GHSA-hhvr-2q69-4563
GitHub Security Advisory
Cross site scripting in sylius/sylius
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of the user's browser.
Affected Packages
Packagist
sylius/sylius
Affected versions:
0
(fixed in 1.9.10)
Packagist
sylius/sylius
Affected versions:
1.10.0
(fixed in 1.10.11)
Packagist
sylius/sylius
Affected versions:
1.11.0
(fixed in 1.11.2)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 12, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.