Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

69 advisories

Loading
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync Low
CVE-2026-52841 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
Dredsen Credited to Dredsen
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass Low
CVE-2026-52839 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
DavidCarliez Credited to DavidCarliez and Classic298 Classic298 Classic298
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API Low
CVE-2026-58445 was published for code.gitea.io/gitea (Go) Jul 21, 2026
CassianStarck Credited to CassianStarck
Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation Low
GHSA-j5mc-p8qg-39j7 was published for kimai/kimai (Composer) Jul 2, 2026
Mitchell45 Credited to Mitchell45
ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers Low
CVE-2026-55670 was published for github.com/zitadel/zitadel (Go) Jun 18, 2026
livio-a Credited to livio-a and emgrav emgrav emgrav
PhoenixStorybook has cross-session PubSub topic injection via URL parameter Low
CVE-2026-47068 was published for phoenix_storybook (Erlang) Jun 9, 2026
PJUllrich Credited to PJUllrich, cblavier, and maennchen cblavier cblavier
maennchen maennchen
Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known Low
CVE-2026-47716 was published for bugsink (pip) Jun 5, 2026
Susen2 Credited to Susen2
Bugsink: Issue event views can show an event from another project if its UUID is known Low
CVE-2026-47715 was published for bugsink (pip) Jun 5, 2026
nuiifornet Credited to nuiifornet
NocoDB: Missing Ownership Check in MCP Attachment Read Low
CVE-2026-47388 was published for nocodb (npm) Jun 5, 2026
helwor-01 Credited to helwor-01
pretix vulnerable to Authorization Bypass Through User-Controlled Key Low
CVE-2026-9712 was published for pretix (pip) May 27, 2026
Concrete CMS is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog Low
CVE-2026-8347 was published for concrete5/concrete5 (Composer) May 26, 2026
ProTip! Advisories are also available from the GraphQL API