3.6 | |
| +20 patch | composer:psy/psysh defined in: bookstackapp/bookstack |
0.12.4 | 0.12.24 | |
| +1 patch | composer:socialiteproviders/microsoft-azure defined in: bookstackapp/bookstack |
5.2.0 | 5.2.1 |
| Dependency | License(s) | Source | |
|---|---|---|---|
| composer: drupal/coder 8.2.12 direct dev defined in: drupal/drupal |
GPL-2.0 | packagist | |
| composer: nette/schema 1.3.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
BSD-3-Clause, GPL-2.0-only, GPL-3.0-only | packagist | |
| composer: nette/utils 4.0.5 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
BSD-3-Clause, GPL-2.0-only, GPL-3.0-only | packagist | |
| composer: phpmyadmin/sql-parser 5.10.0 direct dev defined in: bookstackapp/bookstack |
GPL-2.0-or-later | packagist |
| Dependency | License(s) | Source | |
|---|---|---|---|
| composer: dompdf/dompdf 3.0.0 direct defined in: bookstackapp/bookstack |
LGPL-2.1 | packagist | |
| composer: dompdf/php-font-lib 1.0.0 direct defined in: bookstackapp/bookstack |
LGPL-2.1-or-later | packagist | |
| composer: dompdf/php-svg-lib 1.0.0 direct defined in: bookstackapp/bookstack |
LGPL-3.0-or-later | packagist |
| Dependency | License(s) | Source | |
|---|---|---|---|
| composer: asm89/stack-cors 1.2.0 direct defined in: drupal/drupal |
MIT | packagist | |
| composer: aws/aws-crt-php 1.2.6 direct defined in: bookstackapp/bookstack |
Apache-2.0 | packagist | |
| composer: aws/aws-sdk-php 3.322.6 direct defined in: bookstackapp/bookstack |
Apache-2.0 | packagist | |
| composer: bacon/bacon-qr-code 3.0.0 direct defined in: bookstackapp/bookstack |
BSD-2-Clause | packagist | |
| composer: behat/mink dev-master direct dev defined in: drupal/drupal |
MIT | packagist | |
| composer: behat/mink-browserkit-driver 1.3.2 direct dev defined in: drupal/drupal |
MIT | packagist | |
| composer: behat/mink-goutte-driver 1.2.1 direct dev defined in: drupal/drupal |
MIT | packagist | |
| composer: behat/mink-selenium2-driver dev-master direct dev defined in: drupal/drupal |
MIT | packagist | |
| composer: brick/math 0.12.1 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: carbonphp/carbon-doctrine-types 2.1.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: composer/installers 1.5.0 direct defined in: drupal/drupal |
MIT | packagist | |
| composer: composer/semver 1.4.2 direct defined in: drupal/drupal, symfony/symfony-demo |
MIT | packagist | |
| composer: dama/doctrine-test-bundle 8.2.0 direct dev defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: dasprid/enum 1.0.6 direct defined in: bookstackapp/bookstack |
BSD-2-Clause | packagist | |
| composer: dflydev/dot-access-data 3.0.3 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: doctrine/annotations 1.2.7 direct defined in: drupal/drupal |
MIT | packagist | |
| composer: doctrine/cache 2.2.0 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: doctrine/collections 1.3.0 direct defined in: drupal/drupal, symfony/symfony-demo |
MIT | packagist | |
| composer: doctrine/common 2.6.2 direct defined in: drupal/drupal |
MIT | packagist | |
| composer: doctrine/data-fixtures 1.7.0 direct dev defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: doctrine/dbal 3.9.1 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: doctrine/deprecations 1.1.3 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: doctrine/doctrine-bundle 2.12.0 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: doctrine/doctrine-fixtures-bundle 3.6.1 direct dev defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: doctrine/doctrine-migrations-bundle 3.3.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: doctrine/event-manager 2.0.1 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: doctrine/inflector 2.0.10 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: doctrine/instantiator 2.0.0 direct defined in: drupal/drupal, symfony/symfony-demo |
MIT | packagist | |
| composer: doctrine/lexer 3.0.1 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: doctrine/migrations 3.7.4 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: doctrine/orm 3.2.0 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: doctrine/persistence 3.3.2 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: doctrine/sql-formatter 1.4.0 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: dragonmantank/cron-expression 3.3.3 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: easyrdf/easyrdf 0.9.1 direct defined in: drupal/drupal |
BSD-3-Clause | packagist | |
| composer: egulias/email-validator 4.0.2 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: fabpot/goutte 3.2.1 direct dev defined in: drupal/drupal |
MIT | packagist | |
| composer: fakerphp/faker 1.23.1 direct dev defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: filp/whoops 2.16.0 direct dev defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: firebase/php-jwt 6.10.1 direct defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: fruitcake/php-cors 1.3.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: graham-campbell/result-type 1.1.3 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: guzzlehttp/guzzle 7.9.2 direct defined in: bookstackapp/bookstack, drupal/drupal |
MIT | packagist | |
| composer: guzzlehttp/promises 2.0.3 direct defined in: bookstackapp/bookstack, drupal/drupal |
MIT | packagist | |
| composer: guzzlehttp/psr7 2.7.0 direct defined in: bookstackapp/bookstack, drupal/drupal |
MIT | packagist | |
| composer: guzzlehttp/uri-template 1.0.3 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: hamcrest/hamcrest-php 2.0.1 direct dev defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: instaclick/php-webdriver 1.4.5 direct dev defined in: drupal/drupal |
Apache-2.0 | packagist | |
| composer: intervention/gif 4.2.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: intervention/image 3.8.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: ircmaxell/password-compat 1.0.4 direct dev defined in: drupal/drupal |
MIT | packagist | |
| composer: itsgoingd/clockwork 5.2.2 direct dev defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: jcalderonzumba/gastonjs 1.0.2 direct dev defined in: drupal/drupal |
MIT | packagist | |
| composer: jcalderonzumba/mink-phantomjs-driver 0.3.2 direct dev defined in: drupal/drupal |
MIT | packagist | |
| composer: knplabs/knp-snappy 1.5.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: larastan/larastan 2.9.8 direct dev defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: laravel/framework 10.48.22 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: laravel/prompts 0.1.25 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: laravel/serializable-closure 1.3.5 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: laravel/socialite 5.16.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: laravel/tinker 2.10.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: league/commonmark 2.5.3 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
BSD-3-Clause | packagist | |
| composer: league/config 1.2.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
BSD-3-Clause | packagist | |
| composer: league/flysystem 3.28.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: league/flysystem-aws-s3-v3 3.28.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: league/flysystem-local 3.28.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: league/html-to-markdown 5.1.1 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: league/mime-type-detection 1.16.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: league/oauth1-client 1.10.1 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: league/oauth2-client 2.7.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: league/uri 7.4.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: league/uri-interfaces 7.4.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: masterminds/html5 2.9.0 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: mikey179/vfsStream 1.6.5 direct dev defined in: drupal/drupal |
BSD-3-Clause | packagist | |
| composer: mockery/mockery 1.6.12 direct dev defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: monolog/monolog 3.7.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: mtdowling/jmespath.php 2.8.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: myclabs/deep-copy 1.12.0 direct dev defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: nesbot/carbon 2.72.5 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: nikic/php-parser 5.2.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
BSD-3-Clause | packagist | |
| composer: nunomaduro/collision 7.10.0 direct dev defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: nunomaduro/termwind 1.15.1 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: onelogin/php-saml 4.2.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: paragonie/constant_time_encoding 3.0.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: paragonie/random_compat 9.99.100 direct defined in: bookstackapp/bookstack, drupal/drupal |
MIT | packagist | |
| composer: phar-io/manifest 2.0.4 direct dev defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: phar-io/version 3.2.1 direct dev defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: phpdocumentor/reflection-docblock 2.0.4 direct dev defined in: drupal/drupal |
MIT | packagist | |
| composer: phpoption/phpoption 1.9.3 direct defined in: bookstackapp/bookstack |
Apache-2.0 | packagist | |
| composer: phpseclib/phpseclib 3.0.42 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: phpspec/prophecy 1.7.0 direct dev defined in: drupal/drupal |
MIT | packagist | |
| composer: phpstan/extension-installer 1.3.1 direct dev defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: phpstan/phpstan 1.12.5 direct dev defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: phpstan/phpstan-doctrine 1.4.1 direct dev defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: phpstan/phpstan-symfony 1.4.3 direct dev defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: phpunit/php-code-coverage 10.1.16 direct dev defined in: bookstackapp/bookstack, drupal/drupal |
BSD-3-Clause | packagist | |
| composer: phpunit/php-file-iterator 4.1.0 direct dev defined in: bookstackapp/bookstack, drupal/drupal |
BSD-3-Clause | packagist | |
| composer: phpunit/php-invoker 4.0.0 direct dev defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: phpunit/php-text-template 3.0.1 direct dev defined in: bookstackapp/bookstack, drupal/drupal |
BSD-3-Clause | packagist | |
| composer: phpunit/php-timer 6.0.0 direct dev defined in: bookstackapp/bookstack, drupal/drupal |
BSD-3-Clause | packagist | |
| composer: phpunit/php-token-stream 1.4.11 direct dev defined in: drupal/drupal |
BSD-3-Clause | packagist | |
| composer: phpunit/phpunit 10.5.35 direct dev defined in: bookstackapp/bookstack, drupal/drupal |
BSD-3-Clause | packagist | |
| composer: phpunit/phpunit-mock-objects 2.3.8 direct dev defined in: drupal/drupal |
BSD-3-Clause | packagist | |
| composer: pragmarx/google2fa 8.0.3 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: predis/predis 2.2.2 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: psr/cache 3.0.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: psr/clock 1.0.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: psr/container 2.0.2 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: psr/event-dispatcher 1.0.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: psr/http-client 1.0.3 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: psr/http-factory 1.1.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: psr/http-message 2.0 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: psr/log 3.0.2 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: psr/simple-cache 3.0.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: psy/psysh 0.12.4 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: ralouphie/getallheaders 3.0.3 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: ramsey/collection 2.0.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: ramsey/uuid 4.7.6 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: robrichards/xmlseclibs 3.1.1 direct defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: sabberworm/php-css-parser 8.6.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: sebastian/cli-parser 2.0.1 direct dev defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: sebastian/code-unit 2.0.0 direct dev defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: sebastian/code-unit-reverse-lookup 3.0.0 direct dev defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: sebastian/comparator 5.0.2 direct dev defined in: bookstackapp/bookstack, drupal/drupal |
BSD-3-Clause | packagist | |
| composer: sebastian/complexity 3.2.0 direct dev defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: sebastian/diff 5.1.1 direct dev defined in: bookstackapp/bookstack, drupal/drupal |
BSD-3-Clause | packagist | |
| composer: sebastian/environment 6.1.0 direct dev defined in: bookstackapp/bookstack, drupal/drupal |
BSD-3-Clause | packagist | |
| composer: sebastian/exporter 5.1.2 direct dev defined in: bookstackapp/bookstack, drupal/drupal |
BSD-3-Clause | packagist | |
| composer: sebastian/global-state 6.0.2 direct dev defined in: bookstackapp/bookstack, drupal/drupal |
BSD-3-Clause | packagist | |
| composer: sebastian/lines-of-code 2.0.2 direct dev defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: sebastian/object-enumerator 5.0.0 direct dev defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: sebastian/object-reflector 3.0.0 direct dev defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: sebastian/recursion-context 5.0.0 direct dev defined in: bookstackapp/bookstack, drupal/drupal |
BSD-3-Clause | packagist | |
| composer: sebastian/type 4.0.0 direct dev defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: sebastian/version 4.0.1 direct dev defined in: bookstackapp/bookstack, drupal/drupal |
BSD-3-Clause | packagist | |
| composer: socialiteproviders/discord 4.2.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: socialiteproviders/gitlab 4.1.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: socialiteproviders/manager 4.6.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: socialiteproviders/microsoft-azure 5.2.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: socialiteproviders/okta 4.4.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: socialiteproviders/twitch 5.4.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: squizlabs/php_codesniffer 3.10.3 direct dev defined in: bookstackapp/bookstack, drupal/drupal |
BSD-3-Clause | packagist | |
| composer: ssddanbrown/asserthtml 3.0.0 direct dev defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: ssddanbrown/htmldiff 1.0.3 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: ssddanbrown/symfony-mailer 6.4.x-dev direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: stack/builder 1.0.5 direct defined in: drupal/drupal |
MIT | packagist | |
| composer: symfony-cmf/routing 1.4.1 direct defined in: drupal/drupal |
MIT | packagist | |
| composer: symfony/apache-pack 1.0.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/asset 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/asset-mapper 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/browser-kit 3.4.4 direct dev defined in: drupal/drupal, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/cache 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/cache-contracts 3.5.0 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/class-loader 3.4.4 direct defined in: drupal/drupal |
MIT | packagist | |
| composer: symfony/clock 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/config 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/console 6.4.12 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: symfony/css-selector 6.4.8 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: symfony/debug 3.4.4 direct defined in: drupal/drupal |
MIT | packagist | |
| composer: symfony/debug-bundle 7.1.1 direct dev defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/dependency-injection 3.4.4 direct defined in: drupal/drupal, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/deprecation-contracts 3.5.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/doctrine-bridge 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/dom-crawler 6.4.12 direct dev defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: symfony/dotenv 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/error-handler 6.4.10 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/event-dispatcher 6.4.8 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: symfony/event-dispatcher-contracts 3.5.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/expression-language 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/filesystem 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/finder 6.4.11 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/flex 2.4.5 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/form 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/framework-bundle 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/html-sanitizer 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/http-client 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/http-client-contracts 3.5.0 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/http-foundation 6.4.12 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: symfony/http-kernel 6.4.12 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: symfony/intl 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/mailer 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/maker-bundle 1.59.1 direct dev defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/mime 6.4.12 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/monolog-bridge 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/monolog-bundle 3.10.0 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/options-resolver 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/password-hasher 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/phpunit-bridge 3.4.4 direct dev defined in: drupal/drupal, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/polyfill-ctype 1.31.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/polyfill-iconv 1.6.0 direct defined in: drupal/drupal |
MIT | packagist | |
| composer: symfony/polyfill-intl-grapheme 1.31.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/polyfill-intl-icu 1.29.0 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/polyfill-intl-idn 1.31.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/polyfill-intl-messageformatter 1.29.0 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/polyfill-intl-normalizer 1.31.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/polyfill-mbstring 1.31.0 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: symfony/polyfill-php70 1.6.0 direct defined in: drupal/drupal |
MIT | packagist | |
| composer: symfony/polyfill-php80 1.31.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: symfony/polyfill-php83 1.31.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/polyfill-uuid 1.31.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: symfony/process 6.4.12 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: symfony/property-access 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/property-info 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/psr-http-message-bridge 1.0.2 direct defined in: drupal/drupal |
MIT | packagist | |
| composer: symfony/routing 6.4.12 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: symfony/runtime 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/security-bundle 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/security-core 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/security-csrf 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/security-http 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/serializer 3.4.4 direct defined in: drupal/drupal |
MIT | packagist | |
| composer: symfony/service-contracts 3.5.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/stimulus-bundle 2.17.0 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/stopwatch 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/string 6.4.12 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/translation 6.4.12 direct defined in: bookstackapp/bookstack, drupal/drupal +1 more |
MIT | packagist | |
| composer: symfony/translation-contracts 3.5.0 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/twig-bridge 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/twig-bundle 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/type-info 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/uid 6.4.12 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: symfony/ux-live-component 2.17.0 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/ux-twig-component 2.17.0 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/validator 3.4.4 direct defined in: drupal/drupal, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/var-dumper 6.4.11 direct defined in: bookstackapp/bookstack, symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/var-exporter 7.1.1 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/web-profiler-bundle 7.1.1 direct dev defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: symfony/yaml 3.4.5 direct defined in: drupal/drupal, symfony/symfony-demo |
MIT | packagist | |
| composer: symfonycasts/sass-bundle 0.3.0 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: theseer/tokenizer 1.2.3 direct dev defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: tijsverkoyen/css-to-inline-styles 2.2.7 direct defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: twbs/bootstrap 4.6.2 direct dev defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: twig/extra-bundle 3.10.0 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: twig/intl-extra 3.10.0 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: twig/markdown-extra 3.10.0 direct defined in: symfony/symfony-demo |
MIT | packagist | |
| composer: twig/twig 1.35.0 direct defined in: drupal/drupal, symfony/symfony-demo |
BSD-3-Clause | packagist | |
| composer: vlucas/phpdotenv 5.6.1 direct defined in: bookstackapp/bookstack |
BSD-3-Clause | packagist | |
| composer: voku/portable-ascii 2.0.1 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: webmozart/assert 1.11.0 direct defined in: bookstackapp/bookstack |
MIT | packagist | |
| composer: wikimedia/composer-merge-plugin 1.4.1 direct defined in: drupal/drupal |
MIT | packagist | |
| composer: zendframework/zend-diactoros 1.4.1 direct defined in: drupal/drupal |
BSD-2-Clause | packagist | |
| composer: zendframework/zend-escaper 2.5.2 direct defined in: drupal/drupal |
BSD-3-Clause | packagist | |
| composer: zendframework/zend-feed 2.7.0 direct defined in: drupal/drupal |
BSD-3-Clause | packagist | |
| composer: zendframework/zend-stdlib 3.0.1 direct defined in: drupal/drupal |
BSD-3-Clause | packagist |
| Worst sev | Direct dependency | Current | Pin to ≥ | Maven Central latest | CVEs covered |
|---|---|---|---|---|---|
| CRITICAL | composer:twig/twig | 1.35.0 | 3.27.0 | — | 35 CVE: CVE-2026-46633, CVE-2026-46633, CVE-2022-39261, CVE-2026-24425… |
| CRITICAL | composer:drupal/core | 8.5.0 | 10.6.13 | — | 16 CVE: CVE-2018-7600, CVE-2018-7602, CVE-2026-55803, CVE-2018-9861… |
| CRITICAL | composer:symfony/http-foundation | 3.4.4 | 7.2.0 | — | 12 CVE: CVE-2019-10913, CVE-2019-18888, CVE-2025-64500, CVE-2025-64500… |
| CRITICAL | composer:symfony/dependency-injection | 3.4.4 | 3.4.26 | — | 1 CVE: CVE-2019-10910 |
| CRITICAL | composer:mtdowling/jmespath.php | 2.8.0 | 2.9.1 | — | 1 CVE: CVE-2026-54133 |
| CRITICAL | composer:onelogin/php-saml | 4.2.0 | 4.3.1 | — | 1 CVE: GHSA-5j8p-438x-rgg5 |
| HIGH | composer:league/commonmark | 2.5.3 | 2.10.0 | — | 26 CVE: CVE-2024-58382, CVE-2024-58382, CVE-2026-71488, CVE-2026-71488… |
| HIGH | composer:guzzlehttp/guzzle | 6.3.0 | 7.15.2 | — | 22 CVE: CVE-2022-29248, CVE-2022-31042, CVE-2022-31090, CVE-2022-31091… |
| HIGH | composer:symfony/process | 6.4.12 | 7.1.7 | — | 5 CVE: CVE-2024-51736, CVE-2024-51736, CVE-2024-51736, CVE-2026-24739… |
| HIGH | composer:symfony/security-http | 7.1.1 | 7.2.0 | — | 4 CVE: CVE-2024-51996, CVE-2026-45063, CVE-2026-48489, CVE-2026-45074 |
| HIGH | composer:laravel/framework | 10.48.22 | 12.61.1 | — | 4 CVE: CVE-2024-52301, CVE-2026-48019, CVE-2025-27515, GHSA-crmm-hgp2-wgrp |
| HIGH | composer:phpseclib/phpseclib | 3.0.42 | 3.0.51 | — | 4 CVE: CVE-2026-32935, CVE-2026-44167, CVE-2026-55599, CVE-2026-40194 |
| HIGH | composer:symfony/mime | 6.4.12 | 7.2.0 | — | 4 CVE: CVE-2026-45067, CVE-2026-45067, CVE-2026-45070, CVE-2026-45070 |
| HIGH | composer:symfony/http-kernel | 3.4.4 | 4.0.0 | — | 2 CVE: CVE-2019-18887, CVE-2022-24894 |
| HIGH | composer:robrichards/xmlseclibs | 3.1.1 | 3.1.5 | — | 2 CVE: CVE-2026-32313, CVE-2025-66578 |
| HIGH | composer:knplabs/knp-snappy | 1.5.0 | — (manual triage) | — | 2 CVE: CVE-2026-46643, CVE-2026-46683 |
| HIGH | composer:aws/aws-sdk-php | 3.322.6 | 3.368.0 | — | 2 CVE: GHSA-27qh-8cxx-2cr5, CVE-2025-14761 |
| HIGH | composer:zendframework/zend-diactoros | 1.4.1 | 1.8.4 | — | 2 CVE: GHSA-f6p5-76fp-m248, GHSA-fq4p-86hh-42v9 |
| HIGH | composer:zendframework/zend-feed | 2.7.0 | 2.10.3 | — | 2 CVE: GHSA-f6p5-76fp-m248, GHSA-jmmp-vh96-78rm |
| HIGH | composer:symfony/monolog-bridge | 7.1.1 | 7.2.0 | — | 1 CVE: CVE-2026-45077 |
| MEDIUM | composer:guzzlehttp/psr7 | 1.4.2 | 2.12.3 | — | 10 CVE: CVE-2022-24775, CVE-2023-29197, CVE-2026-48998, CVE-2026-48998… |
| MEDIUM | composer:symfony/routing | 6.4.12 | 7.2.0 | — | 6 CVE: CVE-2026-45065, CVE-2026-45065, CVE-2026-45065, CVE-2026-48784… |
| MEDIUM | composer:dompdf/dompdf | 3.0.0 | 3.1.6 | — | 6 CVE: CVE-2026-56722, CVE-2026-59941, CVE-2026-59942, CVE-2026-59943… |
| MEDIUM | composer:symfony/ux-live-component | 2.17.0 | 2.36.0 | — | 5 CVE: CVE-2025-47946, CVE-2026-49208, CVE-2026-49210, CVE-2026-49209… |
| MEDIUM | composer:symfony/html-sanitizer | 7.1.1 | 7.2.0 | — | 5 CVE: CVE-2026-45064, CVE-2026-45066, CVE-2026-48760, CVE-2026-48761… |
| MEDIUM | composer:symfony/runtime | 7.1.1 | 7.1.7 | — | 1 CVE: CVE-2024-50340 |
| MEDIUM | composer:nesbot/carbon | 2.72.5 | 2.72.6 | — | 1 CVE: CVE-2025-22145 |
| MEDIUM | composer:symfony/ux-twig-component | 2.17.0 | 2.25.1 | — | 1 CVE: CVE-2025-47946 |
| MEDIUM | composer:psy/psysh | 0.12.4 | — (manual triage) | — | 1 CVE: CVE-2026-25129 |
| MEDIUM | composer:symfony/mailer | 7.1.1 | 7.2.0 | — | 1 CVE: CVE-2026-45068 |
| MEDIUM | composer:symfony/cache | 7.1.1 | 7.2.0 | — | 1 CVE: CVE-2026-45073 |
| LOW | composer:symfony/yaml | 3.4.5 | 7.2.0 | — | 6 CVE: CVE-2026-45133, CVE-2026-45133, CVE-2026-45304, CVE-2026-45304… |
| LOW | composer:symfony/validator | 3.4.4 | 7.1.4 | — | 2 CVE: CVE-2024-50343, CVE-2024-50343 |
| LOW | composer:symfony/polyfill-intl-idn | 1.31.0 | 1.38.1 | — | 2 CVE: CVE-2026-46644, CVE-2026-46644 |
| LOW | composer:symfony/security-bundle | 7.1.1 | 7.1.3 | — | 1 CVE: CVE-2024-50341 |
| LOW | composer:symfony/http-client | 7.1.1 | 7.1.8 | — | 1 CVE: CVE-2024-50342 |
| LOW | composer:firebase/php-jwt | 6.10.1 | 7.0.0 | — | 1 CVE: CVE-2025-45769 |
| LOW | composer:twig/intl-extra | 3.10.0 | 3.26.0 | — | 1 CVE: CVE-2026-46629 |
| LOW | composer:twig/markdown-extra | 3.10.0 | 3.26.0 | — | 1 CVE: CVE-2026-46637 |
0. Transitive deps resolved from registries, and committed binaries (chapters 1B/1C), are not descriptors and are excluded here.| Descriptor | Ecosystem | Direct deps |
|---|---|---|
bookstack/composer.json |
Composer | 0 — ranges / no lockfile |
bookstack/composer.lock |
Composer | 147 |
drupal/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/composer.lock |
Composer | 77 |
drupal/core/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/Annotation/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/Assertion/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/Bridge/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/ClassFinder/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/Datetime/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/DependencyInjection/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/Diff/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/Discovery/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/EventDispatcher/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/FileCache/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/FileSystem/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/Gettext/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/Graph/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/HttpFoundation/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/PhpStorage/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/Plugin/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/ProxyBuilder/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/Render/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/Serialization/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/Transliteration/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/Utility/composer.json |
Composer | 0 — ranges / no lockfile |
drupal/core/lib/Drupal/Component/Uuid/composer.json |
Composer | 0 — ranges / no lockfile |
symfony-demo/composer.json |
Composer | 0 — ranges / no lockfile |
symfony-demo/composer.lock |
Composer | 118 |
wp/wp-includes/sodium_compat/composer.json |
Composer | 0 — ranges / no lockfile |
--exclude-path rules, anchored to --src. Paths are relative to the scan root. 8 pruned by default rules, 122 by --exclude-path. Nothing under these paths was read, so any dependency, vendored JS or binary inside them is not covered — re-run with --no-default-excludes or drop an --exclude-path rule to include one.| Directory (relative to --src) | Rule | Matched |
|---|---|---|
bookstack/dev/build | default | default-exclude (build) |
bookstack/public/dist | default | default-exclude (dist) |
bookstack/resources/views/vendor | default | default-exclude (vendor) |
bookstack/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/assets/vendor | default | default-exclude (vendor) |
drupal/core/lib/Drupal/Core/Test | --exclude-path | --exclude-path (**/Test/**) |
drupal/core/modules/action/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/aggregator/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/aggregator/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/ban/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/basic_auth/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/basic_auth/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/big_pipe/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/block_content/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/block_content/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/block_place/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/block/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/block/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/book/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/breakpoint/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/ckeditor/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/color/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/comment/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/comment/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/config_translation/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/config_translation/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/config/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/config/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/contact/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/content_moderation/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/content_translation/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/content_translation/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/contextual/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/contextual/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/datetime_range/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/datetime/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/datetime/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/dblog/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/dynamic_page_cache/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/editor/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/editor/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/field_layout/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/field_ui/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/field_ui/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/field/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/field/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/file/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/file/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/filter/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/forum/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/hal/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/help/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/history/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/image/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/image/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/inline_form_errors/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/language/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/layout_builder/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/layout_discovery/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/link/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/link/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/locale/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/media/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/menu_link_content/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/menu_ui/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/menu_ui/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/migrate_drupal_ui/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/migrate_drupal_ui/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/migrate_drupal/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/migrate_drupal/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/migrate/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/node/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/node/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/options/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/page_cache/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/path/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/path/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/quickedit/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/quickedit/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/rdf/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/rdf/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/responsive_image/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/responsive_image/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/rest/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/rest/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/search/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/search/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/serialization/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/serialization/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/settings_tray/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/shortcut/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/shortcut/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/simpletest/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/simpletest/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/statistics/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/statistics/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/syslog/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/system/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/system/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/taxonomy/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/taxonomy/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/telephone/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/text/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/text/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/toolbar/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/tour/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/tour/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/tracker/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/tracker/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/update/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/update/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/user/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/user/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/views_ui/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/views_ui/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/views/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/modules/views/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/modules/workflows/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/profiles/demo_umami/modules/demo_umami_content/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/profiles/demo_umami/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/profiles/minimal/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/profiles/standard/tests | --exclude-path | --exclude-path (**/tests/**) |
drupal/core/profiles/testing/modules/drupal_system_listing_compatible_test/src/Tests | --exclude-path | --exclude-path (**/Tests/**) |
drupal/core/scripts/test | --exclude-path | --exclude-path (**/test/**) |
drupal/core/tests | --exclude-path | --exclude-path (**/tests/**) |
symfony-demo/bin | default | default-exclude (bin) |
symfony-demo/config/packages | default | default-exclude (packages) |
symfony-demo/tests | --exclude-path | --exclude-path (**/tests/**) |
wp/wp-includes/css/dist | default | default-exclude (dist) |
wp/wp-includes/js/dist | default | default-exclude (dist) |
--offline re-run against the same cache (ship it with --export-cache) reproduces these findings.| Data source | State | As of | Detail |
|---|---|---|---|
| CVEProject (Maven index) | cached | 2026-09-24T06:54:21.297Z | 20191 CVEs |
| OSV.dev | cached | 2026-09-24T15:48:24.793Z | 20365 cached |
| Packagist security advisories | cached | 2026-09-24T15:47:29.429Z | 354 cached |
| OSV local DB (Maven) | cached | 2026-09-24T06:56:13.134Z | |
| NIST NVD | cached | 2026-09-24T15:50:25.789Z | 2035 cached |
| EPSS (FIRST.org) | cached | 2026-09-24T07:41:44.826Z | 743 entries |
| CISA KEV | cached | 2026-09-24T15:47:29.624Z | |
| endoflife.date | cached | 2026-09-24T07:10:41.138Z | 18 entries |
| Maven Central (latest) | cached | 2026-09-24T16:41:13.725Z | 284 entries |
| npm registry | cached | 2026-09-24T15:57:57.979Z | 2694 entries |
| NuGet registry | cached | 2026-09-19T14:06:03.234Z | 8 entries |
| Packagist | cached | 2026-09-24T16:41:13.728Z | 625 entries |
| Go module proxy | cached | 2026-09-19T09:45:19.860Z | 12 entries |
| RubyGems | cached | 2026-09-19T09:46:53.531Z | 6 entries |
MAL- advisories and the free CIRCL KnownMalicious flag; there is no antivirus/behavioural lane.--offline run uses exactly those snapshots.wp-content/plugins/akismet/_inc/akismet-admin.csswp-content/plugins/akismet/_inc/akismet-admin.jswp-content/plugins/akismet/_inc/akismet-frontend.jswp-content/plugins/akismet/_inc/akismet.csswp-content/plugins/akismet/_inc/akismet.jswp-content/plugins/akismet/_inc/fonts/inter.csswp-content/plugins/akismet/_inc/img/akismet-refresh-logo.svgwp-content/plugins/akismet/_inc/img/akismet-refresh-logo@2x.pngwp-content/plugins/akismet/_inc/img/arrow-left.svgwp-content/plugins/akismet/_inc/img/logo-a-2x.pngwp-content/plugins/akismet/_inc/img/logo-full-2x.pngwp-content/plugins/akismet/_inc/rtl/akismet-admin-rtl.csswp-content/plugins/akismet/_inc/rtl/akismet-rtl.csswp-content/plugins/akismet/.htaccesswp-content/plugins/akismet/akismet.phpwp-content/plugins/akismet/changelog.txtwp-content/plugins/akismet/class.akismet-admin.phpwp-content/plugins/akismet/class.akismet-cli.phpwp-content/plugins/akismet/class.akismet-rest-api.phpwp-content/plugins/akismet/class.akismet-widget.phpwp-content/plugins/akismet/class.akismet.phpwp-content/plugins/akismet/index.phpwp-content/plugins/akismet/LICENSE.txtwp-content/plugins/akismet/readme.txtwp-content/plugins/akismet/views/activate.phpwp-content/plugins/akismet/views/config.phpwp-content/plugins/akismet/views/connect-jp.phpwp-content/plugins/akismet/views/enter.phpwp-content/plugins/akismet/views/get.phpwp-content/plugins/akismet/views/logo.phpwp-content/plugins/akismet/views/notice.phpwp-content/plugins/akismet/views/predefined.phpwp-content/plugins/akismet/views/setup.phpwp-content/plugins/akismet/views/start.phpwp-content/plugins/akismet/views/stats.phpwp-content/plugins/akismet/views/title.phpwp-content/plugins/akismet/wrapper.phpwp-includes/css/dist/block-directory/style-rtl.csswp-includes/css/dist/block-directory/style-rtl.min.csswp-includes/css/dist/block-directory/style.csswp-includes/css/dist/block-directory/style.min.csswp-includes/css/dist/block-library/classic-rtl.csswp-includes/css/dist/block-library/classic-rtl.min.csswp-includes/css/dist/block-library/classic.csswp-includes/css/dist/block-library/classic.min.csswp-includes/css/dist/block-library/common-rtl.csswp-includes/css/dist/block-library/common-rtl.min.csswp-includes/css/dist/block-library/common.csswp-includes/css/dist/block-library/common.min.csswp-includes/css/dist/block-library/editor-elements-rtl.csswp-includes/css/dist/block-library/editor-elements-rtl.min.csswp-includes/css/dist/block-library/editor-elements.csswp-includes/css/dist/block-library/editor-elements.min.csswp-includes/css/dist/block-library/editor-rtl.csswp-includes/css/dist/block-library/editor-rtl.min.csswp-includes/css/dist/block-library/editor.csswp-includes/css/dist/block-library/editor.min.csswp-includes/css/dist/block-library/elements-rtl.csswp-includes/css/dist/block-library/elements-rtl.min.csswp-includes/css/dist/block-library/elements.csswp-includes/css/dist/block-library/elements.min.csswp-includes/css/dist/block-library/reset-rtl.csswp-includes/css/dist/block-library/reset-rtl.min.csswp-includes/css/dist/block-library/reset.csswp-includes/css/dist/block-library/reset.min.csswp-includes/css/dist/block-library/style-rtl.csswp-includes/css/dist/block-library/style-rtl.min.csswp-includes/css/dist/block-library/style.csswp-includes/css/dist/block-library/style.min.csswp-includes/css/dist/block-library/theme-rtl.csswp-includes/css/dist/block-library/theme-rtl.min.csswp-includes/css/dist/block-library/theme.csswp-includes/css/dist/block-library/theme.min.csswp-includes/css/dist/edit-post/classic-rtl.csswp-includes/css/dist/edit-post/classic-rtl.min.csswp-includes/css/dist/edit-post/classic.csswp-includes/css/dist/edit-post/classic.min.csswp-includes/css/dist/edit-post/style-rtl.csswp-includes/css/dist/edit-post/style-rtl.min.csswp-includes/css/dist/edit-post/style.csswp-includes/css/dist/edit-post/style.min.csswp-includes/css/dist/edit-site/style-rtl.csswp-includes/css/dist/edit-site/style-rtl.min.csswp-includes/css/dist/edit-site/style.csswp-includes/css/dist/edit-site/style.min.csswp-includes/css/dist/edit-widgets/style-rtl.csswp-includes/css/dist/edit-widgets/style-rtl.min.csswp-includes/css/dist/edit-widgets/style.csswp-includes/css/dist/edit-widgets/style.min.csswp-includes/css/dist/format-library/style-rtl.csswp-includes/css/dist/format-library/style-rtl.min.csswp-includes/css/dist/format-library/style.csswp-includes/css/dist/format-library/style.min.csswp-includes/css/dist/patterns/style-rtl.csswp-includes/css/dist/patterns/style-rtl.min.csswp-includes/css/dist/patterns/style.csswp-includes/css/dist/patterns/style.min.csswp-includes/css/dist/widgets/style-rtl.csswp-includes/css/dist/widgets/style-rtl.min.csswp-includes/css/dist/widgets/style.min.csswordpress:wp| Application | Component | Version | Visibility | Path |
|---|---|---|---|---|
symfony · symfony-demo | library · dflydev/dot-access-data | 3.0.2 | unknown | ? |
symfony · symfony-demo | library · doctrine/cache | 2.2.0 | unknown | ? |
symfony · symfony-demo | library · doctrine/dbal | 4.0.2 | unknown | ? |
symfony · symfony-demo | library · doctrine/deprecations | 1.1.3 | unknown | ? |
symfony · symfony-demo | library · doctrine/event-manager | 2.0.1 | unknown | ? |
symfony · symfony-demo | library · doctrine/inflector | 2.0.10 | unknown | ? |
symfony · symfony-demo | library · doctrine/lexer | 3.0.1 | unknown | ? |
symfony · symfony-demo | library · egulias/email-validator | 4.0.2 | unknown | ? |
symfony · symfony-demo | library · league/commonmark | 2.4.2 | unknown | ? |
symfony · symfony-demo | library · league/config | 1.2.0 | unknown | ? |
symfony · symfony-demo | library · masterminds/html5 | 2.9.0 | unknown | ? |
symfony · symfony-demo | library · monolog/monolog | 3.6.0 | unknown | ? |
symfony · symfony-demo | library · nette/schema | 1.3.0 | unknown | ? |
symfony · symfony-demo | library · nette/utils | 4.0.4 | unknown | ? |
symfony · symfony-demo | library · nikic/php-parser | 5.0.2 | unknown | ? |
symfony · symfony-demo | library · psr/cache | 3.0.0 | unknown | ? |
symfony · symfony-demo | library · psr/clock | 1.0.0 | unknown | ? |
symfony · symfony-demo | library · psr/container | 2.0.2 | unknown | ? |
symfony · symfony-demo | library · psr/event-dispatcher | 1.0.0 | unknown | ? |
symfony · symfony-demo | library · psr/http-factory | 1.1.0 | unknown | ? |
symfony · symfony-demo | library · psr/http-message | 2.0 | unknown | ? |
symfony · symfony-demo | library · psr/log | 3.0.0 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/console | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/css-selector | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · symfony/deprecation-contracts | 3.5.0 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/error-handler | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/event-dispatcher | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · symfony/event-dispatcher-contracts | 3.5.0 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/finder | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/http-foundation | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/http-kernel | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/mime | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · symfony/polyfill-ctype | 1.29.0 | unknown | ? |
symfony · symfony-demo | library · symfony/polyfill-intl-grapheme | 1.29.0 | unknown | ? |
symfony · symfony-demo | library · symfony/polyfill-intl-idn | 1.29.0 | unknown | ? |
symfony · symfony-demo | library · symfony/polyfill-intl-normalizer | 1.29.0 | unknown | ? |
symfony · symfony-demo | library · symfony/polyfill-mbstring | 1.29.0 | unknown | ? |
symfony · symfony-demo | library · symfony/polyfill-php83 | 1.29.0 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/process | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/routing | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · symfony/service-contracts | 3.5.0 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/string | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/translation | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · symfony/translation-contracts | 3.5.0 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/var-dumper | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · phpstan/phpstan | 1.11.3 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/dom-crawler | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · composer/semver | 3.4.0 | unknown | ? |
symfony · symfony-demo | library · doctrine/collections | 2.2.2 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/dependency-injection | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/validator | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/yaml | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · twig/twig | 3.10.3 | unknown | ? |
symfony · symfony-demo | library · doctrine/instantiator | 2.0.0 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/browser-kit | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · symfony/phpunit-bridge | 7.1.1 | unknown | ? |
symfony · symfony-demo | bundle · doctrine/doctrine-bundle | 2.12.0 | unknown | ? |
symfony · symfony-demo | bundle · doctrine/doctrine-migrations-bundle | 3.3.1 | unknown | ? |
symfony · symfony-demo | library · doctrine/migrations | 3.7.4 | unknown | ? |
symfony · symfony-demo | library · doctrine/orm | 3.2.0 | unknown | ? |
symfony · symfony-demo | library · doctrine/persistence | 3.3.2 | unknown | ? |
symfony · symfony-demo | library · doctrine/sql-formatter | 1.4.0 | unknown | ? |
symfony · symfony-demo | library · league/uri | 7.4.1 | unknown | ? |
symfony · symfony-demo | library · league/uri-interfaces | 7.4.1 | unknown | ? |
symfony · symfony-demo | library · symfony/apache-pack | 1.0.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/asset | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/asset-mapper | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/cache | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · symfony/cache-contracts | 3.5.0 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/clock | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/config | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/doctrine-bridge | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/dotenv | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/expression-language | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/filesystem | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · symfony/flex | 2.4.5 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/form | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework · symfony/framework-bundle | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · symfony/html-sanitizer | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/http-client | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · symfony/http-client-contracts | 3.5.0 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/intl | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/mailer | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/monolog-bridge | 7.1.1 | unknown | ? |
symfony · symfony-demo | bundle · symfony/monolog-bundle | 3.10.0 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/options-resolver | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/password-hasher | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · symfony/polyfill-intl-icu | 1.29.0 | unknown | ? |
symfony · symfony-demo | library · symfony/polyfill-intl-messageformatter | 1.29.0 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/property-access | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/property-info | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · symfony/runtime | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/security-bundle | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/security-core | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/security-csrf | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/security-http | 7.1.1 | unknown | ? |
symfony · symfony-demo | bundle · symfony/stimulus-bundle | 2.17.0 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/stopwatch | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/twig-bridge | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/twig-bundle | 7.1.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/type-info | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · symfony/ux-live-component | 2.17.0 | unknown | ? |
symfony · symfony-demo | library · symfony/ux-twig-component | 2.17.0 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/var-exporter | 7.1.1 | unknown | ? |
symfony · symfony-demo | bundle · symfonycasts/sass-bundle | 0.3.0 | unknown | ? |
symfony · symfony-demo | bundle · twig/extra-bundle | 3.10.0 | unknown | ? |
symfony · symfony-demo | library · twig/intl-extra | 3.10.0 | unknown | ? |
symfony · symfony-demo | library · twig/markdown-extra | 3.10.0 | unknown | ? |
symfony · symfony-demo | bundle · dama/doctrine-test-bundle | 8.2.0 | unknown | ? |
symfony · symfony-demo | library · doctrine/data-fixtures | 1.7.0 | unknown | ? |
symfony · symfony-demo | bundle · doctrine/doctrine-fixtures-bundle | 3.6.1 | unknown | ? |
symfony · symfony-demo | library · phpstan/extension-installer | 1.3.1 | unknown | ? |
symfony · symfony-demo | library · phpstan/phpstan-doctrine | 1.4.1 | unknown | ? |
symfony · symfony-demo | library · phpstan/phpstan-symfony | 1.4.3 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/debug-bundle | 7.1.1 | unknown | ? |
symfony · symfony-demo | bundle · symfony/maker-bundle | 1.59.1 | unknown | ? |
symfony · symfony-demo | framework-component · symfony/web-profiler-bundle | 7.1.1 | unknown | ? |
symfony · symfony-demo | library · twbs/bootstrap | 4.6.2 | unknown | ? |
wordpress · wp | core · WordPress | 6.4.2 | public | wp |
wordpress · wp | theme · Twenty Eleven | 4.5 | unknown | wp/wp-content/themes/twentyeleven |
wordpress · wp | theme · Twenty Fifteen | 3.6 | unknown | wp/wp-content/themes/twentyfifteen |
wordpress · wp | theme · Twenty Fourteen | 3.8 | unknown | wp/wp-content/themes/twentyfourteen |
wordpress · wp | theme · Twenty Nineteen | 2.7 | unknown | wp/wp-content/themes/twentynineteen |
wordpress · wp | theme · Twenty Seventeen | 3.4 | unknown | wp/wp-content/themes/twentyseventeen |
wordpress · wp | theme · Twenty Sixteen | 3.1 | unknown | wp/wp-content/themes/twentysixteen |
wordpress · wp | theme · Twenty Ten | 4.0 | unknown | wp/wp-content/themes/twentyten |
wordpress · wp | theme · Twenty Thirteen | 4.0 | unknown | wp/wp-content/themes/twentythirteen |
wordpress · wp | theme · Twenty Twelve | 4.1 | unknown | wp/wp-content/themes/twentytwelve |
wordpress · wp | theme · Twenty Twenty | 2.4 | unknown | wp/wp-content/themes/twentytwenty |
wordpress · wp | theme · Twenty Twenty-Four | 1.0 | unknown | wp/wp-content/themes/twentytwentyfour |
wordpress · wp | theme · Twenty Twenty-One | 2.0 | unknown | wp/wp-content/themes/twentytwentyone |
wordpress · wp | theme · Twenty Twenty-Three | 1.3 | unknown | wp/wp-content/themes/twentytwentythree |
wordpress · wp | theme · Twenty Twenty-Two | 1.6 | unknown | wp/wp-content/themes/twentytwentytwo |
drupal · drupal | core · Drupal | 8.5.0 | public | drupal |
laravel · bookstack | library · aws/aws-crt-php | 1.2.6 | unknown | ? |
laravel · bookstack | library · aws/aws-sdk-php | 3.322.6 | unknown | ? |
laravel · bookstack | library · bacon/bacon-qr-code | 3.0.0 | unknown | ? |
laravel · bookstack | library · brick/math | 0.12.1 | unknown | ? |
laravel · bookstack | library · carbonphp/carbon-doctrine-types | 2.1.0 | unknown | ? |
laravel · bookstack | library · dasprid/enum | 1.0.6 | unknown | ? |
laravel · bookstack | library · dflydev/dot-access-data | 3.0.3 | unknown | ? |
laravel · bookstack | library · doctrine/cache | 2.2.0 | unknown | ? |
laravel · bookstack | library · doctrine/dbal | 3.9.1 | unknown | ? |
laravel · bookstack | library · doctrine/deprecations | 1.1.3 | unknown | ? |
laravel · bookstack | library · doctrine/event-manager | 2.0.1 | unknown | ? |
laravel · bookstack | library · doctrine/inflector | 2.0.10 | unknown | ? |
laravel · bookstack | library · doctrine/lexer | 3.0.1 | unknown | ? |
laravel · bookstack | library · dompdf/dompdf | 3.0.0 | unknown | ? |
laravel · bookstack | library · dompdf/php-font-lib | 1.0.0 | unknown | ? |
laravel · bookstack | library · dompdf/php-svg-lib | 1.0.0 | unknown | ? |
laravel · bookstack | library · dragonmantank/cron-expression | 3.3.3 | unknown | ? |
laravel · bookstack | library · egulias/email-validator | 4.0.2 | unknown | ? |
laravel · bookstack | library · firebase/php-jwt | 6.10.1 | unknown | ? |
laravel · bookstack | library · fruitcake/php-cors | 1.3.0 | unknown | ? |
laravel · bookstack | library · graham-campbell/result-type | 1.1.3 | unknown | ? |
laravel · bookstack | library · guzzlehttp/guzzle | 7.9.2 | unknown | ? |
laravel · bookstack | library · guzzlehttp/promises | 2.0.3 | unknown | ? |
laravel · bookstack | library · guzzlehttp/psr7 | 2.7.0 | unknown | ? |
laravel · bookstack | library · guzzlehttp/uri-template | 1.0.3 | unknown | ? |
laravel · bookstack | library · intervention/gif | 4.2.0 | unknown | ? |
laravel · bookstack | library · intervention/image | 3.8.0 | unknown | ? |
laravel · bookstack | library · knplabs/knp-snappy | 1.5.0 | unknown | ? |
laravel · bookstack | framework · laravel/framework | 10.48.22 | unknown | ? |
laravel · bookstack | framework-component · laravel/prompts | 0.1.25 | unknown | ? |
laravel · bookstack | framework-component · laravel/serializable-closure | 1.3.5 | unknown | ? |
laravel · bookstack | framework-component · laravel/socialite | 5.16.0 | unknown | ? |
laravel · bookstack | framework-component · laravel/tinker | 2.10.0 | unknown | ? |
laravel · bookstack | library · league/commonmark | 2.5.3 | unknown | ? |
laravel · bookstack | library · league/config | 1.2.0 | unknown | ? |
laravel · bookstack | library · league/flysystem | 3.28.0 | unknown | ? |
laravel · bookstack | library · league/flysystem-aws-s3-v3 | 3.28.0 | unknown | ? |
laravel · bookstack | library · league/flysystem-local | 3.28.0 | unknown | ? |
laravel · bookstack | library · league/html-to-markdown | 5.1.1 | unknown | ? |
laravel · bookstack | library · league/mime-type-detection | 1.16.0 | unknown | ? |
laravel · bookstack | library · league/oauth1-client | 1.10.1 | unknown | ? |
laravel · bookstack | library · league/oauth2-client | 2.7.0 | unknown | ? |
laravel · bookstack | library · masterminds/html5 | 2.9.0 | unknown | ? |
laravel · bookstack | library · monolog/monolog | 3.7.0 | unknown | ? |
laravel · bookstack | library · mtdowling/jmespath.php | 2.8.0 | unknown | ? |
laravel · bookstack | library · nesbot/carbon | 2.72.5 | unknown | ? |
laravel · bookstack | library · nette/schema | 1.3.0 | unknown | ? |
laravel · bookstack | library · nette/utils | 4.0.5 | unknown | ? |
laravel · bookstack | library · nikic/php-parser | 5.2.0 | unknown | ? |
laravel · bookstack | library · nunomaduro/termwind | 1.15.1 | unknown | ? |
laravel · bookstack | library · onelogin/php-saml | 4.2.0 | unknown | ? |
laravel · bookstack | library · paragonie/constant_time_encoding | 3.0.0 | unknown | ? |
laravel · bookstack | library · paragonie/random_compat | 9.99.100 | unknown | ? |
laravel · bookstack | library · phpoption/phpoption | 1.9.3 | unknown | ? |
laravel · bookstack | library · phpseclib/phpseclib | 3.0.42 | unknown | ? |
laravel · bookstack | library · pragmarx/google2fa | 8.0.3 | unknown | ? |
laravel · bookstack | library · predis/predis | 2.2.2 | unknown | ? |
laravel · bookstack | library · psr/cache | 3.0.0 | unknown | ? |
laravel · bookstack | library · psr/clock | 1.0.0 | unknown | ? |
laravel · bookstack | library · psr/container | 2.0.2 | unknown | ? |
laravel · bookstack | library · psr/event-dispatcher | 1.0.0 | unknown | ? |
laravel · bookstack | library · psr/http-client | 1.0.3 | unknown | ? |
laravel · bookstack | library · psr/http-factory | 1.1.0 | unknown | ? |
laravel · bookstack | library · psr/http-message | 2.0 | unknown | ? |
laravel · bookstack | library · psr/log | 3.0.2 | unknown | ? |
laravel · bookstack | library · psr/simple-cache | 3.0.0 | unknown | ? |
laravel · bookstack | library · psy/psysh | 0.12.4 | unknown | ? |
laravel · bookstack | library · ralouphie/getallheaders | 3.0.3 | unknown | ? |
laravel · bookstack | library · ramsey/collection | 2.0.0 | unknown | ? |
laravel · bookstack | library · ramsey/uuid | 4.7.6 | unknown | ? |
laravel · bookstack | library · robrichards/xmlseclibs | 3.1.1 | unknown | ? |
laravel · bookstack | library · sabberworm/php-css-parser | 8.6.0 | unknown | ? |
laravel · bookstack | library · socialiteproviders/discord | 4.2.0 | unknown | ? |
laravel · bookstack | library · socialiteproviders/gitlab | 4.1.0 | unknown | ? |
laravel · bookstack | library · socialiteproviders/manager | 4.6.0 | unknown | ? |
laravel · bookstack | library · socialiteproviders/microsoft-azure | 5.2.0 | unknown | ? |
laravel · bookstack | library · socialiteproviders/okta | 4.4.0 | unknown | ? |
laravel · bookstack | library · socialiteproviders/twitch | 5.4.0 | unknown | ? |
laravel · bookstack | library · ssddanbrown/htmldiff | 1.0.3 | unknown | ? |
laravel · bookstack | library · ssddanbrown/symfony-mailer | 6.4.x-dev | unknown | ? |
laravel · bookstack | library · symfony/console | 6.4.12 | unknown | ? |
laravel · bookstack | library · symfony/css-selector | 6.4.8 | unknown | ? |
laravel · bookstack | library · symfony/deprecation-contracts | 3.5.0 | unknown | ? |
laravel · bookstack | library · symfony/error-handler | 6.4.10 | unknown | ? |
laravel · bookstack | library · symfony/event-dispatcher | 6.4.8 | unknown | ? |
laravel · bookstack | library · symfony/event-dispatcher-contracts | 3.5.0 | unknown | ? |
laravel · bookstack | library · symfony/finder | 6.4.11 | unknown | ? |
laravel · bookstack | library · symfony/http-foundation | 6.4.12 | unknown | ? |
laravel · bookstack | library · symfony/http-kernel | 6.4.12 | unknown | ? |
laravel · bookstack | library · symfony/mime | 6.4.12 | unknown | ? |
laravel · bookstack | library · symfony/polyfill-ctype | 1.31.0 | unknown | ? |
laravel · bookstack | library · symfony/polyfill-intl-grapheme | 1.31.0 | unknown | ? |
laravel · bookstack | library · symfony/polyfill-intl-idn | 1.31.0 | unknown | ? |
laravel · bookstack | library · symfony/polyfill-intl-normalizer | 1.31.0 | unknown | ? |
laravel · bookstack | library · symfony/polyfill-mbstring | 1.31.0 | unknown | ? |
laravel · bookstack | library · symfony/polyfill-php80 | 1.31.0 | unknown | ? |
laravel · bookstack | library · symfony/polyfill-php83 | 1.31.0 | unknown | ? |
laravel · bookstack | library · symfony/polyfill-uuid | 1.31.0 | unknown | ? |
laravel · bookstack | library · symfony/process | 6.4.12 | unknown | ? |
laravel · bookstack | library · symfony/routing | 6.4.12 | unknown | ? |
laravel · bookstack | library · symfony/service-contracts | 3.5.0 | unknown | ? |
laravel · bookstack | library · symfony/string | 6.4.12 | unknown | ? |
laravel · bookstack | library · symfony/translation | 6.4.12 | unknown | ? |
laravel · bookstack | library · symfony/translation-contracts | 3.5.0 | unknown | ? |
laravel · bookstack | library · symfony/uid | 6.4.12 | unknown | ? |
laravel · bookstack | library · symfony/var-dumper | 6.4.11 | unknown | ? |
laravel · bookstack | library · tijsverkoyen/css-to-inline-styles | 2.2.7 | unknown | ? |
laravel · bookstack | library · vlucas/phpdotenv | 5.6.1 | unknown | ? |
laravel · bookstack | library · voku/portable-ascii | 2.0.1 | unknown | ? |
laravel · bookstack | library · webmozart/assert | 1.11.0 | unknown | ? |
laravel · bookstack | library · fakerphp/faker | 1.23.1 | unknown | ? |
laravel · bookstack | library · filp/whoops | 2.16.0 | unknown | ? |
laravel · bookstack | library · hamcrest/hamcrest-php | 2.0.1 | unknown | ? |
laravel · bookstack | library · itsgoingd/clockwork | 5.2.2 | unknown | ? |
laravel · bookstack | library · larastan/larastan | 2.9.8 | unknown | ? |
laravel · bookstack | library · mockery/mockery | 1.6.12 | unknown | ? |
laravel · bookstack | library · myclabs/deep-copy | 1.12.0 | unknown | ? |
laravel · bookstack | library · nunomaduro/collision | 7.10.0 | unknown | ? |
laravel · bookstack | library · phar-io/manifest | 2.0.4 | unknown | ? |
laravel · bookstack | library · phar-io/version | 3.2.1 | unknown | ? |
laravel · bookstack | library · phpmyadmin/sql-parser | 5.10.0 | unknown | ? |
laravel · bookstack | library · phpstan/phpstan | 1.12.5 | unknown | ? |
laravel · bookstack | library · phpunit/php-code-coverage | 10.1.16 | unknown | ? |
laravel · bookstack | library · phpunit/php-file-iterator | 4.1.0 | unknown | ? |
laravel · bookstack | library · phpunit/php-invoker | 4.0.0 | unknown | ? |
laravel · bookstack | library · phpunit/php-text-template | 3.0.1 | unknown | ? |
laravel · bookstack | library · phpunit/php-timer | 6.0.0 | unknown | ? |
laravel · bookstack | library · phpunit/phpunit | 10.5.35 | unknown | ? |
laravel · bookstack | library · sebastian/cli-parser | 2.0.1 | unknown | ? |
laravel · bookstack | library · sebastian/code-unit | 2.0.0 | unknown | ? |
laravel · bookstack | library · sebastian/code-unit-reverse-lookup | 3.0.0 | unknown | ? |
laravel · bookstack | library · sebastian/comparator | 5.0.2 | unknown | ? |
laravel · bookstack | library · sebastian/complexity | 3.2.0 | unknown | ? |
laravel · bookstack | library · sebastian/diff | 5.1.1 | unknown | ? |
laravel · bookstack | library · sebastian/environment | 6.1.0 | unknown | ? |
laravel · bookstack | library · sebastian/exporter | 5.1.2 | unknown | ? |
laravel · bookstack | library · sebastian/global-state | 6.0.2 | unknown | ? |
laravel · bookstack | library · sebastian/lines-of-code | 2.0.2 | unknown | ? |
laravel · bookstack | library · sebastian/object-enumerator | 5.0.0 | unknown | ? |
laravel · bookstack | library · sebastian/object-reflector | 3.0.0 | unknown | ? |
laravel · bookstack | library · sebastian/recursion-context | 5.0.0 | unknown | ? |
laravel · bookstack | library · sebastian/type | 4.0.0 | unknown | ? |
laravel · bookstack | library · sebastian/version | 4.0.1 | unknown | ? |
laravel · bookstack | library · squizlabs/php_codesniffer | 3.10.3 | unknown | ? |
laravel · bookstack | library · ssddanbrown/asserthtml | 3.0.0 | unknown | ? |
laravel · bookstack | library · symfony/dom-crawler | 6.4.12 | unknown | ? |
laravel · bookstack | library · theseer/tokenizer | 1.2.3 | unknown | ? |
| Application | Capability / source | Component | Execution | Result | Checked | Diagnostic |
|---|---|---|---|---|---|---|
| symfony:symfony-demo | inventory | — | completed | not-applicable | 118/118 | — |
| symfony:symfony-demo | advisories · dependency-lanes | — | completed | not-applicable | 118/118 | — |
| symfony:symfony-demo | recipes | — | completed | not-applicable | 110/110 | — |
| wordpress:wp | inventory | — | completed | not-applicable | 15/15 | — |
| wordpress:wp | advisories · wordfence-v3 | — | not-run | indeterminate | 0/15 | CMS_PROVIDER_UNCONFIGURED |
| wordpress:wp | integrity · wordpress-checksums | — | completed | no-match | 2960/2960 | — |
| drupal:drupal | inventory | — | completed | not-applicable | 1/1 | — |
| drupal:drupal | advisories · drupal-security-advisories | core · Drupaldrupaldrupal:drupal:core | completed | affected | 1/1 | — |
| laravel:bookstack | inventory | — | completed | not-applicable | 147/147 | — |
| laravel:bookstack | advisories · dependency-lanes | — | completed | not-applicable | 147/147 | — |