CVE-2020-25912: Getsymphony Symphony
Critical severity, CVSS 9.1. EPSS: 1.4% chance of exploitation in the next 30 days.
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
Affected products
- Getsymphony Symphony: version 2.7.10 only
Published 2021-10-31. Last modified 2026-07-09.