#CodeExtension
🔐 CVE-2026-45072: Stored XSS in WebProfiler CodeExtension::fileExcerpt(): Unescaped Non-PHP File Rendering
➡️ https://symfony.com/blog/cve-2026-45072-stored-xss-in-webprofiler-codeextension-fileexcerpt-unescaped-non-php-file-rendering
May 20, 2026 at 10:57 AM
CVE-2026-45072 - Symfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
CVE ID : CVE-2026-45072

Published : July 14, 2026, 7:17 p.m. | 13 minutes ago

Description : Symfony is a PHP framework for web and console applications and...
CVE-2026-45072 - Symfony: Stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 6.4.24 until 6.4.40, 7.4.12, and 8.0.12, the development profiler file_excerpt Twig filter escapes PHP files through highlight_string() but interpolates lines from non-PHP files directly into elements, allowing stored XSS against a …
cvefeed.io
July 14, 2026 at 8:14 PM
Simplify localization in SharePoint Framework projects http://symp.info/8qw <- Really smart localization plan AND a very handy @codeextension... I think we're hugging again @eliostruyf
Simplify localization in SharePoint Framework projects
When you need to support multiple languages for your Shar...
symp.info
November 23, 2024 at 1:10 AM