Symbiote's vulnerability profile centers on a set of web-application and content-management components, including Seed, SilverStripe Queued Jobs, and VersionedFiles, with the recurring signal anchored in application-layer input-handling and navigation issues such as cross-site scripting and open redirects. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Symbiote over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-20164MEDIUM A vulnerability was found in Symbiote Seed up to 6.0.2. It has been classified as critical. Affected is the function onBeforeSecurityLogin of the file code/extensions/SecurityLogin | Jan 7, 2023 | 6.1 | 21 | NO | NO |
CVE-2021-27938MEDIUM A vulnerability has been identified in the Silverstripe CMS 3 and 4 version of the symbiote/silverstripe-queuedjobs module. A Cross Site Scripting vulnerability allows an attacker | Mar 16, 2021 | 6.1 | 21 | NO | NO |
CVE-2019-16409MEDIUM In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to anyone who can guess their URL. This guess could be highly i | Sep 26, 2019 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Symbiote.
Media articles that mention a CVE ID that affects a product developed by Symbiote — matched by CVE ID, not by vendor name.