A set of PHP Components and Web Application framework for Mac

Symfony for Mac

Symfony 7.4.13

  -  14.6 MB  -  Open Source

Sometimes latest versions of the software can cause issues when installed on older devices or devices running an older version of the operating system.

Software makers usually fix these issues but it can take them some time. What you can do in the meantime is to download and install an older version of Symfony 7.4.13.


For those interested in downloading the most recent release of Symfony for Mac or reading our review, simply click here.


All old versions distributed on our website are completely virus-free and available for download at no cost.


We would love to hear from you

If you have any questions or ideas that you want to share with us - head over to our Contact page and let us know. We value your feedback!

Why is this app published on FileHorse? (More info)

What's new in this version:

- data #64372 Release v7.4.13
- security #cve-2026-48747 [Mailer] Pin Mailomat webhook signature algorithm to SHA-256
- security #cve-2026-48761 [HtmlSanitizer] Sanitize URL attributes on , , <iframe>, , and the URL inside content
- security #cve-2026-48760 [HtmlSanitizer] Reject percent-encoded BiDi marks and Unicode whitespace in URLs
- security #cve-2026-48736 [HttpFoundation] Block IPv6 transition forms in IpUtils::PRIVATE_SUBNETS
- security #cve-2026-48736 [HttpClient] Block IPv6 transition forms in NoPrivateNetworkHttpClient
- security #cve-2026-48489 [Security] Don't honor user-supplied _failure_path on failure_forward
- security #cve-2026-48784 [Routing] Fix dot-segment encoding for chained "../" and "./" in generated URLs
- bug #64355 [Console] Format message in ConsoleSectionOutput::overwrite()
- bug #64349 [HttpClient] ntlm regression on authPersistNonNTLM=false connections with reset()
- bug #64348 [FrameworkBundle] Allow to pass doctrine_open_transaction_logger’s entity manager name positionally
- bug #64345 [Mime][String] Reject objects in typed-string properties during __unserialize
- bug #64344 [Mailer][Notifier] Harden Mailchimp signature comparison and Smsbox IP allowlist
- bug #64330 [Cache] Fix strlen(null) deprecation on RelayCluster path in RedisTrait::doClear()
- bug #64335 [Scheduler] Recover pending RecurringMessages after consumer stops midway
- bug #64338 [SecurityBundle] Fix Security::login() across firewalls
- bug #64347 [Process] Stop leaking CGI/FastCGI request-context vars to subprocesses
- bug #64343 [Mime][RateLimiter][Routing][Security] Harden __unserialize against __toString trampolines
- bug #64342 [HtmlSanitizer] Honor universal attribute sanitizers, apply maxInputLength to text contexts, document forceAttribute and allowAttribute caveats
- bug #64341 [FrameworkBundle][Mailer] Harden default IP allowlist for Postmark and Brevo webhook parsers
- bug #64337 [Security] Initialize lazy users before serializing them
- bug #64346 [Runtime] Trust argv on CLI-like SAPIs to fix subprocess args
- bug #64336 [Cache] Accept '_' and ':' in prefix passed to AbstractAdapter::clear()
- bug #64316 [Yaml] Allow trailing newlines after the end-of-document marker
- bug #64289 [Translation] Don’t check the error message to know if Lokalise keys are missing
- bug #64208 [AssetMapper] Rewrite relative paths in export ... from statements
- bug #64311 [DependencyInjection] Fix service() as invokable factory in array-based PHP config
- bug #64310 [HttpKernel][WebProfilerBundle] Check logs priority name for both WARNING and warning
- bug #64260 [HttpClient] Various fixes and hardenings
- bug #64260 [HttpClient] Various fixes and hardenings
- bug #64309 [FrameworkBundle] Sign transports for unrouted messages too
- data #64302 Release v5.4.52