CVE-2020-25912: Getsymphony Symphony

Critical severity, CVSS 9.1. EPSS: 1.4% chance of exploitation in the next 30 days.

A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).

Affected products

Published 2021-10-31. Last modified 2026-07-09.