CVE Tools

Symphony

30 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Symphony, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Symphony CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Symphony CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-121
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 30 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical310%
  • High827%
  • Medium1963%

Latest CVEs

The 15 most recently published vulnerabilities affecting Symphony.

  1. CVE-2025-12491Senstar Symphony FetchStoredLicense Information Disclosure Vulnerability7.5
  2. CVE-2024-23049An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.9.8
  3. CVE-2020-25912A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).9.1
  4. CVE-2020-25343Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script or HTML to fields['body'] param via events\event.publish_article.php5.4
  5. CVE-2020-17405This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Senstar Symphony 7.3.2.2. Authentication is not required to exploit this vulnerability. T...8.8
  6. CVE-2020-15071content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading.6.1
  7. CVE-2019-17488b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header.6.1
  8. CVE-2018-16249In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/poin...4.8
  9. CVE-2019-9142An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java.6.1
  10. CVE-2018-12043content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page.6.1
  11. CVE-2018-10469b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI.9.8
  12. CVE-2017-16956b3log Symphony (aka Sym) 2.2.0 allows an XSS attack by sending a private letter with a certain /article URI, and a second private letter with a modified title.6.1
  13. CVE-2017-16881b3log Symphony (aka Sym) 2.2.0 does not properly address XSS in JSON objects, as demonstrated by a crafted userAvatarURL value to /settings/avatar, related to processor/AdminProcessor.java, process...6.1
  14. CVE-2017-16821b3log Symphony (aka Sym) 2.2.0 has XSS in processor/AdminProcessor.java in the admin console, as demonstrated by a crafted X-Forwarded-For HTTP header that is mishandled during display of a client ...5.4
  15. CVE-2017-8876Symphony 2 2.6.11 has XSS in the meta[navigation_group] parameter to content/content.blueprintssections.php.6.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store