CVE-2026-53637
Last modified
CVE-2026-53637 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is completed while its cart page remains open, the stale LiveComponent does not detect the order’s changed state and continues to permit cart actions, allowing an authenticated customer to modify or permanently delete an already completed order. Versions 2.0.18, 2.1.15, and 2.2.6 contain a patch. As a workaround, deployments can copy the patched `FormComponent` into the application's `src/` directory and override the `sylius_shop.twig.component.cart.form` service definition to use that class.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Sylius | Sylius | >= 2.0.0, < 2.0.18; >= 2.1.0, < 2.1.15; >= 2.2.0, < 2.2.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-53637?
How severe is CVE-2026-53637?
How do I fix CVE-2026-53637?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5363Inadequate Encryption Strength vulnerability in TP-Link Arch…8.8
- CVE-2026-53632launch-editor allows users to open files with line numbers i…5.5
- CVE-2026-53633Vitest is a testing framework powered by Vite. From 3.0.0 un…9.8
- CVE-2026-53634Sharp is a content management framework built for Laravel as…4.3
- CVE-2026-53635Open edX Platform enables the authoring and delivery of onli…7.6
- CVE-2026-53636Open edX Platform enables the authoring and delivery of onli…4.7
- CVE-2026-53638Sylius is an Open Source eCommerce Framework on Symfony. Sta…4.3
- CVE-2026-53639Sylius is an Open Source eCommerce Framework on Symfony. Sta…6.3
- CVE-2026-5364The Drag and Drop File Upload for Contact Form 7 plugin for …8.1
- CVE-2026-53640FOSSBilling is a free, open-source billing and client manage…2.3
- CVE-2026-53641FOSSBilling is a free, open-source billing and client manage…4.8
- CVE-2026-53642FOSSBilling is a free, open-source billing and client manage…5.3
Are you affected by CVE-2026-53637?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
