symfony
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 88 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 31, 2001 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Twig: Sandbox resource exhaustion via unbounded `for` / `range()`
Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
Symfony UX: XSS in symfony/ux-autocomplete via unescaped AJAX response data
Symfony UX: CSRF Protection Bypass in symfony/ux-live-component — Accept Header is CORS-Safelisted
Symfony UX: LiveComponentHydrator HMAC checksum lacks component and slot binding
Symfony UX: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Monitor symfony in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.