nette/application
🏆 Nette Application: a full-stack component-based MVC kernel for PHP that helps you write powerful and modern web applications. Write less, have cleaner code and your work will bring you joy.
Activity
- Latest release
- 2mo ago
- Total releases
- 81
- Cadence
- ~40 days
- Last 12 months
- 6
Reach
- Stars
- —
Details
- License
- BSD-3-Clause OR unknown
- First release
- May 06, 2014
| Version | Released | |
|---|---|---|
v3.3.0
minor
| ||
v3.2.12
patch
| ||
v3.3.0-RC
pre
| ||
v3.2.10
patch
| ||
v3.2.9
patch
| ||
v3.2.8
patch
| ||
v3.2.7
patch
| ||
v3.2.6
patch
| ||
v3.2.5
patch
| ||
v3.2.4
patch
| ||
v3.1.15
patch
| ||
v3.2.3
patch
| ||
v3.2.1
patch
| ||
v3.2.0
minor
| ||
v3.1.14
patch
| ||
v3.1.13
patch
| ||
v3.1.11
patch
| ||
v3.1.10
patch
| ||
v3.1.8
patch
| ||
v3.1.7
patch
| ||
v3.1.6
patch
| ||
v3.1.5
patch
| ||
v3.1.4
patch
| ||
v3.1.3
patch
| ||
v3.1.2
patch
| ||
v3.0.8
patch
| ||
v3.1.1
patch
| ||
v3.1.0
minor
| ||
v2.4.17
patch
| ||
v3.0.7
patch
| ||
v3.0.2.1
patch
1 CVE
CVE-2020-15227
GHSA-8gv3-3j7f-wg94
Oct 02, 2020
Potential Remote Code Execution vulnerability
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ImpactCode injection, possible remote code execution. PatchesFixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13 Affected versions
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.1
+ 35 more Show less
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v3.0.0
v3.0.1
v3.0.2
v3.0.2.1
v3.0.3
v3.0.4
v3.0.5
Fixed in
2.0.19
2.1.13
2.2.10
2.3.14
2.4.16
3.0.6
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v3.0.6
patch
| ||
v2.4.16
patch
| ||
v2.3.14
patch
| ||
v2.2.10
patch
| ||
v2.4.15
patch
1 CVE
CVE-2020-15227
GHSA-8gv3-3j7f-wg94
Oct 02, 2020
Potential Remote Code Execution vulnerability
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ImpactCode injection, possible remote code execution. PatchesFixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13 Affected versions
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.1
+ 35 more Show less
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v3.0.0
v3.0.1
v3.0.2
v3.0.2.1
v3.0.3
v3.0.4
v3.0.5
Fixed in
2.0.19
2.1.13
2.2.10
2.3.14
2.4.16
3.0.6
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v3.0.5
patch
1 CVE
CVE-2020-15227
GHSA-8gv3-3j7f-wg94
Oct 02, 2020
Potential Remote Code Execution vulnerability
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ImpactCode injection, possible remote code execution. PatchesFixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13 Affected versions
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.1
+ 35 more Show less
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v3.0.0
v3.0.1
v3.0.2
v3.0.2.1
v3.0.3
v3.0.4
v3.0.5
Fixed in
2.0.19
2.1.13
2.2.10
2.3.14
2.4.16
3.0.6
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v3.0.4
patch
1 CVE
CVE-2020-15227
GHSA-8gv3-3j7f-wg94
Oct 02, 2020
Potential Remote Code Execution vulnerability
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ImpactCode injection, possible remote code execution. PatchesFixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13 Affected versions
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.1
+ 35 more Show less
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v3.0.0
v3.0.1
v3.0.2
v3.0.2.1
v3.0.3
v3.0.4
v3.0.5
Fixed in
2.0.19
2.1.13
2.2.10
2.3.14
2.4.16
3.0.6
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v3.0.3
patch
1 CVE
CVE-2020-15227
GHSA-8gv3-3j7f-wg94
Oct 02, 2020
Potential Remote Code Execution vulnerability
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ImpactCode injection, possible remote code execution. PatchesFixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13 Affected versions
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.1
+ 35 more Show less
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v3.0.0
v3.0.1
v3.0.2
v3.0.2.1
v3.0.3
v3.0.4
v3.0.5
Fixed in
2.0.19
2.1.13
2.2.10
2.3.14
2.4.16
3.0.6
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.4.14
patch
1 CVE
CVE-2020-15227
GHSA-8gv3-3j7f-wg94
Oct 02, 2020
Potential Remote Code Execution vulnerability
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ImpactCode injection, possible remote code execution. PatchesFixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13 Affected versions
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.1
+ 35 more Show less
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v3.0.0
v3.0.1
v3.0.2
v3.0.2.1
v3.0.3
v3.0.4
v3.0.5
Fixed in
2.0.19
2.1.13
2.2.10
2.3.14
2.4.16
3.0.6
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v3.0.2
patch
1 CVE
CVE-2020-15227
GHSA-8gv3-3j7f-wg94
Oct 02, 2020
Potential Remote Code Execution vulnerability
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ImpactCode injection, possible remote code execution. PatchesFixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13 Affected versions
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.1
+ 35 more Show less
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v3.0.0
v3.0.1
v3.0.2
v3.0.2.1
v3.0.3
v3.0.4
v3.0.5
Fixed in
2.0.19
2.1.13
2.2.10
2.3.14
2.4.16
3.0.6
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v3.0.1
patch
1 CVE
CVE-2020-15227
GHSA-8gv3-3j7f-wg94
Oct 02, 2020
Potential Remote Code Execution vulnerability
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ImpactCode injection, possible remote code execution. PatchesFixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13 Affected versions
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.1
+ 35 more Show less
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v3.0.0
v3.0.1
v3.0.2
v3.0.2.1
v3.0.3
v3.0.4
v3.0.5
Fixed in
2.0.19
2.1.13
2.2.10
2.3.14
2.4.16
3.0.6
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v3.0.0
major
1 CVE
CVE-2020-15227
GHSA-8gv3-3j7f-wg94
Oct 02, 2020
Potential Remote Code Execution vulnerability
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ImpactCode injection, possible remote code execution. PatchesFixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13 Affected versions
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.1
+ 35 more Show less
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v3.0.0
v3.0.1
v3.0.2
v3.0.2.1
v3.0.3
v3.0.4
v3.0.5
Fixed in
2.0.19
2.1.13
2.2.10
2.3.14
2.4.16
3.0.6
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.4.13
patch
1 CVE
CVE-2020-15227
GHSA-8gv3-3j7f-wg94
Oct 02, 2020
Potential Remote Code Execution vulnerability
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ImpactCode injection, possible remote code execution. PatchesFixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13 Affected versions
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.1
+ 35 more Show less
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v3.0.0
v3.0.1
v3.0.2
v3.0.2.1
v3.0.3
v3.0.4
v3.0.5
Fixed in
2.0.19
2.1.13
2.2.10
2.3.14
2.4.16
3.0.6
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.4.12
patch
1 CVE
CVE-2020-15227
GHSA-8gv3-3j7f-wg94
Oct 02, 2020
Potential Remote Code Execution vulnerability
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ImpactCode injection, possible remote code execution. PatchesFixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13 Affected versions
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.1
+ 35 more Show less
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v3.0.0
v3.0.1
v3.0.2
v3.0.2.1
v3.0.3
v3.0.4
v3.0.5
Fixed in
2.0.19
2.1.13
2.2.10
2.3.14
2.4.16
3.0.6
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.4.11
patch
1 CVE
CVE-2020-15227
GHSA-8gv3-3j7f-wg94
Oct 02, 2020
Potential Remote Code Execution vulnerability
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ImpactCode injection, possible remote code execution. PatchesFixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13 Affected versions
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.1
+ 35 more Show less
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v3.0.0
v3.0.1
v3.0.2
v3.0.2.1
v3.0.3
v3.0.4
v3.0.5
Fixed in
2.0.19
2.1.13
2.2.10
2.3.14
2.4.16
3.0.6
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.4.10
patch
1 CVE
CVE-2020-15227
GHSA-8gv3-3j7f-wg94
Oct 02, 2020
Potential Remote Code Execution vulnerability
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ImpactCode injection, possible remote code execution. PatchesFixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13 Affected versions
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.1
+ 35 more Show less
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v3.0.0
v3.0.1
v3.0.2
v3.0.2.1
v3.0.3
v3.0.4
v3.0.5
Fixed in
2.0.19
2.1.13
2.2.10
2.3.14
2.4.16
3.0.6
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.4.9
patch
1 CVE
CVE-2020-15227
GHSA-8gv3-3j7f-wg94
Oct 02, 2020
Potential Remote Code Execution vulnerability
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ImpactCode injection, possible remote code execution. PatchesFixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13 Affected versions
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.1
+ 35 more Show less
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v3.0.0
v3.0.1
v3.0.2
v3.0.2.1
v3.0.3
v3.0.4
v3.0.5
Fixed in
2.0.19
2.1.13
2.2.10
2.3.14
2.4.16
3.0.6
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.4.8
patch
1 CVE
CVE-2020-15227
GHSA-8gv3-3j7f-wg94
Oct 02, 2020
Potential Remote Code Execution vulnerability
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ImpactCode injection, possible remote code execution. PatchesFixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13 Affected versions
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.1
+ 35 more Show less
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v3.0.0
v3.0.1
v3.0.2
v3.0.2.1
v3.0.3
v3.0.4
v3.0.5
Fixed in
2.0.19
2.1.13
2.2.10
2.3.14
2.4.16
3.0.6
References
Updated Jul 08, 2026 · Source: OSV.dev | ||
v2.4.7
patch
1 CVE
CVE-2020-15227
GHSA-8gv3-3j7f-wg94
Oct 02, 2020
Potential Remote Code Execution vulnerability
8.7
/ 10
High
Network
High
None
None
Changed
High
High
None
Packages nette/application versions prior to 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette versions prior to 2.0.19 and 2.1.13 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Reported by Cyku Hong from DEVCORE (https://devco.re) ImpactCode injection, possible remote code execution. PatchesFixed in nette/application 2.2.10, 2.3.14, 2.4.16, 3.0.6 and nette/nette 2.0.19 and 2.1.13 Affected versions
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v2.3.0
v2.3.1
+ 35 more Show less
v2.3.10
v2.3.11
v2.3.12
v2.3.13
v2.3.2
v2.3.3
v2.3.4
v2.3.5
v2.3.6
v2.3.7
v2.3.8
v2.3.9
v2.4.0
v2.4.1
v2.4.10
v2.4.11
v2.4.12
v2.4.13
v2.4.14
v2.4.15
v2.4.2
v2.4.3
v2.4.4
v2.4.5
v2.4.6
v2.4.7
v2.4.8
v2.4.9
v3.0.0
v3.0.1
v3.0.2
v3.0.2.1
v3.0.3
v3.0.4
v3.0.5
Fixed in
2.0.19
2.1.13
2.2.10
2.3.14
2.4.16
3.0.6
References
Updated Jul 08, 2026 · Source: OSV.dev |