CVEs we hold for Sylius
Records whose assigning authority named Sylius as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-68501Sylius Mollie Plugin: Unauthenticated IDOR leaks order token and customer PIISylius MolliePlugin
CVE-2026-68500Sylius Mollie Plugin: Payment status forgery via the payment webhookSylius MolliePlugin
CVE-2026-53638Sylius: Channel-based payment method restriction bypass on shop account orders API endpointSylius
CVE-2026-53637Sylius: Cart FormComponent allows modification or deletion of an already-completed orderSylius
CVE-2025-30152Sylius PayPal Plugin has an Order Manipulation Vulnerability after PayPal CheckoutSylius PayPalPlugin
CVE-2024-34349Sylius potentially vulnerable to Cross Site Scripting via "Name" field (Taxons, Products, Options, Variants) in Admin…Sylius
CVE-2022-24749Basic Cross-site Scripting and Unrestricted Upload of File with Dangerous Type in SyliusSylius
CVE-2021-32720List of order ids, number, items total and token value exposed for unauthorized uses via new APISylius
CVE-2020-5220Ability to expose data in Sylius by using an unintended serialisation groupSylius SyliusResourceBundle
CVE-2020-5218Ability in Sylius to switch channels via GET parameter enabled in production environmentsSylius
30 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.