HIGH7.5Packagist
GHSA-rc52-c4hv-w89p· CVE-2026-68500Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
Modified: 7/31/2026
package
pkg:packagist/sylius/mollie-plugin
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
Modified: 7/31/2026
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
Modified: 7/31/2026