PatchSiren

Sylius CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Sylius CVE published 2026-07-30

CVE-2026-68500

The Sylius Mollie Plugin, used for integrating Mollie payment gateway with Sylius applications, contains a vulnerability. Specifically, the POST /{_locale}/update-payment payment webhook does not verify that the Mollie payment belongs to the referenced Sylius order. This oversight allows an unauthenticated attacker with any valid paid Mollie payment ID to mark a victim order as paid without transferring f [truncated]