← Back

Symphony

symphony

Vendor: B3log • 6 CVEs

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1B3log
1Symphony
Jun 17, 2026
Feb 5, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.
1B3log
1Symphony
Jun 17, 2026
Oct 10, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
b3log Symphony (aka Sym) before 3.6.0 has XSS via the HTTP User-Agent header.
1B3log
1Symphony
Nov 21, 2024
Jun 20, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/points URI, allowing remote...Show more
In Symphony before 3.3.0, there is XSS in the Title under Post. The ID "articleTitle" of this is stored in the "articleTitle" JSON field, and executes a payload when accessing the /member/test/points URI, allowing remote attacks. Any Web script or HTML can be inserted by an admin-authenticated user via a crafted web site name.Show less
1B3log
1Symphony
Jun 17, 2026
Feb 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in b3log Symphony (aka Sym) before v3.4.7. XSS exists via the userIntro and userNickname fields to processor/SettingsProcessor.java.
1B3log
1Symphony
Nov 21, 2024
Apr 27, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI.
1B3log
1Symphony
May 13, 2026
Nov 15, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
b3log Symphony (aka Sym) 2.2.0 has XSS in processor/AdminProcessor.java in the admin console, as demonstrated by a crafted X-Forwarded-For HTTP header that is mishandled during display of a client IP address in /admin/us...Show more
b3log Symphony (aka Sym) 2.2.0 has XSS in processor/AdminProcessor.java in the admin console, as demonstrated by a crafted X-Forwarded-For HTTP header that is mishandled during display of a client IP address in /admin/user/userid.Show less