Friendsofsymfony1 is a legacy community extension framework for the Symfony1 PHP application framework, with vulnerability exposure centered on the core Symfony1 product itself. The observed weakness class involves deserialization of untrusted data, a consequence of the framework's object-handling mechanisms and the serialization patterns common in older PHP codebases. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Friendsofsymfony1 over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-28861CRITICAL Symfony 1 is a community-driven fork of the 1.x branch of Symfony, a PHP framework for web projects. Starting in version 1.1.0 and prior to version 1.5.19, Symfony 1 has a gadget c | Mar 22, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-28859CRITICAL Symfony1 is a community fork of symfony 1.4 with DIC, form enhancements, latest Swiftmailer, better performance, composer compatible and PHP 8 support. Symfony 1 has a gadget chain | Mar 15, 2024 | 9.0 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Friendsofsymfony1.
Media articles that mention a CVE ID that affects a product developed by Friendsofsymfony1 — matched by CVE ID, not by vendor name.