Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,377 advisories

Loading
Statamic Vulnerable to CSV formula injection in form submission exports Moderate
CVE-2026-54243 was published for statamic/cms (Composer) Jun 26, 2026
kah-ja Credited to kah-ja
Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding) Moderate
CVE-2026-54242 was published for statamic/cms (Composer) Jun 26, 2026
jqr1449186277 Credited to jqr1449186277
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources Moderate
CVE-2026-49288 was published for statamic/cms (Composer) Jun 26, 2026
offset Credited to offset, Eszh, and geo-chen Eszh Eszh
geo-chen geo-chen
PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option Moderate
CVE-2026-49359 was published for pontedilana/php-weasyprint (Composer) Jun 26, 2026
WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs Moderate
GHSA-q683-8468-r6h6 was published for web-auth/webauthn-symfony-bundle (Composer) Jun 26, 2026
CakePHP: View::element() is missing a path containment check Moderate
CVE-2026-48820 was published for cakephp/cakephp (Composer) Jun 26, 2026
z3moo Credited to z3moo, get-wright, markstory, and dereuromark get-wright get-wright
markstory markstory dereuromark dereuromark
Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system Moderate
GHSA-j7f5-gfqm-pcx3 was published for pterodactyl/panel (Composer) Jun 26, 2026
CybranceeHosting Credited to CybranceeHosting, YoloFTW, and TheCyberDesk YoloFTW YoloFTW
TheCyberDesk TheCyberDesk
Snipe-IT Vulnerable to Privilege Escalation via Missing admin Permission Check in User Creation Moderate
CVE-2026-55483 was published for snipe/snipe-it (Composer) Jun 23, 2026
0xrdi Credited to 0xrdi
Snipe-IT has Multi-Tenancy Bypass via Bulk Asset Update Moderate
CVE-2026-55482 was published for snipe/snipe-it (Composer) Jun 23, 2026
TristanInSec Credited to TristanInSec
Snipe-IT has a 2FA reset privilege bypass Moderate
CVE-2026-50550 was published for snipe/snipe-it (Composer) Jun 23, 2026
whatisproblem Credited to whatisproblem
Snipe-IT Vulnerable to User Account Escalation via CSV Import Moderate
CVE-2026-49976 was published for snipe/snipe-it (Composer) Jun 23, 2026
SakusenSec Credited to SakusenSec
Snipe-IT's TOTP is Brute-Forceable Due to Missing Rate Limiting on `POST /two-factor` Moderate
CVE-2026-49870 was published for snipe/snipe-it (Composer) Jun 23, 2026
SakusenSec Credited to SakusenSec
phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix) Moderate
CVE-2026-49205 was published for phpmyfaq/phpmyfaq (Composer) Jun 23, 2026
santhoshinipayload Credited to santhoshinipayload
Filament: Unauthenticated temporary file upload on auth pages Moderate
CVE-2026-48500 was published for filament/filament (Composer) Jun 23, 2026
wsparks-vc Credited to wsparks-vc and danharrin danharrin danharrin
Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment Moderate
CVE-2026-48493 was published for snipe/snipe-it (Composer) Jun 23, 2026
tienneR Credited to tienneR and iltosec iltosec iltosec
Snipe-IT's selectlist visibility is too permissive Moderate
CVE-2026-48492 was published for snipe/snipe-it (Composer) Jun 23, 2026
iltosec Credited to iltosec
Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS Moderate
CVE-2026-48167 was published for filament/infolists (Composer) Jun 23, 2026
wsparks-vc Credited to wsparks-vc and danharrin danharrin danharrin
Filament: Timing-based user enumeration on login page Moderate
CVE-2026-48166 was published for filament/filament (Composer) Jun 23, 2026
wsparks-vc Credited to wsparks-vc and danharrin danharrin danharrin
Slim has Reflected XSS in the HtmlErrorRenderer Moderate
CVE-2026-48157 was published for slim/slim (Composer) Jun 23, 2026
0xEr3n Credited to 0xEr3n
tonghuaroot Credited to tonghuaroot
Paymenter has broken object level authorization via service reference manipulation on ticket creation Moderate
CVE-2026-44585 was published for paymenter/paymenter (Composer) Jun 22, 2026
ljskatt Credited to ljskatt and CorwinDev CorwinDev CorwinDev
Paymenter doesn't reset email verification status after email change Moderate
CVE-2026-44584 was published for paymenter/paymenter (Composer) Jun 22, 2026
ljskatt Credited to ljskatt and CorwinDev CorwinDev CorwinDev
Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module Moderate
CVE-2026-44583 was published for paymenter/paymenter (Composer) Jun 22, 2026
boomerangBS Credited to boomerangBS and CorwinDev CorwinDev CorwinDev
AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data Moderate
CVE-2026-33731 was published for wwbn/avideo (Composer) Jun 22, 2026
offset Credited to offset
offset Credited to offset
ProTip! Advisories are also available from the GraphQL API