Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,377 advisories

Loading
TYPO3 sf_register extension allows unauthorized assignment of frontend user groups Moderate
CVE-2026-46721 was published for evoweb/sf-register (Composer) May 19, 2026
eliashaeussler Credited to eliashaeussler
TYPO3 ke_search path traversal due to lack of normalization on config directory from file indexer Moderate
CVE-2026-46724 was published for tpwd/ke_search (Composer) May 19, 2026
eliashaeussler Credited to eliashaeussler
TYPO3 ke_search XML External Entity Injection Moderate
CVE-2026-46722 was published for tpwd/ke_search (Composer) May 19, 2026
eliashaeussler Credited to eliashaeussler
TYPO3 ke_search path traversal from arbitrary table configuration input Moderate
CVE-2026-46723 was published for tpwd/ke_search (Composer) May 19, 2026
eliashaeussler Credited to eliashaeussler
Statamic Vulnerable to CSV formula injection in form submission exports Moderate
CVE-2026-54243 was published for statamic/cms (Composer) Jun 26, 2026
kah-ja Credited to kah-ja
Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding) Moderate
CVE-2026-54242 was published for statamic/cms (Composer) Jun 26, 2026
jqr1449186277 Credited to jqr1449186277
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources Moderate
CVE-2026-49288 was published for statamic/cms (Composer) Jun 26, 2026
offset Credited to offset, Eszh, and geo-chen Eszh Eszh
geo-chen geo-chen
PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option Moderate
CVE-2026-49359 was published for pontedilana/php-weasyprint (Composer) Jun 26, 2026
WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs Moderate
GHSA-q683-8468-r6h6 was published for web-auth/webauthn-symfony-bundle (Composer) Jun 26, 2026
CakePHP: View::element() is missing a path containment check Moderate
CVE-2026-48820 was published for cakephp/cakephp (Composer) Jun 26, 2026
z3moo Credited to z3moo, get-wright, markstory, and dereuromark get-wright get-wright
markstory markstory dereuromark dereuromark
Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system Moderate
GHSA-j7f5-gfqm-pcx3 was published for pterodactyl/panel (Composer) Jun 26, 2026
CybranceeHosting Credited to CybranceeHosting, YoloFTW, and TheCyberDesk YoloFTW YoloFTW
TheCyberDesk TheCyberDesk
Concrete CMS is vulnerable to IDOR in surveys Moderate
CVE-2026-8337 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS is Vulnerable to Reflected XSS in Legacy Pagination Moderate
CVE-2026-8245 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS has a session-hardening bypass and allows password change without reauthorization Moderate
CVE-2026-8327 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS is vulnerable to unauthenticated page metadata disclosure Moderate
CVE-2026-8240 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS is vulnerable to IDOR Moderate
CVE-2026-8239 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS is vulnerable to IDOR Moderate
CVE-2026-8238 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS is vulnerable to IDOR Moderate
CVE-2026-8237 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS is vulnerable to IDOR combined with a missing authentication gate Moderate
CVE-2026-8236 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS is vulnerable to authorization bypass in the Calendar Event Frontend Dialog Moderate
CVE-2026-8204 was published for concrete5/concrete5 (Composer) May 21, 2026
Concrete CMS is vulnerable to authorization bypass in the Calendar Block Moderate
CVE-2026-8205 was published for concrete5/concrete5 (Composer) May 21, 2026
Concrete CMS is subject to Insecure Direct Object Reference (IDOR) in the Express Entry Detail block Moderate
CVE-2026-7881 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS has an unauthorized file access issue Moderate
CVE-2026-7879 was published for concrete5/concrete5 (Composer) May 22, 2026
Snipe-IT Vulnerable to Privilege Escalation via Missing admin Permission Check in User Creation Moderate
CVE-2026-55483 was published for snipe/snipe-it (Composer) Jun 23, 2026
0xrdi Credited to 0xrdi
Snipe-IT has Multi-Tenancy Bypass via Bulk Asset Update Moderate
CVE-2026-55482 was published for snipe/snipe-it (Composer) Jun 23, 2026
TristanInSec Credited to TristanInSec
ProTip! Advisories are also available from the GraphQL API