CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2020-25912

Critical · CVSS 9.1

Symphony CMS — XML External Entity (XXE) injection

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-611

Description

A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).

Search profile — drives PoC discovery

Symbols class.xmlelement.phpsymphony\lib\toolkit\class.xmlelement.phpXMLElementsymphonycms
Keywords CVE-2020-25912Symphony CMS XXESymphony 2.7.10 XML External Entityclass.xmlelement.php XXEsymphonycms XXE information disclosureCWE-611 Symphony
Versions: 2.7.10

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z