Vulnerabilidades em api-platform
7 resultadosAnálise Vexday
API Platform acumula 7 vulnerabilidades no histórico, duas delas publicadas nos últimos 90 dias, sem registro de exploração ativa em campo. A fraqueza dominante é validação inadequada de entrada (CWE-20), padrão típico em plataformas web que requer atenção contínua mas não representa risco crítico imediato dado o perfil de severidade.
CVE-2023-25575HIGHSecured properties in API Platform Core may be accessible within collectionsEPSS 0.6%CVE-2025-31485HIGHGraphQL grant on a property might be cached with different objectsEPSS 0.6%CVE-2025-31481HIGHGraphQL query operations security can be bypassedEPSS 0.4%CVE-2023-47639MEDIUMAPI Platform Core can leak exceptions message that may contain sensitive informationEPSS 0.4%CVE-2025-23204MEDIUMGraphQl securityAfterResolver not calledEPSS 0.3%CVE-2026-49858MEDIUMAPI Platform Core: Cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gateEPSS 0.2%CVE-2026-54164MEDIUMAPI Platform Core: Missing IRI type check enables resource type confusionEPSS 0.2%