Description
In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. This is related to symfony/framework-bundle.
Remediation
References
Related Vulnerabilities
PHP Improper Input Validation Vulnerability (CVE-2016-4072)
Sqlite Integer Overflow or Wraparound Vulnerability (CVE-2025-3277)
WordPress Plugin Zedna Contact form Arbitrary File Upload (1.0)
Oracle JRE CVE-2020-2756 Vulnerability (CVE-2020-2756)
WordPress Plugin Ivory Search-WordPress Search Cross-Site Scripting (4.5.10)