Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

148 advisories

Loading
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module Low
CVE-2026-57232 was published for contao/contao (Composer) Sep 24, 2026
Para213 Credited to Para213
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials High
CVE-2026-76086 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
AVideo has Authenticated Server-Side Request Forgery via downloadURL in aVideoEncoder.json.php High
CVE-2026-27732 was published for wwbn/avideo (Composer) Feb 25, 2026
arkmarta Credited to arkmarta and kgnio kgnio kgnio
Smarty: SSRF via redirect bypass of trusted_uri using {fetch} Moderate
CVE-2026-62993 was published for smarty/smarty (Composer) Sep 1, 2026
elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback High
CVE-2026-81889 was published for studio-42/elfinder (Composer) Aug 31, 2026
Marco198333 Credited to Marco198333
Koillection has an authenticated Server-Side Request Forgery issue High
CVE-2026-50888 was published for koillection/koillection (Composer) Jun 15, 2026
shlink has a Server-Side Request Forgery issue Critical
CVE-2026-50887 was published for shlinkio/shlink (Composer) Jun 15, 2026
LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page High
GHSA-7gww-x7fh-jf9j was published for librenms/librenms (Composer) Aug 18, 2026
k1bana Credited to k1bana
Guzzle: Noncanonical host can bypass host-based checks High
CVE-2026-69246 was published for guzzlehttp/guzzle (Composer) Aug 3, 2026
bilguunbicktivism Credited to bilguunbicktivism
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network Low
CVE-2026-52840 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
Dredsen Credited to Dredsen
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist High
CVE-2026-59931 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
longcalif Credited to longcalif and sondt99 sondt99 sondt99
guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation Moderate
CVE-2026-48998 was published for guzzlehttp/psr7 (Composer) Jun 11, 2026
edorian Credited to edorian
Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail Moderate
CVE-2026-50552 was published for phanan/koel (Composer) Jul 15, 2026
Yunkaiwjs Credited to Yunkaiwjs
Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths High
CVE-2026-54491 was published for phanan/koel (Composer) Jul 15, 2026
kiffa-australis256 Credited to kiffa-australis256
Koel has SSRF through Authenticated Subsonic podcast feed URLs Moderate
GHSA-8q6q-m837-fv64 was published for phanan/koel (Composer) Jul 15, 2026
DavidCarliez Credited to DavidCarliez
Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations High
CVE-2026-54493 was published for phanan/koel (Composer) Jul 15, 2026
dennyabrahamsinaga Credited to dennyabrahamsinaga
Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation Moderate
CVE-2026-54492 was published for phanan/koel (Composer) Jul 15, 2026
dennyabrahamsinaga Credited to dennyabrahamsinaga
FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn` Critical
CVE-2026-45262 was published for facturascripts/facturascripts (Composer) Jul 14, 2026
offset Credited to offset
NukeViet: Pre-authentication SSRF via X-Forwarded-Host High
CVE-2026-55372 was published for nukeviet/nukeviet (Composer) Jul 13, 2026
g03m0n Credited to g03m0n and hoaquynhtim99 hoaquynhtim99 hoaquynhtim99
Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs Moderate
CVE-2026-49865 was published for kimai/kimai (Composer) Jul 10, 2026
Mitchell45 Credited to Mitchell45
YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId` High
CVE-2026-52769 was published for yeswiki/yeswiki (Composer) Jul 9, 2026
hash3liZer Credited to hash3liZer
EvidentObscurity Credited to EvidentObscurity
Spatie Laravel Media Library contains a server-side request forgery vulnerability Moderate
CVE-2026-48555 was published for spatie/laravel-medialibrary (Composer) May 29, 2026
Mautic Focus component Vulnerable to SSRF Moderate
CVE-2026-9557 was published for mautic/core (Composer) Jul 2, 2026
r1beirin Credited to r1beirin, patrykgruszka, dungNHVhust, escopecz, and Mitchell45 patrykgruszka patrykgruszka
dungNHVhust dungNHVhust escopecz escopecz Mitchell45 Mitchell45
ProTip! Advisories are also available from the GraphQL API