Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,441 advisories

Loading
league/commonmark: Denial of service via deeply nested XML output Moderate
GHSA-mj63-m3rc-8ppr was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Denial of service via colliding heading slugs High
GHSA-mh25-x5hq-wrqp was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Denial of service via duplicate footnote definitions High
GHSA-jfm3-95jq-q3rf was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Denial of service via adjacent inline attribute blocks High
GHSA-g2gp-3wwq-f4ph was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: Quadratic-time denial of service when parsing crafted Markdown High
CVE-2026-71488 was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes Moderate
CVE-2026-71478 was published for league/commonmark (Composer) Aug 6, 2026
TungNGo02 Credited to TungNGo02
Silverstripe: XSS in breadcrumbs in page list view Moderate
CVE-2026-54717 was published for silverstripe/cms (Composer) Aug 6, 2026
Contao: Possible path traversal in job download URIs Low
CVE-2026-55825 was published for contao/contao (Composer) Aug 6, 2026
0x1saac Credited to 0x1saac
Contao crawler leaks auth credentials to external hosts Low
CVE-2026-55824 was published for contao/contao (Composer) Aug 6, 2026
0x1saac Credited to 0x1saac
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template Moderate
CVE-2026-71435 was published for statamic/cms (Composer) Aug 6, 2026
ya3raj Credited to ya3raj
Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types Moderate
CVE-2026-71434 was published for statamic/cms (Composer) Aug 6, 2026
ya3raj Credited to ya3raj
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries Moderate
CVE-2026-64662 was published for statamic/cms (Composer) Aug 6, 2026
Pig-Tail Credited to Pig-Tail and luuhung1217 luuhung1217 luuhung1217
Statamic: Unsafe method invocation via Antlers template resolution allows data destruction Moderate
CVE-2026-64663 was published for statamic/cms (Composer) Aug 6, 2026
manus-use Credited to manus-use
Statamic: Account takeover via OAuth email matching without email-verification check High
CVE-2026-64665 was published for statamic/cms (Composer) Aug 6, 2026
luuhung1217 Credited to luuhung1217
Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence Moderate
CVE-2026-64664 was published for statamic/cms (Composer) Aug 6, 2026
ya3raj Credited to ya3raj
Statamic CMS exposes two-factor recovery codes through dynamic Antlers rendering Moderate
CVE-2026-71293 was published for statamic/cms (Composer) Aug 5, 2026
Guzzle: Noncanonical host can bypass host-based checks High
CVE-2026-69246 was published for guzzlehttp/guzzle (Composer) Aug 3, 2026
bilguunbicktivism Credited to bilguunbicktivism
Guzzle: Noncanonical cookie domain keeps subdomain scope Moderate
CVE-2026-69245 was published for guzzlehttp/guzzle (Composer) Aug 3, 2026
GrahamCampbell Credited to GrahamCampbell
Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers High
GHSA-mqq9-gxg5-m58g was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service Moderate
GHSA-3fvr-2jw6-crq4 was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved High
GHSA-mjrx-74jh-7xgw was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers Moderate
GHSA-32rq-jhr7-m3hh was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
lukegranto23 Credited to lukegranto23
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII Moderate
CVE-2026-68501 was published for sylius/mollie-plugin (Composer) Jul 31, 2026
ProTip! Advisories are also available from the GraphQL API