Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sensiolabs

First CVE: Jun 7, 2012Active for: 14 yearsTotal CVEs: 90
48.7
VTI Score
High

Sensiolabs maintains a focused set of widely embedded web-development frameworks and libraries—most prominently Symfony, HTTPClient, HTTPFoundation, and Twig—that form the foundation of numerous PHP applications and are deployed across a substantial portion of the web application landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur through weakness classes endemic to web frameworks: cross-site scripting, improper authentication, code injection, and input-validation flaws that reflect the parsing and template-rendering demands of modern PHP development. The concentration of the vendor's exposure in a small number of core, deeply integrated libraries means that individual flaws can propagate rapidly through the downstream ecosystem, making each disclosure material to a broad set of dependent applications. Defenders should monitor this vendor's releases closely and prioritize patching web-application dependencies that embed these frameworks. Current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
90
Total CVEs
More Total CVEs than 99% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 51% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sensiolabs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 7, 2012
14 years ago
Most Recent CVE
Jul 14, 2026
12 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (90 CVEs).

90 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-14773MEDIUM
An issue was discovered in Http Foundation in Symfony 2.7.0 through 2.7.48, 2.8.0 through 2.8.43, 3.3.0 through 3.3.17, 3.4.0 through 3.4.13, 4.0.0 through 4.0.13, and 4.1.0 throug
Aug 3, 20186.554NONO
CVE-2019-18889CRITICAL
An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code inj
Nov 21, 20199.849NONO
CVE-2026-47767CRITICAL
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated
Jul 14, 20269.841NONO
CVE-2026-45063CRITICAL
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, X509Authenticator extracts the user i
Jul 14, 20269.139NONO
CVE-2025-64500HIGH
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP s
Nov 12, 20257.339NOYES
CVE-2026-45069CRITICAL
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 6.4.40, 7.4.12, and 8.0.12, OidcTokenHandler::verifyClaims() registered a
Jul 14, 20269.138NONO
CVE-2026-45074HIGH
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter f
Jul 14, 20268.136NONO
CVE-2026-45077HIGH
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Brid
Jul 14, 20268.636NONO
CVE-2026-48736HIGH
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.0 to 5.4.53, 6.4.41, 7.4.13, and 8.0.13, NoPrivateNetworkHttpClient and I
Jul 14, 20268.635NONO
CVE-2026-45075HIGH
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 7.4.12 and 8.0.12, method-scoped #[IsGranted], #[IsSignatureValid], and #
Jul 14, 20268.235NONO
View all 90 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products90 CVEs
50%
38%
12%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (1.1%)
Network78 (86.7%)
Unknown11 (12.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low73 (81.1%)
High6 (6.7%)
Unknown11 (12.2%)
User Interaction
None54 (60.0%)
Unknown11 (12.2%)
Required25 (27.8%)
Privileges Required
Low16 (17.8%)
High0 (0.0%)
None63 (70.0%)
Unknown11 (12.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (90 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
2.2% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sensiolabs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sensiolabs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sensiolabs's Products

View all 3 CNAs →

Top CWEs