Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: languages Tag: ux Clear
ID Title
CVE-2026-55877 Cross-Site Scripting (XSS) in symfony/ux-icons (CVE-2026-55877)
cross-site scripting in symfony/ux-icons (CVE-2026-55877). Risk of unauthorized operations or information disclosure. Exploitable via ``body``. Mitigation: upgrade to `3.2.0` or later.
CVE-2026-49216 Cross-Site Scripting (XSS) in symfony/ux-autocomplete (CVE-2026-49216)
cross-site scripting in symfony/ux-autocomplete (CVE-2026-49216). Risk of unauthorized operations or information disclosure. Exploitable via ``text``. Mitigation: upgrade to `3.1.0` or later.
CVE-2026-49215 Cross-Site Request Forgery (CSRF) in symfony/ux-live-component (CVE-2026-49215)
vulnerability in symfony/ux-live-component (CVE-2026-49215). Risk of unauthorized operations or information disclosure. Exploitable via ``Accept``. Mitigation: upgrade to `3.1.0` or later.
CVE-2026-49212 Vulnerability in symfony/ux-live-component (CVE-2026-49212)
vulnerability in symfony/ux-live-component (CVE-2026-49212). Data can be tampered with by attackers. Exploitable via ``propsFromParent``. Mitigation: upgrade to `3.1.0` or later.
CVE-2026-49211 Information Disclosure in symfony/ux-autocomplete (CVE-2026-49211)
vulnerability in symfony/ux-autocomplete (CVE-2026-49211). Confidential information can be exposed externally. Exploitable via ``LIKE``. Mitigation: upgrade to `3.1.0` or later.
CVE-2026-49210 Cross-Site Scripting (XSS) in symfony/ux-live-component (CVE-2026-49210)
cross-site scripting in symfony/ux-live-component (CVE-2026-49210). Risk of unauthorized operations or information disclosure. Exploitable via ``LiveComponentSubscriber``. Mitigation: upgrade to `3.1.0` or later.
CVE-2026-49209 Vulnerability in symfony/ux-live-component (CVE-2026-49209)
vulnerability in symfony/ux-live-component (CVE-2026-49209). Risk of unauthorized operations or information disclosure. Exploitable via ``actions``. Mitigation: upgrade to `3.1.0` or later.
CVE-2026-49208 Vulnerability in symfony/ux-live-component (CVE-2026-49208)
vulnerability in symfony/ux-live-component (CVE-2026-49208). Risk of unauthorized operations or information disclosure. Exploitable via ``DateTimeInterface``. Mitigation: upgrade to `3.1.0` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →