Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sylius

First CVE: Dec 5, 2019Active for: 7 yearsTotal CVEs: 24
21.5
VTI Score
Low

Sylius is a modestly represented e-commerce platform and product framework composed of focused, purpose-built components including core storefront, resource bundles, and grid systems. The vendor's vulnerability footprint concentrates on application-layer weaknesses endemic to web platforms: cross-site scripting, injection flaws, expression language injection, and authorization bypass conditions that arise across input handling, template rendering, and access control boundaries. Information disclosure and improper neutralization of user-supplied data recur across the product line, reflecting the integration points and data-flow complexity characteristic of commerce platforms that process user input, payment metadata, and administrative directives. Defenders should prioritize this vendor's updates for internet-facing storefronts and treat component disclosures as broadly applicable across instances; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sylius over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 5, 2019
6 years ago
Most Recent CVE
Mar 10, 2026
136 days ago

Products(5 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-24752CRITICAL
SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query sorting were passed directly t
Mar 15, 20229.831NONO
CVE-2020-15143HIGH
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expression evaluated by `symfony/expression-language` package haven't
Aug 20, 20208.828NONO
CVE-2022-24743HIGH
Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set to null after the password was changed. The same token could
Mar 14, 20228.226NONO
CVE-2021-41120HIGH
sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment page done after checkout was created with autoincremented p
Oct 5, 20217.525NONO
CVE-2026-31820MEDIUM
Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulnerability exists in multiple shop LiveComponents due to unvali
Mar 10, 20266.522NONO
CVE-2022-24749MEDIUM
Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-site scripting (XSS) code in th
Mar 14, 20226.122NONO
CVE-2022-24733MEDIUM
Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to load the website within an iframe
Mar 14, 20226.122NONO
CVE-2020-15146HIGH
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression evaluated by `symfony/expression-language` package haven't
Aug 20, 20208.822NONO
CVE-2026-31824MEDIUM
Sylius is an Open Source eCommerce Framework on Symfony. A Time-of-Check To Time-of-Use (TOCTOU) race condition was discovered in the promotion usage limit enforcement. The same cl
Mar 10, 20265.921NONO
CVE-2026-31819MEDIUM
Sylius is an Open Source eCommerce Framework on Symfony. CurrencySwitchController::switchAction(), ImpersonateUserController::impersonateAction() and StorageBasedLocaleSwitcher::ha
Mar 10, 20266.121NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
75%
21%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.2%)
Network23 (95.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (95.8%)
High1 (4.2%)
Unknown0 (0.0%)
User Interaction
None16 (66.7%)
Unknown0 (0.0%)
Required8 (33.3%)
Privileges Required
Low8 (33.3%)
High2 (8.3%)
None14 (58.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sylius.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sylius — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sylius's Products

View all 3 CNAs →

Top CWEs