CVE-2020-25912
Critical · CVSS 9.1Symphony CMS — XML External Entity (XXE) injection
- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-611
Description
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
Search profile — drives PoC discovery
Symbols class.xmlelement.phpsymphony\lib\toolkit\class.xmlelement.phpXMLElementsymphonycms
Keywords CVE-2020-25912Symphony CMS XXESymphony 2.7.10 XML External Entityclass.xmlelement.php XXEsymphonycms XXE information disclosureCWE-611 Symphony
Versions: 2.7.10
References
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T06:30:39.000Z