CVE-2026-53637

    Dashboard / Vulnerabilities / CVE-2026-53637

    CVE-2026-53637

    Published: 8 Sept 2026Last Modified: 11 Sept 2026

    Summary: Sylius: Cart FormComponent allows modification or deletion of an already-completed order

    Details: Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the cart `FormComponent`. When an order is completed while its cart page remains open, the stale LiveComponent does not detect the order’s changed state and continues to permit cart actions, allowing an authenticated customer to modify or permanently delete an already completed order. Versions 2.0.18, 2.1.15, and 2.2.6 contain a patch. As a workaround, deployments can copy the patched `FormComponent` into the application's `src/` directory and override the `sylius_shop.twig.component.cart.form` service definition to use that class.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 6dd3ca9895be7ab7e6cb71f37af2ef66af17cbe0

    Affected versions

    v2.2.5
    v2.2.4
    v2.2.3
    v2.2.2
    v2.2.1
    v2.2.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-53637 | CVE-DB