Skip to content
RequestGuard Vulnerabilities
Pricing

symfony/web-profiler-bundle

Provides a development tool that gives detailed information about the execution of any request

Composer latest 8.1.7 MIT

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

8.1.7

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

High

2 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

2

Symfony Cross-Site Request Forgery vulnerability in the Web Profiler

Affected range

ECOSYSTEM: introduced 2.0.0; fixed 2.3.19ECOSYSTEM: introduced 2.4.0; fixed 2.4.9ECOSYSTEM: introduced 2.5.0; fixed 2.5.4>=2.0.0,<2.1.0|>=2.1.0,<2.2.0|>=2.2.0,<2.3.0|>=2.3.0,<2.3.19|>=2.4.0,<2.4.9|>=2.5.0,<2.5.4

Fixed versions: 2.3.19, 2.4.9, 2.5.4

Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering

Affected range

ECOSYSTEM: introduced 7.2.9; fixed 7.4.12ECOSYSTEM: introduced 8.0.0; fixed 8.0.12>=7.2.9,<7.3.0|>=7.3.0,<7.4.0|>=7.4.0,<7.4.12|>=8.0.0,<8.0.12

Fixed versions: 7.4.12, 8.0.12