PKSA-jv9x-q24z-dm7x Security Advisory
-
[MEDIUM] Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
PKSA-jv9x-q24z-dm7x CVE-2026-68501 GHSA-x83g-979r-f5fh
Affected package: sylius/mollie-plugin
Affected version: >=3.3.0,<3.3.1|>=3.0.0,<3.2.4|<2.2.8
Reported by:
GitHub