Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,784 advisories

Loading
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames High
CVE-2026-63222 was published for codeigniter4/framework (Composer) Aug 7, 2026
gr8man Credited to gr8man
PHP_CodeSniffer gitblame report command injection via crafted filename High
CVE-2026-67434 was published for squizlabs/php_codesniffer (Composer) Aug 6, 2026
Faze-up Credited to Faze-up, edorian, rodrigoprimo, and jrfnl edorian edorian
rodrigoprimo rodrigoprimo jrfnl jrfnl
Craft CMS: Arbitrary user password reset leading to administrator account takeover High
GHSA-p8x7-9vfw-p7vc was published for craftcms/cms (Composer) Aug 6, 2026
mHe4am Credited to mHe4am
Craft CMS: Authenticated RCE through Twig sandbox escape High
GHSA-f5wm-88jv-g5hx was published for craftcms/cms (Composer) Aug 6, 2026
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass High
GHSA-265m-7826-wjqm was published for craftcms/cms (Composer) Aug 6, 2026
saladin0x1 Credited to saladin0x1
league/commonmark: Denial of service via colliding heading slugs High
GHSA-mh25-x5hq-wrqp was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Denial of service via duplicate footnote definitions High
GHSA-jfm3-95jq-q3rf was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Denial of service via adjacent inline attribute blocks High
GHSA-g2gp-3wwq-f4ph was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Quadratic-time denial of service when parsing crafted Markdown High
CVE-2026-71488 was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
Statamic: Account takeover via OAuth email matching without email-verification check High
CVE-2026-64665 was published for statamic/cms (Composer) Aug 6, 2026
luuhung1217 Credited to luuhung1217
Guzzle: Noncanonical host can bypass host-based checks High
CVE-2026-69246 was published for guzzlehttp/guzzle (Composer) Aug 3, 2026
bilguunbicktivism Credited to bilguunbicktivism
Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers High
GHSA-mqq9-gxg5-m58g was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved High
GHSA-mjrx-74jh-7xgw was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook High
CVE-2026-68500 was published for sylius/mollie-plugin (Composer) Jul 31, 2026
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure High
CVE-2026-55651 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
0xmupa Credited to 0xmupa
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions High
CVE-2026-54593 was published for github.com/pterodactyl/wings (Composer) Jul 28, 2026
TrixterTheTux Credited to TrixterTheTux
0x7d8 Credited to 0x7d8
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability High
CVE-2026-45293 was published for wp-coding-standards/wpcs (Composer) Jul 28, 2026
FORIMOC Credited to FORIMOC and rodrigoprimo rodrigoprimo rodrigoprimo
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover High
GHSA-cmwh-g2h8-c222 was published for poweradmin/poweradmin (Composer) Jul 24, 2026
William957-web Credited to William957-web
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own High
GHSA-rm67-g9ch-vxff was published for poweradmin/poweradmin (Composer) Jul 24, 2026
SaifSalah Credited to SaifSalah
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account High
GHSA-h4hf-v6w5-897x was published for poweradmin/poweradmin (Composer) Jul 24, 2026
SaifSalah Credited to SaifSalah
anir0y Credited to anir0y, manus-use, sermikr0, adamyordan, Pig-Tail, tonghuaroot, and alimony manus-use manus-use
sermikr0 sermikr0 adamyordan adamyordan Pig-Tail Pig-Tail tonghuaroot tonghuaroot alimony alimony
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion High
CVE-2026-59933 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion High
CVE-2026-59932 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
ProTip! Advisories are also available from the GraphQL API