symfony/ux-autocomplete
JavaScript Autocomplete functionality for Symfony
Activity
- Latest release
- 1mo ago
- Total releases
- 57
- Cadence
- ~15 days
- Last 12 months
- 12
Reach
- Stars
- 63
Details
- License
- MIT
- First release
- Jun 15, 2022
| Version | Released | |
|---|---|---|
v3.4.0
minor
|
v3.4.0
minor
Dependencies (5)
Changelog
Compare changes
|
|
v3.3.0
minor
| ||
v2.36.2
patch
| ||
v3.2.0
minor
| ||
v3.1.0
minor
| ||
v2.36.0
minor
| ||
v3.0.0
major
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.35.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.34.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.33.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.32.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.31.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.30.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.29.2
patch
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.29.1
patch
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.29.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.28.2
patch
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.28.1
patch
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v2.28.1
patch
Changelog
Compare changes
|
|
v2.28.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.27.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.26.1
patch
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.26.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.25.2
patch
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.25.1
patch
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.25.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.24.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.23.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.22.1
patch
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.22.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.21.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.20.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev |
v2.20.0
minor
Dependencies (6)
Changelog
Compare changes
|
|
v2.19.2
patch
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.19.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.18.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.17.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.16.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.15.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.14.2
patch
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.14.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.13.3
patch
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.13.2
patch
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.13.1
patch
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.13.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.12.0
minor
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.11.2
patch
2 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.11.1
minor
3 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-41336
GHSA-4cpv-669c-r79x
Sep 11, 2023
Prevent injection of invalid entity ids for "autocomplete" fields
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
ImpactUnder certain circumstances, an attacker could successfully submit an entity id for an Affected applications are any that use:
Under this circumstance, if an id is submitted, it is accepted even if the matching record would not be returned by the custom query built with PatchesThe problem has been fixed in WorkaroundsUpgrade to version 2.11.2 or greater of Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
+ 3 more Show less
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.11.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.9.1
patch
3 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-41336
GHSA-4cpv-669c-r79x
Sep 11, 2023
Prevent injection of invalid entity ids for "autocomplete" fields
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
ImpactUnder certain circumstances, an attacker could successfully submit an entity id for an Affected applications are any that use:
Under this circumstance, if an id is submitted, it is accepted even if the matching record would not be returned by the custom query built with PatchesThe problem has been fixed in WorkaroundsUpgrade to version 2.11.2 or greater of Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
+ 3 more Show less
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.11.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.9.0
minor
3 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-41336
GHSA-4cpv-669c-r79x
Sep 11, 2023
Prevent injection of invalid entity ids for "autocomplete" fields
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
ImpactUnder certain circumstances, an attacker could successfully submit an entity id for an Affected applications are any that use:
Under this circumstance, if an id is submitted, it is accepted even if the matching record would not be returned by the custom query built with PatchesThe problem has been fixed in WorkaroundsUpgrade to version 2.11.2 or greater of Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
+ 3 more Show less
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.11.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.8.1
minor
3 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-41336
GHSA-4cpv-669c-r79x
Sep 11, 2023
Prevent injection of invalid entity ids for "autocomplete" fields
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
ImpactUnder certain circumstances, an attacker could successfully submit an entity id for an Affected applications are any that use:
Under this circumstance, if an id is submitted, it is accepted even if the matching record would not be returned by the custom query built with PatchesThe problem has been fixed in WorkaroundsUpgrade to version 2.11.2 or greater of Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
+ 3 more Show less
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.11.2
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v2.7.1
patch
3 CVEs
CVE-2026-49216
GHSA-mwqm-4fw3-cjvr
Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data
Medium
Network
Low
None
DescriptionThe Stimulus controller shipped with When the dropdown values are derived from user-supplied content, an attacker can craft a string that triggers stored XSS in the browser of any other user who later opens a page containing an autocomplete widget backed by the same data. ResolutionThe The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Alex Ashkov for reporting the issue and Hugo Alliaume for providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-49211
GHSA-946h-jp5c-8fvh
Jun 19, 2026
symfony/ux-autocomplete: Information exposure via unescaped LIKE wildcards in EntitySearchUtil
Medium
Network
High
None
None
Description
Because Resolution
The patch for this issue is available here for branch 2.x (and forward-ported to 3.x). CreditsSymfony would like to thank Pascal Cescon for reporting the issue and providing the fix. Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.12.0
v2.13.0
v2.13.1
v2.13.2
v2.13.3
v2.14.0
v2.14.2
v2.15.0
+ 42 more Show less
v2.16.0
v2.17.0
v2.18.0
v2.19.0
v2.19.2
v2.2.0
v2.20.0
v2.21.0
v2.22.0
v2.22.1
v2.23.0
v2.24.0
v2.25.0
v2.25.1
v2.25.2
v2.26.0
v2.26.1
v2.27.0
v2.28.0
v2.28.1
v2.28.2
v2.29.0
v2.29.1
v2.29.2
v2.3.0
v2.30.0
v2.31.0
v2.32.0
v2.33.0
v2.34.0
v2.35.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v3.0.0
Fixed in
2.36.0
3.1.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2023-41336
GHSA-4cpv-669c-r79x
Sep 11, 2023
Prevent injection of invalid entity ids for "autocomplete" fields
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
Low
Low
None
ImpactUnder certain circumstances, an attacker could successfully submit an entity id for an Affected applications are any that use:
Under this circumstance, if an id is submitted, it is accepted even if the matching record would not be returned by the custom query built with PatchesThe problem has been fixed in WorkaroundsUpgrade to version 2.11.2 or greater of Affected versions
v2.10.0
v2.11.0
v2.11.1
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.7.1
v2.8.0
+ 3 more Show less
v2.8.1
v2.9.0
v2.9.1
Fixed in
2.11.2
References
Updated Sep 10, 2026 · Source: OSV.dev |