Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,441 advisories

Loading
phpMyFAQ public FAQ APIs expose inactive FAQ content Moderate
GHSA-mf8r-wm2w-f8c5 was published for phpmyfaq/phpmyfaq (Composer) Aug 25, 2026
YHalo-wyh Credited to YHalo-wyh
phpMyFAQ has Potential Authenticated Path Traversal in PDF Export Moderate
GHSA-88g4-74f3-63x9 was published for phpmyfaq/phpmyfaq (Composer) Aug 25, 2026
DomainXTech Credited to DomainXTech
YOURLS has stored XSS in referrer statistics chart via crafted Referer header High
CVE-2026-63135 was published for yourls/yourls (Composer) Aug 21, 2026
sondt99 Credited to sondt99, dgw, ozh, and LeoColomb dgw dgw
ozh ozh LeoColomb LeoColomb
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE) Critical
CVE-2026-59989 was published for phalcon/cphalcon (Composer) Aug 21, 2026
nikkoenggaliano Credited to nikkoenggaliano
skeletonsec Credited to skeletonsec
Winter: Reflected XSS through the search query parameter in the backend Table widget Moderate
GHSA-hq84-x37p-j6q5 was published for winter/wn-backend-module (Composer) Aug 20, 2026
NRAwwad Credited to NRAwwad
Winter: CSRF through AJAX handler names reachable as backend page actions Moderate
GHSA-p2ch-c2c3-4xm5 was published for winter/wn-backend-module (Composer) Aug 20, 2026
NRAwwad Credited to NRAwwad
Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles Moderate
GHSA-5cwr-5jxg-pcf6 was published for winter/wn-backend-module (Composer) Aug 20, 2026
NRAwwad Credited to NRAwwad
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate High
GHSA-fm29-4mq3-phg6 was published for winter/wn-backend-module (Composer) Aug 20, 2026
manus-use Credited to manus-use
Winter: My Account preview exposes another backend user's profile by record ID Moderate
GHSA-mpmw-f6h6-3g26 was published for winter/wn-backend-module (Composer) Aug 20, 2026
NRAwwad Credited to NRAwwad
Winter: Stored XSS through Backend List widget image columns Low
GHSA-7mpf-4465-7fc2 was published for winter/wn-backend-module (Composer) Aug 20, 2026
Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149) High
GHSA-8cfw-pcwh-v63w was published for winter/wn-system-module (Composer) Aug 20, 2026
M9nx Credited to M9nx
Winter: Local File Inclusion through =include directives in JavaScript asset compilation Moderate
GHSA-2223-f22x-24cq was published for winter/wn-system-module (Composer) Aug 20, 2026
elmahy111 Credited to elmahy111
Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets Moderate
CVE-2026-63179 was published for winter/wn-backend-module (Composer) Aug 20, 2026
hypnguyen1209 Credited to hypnguyen1209
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata Moderate
CVE-2026-54256 was published for winter/wn-backend-module (Composer) Aug 20, 2026
r00tn0b0dy Credited to r00tn0b0dy and baradika baradika baradika
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
Laravel Backpack CRUD: Stored XSS in the color column — the `@if($column['escaped'])` branches are inverted Moderate
CVE-2026-54181 was published for backpack/crud (Composer) Aug 20, 2026
therawdev Credited to therawdev and tabacitu tabacitu tabacitu
tabacitu Credited to tabacitu
pxpm Credited to pxpm and tabacitu tabacitu tabacitu
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check Moderate
CVE-2026-54176 was published for backpack/crud (Composer) Aug 20, 2026
pxpm Credited to pxpm and tabacitu tabacitu tabacitu
Laravel Backpack CRUD: Unverified password change in MyAccountController via mass assignment High
CVE-2026-54175 was published for backpack/crud (Composer) Aug 20, 2026
therawdev Credited to therawdev and tabacitu tabacitu tabacitu
Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems High
CVE-2026-62673 was published for getgrav/grav (Composer) Aug 19, 2026
replit-svg Credited to replit-svg
ProTip! Advisories are also available from the GraphQL API