CVE-2026-54087High· 7.6▾ TwilightEasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageField can accept browser-executable uploads while templates/crud/field/file.html.twig links to stored files for inline s…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageField can accept browser-executable uploads while templates/crud/field/file.html.twig links to stored files for inline same-origin rendering without a download attribute or Content-Disposition attachment header. When uploads are stored under the public web root, an attacker with access to an affected form can upload HTML through FileField or SVG through ImageField, and JavaScript executes in an authenticated administrator's origin when the file is opened from the backend. Exploitation requires a privilege gap between the uploader and viewer. The issue can expose session or CSRF tokens and enable privilege escalation, but does not permit PHP or PHTML code execution because Symfony guessExtension does not produce those stored extensions. This issue is fixed in version 5.0.13.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
easycorp/easyadmin-bundle >= 5.0.0, < 5.0.13Patched in:
easycorp/easyadmin-bundle 5.0.13Connected by shared product, vendor, weakness, or advisory.
CVE-2024-50623Critical· 9.8In Cleo Harmony before 5.8.0.21, VLTrader before 5.8.0.21, and LexiCom before 5.8.0.21, there is an unrestricted file upload and download that could lead to remote code execution.
GHSA-2wwr-9x6f-88gpMedium· 5.3EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
CVE-2026-88745Medium· 6.1EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell.
CVE-2026-54179Medium· 4.4backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels
CVE-2026-45140Critical· 9.8Chamilo LMS is an open-source learning management system
CVE-2026-65986NoneCVAT is an open source interactive video and image annotation tool for computer vision