Sensiolabs maintains a focused set of widely embedded web-development frameworks and libraries—most prominently Symfony, HTTPClient, HTTPFoundation, and Twig—that form the foundation of numerous PHP applications and are deployed across a substantial portion of the web application landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes endemic to web frameworks: cross-site scripting, improper authentication, code injection, and input-validation flaws that reflect the parsing and template-rendering demands of modern PHP development. The concentration of the vendor's exposure in a small number of core, deeply integrated libraries means that individual flaws can propagate rapidly through the downstream ecosystem, making each disclosure material to a broad set of dependent applications. Defenders should monitor this vendor's releases closely and prioritize patching web-application dependencies that embed these frameworks. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sensiolabs over time
Signals from CVEs in this vendor scope (90 CVEs).
90 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-14773MEDIUM An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 throug | Aug 3, 2018 | 6.5 | 54 | NO | NO |
CVE-2019-18889CRITICAL An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code inj | Nov 21, 2019 | 9.8 | 49 | NO | NO |
CVE-2026-47767CRITICAL Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated | Jul 14, 2026 | 9.8 | 41 | NO | NO |
CVE-2026-45063CRITICAL Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user i | Jul 14, 2026 | 9.1 | 39 | NO | NO |
CVE-2025-64500HIGH Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP s | Nov 12, 2025 | 7.3 | 39 | NO | YES |
CVE-2026-45069CRITICAL Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered a | Jul 14, 2026 | 9.1 | 38 | NO | NO |
CVE-2026-45074HIGH Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter f | Jul 14, 2026 | 8.1 | 36 | NO | NO |
CVE-2026-45077HIGH Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Brid | Jul 14, 2026 | 8.6 | 36 | NO | NO |
CVE-2026-48736HIGH Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and I | Jul 14, 2026 | 8.6 | 35 | NO | NO |
CVE-2026-45075HIGH Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and # | Jul 14, 2026 | 8.2 | 35 | NO | NO |
Signals from CVEs in this vendor scope (90 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sensiolabs.
Media articles that mention a CVE ID that affects a product developed by Sensiolabs — matched by CVE ID, not by vendor name.