easycorp/easyadmin-bundle
EasyAdmin is a fast, beautiful and modern admin generator for Symfony applications.
Activity
- Latest release
- 1mo ago
- Total releases
- 397
- Cadence
- ~3 days
- Last 12 months
- 59
Reach
- Stars
- 4.3k
Details
- License
- MIT
- First release
- Jan 16, 2015
| Version | Released | |
|---|---|---|
v5.5.1
patch
|
v5.5.1
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
v4.29.16
patch
|
v4.29.16
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
v5.5.0
minor
1 CVE
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev |
v5.5.0
minor
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
v4.29.15
patch
1 CVE
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev |
v4.29.15
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
v5.4.1
patch
1 CVE
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev |
v5.4.1
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
v5.4.0
minor
1 CVE
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev |
v5.4.0
minor
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
v5.3.0
minor
1 CVE
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev | ||
v5.2.0
minor
1 CVE
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev | ||
v4.29.14
patch
1 CVE
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev |
v4.29.14
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
v5.1.0
minor
1 CVE
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev | ||
v4.29.13
patch
1 CVE
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev | ||
v5.0.15
patch
1 CVE
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev | ||
v5.0.14
patch
1 CVE
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev | ||
v5.0.13
patch
1 CVE
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev | ||
v5.0.12
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54087
GHSA-8559-gwj3-q37r
Jul 14, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
EasyAdmin's An attacker with access to a form using these fields can upload an Exploitation requires the developer to store uploads in the public directory and a privilege gap between the uploading user and the viewing administrator. This is stored XSS only — it does not allow remote code execution, because uploaded filenames are derived from Symfony's Credit We would like to thank Emre Dogan for reporting the issue. Affected versions
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
+ 1 more Show less
v5.0.9
Fixed in
5.0.13
References Updated Jul 14, 2026 · Source: OSV.dev | ||
v4.29.12
patch
1 CVE
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev | ||
v5.0.11
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54087
GHSA-8559-gwj3-q37r
Jul 14, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
EasyAdmin's An attacker with access to a form using these fields can upload an Exploitation requires the developer to store uploads in the public directory and a privilege gap between the uploading user and the viewing administrator. This is stored XSS only — it does not allow remote code execution, because uploaded filenames are derived from Symfony's Credit We would like to thank Emre Dogan for reporting the issue. Affected versions
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
+ 1 more Show less
v5.0.9
Fixed in
5.0.13
References Updated Jul 14, 2026 · Source: OSV.dev | ||
v4.29.11
patch
1 CVE
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev | ||
v5.0.10
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54087
GHSA-8559-gwj3-q37r
Jul 14, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
EasyAdmin's An attacker with access to a form using these fields can upload an Exploitation requires the developer to store uploads in the public directory and a privilege gap between the uploading user and the viewing administrator. This is stored XSS only — it does not allow remote code execution, because uploaded filenames are derived from Symfony's Credit We would like to thank Emre Dogan for reporting the issue. Affected versions
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
+ 1 more Show less
v5.0.9
Fixed in
5.0.13
References Updated Jul 14, 2026 · Source: OSV.dev | ||
v4.29.10
patch
1 CVE
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev | ||
v5.0.9
patch
3 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54087
GHSA-8559-gwj3-q37r
Jul 14, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
EasyAdmin's An attacker with access to a form using these fields can upload an Exploitation requires the developer to store uploads in the public directory and a privilege gap between the uploading user and the viewing administrator. This is stored XSS only — it does not allow remote code execution, because uploaded filenames are derived from Symfony's Credit We would like to thank Emre Dogan for reporting the issue. Affected versions
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
+ 1 more Show less
v5.0.9
Fixed in
5.0.13
References Updated Jul 14, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v4.29.9
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v5.0.8
patch
3 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54087
GHSA-8559-gwj3-q37r
Jul 14, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
EasyAdmin's An attacker with access to a form using these fields can upload an Exploitation requires the developer to store uploads in the public directory and a privilege gap between the uploading user and the viewing administrator. This is stored XSS only — it does not allow remote code execution, because uploaded filenames are derived from Symfony's Credit We would like to thank Emre Dogan for reporting the issue. Affected versions
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
+ 1 more Show less
v5.0.9
Fixed in
5.0.13
References Updated Jul 14, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v4.29.8
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v5.0.7
patch
3 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54087
GHSA-8559-gwj3-q37r
Jul 14, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
EasyAdmin's An attacker with access to a form using these fields can upload an Exploitation requires the developer to store uploads in the public directory and a privilege gap between the uploading user and the viewing administrator. This is stored XSS only — it does not allow remote code execution, because uploaded filenames are derived from Symfony's Credit We would like to thank Emre Dogan for reporting the issue. Affected versions
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
+ 1 more Show less
v5.0.9
Fixed in
5.0.13
References Updated Jul 14, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v4.29.7
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v5.0.6
patch
3 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54087
GHSA-8559-gwj3-q37r
Jul 14, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
EasyAdmin's An attacker with access to a form using these fields can upload an Exploitation requires the developer to store uploads in the public directory and a privilege gap between the uploading user and the viewing administrator. This is stored XSS only — it does not allow remote code execution, because uploaded filenames are derived from Symfony's Credit We would like to thank Emre Dogan for reporting the issue. Affected versions
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
+ 1 more Show less
v5.0.9
Fixed in
5.0.13
References Updated Jul 14, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v4.29.6
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v5.0.5
patch
3 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54087
GHSA-8559-gwj3-q37r
Jul 14, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
EasyAdmin's An attacker with access to a form using these fields can upload an Exploitation requires the developer to store uploads in the public directory and a privilege gap between the uploading user and the viewing administrator. This is stored XSS only — it does not allow remote code execution, because uploaded filenames are derived from Symfony's Credit We would like to thank Emre Dogan for reporting the issue. Affected versions
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
+ 1 more Show less
v5.0.9
Fixed in
5.0.13
References Updated Jul 14, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev |
v5.0.5
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
v5.0.4
patch
3 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54087
GHSA-8559-gwj3-q37r
Jul 14, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
EasyAdmin's An attacker with access to a form using these fields can upload an Exploitation requires the developer to store uploads in the public directory and a privilege gap between the uploading user and the viewing administrator. This is stored XSS only — it does not allow remote code execution, because uploaded filenames are derived from Symfony's Credit We would like to thank Emre Dogan for reporting the issue. Affected versions
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
+ 1 more Show less
v5.0.9
Fixed in
5.0.13
References Updated Jul 14, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v4.29.5
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v5.0.3
patch
3 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54087
GHSA-8559-gwj3-q37r
Jul 14, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
EasyAdmin's An attacker with access to a form using these fields can upload an Exploitation requires the developer to store uploads in the public directory and a privilege gap between the uploading user and the viewing administrator. This is stored XSS only — it does not allow remote code execution, because uploaded filenames are derived from Symfony's Credit We would like to thank Emre Dogan for reporting the issue. Affected versions
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
+ 1 more Show less
v5.0.9
Fixed in
5.0.13
References Updated Jul 14, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v4.29.4
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v5.0.2
patch
3 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54087
GHSA-8559-gwj3-q37r
Jul 14, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
EasyAdmin's An attacker with access to a form using these fields can upload an Exploitation requires the developer to store uploads in the public directory and a privilege gap between the uploading user and the viewing administrator. This is stored XSS only — it does not allow remote code execution, because uploaded filenames are derived from Symfony's Credit We would like to thank Emre Dogan for reporting the issue. Affected versions
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
+ 1 more Show less
v5.0.9
Fixed in
5.0.13
References Updated Jul 14, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev |
v5.0.2
patch
Dependencies (28)
+ 20 more
Changelog
Compare changes
|
|
v4.29.3
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v5.0.1
patch
3 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54087
GHSA-8559-gwj3-q37r
Jul 14, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
EasyAdmin's An attacker with access to a form using these fields can upload an Exploitation requires the developer to store uploads in the public directory and a privilege gap between the uploading user and the viewing administrator. This is stored XSS only — it does not allow remote code execution, because uploaded filenames are derived from Symfony's Credit We would like to thank Emre Dogan for reporting the issue. Affected versions
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
+ 1 more Show less
v5.0.9
Fixed in
5.0.13
References Updated Jul 14, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v4.29.2
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v5.0.0
major
3 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
CVE-2026-54087
GHSA-8559-gwj3-q37r
Jul 14, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
7.6
/ 10
High
Network
Low
Low
Required
Changed
High
Low
None
EasyAdmin's An attacker with access to a form using these fields can upload an Exploitation requires the developer to store uploads in the public directory and a privilege gap between the uploading user and the viewing administrator. This is stored XSS only — it does not allow remote code execution, because uploaded filenames are derived from Symfony's Credit We would like to thank Emre Dogan for reporting the issue. Affected versions
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
+ 1 more Show less
v5.0.9
Fixed in
5.0.13
References Updated Jul 14, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v5.0.0-BETA2
pre
| ||
v4.29.1
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v5.0.0-BETA1
pre
| ||
v4.29.0
minor
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v4.28.1
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v4.28.0
minor
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v4.27.8
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v4.27.7
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v4.27.6
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v4.27.5
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v4.27.4
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev |
v4.27.4
patch
Dependencies (27)
+ 19 more
Changelog
Compare changes
|
|
v4.27.3
patch
2 CVEs
CVE-2026-81892
GHSA-g2fm-8hr4-j82h
Sep 02, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryEasyAdmin serves all backend requests through a single dashboard route and, for custom actions ( That swap happens after Symfony's security firewall has already evaluated ImpactAny application where Only path-based protections are bypassed. Routes whose controller enforces its own authorization with PatchesFixed in 4.29.16 and 5.5.1. Before dispatching a custom-action route, EasyAdmin now re-evaluates the target route's WorkaroundsAdd controller-level authorization ( CreditsReported by @TungNGo02. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 172 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.10
v4.29.11
v4.29.12
v4.29.13
v4.29.14
v4.29.15
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.10
v5.0.11
v5.0.12
v5.0.13
v5.0.14
v5.0.15
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
v5.1.0
v5.2.0
v5.3.0
v5.4.0
v5.4.1
v5.5.0
Fixed in
4.29.16
5.5.1
References
Updated Sep 02, 2026 · Source: OSV.dev
GHSA-2wwr-9x6f-88gp
Jul 01, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
EasyAdminBundle ships two public Twig components — When an application binds either of those properties to data that is influenced by an end user, the lack of validation on the property value leads to two distinct issues:
The first-party usage shipped by EasyAdminBundle itself is not affected: the bundle only passes ISO 3166 alpha-2 codes validated through ImpactPath traversal is information disclosure bounded by the Affected components
CreditEasyAdmin would like to thank Claude Mythos Preview (via Project Glasswing and The PHP Foundation) for reporting the issue and providing the fix. Affected versions
v4.0.0
v4.0.1
v4.0.10
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
+ 154 more Show less
v4.1.1
v4.1.2
v4.10.0
v4.10.1
v4.10.2
v4.10.3
v4.10.4
v4.10.5
v4.11.0
v4.11.1
v4.12.0
v4.13.0
v4.13.1
v4.13.2
v4.13.3
v4.13.4
v4.13.5
v4.13.6
v4.14.0
v4.14.1
v4.14.2
v4.14.3
v4.14.4
v4.14.5
v4.15.0
v4.15.1
v4.16.0
v4.16.1
v4.16.2
v4.17.0
v4.18.0
v4.19.0
v4.2.0
v4.2.1
v4.2.2
v4.2.3
v4.2.4
v4.20.0
v4.20.1
v4.20.2
v4.20.3
v4.20.4
v4.20.5
v4.20.6
v4.20.7
v4.20.8
v4.21.0
v4.21.1
v4.22.0
v4.22.1
v4.22.2
v4.23.0
v4.23.1
v4.23.2
v4.23.3
v4.24.0
v4.24.1
v4.24.2
v4.24.3
v4.24.4
v4.24.5
v4.24.6
v4.24.7
v4.24.8
v4.24.9
v4.25.0
v4.25.1
v4.26.0
v4.26.1
v4.26.2
v4.26.3
v4.26.4
v4.26.5
v4.27.0
v4.27.1
v4.27.2
v4.27.3
v4.27.4
v4.27.5
v4.27.6
v4.27.7
v4.27.8
v4.28.0
v4.28.1
v4.29.0
v4.29.1
v4.29.2
v4.29.3
v4.29.4
v4.29.5
v4.29.6
v4.29.7
v4.29.8
v4.29.9
v4.3.0
v4.3.1
v4.3.2
v4.3.3
v4.3.4
v4.3.5
v4.4.0
v4.4.1
v4.4.2
v4.4.3
v4.4.4
v4.4.5
v4.5.0
v4.5.1
v4.5.2
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.7.0
v4.7.1
v4.7.2
v4.7.3
v4.7.4
v4.7.5
v4.7.6
v4.7.7
v4.8.0
v4.8.1
v4.8.10
v4.8.11
v4.8.12
v4.8.13
v4.8.2
v4.8.3
v4.8.4
v4.8.5
v4.8.6
v4.8.7
v4.8.8
v4.8.9
v4.9.0
v4.9.1
v4.9.2
v4.9.3
v4.9.4
v4.9.5
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4
v5.0.5
v5.0.6
v5.0.7
v5.0.8
v5.0.9
Fixed in
4.29.10
5.0.10
References Updated Sep 10, 2026 · Source: OSV.dev |