Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,792 advisories

Loading
Grav: Unauthenticated denial of service via unbounded image derivative dimensions High
CVE-2026-53653 was published for getgrav/grav (Composer) Aug 14, 2026
iliaal Credited to iliaal
Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name High
CVE-2026-55072 was published for pimcore/pimcore (Composer) Aug 13, 2026
dhairya7760 Credited to dhairya7760
Winter: Authenticated backend users can bypass Users controller permission checks High
CVE-2026-35445 was published for winter/wn-backend-module (Composer) Aug 12, 2026
everythingBlackkk Credited to everythingBlackkk
Winter: Stored XSS through Editor Settings custom styles High
CVE-2026-32258 was published for winter/wn-backend-module (Composer) Aug 12, 2026
skyhex19 Credited to skyhex19
Winter: Stored XSS through Brand Settings custom styles High
CVE-2026-32257 was published for winter/wn-backend-module (Composer) Aug 12, 2026
skyhex19 Credited to skyhex19
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames High
CVE-2026-63222 was published for codeigniter4/framework (Composer) Aug 7, 2026
gr8man Credited to gr8man
PHP_CodeSniffer gitblame report command injection via crafted filename High
CVE-2026-67434 was published for squizlabs/php_codesniffer (Composer) Aug 6, 2026
Faze-up Credited to Faze-up, edorian, rodrigoprimo, and jrfnl edorian edorian
rodrigoprimo rodrigoprimo jrfnl jrfnl
Craft CMS: Arbitrary user password reset leading to administrator account takeover High
GHSA-p8x7-9vfw-p7vc was published for craftcms/cms (Composer) Aug 6, 2026
mHe4am Credited to mHe4am
Craft CMS: Authenticated RCE through Twig sandbox escape High
GHSA-f5wm-88jv-g5hx was published for craftcms/cms (Composer) Aug 6, 2026
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass High
GHSA-265m-7826-wjqm was published for craftcms/cms (Composer) Aug 6, 2026
saladin0x1 Credited to saladin0x1
league/commonmark: Denial of service via colliding heading slugs High
GHSA-mh25-x5hq-wrqp was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Denial of service via duplicate footnote definitions High
GHSA-jfm3-95jq-q3rf was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Denial of service via adjacent inline attribute blocks High
GHSA-g2gp-3wwq-f4ph was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Quadratic-time denial of service when parsing crafted Markdown High
CVE-2026-71488 was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
Statamic: Account takeover via OAuth email matching without email-verification check High
CVE-2026-64665 was published for statamic/cms (Composer) Aug 6, 2026
luuhung1217 Credited to luuhung1217
Guzzle: Noncanonical host can bypass host-based checks High
CVE-2026-69246 was published for guzzlehttp/guzzle (Composer) Aug 3, 2026
bilguunbicktivism Credited to bilguunbicktivism
Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers High
GHSA-mqq9-gxg5-m58g was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved High
GHSA-mjrx-74jh-7xgw was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook High
CVE-2026-68500 was published for sylius/mollie-plugin (Composer) Jul 31, 2026
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure High
CVE-2026-55651 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
0xmupa Credited to 0xmupa
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions High
CVE-2026-54593 was published for github.com/pterodactyl/wings (Composer) Jul 28, 2026
TrixterTheTux Credited to TrixterTheTux
0x7d8 Credited to 0x7d8
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability High
CVE-2026-45293 was published for wp-coding-standards/wpcs (Composer) Jul 28, 2026
FORIMOC Credited to FORIMOC, rodrigoprimo, and jrfnl rodrigoprimo rodrigoprimo
jrfnl jrfnl
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover High
GHSA-cmwh-g2h8-c222 was published for poweradmin/poweradmin (Composer) Jul 24, 2026
William957-web Credited to William957-web
ProTip! Advisories are also available from the GraphQL API