API Platform is a PHP-based API development framework focused on building REST and GraphQL services, with a modestly scoped but strategically positioned footprint in the API and web-service layer. The observed vulnerability surface centers on its core framework product. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Api Platform over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25575MEDIUM API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs. Resource properties secured with the `security` option of the `ApiPlatform\Metadata\ApiPrope | Feb 28, 2023 | 6.5 | 21 | NO | NO |
CVE-2019-1000011MEDIUM API Platform version from 2.2.0 to 2.3.5 contains an Incorrect Access Control vulnerability in GraphQL delete mutations that can result in a user authorized to delete a resource ca | Feb 4, 2019 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Api Platform.
Media articles that mention a CVE ID that affects a product developed by Api Platform — matched by CVE ID, not by vendor name.