Sylius is a modestly represented e-commerce platform and product framework composed of focused, purpose-built components including core storefront, resource bundles, and grid systems. The vendor's vulnerability footprint concentrates on application-layer weaknesses endemic to web platforms: cross-site scripting, injection flaws, expression language injection, and authorization bypass conditions that arise across input handling, template rendering, and access control boundaries. Information disclosure and improper neutralization of user-supplied data recur across the product line, reflecting the integration points and data-flow complexity characteristic of commerce platforms that process user input, payment metadata, and administrative directives. Defenders should prioritize this vendor's updates for internet-facing storefronts and treat component disclosures as broadly applicable across instances; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sylius over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24752CRITICAL SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query sorting were passed directly t | Mar 15, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-15143HIGH In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expression evaluated by `symfony/expression-language` package haven't | Aug 20, 2020 | 8.8 | 28 | NO | NO |
CVE-2022-24743HIGH Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set to null after the password was changed. The same token could | Mar 14, 2022 | 8.2 | 26 | NO | NO |
CVE-2021-41120HIGH sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment page done after checkout was created with autoincremented p | Oct 5, 2021 | 7.5 | 25 | NO | NO |
CVE-2026-31820MEDIUM Sylius is an Open Source eCommerce Framework on Symfony. An authenticated Insecure Direct Object Reference (IDOR) vulnerability exists in multiple shop LiveComponents due to unvali | Mar 10, 2026 | 6.5 | 22 | NO | NO |
CVE-2022-24749MEDIUM Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-site scripting (XSS) code in th | Mar 14, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-24733MEDIUM Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to load the website within an iframe | Mar 14, 2022 | 6.1 | 22 | NO | NO |
CVE-2020-15146HIGH In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression evaluated by `symfony/expression-language` package haven't | Aug 20, 2020 | 8.8 | 22 | NO | NO |
CVE-2026-31824MEDIUM Sylius is an Open Source eCommerce Framework on Symfony. A Time-of-Check To Time-of-Use (TOCTOU) race condition was discovered in the promotion usage limit enforcement. The same cl | Mar 10, 2026 | 5.9 | 21 | NO | NO |
CVE-2026-31819MEDIUM Sylius is an Open Source eCommerce Framework on Symfony. CurrencySwitchController::switchAction(), ImpersonateUserController::impersonateAction() and StorageBasedLocaleSwitcher::ha | Mar 10, 2026 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sylius.
Media articles that mention a CVE ID that affects a product developed by Sylius — matched by CVE ID, not by vendor name.