Known Vulnerabilities for products from Symphony Project
Listed below are 2 of the newest known vulnerabilities associated with the vendor "Symphony Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2017-16956 json | b3log Symphony (aka Sym) 2.2.0 allows an XSS attack by sending a private letter with a certain /article URI, and a second pri... | Not Provided | 2017-11-27 | 2025-04-20 |
| CVE-2017-16881 json | b3log Symphony (aka Sym) 2.2.0 does not properly address XSS in JSON objects, as demonstrated by a crafted userAvatarURL valu... | Not Provided | 2017-11-18 | 2025-04-20 |