← Back to all sparks
S

Sylius

E-COMM
Velocity5.0

Open source headless commerce platform built on Symfony for tailored ecommerce experiences.

Sylius patched critical JWT and Host header auth vulnerabilities across three stable branches simultaneously.

securityecommercemulti-branch-supportsymfonypromotionsplatform-upgrade
Current state
Sylius shipped coordinated security patches across v1.12, v1.13, and v1.14 in the same release window, closing two serious vulnerabilities: a JWT audience confusion flaw that let shop customers authenticate as administrators, and a Host header injection that could enable reset-token theft. These are production-critical fixes for live storefronts. Meanwhile, v2.3.0-ALPHA.1 is in active development with Symfony 8 + PHP 8.3 support, dark mode in the admin panel, and per-channel promotion rules.
Where it's heading
The v2.x alpha signals a significant platform modernization effort — Symfony 8, PHP 8.3, and DBAL 4 adoption. The per-channel promotion rules feature in v2.3 is the most notable new commerce capability: it allows a single promotion to have independent configuration per sales channel, which is important for multi-region merchants with different pricing or discount strategies per market.
Prediction
v2.3 will reach beta in the next release cycle; the most likely next feature push is around promotion configuration depth or checkout flow improvements to compete with more modern headless commerce platforms.

Recent moves

  1. 13d ago

    v1.12.25: Critical JWT and Host header security patch

    Security patch for v1.12: fixes JWT audience confusion (shop customer auth as admin) and Host header injection in admin password-reset links. These are the same vulnerabilities patched simultaneously in v1.13 and v1.14 — coordinated multi-branch security release.

    View source ↗
  2. 13d ago

    v1.14.20: Critical JWT and Host header security patch

    Security patch for v1.14: same two vulnerabilities as v1.12.25 and v1.13.17 — JWT audience confusion and Host header injection in admin password reset. Multi-version coordinated release.

    View source ↗
  3. 13d ago

    v1.13.17: Critical JWT and Host header security patch

    Security patch for v1.13: closes the same JWT audience confusion and Host header injection vulnerabilities shipped simultaneously across all supported stable branches. Sylius' ability to patch three concurrent major versions in one release window reflects a mature support model.

    View source ↗
  4. 1mo ago

    v2.3.0-ALPHA.1: Symfony 8, dark mode, and per-channel promotions

    v2.3.0-ALPHA.1 is the most significant entry in this window: PHP 8.3+, Symfony 8, and DBAL 4 support alongside dark mode for the admin panel and per-channel promotion rules. The per-channel promotion configuration is a real commerce capability gain for multi-market merchants, but it remains alpha and not yet suitable for production.

    View source ↗
  5. 6mo ago

    v1.14.19

    v1.14.19 ships telemetry improvements — internal instrumentation changes with no user-visible effect.

    View source ↗
  6. 6mo ago

    v1.13.16

    v1.13.16 ships the same telemetry improvements as v1.14.19 — coordinated internal instrumentation update across branches with no user-visible effect.

    View source ↗