CVE-2026-68500High· 7.5▾ TwilightSylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId paramete…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 31.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but does not verify that the Mollie payment belongs to the referenced Sylius order, allowing an unauthenticated attacker with any valid paid Mollie payment ID to mark a victim order as paid without transferring funds for that order. This issue is fixed in 2.2.8, 3.2.4, and 3.3.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
sylius/mollie-plugin < 2.2.8sylius/mollie-plugin >= 3.0.0, < 3.2.4sylius/mollie-plugin >= 3.3.0, < 3.3.1Patched in:
sylius/mollie-plugin 2.2.8sylius/mollie-plugin 3.2.4sylius/mollie-plugin 3.3.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-68501Medium· 6.5Sylius Mollie Plugin provides Mollie payment integration for Sylius applications
CVE-2026-53639Medium· 6.3Sylius is an Open Source eCommerce Framework on Symfony
CVE-2021-46416High· 8.1Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
CVE-2026-53637Medium· 6.5Sylius is an Open Source eCommerce Framework on Symfony
CVE-2026-53638Medium· 4.3Sylius is an Open Source eCommerce Framework on Symfony
CVE-2025-14459High· 8.5A flaw was found in KubeVirt Containerized Data Importer (CDI)