symfony/web-profiler-bundle
Provides a development tool that gives detailed information about the execution of any request
Activity
- Latest release
- 1w ago
- Total releases
- 559
- Cadence
- ~daily
- Last 12 months
- 53
Reach
- Stars
- 2.3k
Details
- License
- MIT
- First release
- Nov 24, 2011
| Version | Released | |
|---|---|---|
v8.1.7
patch
|
v8.1.7
patch
Dependencies (5)
Changelog
Compare changes
|
|
v7.4.19
patch
|
v7.4.19
patch
Dependencies (7)
Changelog
Compare changes
|
|
v6.4.46
patch
|
v6.4.46
patch
Dependencies (6)
Changelog
Compare changes
|
|
v8.1.5
patch
|
v8.1.5
patch
Dependencies (5)
Changelog
Compare changes
|
|
v7.4.17
patch
|
v7.4.17
patch
Dependencies (7)
Changelog
Compare changes
|
|
v6.4.44
patch
|
v6.4.44
patch
Dependencies (6)
Changelog
Compare changes
|
|
v8.1.4
patch
|
v8.1.4
patch
Dependencies (5)
Changelog
Compare changes
|
|
v7.4.16
patch
|
v7.4.16
patch
Dependencies (7)
Changelog
Compare changes
|
|
v7.4.15
patch
|
v7.4.15
patch
Dependencies (7)
Changelog
Compare changes
|
|
v6.4.43
patch
|
v6.4.43
patch
Dependencies (6)
Changelog
Compare changes
|
|
v8.0.15
patch
| ||
v8.1.2
patch
|
v8.1.2
patch
Dependencies (5)
Changelog
Compare changes
|
|
v8.1.1
patch
| ||
v8.0.14
patch
| ||
v7.4.14
patch
|
v7.4.14
patch
Dependencies (7)
Changelog
Compare changes
|
|
v6.4.42
patch
| ||
v8.1.0
minor
| ||
v8.1.0-RC1
pre
| ||
v8.0.13
patch
| ||
v7.4.13
patch
| ||
v6.4.41
patch
| ||
v8.1.0-BETA3
pre
| ||
v8.0.12
patch
| ||
v7.4.12
patch
| ||
v8.1.0-BETA2
pre
| ||
v8.0.11
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.11
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.39
patch
| ||
v8.1.0-BETA1
pre
| ||
v8.0.9
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.9
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.8
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.8
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.36
patch
| ||
v8.0.7
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.7
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.35
patch
| ||
v8.0.6
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.6
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.34
patch
| ||
v8.0.4
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.4
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.10
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v6.4.32
patch
| ||
v8.0.3
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.3
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.3.9
patch
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.0
major
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v7.4.0
minor
1 CVE
CVE-2026-45072
GHSA-hmr5-2xcr-v8pp
May 27, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
Network
Low
Low
DescriptionSymfony's profiler, a development only debug UI, renders source-code excerpts on several pages using Twig's custom An attacker who can write arbitrary bytes into any file under the project root (including e.g. ResolutionThe The patch for this issue is available here for branch 6.4. CreditsSymfony would like to thank Claude Mythos Preview (via Project Glasswing) for reporting the issue and providing the fix. Affected versions
v7.2.9
v7.3.0
v7.3.0-BETA1
v7.3.0-RC1
v7.3.1
v7.3.10
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.9
v7.4.0
+ 18 more Show less
v7.4.0-BETA1
v7.4.0-RC1
v7.4.0-RC3
v7.4.11
v7.4.3
v7.4.4
v7.4.6
v7.4.7
v7.4.8
v7.4.9
v8.0.0
v8.0.11
v8.0.3
v8.0.4
v8.0.6
v8.0.7
v8.0.8
v8.0.9
Fixed in
7.4.12
8.0.12
References
Updated Sep 10, 2026 · Source: OSV.dev | ||
v8.0.0-RC1
pre
|