sylius/mollie-plugin Security Advisories for v3.1.1 (2)
-
[MEDIUM] Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
PKSA-jv9x-q24z-dm7x CVE-2026-68501 GHSA-x83g-979r-f5fh
Affected version: >=3.3.0,<3.3.1|>=3.0.0,<3.2.4|<2.2.8
Reported by:
GitHub -
[HIGH] Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
PKSA-b8jy-36rm-9gkc CVE-2026-68500 GHSA-rc52-c4hv-w89p
Affected version: >=3.3.0,<3.3.1|>=3.0.0,<3.2.4|<2.2.8
Reported by:
GitHub