PatchSiren

Sylius CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Sylius CVE published 2026-07-30

CVE-2026-68501

The Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to versions 2.2.8, 3.2.4, and 3.3.1, the plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCodeAction::fetchQrCodeFromOrder endpoints do not perform ownership or session checks when looking up sequential orderId values. This exposes order tokenValue values that c [truncated]

HIGH Sylius CVE published 2026-07-30

CVE-2026-68500

The Sylius Mollie Plugin, used for integrating Mollie payment gateway with Sylius applications, contains a vulnerability. Specifically, the POST /{_locale}/update-payment payment webhook does not verify that the Mollie payment belongs to the referenced Sylius order. This oversight allows an unauthenticated attacker with any valid paid Mollie payment ID to mark a victim order as paid without transferring f [truncated]