Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

438 advisories

Loading
Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read Low
CVE-2026-56394 was published for craftcms/cms (Composer) Jul 9, 2026
GCXWLP Credited to GCXWLP
GCXWLP Credited to GCXWLP
Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options Low
CVE-2026-56393 was published for craftcms/cms (Composer) Mar 3, 2026
mHe4am Credited to mHe4am
Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page Low
CVE-2026-56381 was published for craftcms/cms (Composer) Mar 11, 2026
mHe4am Credited to mHe4am
Craft CMS: Incorrect path validation could potentially lead to path traversal Low
GHSA-7hxc-f267-h5q7 was published for craftcms/cms (Composer) Aug 6, 2026
Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type Low
CVE-2026-56383 was published for craftcms/cms (Composer) Feb 25, 2026
mHe4am Credited to mHe4am
Contao: Possible path traversal in job download URIs Low
CVE-2026-55825 was published for contao/contao (Composer) Aug 6, 2026
0x1saac Credited to 0x1saac
Contao crawler leaks auth credentials to external hosts Low
CVE-2026-55824 was published for contao/contao (Composer) Aug 6, 2026
0x1saac Credited to 0x1saac
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS Low
CVE-2026-52838 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync Low
CVE-2026-52841 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
Dredsen Credited to Dredsen
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass Low
CVE-2026-52839 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network Low
CVE-2026-52840 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
Dredsen Credited to Dredsen
Dompdf: File existence oracle via font-face stylesheet declaration Low
CVE-2026-55555 was published for dompdf/dompdf (Composer) Jul 22, 2026
g4nkd Credited to g4nkd
Dompdf: Chroot Validation Bypass Low
CVE-2026-55554 was published for dompdf/dompdf (Composer) Jul 22, 2026
vxhex Credited to vxhex and snoopysecurity snoopysecurity snoopysecurity
Dolibarr ERP CRM is vulnerable to Improper Authorization through its Leave Request REST API Low
CVE-2026-10215 was published for dolibarr/dolibarr (Composer) Jun 1, 2026
Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation Low
GHSA-j5mc-p8qg-39j7 was published for kimai/kimai (Composer) Jul 2, 2026
Mitchell45 Credited to Mitchell45
Kimai Password Reset Link Remains Valid After Password Change Low
GHSA-m492-gv72-xvxj was published for kimai/kimai (Composer) Jul 1, 2026
AzureADTrent Credited to AzureADTrent
Schema.org has cross-site scripting (XSS) via script break-out in toScript() output Low
GHSA-hwmc-r6mf-jh83 was published for spatie/schema-org (Composer) Jul 1, 2026
Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php` Low
CVE-2026-48805 was published for twig/twig (Composer) Jun 30, 2026
fabpot Credited to fabpot
Concrete CMS is vulnerable to Stored XSS via page name in the Atomik theme Low
CVE-2026-8353 was published for concrete5/concrete5 (Composer) May 26, 2026
Concrete CMS is vulnerable to CSRF via Backend\File::approveVersion Low
CVE-2026-8340 was published for concrete5/concrete5 (Composer) May 26, 2026
Concrete CMS is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog Low
CVE-2026-8347 was published for concrete5/concrete5 (Composer) May 26, 2026
Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors Low
CVE-2026-54244 was published for statamic/cms (Composer) Jun 26, 2026
jqr1449186277 Credited to jqr1449186277
ProTip! Advisories are also available from the GraphQL API