Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

405 advisories

Loading
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII Moderate
CVE-2026-68501 was published for sylius/mollie-plugin (Composer) Jul 31, 2026
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook High
CVE-2026-68500 was published for sylius/mollie-plugin (Composer) Jul 31, 2026
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync Low
CVE-2026-52841 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
Dredsen Credited to Dredsen
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page Moderate
CVE-2026-52837 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
peoplstar Credited to peoplstar
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass Low
CVE-2026-52839 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API Moderate
GHSA-86cx-wwf4-phq4 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, xrgzs, jyxjjj, and sondt99 xrgzs xrgzs
jyxjjj jyxjjj sondt99 sondt99
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search Moderate
GHSA-p6ph-3jx2-3337 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, jyxjjj, and xrgzs jyxjjj jyxjjj
xrgzs xrgzs
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own High
GHSA-rm67-g9ch-vxff was published for poweradmin/poweradmin (Composer) Jul 24, 2026
SaifSalah Credited to SaifSalah
OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check Critical
GHSA-p279-2cqp-84jg was published for org.openidentityplatform.opendj:opendj-server-legacy (Maven) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
themudhaxk Credited to themudhaxk and Ardeey-code Ardeey-code Ardeey-code
DavidCarliez Credited to DavidCarliez and Classic298 Classic298 Classic298
waiveyk Credited to waiveyk and Classic298 Classic298 Classic298
@better-auth/stripe: cross-organization billing tampering in organization subscription actions High
GHSA-h3rm-78g3-j7cp was published for @better-auth/stripe (npm) Jul 24, 2026
@better-auth/scim: account takeover and stale access via SCIM provider-id collision Critical
GHSA-rjg6-39jm-rgg4 was published for @better-auth/scim (npm) Jul 24, 2026
HO-9 Credited to HO-9
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials Moderate
CVE-2026-59254 was published for n8n (npm) Jul 22, 2026
n8n: External Secrets Permission Bypass via Expression Parser Mismatch Moderate
CVE-2026-59259 was published for n8n (npm) Jul 22, 2026
YLChen-007 Credited to YLChen-007
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner High
CVE-2026-65016 was published for n8n (npm) Jul 22, 2026
ttzero25 Credited to ttzero25
Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner High
GHSA-mwq7-vcmc-cm4q was published for n8n (npm) Jul 22, 2026 withdrawn
Gitea LFS Deploy-Key Privilege Escalation Moderate
CVE-2026-58435 was published for code.gitea.io/gitea (Go) Jul 21, 2026
adrian-doyensec Credited to adrian-doyensec
Gitea: Cross-repository label-ID enumeration oracle via unscoped DeleteIssueLabel API Low
CVE-2026-58445 was published for code.gitea.io/gitea (Go) Jul 21, 2026
CassianStarck Credited to CassianStarck
Gitea: Git LFS object reuse allows non-Code access to authorize private source objects High
CVE-2026-28740 was published for gitea.dev (Go) Jul 21, 2026
m2hcz Credited to m2hcz
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content Moderate
CVE-2026-57886 was published for code.gitea.io/gitea (Go) Jul 21, 2026
zulloper Credited to zulloper
Gitea: draft release attachment disclosure via missing web authorization Moderate
CVE-2026-58432 was published for code.gitea.io/gitea (Go) Jul 21, 2026
z3r0s6 Credited to z3r0s6
Directus: Authorization-dependent response served from unsegmented cache key High
CVE-2026-61836 was published for directus (npm) Jul 20, 2026
tr4ce-ju Credited to tr4ce-ju
ProTip! Advisories are also available from the GraphQL API