CVE-2026-100872
7.5 HIGHpublic exploit availablePublished 2026-09-27 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have the system mark the inflated order as fully paid while the gateway captured only the original amount.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weaknesses
CWE-345
Public exploit & PoC references
- https://github.com/Sylius/Sylius
- https://github.com/Sylius/Sylius/commit/9e9aeaacbc97b1fc01d573e44d6679194527905d
- https://github.com/Sylius/Sylius/pull/19216
- https://github.com/Sylius/Sylius/releases/tag/v2.2.9
- https://github.com/Sylius/Sylius/security/advisories/GHSA-vv4h-q2x8-74g4
- https://github.com/Sylius/Sylius/security/advisories/GHSA-vv4h-q2x8-74g4
All references
- https://github.com/Sylius/Sylius
- https://github.com/Sylius/Sylius/commit/9e9aeaacbc97b1fc01d573e44d6679194527905d
- https://github.com/Sylius/Sylius/pull/19216
- https://github.com/Sylius/Sylius/releases/tag/v2.2.9
- https://github.com/Sylius/Sylius/security/advisories/GHSA-vv4h-q2x8-74g4
- https://www.vulncheck.com/advisories/sylius-2-x-before-2.1.16-and-2.2.9-payment-amount-overwrite
- https://github.com/Sylius/Sylius/security/advisories/GHSA-vv4h-q2x8-74g4
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- UNSCOREDCVE-2025-12999PoC
- MEDIUMCVE-2026-101278
- HIGHCVE-2026-102267PoC
- MEDIUMCVE-2026-102275PoC
- HIGHCVE-2026-102677PoC
- UNSCOREDCVE-2026-102711PoC
- HIGHCVE-2026-102831PoC
- MEDIUMCVE-2026-19941
Related by shared AI tags and CWE weakness class. Browse the full archive.