CVE-2026-31825: Sylius
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Sylius is an Open Source eCommerce Framework on Symfony. Sylius API filters ProductPriceOrderFilter and TranslationOrderNameAndLocaleFilter pass user-supplied order direction values directly to Doctrine's orderBy() without validation. An attacker can inject arbitrary DQL. The issue is fixed in versions: 1.9.12, 1.10.16, 1.11.17, 1.12.23, 1.13.15, 1.14.18, 2.0.16, 2.1.12, 2.2.3 and above.
Affected products
- Sylius Sylius: before 1.9.12 (fixed in 1.9.12); from 1.10.0, before 1.10.16 (fixed in 1.10.16); from 1.11.0, before 1.11.17 (fixed in 1.11.17); from 1.12.0, before 1.12.23 (fixed in 1.12.23); from 1.13.0, before 1.13.15 (fixed in 1.13.15); from 1.14.0, before 1.14.18 (fixed in 1.14.18); …
Published 2026-03-10. Last modified 2026-06-17.