{"api_version":"v1","generated_at":"2026-10-09T10:05:00+00:00","product":{"cve_count":24,"evidence_gap_note":"This CVE identity is linked to an existing Lifecycle product history.","id":"security:cve-sylius-sylius-7303eb1c6cd9","lifecycle_state":"covered","linked_lifecycle_url":"https://lifecycle.blacktree.nl/targets/sylius","name":"Sylius","next_cursor":null,"observations":[{"affected":"Sylius: 2.0.0 < 2.1.16, 2.2.0 < 2.2.9","affected_versions_present":true,"cve_id":"CVE-2026-100872","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-100872","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-06T13:36:51.750Z","patch_url":"","primary_source":"","published":"2026-09-27T13:09:56.034Z"},{"affected":"Sylius: 1.11.0 < 1.12.25, 1.13.0 < 1.13.17, 1.14.0 < 1.14.20, 2.0.0 < 2.1.16, 2.2.0 < 2.2.9","affected_versions_present":true,"cve_id":"CVE-2026-100871","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-100871","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-06T13:36:51.028Z","patch_url":"","primary_source":"","published":"2026-09-27T13:09:55.386Z"},{"affected":"Sylius: 1.12.0 < 1.12.25, 1.13.0 < 1.13.17, 1.14.0 < 1.14.20, 2.0.0 < 2.1.16, 2.2.0 < 2.2.9","affected_versions_present":true,"cve_id":"CVE-2026-100870","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-100870","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-06T13:36:50.158Z","patch_url":"","primary_source":"","published":"2026-09-27T13:09:54.715Z"},{"affected":"Sylius: 2.0.0 < 2.1.16, 2.2.0 < 2.2.9","affected_versions_present":true,"cve_id":"CVE-2026-100869","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-100869","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-10-06T13:36:49.073Z","patch_url":"","primary_source":"","published":"2026-09-27T13:09:54.038Z"},{"affected":">= 2.0.0, < 2.0.18; >= 2.1.0, < 2.1.15; >= 2.2.0, < 2.2.6","affected_versions_present":true,"cve_id":"CVE-2026-53637","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53637","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-09T15:37:23.362Z","patch_url":"","primary_source":"","published":"2026-09-08T22:31:39.758Z"},{"affected":"Sylius: >= 2.0.0, < 2.0.18, >= 2.1.0, < 2.1.15, >= 2.2.0, < 2.2.6","affected_versions_present":true,"cve_id":"CVE-2026-53638","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53638","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-14T12:05:51.544Z","patch_url":"","primary_source":"","published":"2026-09-08T22:25:26.679Z"},{"affected":">= 2.0.0, < 2.0.18; >= 2.1.0, < 2.1.15; >= 2.2.0, < 2.2.6","affected_versions_present":true,"cve_id":"CVE-2026-53639","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-53639","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-09T16:03:44.749Z","patch_url":"","primary_source":"","published":"2026-09-08T22:22:24.578Z"},{"affected":">= 2.2.0, < 2.2.3; >= 2.1.0, < 2.1.12; >= 2.0.0, < 2.0.16; >= 1.14.0, < 1.14.18; >= 1.13.0, < 1.13.15; >= 1.12.0, < 1.12.23; >= 1.11.0, < 1.11.17; >= 1.10.0, < 1.10.16","affected_versions_present":true,"cve_id":"CVE-2026-31825","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31825","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-11T15:19:28.740Z","patch_url":"https://github.com/Sylius/Sylius/security/advisories/GHSA-xcwx-r2gw-w93m","primary_source":"","published":"2026-03-10T21:33:26.471Z"},{"affected":">= 2.2.0, < 2.2.3; >= 2.1.0, < 2.1.12; >= 2.0.0, < 2.0.16; >= 1.14.0, < 1.14.18; >= 1.13.0, < 1.13.15; >= 1.12.0, < 1.12.23; >= 1.11.0, < 1.11.17; >= 1.10.0, < 1.10.16","affected_versions_present":true,"cve_id":"CVE-2026-31824","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31824","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-11T15:59:35.695Z","patch_url":"https://github.com/Sylius/Sylius/security/advisories/GHSA-7mp4-25j8-hp5q","primary_source":"","published":"2026-03-10T21:32:16.811Z"},{"affected":">= 2.2.0, < 2.2.3; >= 2.1.0, < 2.1.12; >= 2.0.0, < 2.0.16","affected_versions_present":true,"cve_id":"CVE-2026-31823","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31823","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-11T15:59:42.607Z","patch_url":"https://github.com/Sylius/Sylius/security/advisories/GHSA-mx4q-xxc9-pf5q","primary_source":"","published":"2026-03-10T21:29:13.828Z"},{"affected":">= 2.2.0, < 2.2.3; >= 2.1.0, < 2.1.12; >= 2.0.0, < 2.0.16","affected_versions_present":true,"cve_id":"CVE-2026-31822","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31822","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-11T15:59:48.465Z","patch_url":"https://github.com/Sylius/Sylius/security/advisories/GHSA-vgh8-c6fp-7gcg","primary_source":"","published":"2026-03-10T21:27:38.691Z"},{"affected":">= 2.2.0, < 2.2.3; >= 2.1.0, < 2.1.12; >= 2.0.0, < 2.0.16","affected_versions_present":true,"cve_id":"CVE-2026-31821","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31821","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-11T15:19:28.880Z","patch_url":"https://github.com/Sylius/Sylius/security/advisories/GHSA-wjmg-4cq5-m8hg","primary_source":"","published":"2026-03-10T21:25:20.368Z"},{"affected":">= 2.2.0, < 2.2.3; >= 2.1.0, < 2.1.12; >= 2.0.0, < 2.0.16","affected_versions_present":true,"cve_id":"CVE-2026-31820","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31820","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-11T15:59:53.833Z","patch_url":"https://github.com/Sylius/Sylius/security/advisories/GHSA-2xc6-348p-c2x6","primary_source":"","published":"2026-03-10T21:22:37.052Z"},{"affected":">= 2.2.0, < 2.2.3; >= 2.1.0, < 2.1.12; >= 2.0.0, < 2.0.16; >= 1.14.0, < 1.14.18; >= 1.13.0, < 1.13.15; >= 1.12.0, < 1.12.23; >= 1.11.0, < 1.11.17; >= 1.10.0, < 1.10.16","affected_versions_present":true,"cve_id":"CVE-2026-31819","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31819","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-11T15:59:59.496Z","patch_url":"https://github.com/Sylius/Sylius/security/advisories/GHSA-9ffx-f77r-756w","primary_source":"","published":"2026-03-10T21:18:59.634Z"},{"affected":"< 1.12.19; >= 1.13.0, < 1.13.4","affected_versions_present":true,"cve_id":"CVE-2024-40633","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-40633","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-02T04:33:11.961Z","patch_url":"","primary_source":"","published":"2024-07-17T17:51:45.986Z"},{"affected":"< 1.12.16; >= 1.13.0-alpha.1, < 1.13.1","affected_versions_present":true,"cve_id":"CVE-2024-34349","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-34349","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-02T02:51:11.424Z","patch_url":"","primary_source":"","published":"2024-05-10T15:29:39.791Z"},{"affected":"< 1.9.10; >= 1.10.0, < 1.10.11; >= 1.11.0, < 1.11.2","affected_versions_present":true,"cve_id":"CVE-2022-24749","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24749","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-22T18:18:36.653Z","patch_url":"","primary_source":"","published":"2022-03-14T21:45:13.000Z"},{"affected":"< 1.10.11; >= 1.11.0, < 1.11.2","affected_versions_present":true,"cve_id":"CVE-2022-24743","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24743","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-22T18:18:50.307Z","patch_url":"","primary_source":"","published":"2022-03-14T21:00:14.000Z"},{"affected":"< 1.9.10; >= 1.10.0, < 1.10.11; >= 1.11.0, < 1.11.2","affected_versions_present":true,"cve_id":"CVE-2022-24742","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24742","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-23T18:54:10.363Z","patch_url":"https://github.com/Sylius/Sylius/security/advisories/GHSA-7563-75j9-6h5p","primary_source":"","published":"2022-03-14T19:20:10.000Z"},{"affected":"< 1.9.10; >= 1.10.0, < 1.10.11; >= 1.11.0, < 1.11.2","affected_versions_present":true,"cve_id":"CVE-2022-24733","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-24733","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-23T18:54:19.052Z","patch_url":"https://github.com/Sylius/Sylius/security/advisories/GHSA-4jp3-q2qm-9fmw","primary_source":"","published":"2022-03-14T18:50:10.000Z"},{"affected":">= 1.9.0, < 1.9.5; >= 1.10.0-ALPHA.1, <= 1.10.0-BETA.1","affected_versions_present":true,"cve_id":"CVE-2021-32720","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-32720","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-03T23:25:31.162Z","patch_url":"https://github.com/Sylius/Sylius/security/advisories/GHSA-rpxh-vg2x-526v","primary_source":"","published":"2021-06-28T18:45:11.000Z"},{"affected":">= 9.0.0, < 9.4.4","affected_versions_present":true,"cve_id":"CVE-2020-15245","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-15245","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T13:08:23.223Z","patch_url":"https://github.com/Sylius/Sylius/commit/60636d711a4011e8694d10d201b53632c7e8ecaf","primary_source":"","published":"2020-10-19T20:50:16.000Z"},{"affected":"< 1.3.13; >= 1.4.0, < 1.4.6; >= 1.5.0, < 1.5.1; >= 1.6.0, < 1.6.3","affected_versions_present":true,"cve_id":"CVE-2020-5218","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-5218","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-08-04T08:22:08.934Z","patch_url":"https://github.com/Sylius/SyliusResourceBundle/security/advisories/GHSA-8vp7-j5cj-vvm2","primary_source":"","published":"2020-01-27T20:25:13.000Z"},{"affected":"< 1.3.14 < 1.3.14","affected_versions_present":true,"cve_id":"CVE-2019-16768","cve_url":"https://cve.blacktree.nl/cve/CVE-2019-16768","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-05T01:24:47.238Z","patch_url":"https://github.com/Sylius/Sylius/security/advisories/GHSA-3r8j-pmch-5j2h","primary_source":"","published":"2019-12-05T20:00:21.000Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"Sylius"}}
