Symfony ↗
Symfony · Web / Runtime
100/100 Healthy
Summary iPlain-English security verdict for Symfony, generated from its current health score, actively-exploited vulnerabilities, and latest supported version.
Symfony currently scores 100/100 — healthy. No tracked vulnerabilities are currently known to be exploited in the wild. The latest supported release is 8.1.0. It's on the latest patch with no significant known issues — keep it current.
Disclosure trend iNew CVEs published for Symfony each year (NVD). A higher bar means more disclosures that year — more scrutiny, not necessarily less safe.
'19
'20
'21
'22
'23
'24
'25
'26
Patch priority — what to act on iThe issues to fix first — actively exploited (CISA KEV) first, then by exploitation probability (EPSS), then severity. Each row's "→ fixed in" is the earliest version that patches it; "see advisory" means no fixed version is published.
Most urgent first — actively exploited, then likeliest to be exploited.
CVE-2015-4050 MEDIUM Improper access control EPSS 76% → see advisory CVE-2019-10910 CRITICAL SQL injection EPSS 12% → fixed in 4.2.7 CVE-2019-18889 CRITICAL Code injection EPSS 5% → see advisory CVE-2019-11325 CRITICAL CWE-116 EPSS 5% → fixed in 4.3.8 CVE-2017-11365 CRITICAL Improper access control EPSS 0% → see advisory CVE-2019-10913 CRITICAL Cross-site scripting (XSS) EPSS 0% → fixed in 4.2.7 CVE-2016-2403 CRITICAL Improper authentication EPSS 0% → see advisory CVE-2018-11407 CRITICAL Improper authentication EPSS 0% → fixed in 4.0.7Versions & lifecycle iWhen each release line stops receiving security patches (end-of-life). After EOL there are no more fixes — plan upgrades before these dates.
How long each Symfony release line is supported — and when it sunsets.
8.1 latest 8.1.0 Supported until 2027-01-31
8.0 latest 8.0.13 Supported until 2026-07-31
7.4 latest 7.4.13 Supported until 2029-11-30
7.3 latest 7.3.11 End of life ended 2026-01-31
7.2 latest 7.2.9 End of life ended 2025-07-31
7.1 latest 7.1.11 End of life ended 2025-01-31
7.0 latest 7.0.10 End of life ended 2024-07-31
6.4 latest 6.4.41 Supported until 2027-11-30
6.3 latest 6.3.12 End of life ended 2024-01-31
6.2 latest 6.2.14 End of life ended 2023-07-31
See all upcoming end-of-life dates →