VulnSea

sulu has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was August 2026 with 3. The median CVSS is 6.2 (medium). Most affected products: sulu/sulu (3), sulu (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.2
Publish → KEV
Last 90 days
4 prev 0

Products

  • sulu/sulu 3
  • sulu 1
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

sulu vulnerabilities

CVEs affecting sulu, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-92692Medium· 6.9
yesterday

Sulu is an open-source PHP content management system based on the Symfony framework

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to 2.6.25 and 3.0.8, the affected Sulu 2.6 and 3.0 release lines have a Smart Content QueryBuilder in src/Sulu/Component/Content/SmartContent/Quer…

Sunlitsulu · suluvia NVD
CVE-2026-82395Medium
3w ago

Sulu is an open-source PHP content management system based on the Symfony framework

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied collection value instead of the media …

Sunlitsulu · sulu/suluEPSS 0.25%via NVD
CVE-2026-82394Medium
3w ago

Sulu is an open-source PHP content management system based on the Symfony framework

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php do not enforc…

Sunlitsulu · sulu/suluEPSS 0.32%via NVD
CVE-2026-82396Medium· 5.4
3w ago

Sulu is an open-source PHP content management system based on the Symfony framework

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /media/{id}/download/{slug} route and it…

Sunlitsulu · sulu/suluEPSS 0.17%via NVD
sulu vulnerabilities (CVEs) · VulnSea