Sulu is a content-management and digital-experience platform with a focused product portfolio that occupies a prominent position among specialized enterprise software. Its vulnerability profile concentrates on application-layer input-handling and authentication mechanisms, with recurring exposure to cross-site scripting variants, authentication bypass conditions, path-traversal issues, and sensitive information disclosure—characteristic of web applications where request parsing and access control remain high-friction surfaces. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sulu over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43836HIGH Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions an attacker can read arbitrary local files via a PHP file include. In a de | Dec 15, 2021 | 8.8 | 28 | NO | NO |
CVE-2024-27915HIGH Sulu is a PHP content management system. Starting in verson 2.2.0 and prior to version 2.4.17 and 2.5.13, access to pages is granted regardless of role permissions for webspaces wh | Mar 6, 2024 | 8.1 | 23 | NO | NO |
CVE-2021-43835HIGH Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions Sulu users who have access to any subset of the admin UI are able to eleva | Dec 15, 2021 | 7.2 | 23 | NO | NO |
CVE-2020-15132MEDIUM In Sulu before versions 1.6.35, 2.0.10, and 2.1.1, when the "Forget password" feature on the login screen is used, Sulu asks the user for a username or email address. If the given | Aug 5, 2020 | 5.3 | 20 | NO | NO |
CVE-2024-47617MEDIUM Sulu is a PHP content management system. This vulnerability allows an attacker to inject arbitrary HTML/JavaScript code through the media download URL in Sulu CMS. It affects the S | Oct 3, 2024 | 6.1 | 19 | NO | NO |
CVE-2021-41169MEDIUM Sulu is an open-source PHP content management system based on the Symfony framework. In versions before 1.6.43 are subject to stored cross site scripting attacks. HTML input into T | Oct 21, 2021 | 4.8 | 19 | NO | NO |
CVE-2024-47618MEDIUM Sulu is a PHP content management system. Sulu is vulnerable against XSS whereas a low privileged user with access to the “Media” section can upload an SVG file with a malicious pay | Oct 3, 2024 | 5.4 | 18 | NO | NO |
CVE-2024-37156MEDIUM The SuluFormBundle adds support for creating dynamic forms in Sulu Admin. The TokenController get parameter formName is not sanitized in the returned input field which leads to XSS | Jun 6, 2024 | 6.1 | 18 | NO | NO |
CVE-2017-1000465MEDIUM Sulu-standard version 1.6.6 is vulnerable to stored cross-site scripting vulnerability, within the page creation page, which can result in disruption of service and execution of ja | Jan 9, 2018 | 5.4 | 18 | NO | NO |
CVE-2021-32737MEDIUM Sulu is an open-source PHP content management system based on the Symfony framework. In versions of Sulu prior to 1.6.41, it is possible for a logged in admin user to add a script | Jul 2, 2021 | 4.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sulu.
Media articles that mention a CVE ID that affects a product developed by Sulu — matched by CVE ID, not by vendor name.