CVE-2026-68501Medium· 6.5▾ SunlitSylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCode…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 31.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
0.3% → 0.4%
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCodeAction::fetchQrCodeFromOrder endpoints look up sequential orderId values without ownership or session checks, exposing order tokenValue values that can be used with GET /{_locale}/register-after-checkout/{tokenValue} to view customer first name, last name, and email. This issue is fixed in 2.2.8, 3.2.4, and 3.3.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
sylius/mollie-plugin < 2.2.8sylius/mollie-plugin >= 3.0.0, < 3.2.4sylius/mollie-plugin >= 3.3.0, < 3.3.1Patched in:
sylius/mollie-plugin 2.2.8sylius/mollie-plugin 3.2.4sylius/mollie-plugin 3.3.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-68500High· 7.5Sylius Mollie Plugin provides Mollie payment integration for Sylius applications
CVE-2026-53639Medium· 6.3Sylius is an Open Source eCommerce Framework on Symfony
CVE-2021-46416High· 8.1Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
CVE-2026-53637Medium· 6.5Sylius is an Open Source eCommerce Framework on Symfony
CVE-2026-53638Medium· 4.3Sylius is an Open Source eCommerce Framework on Symfony
CVE-2025-14459High· 8.5A flaw was found in KubeVirt Containerized Data Importer (CDI)