Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,442 advisories

Loading
TYPO3 CMS - Broken Access Control in Backend and Install Tool High
CVE-2026-19418 was published for typo3/cms-backend (Composer) Sep 1, 2026
Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used Moderate
CVE-2026-84306 was published for filament/filament (Composer) Sep 1, 2026
rianorie Credited to rianorie and danharrin danharrin danharrin
Filament: Password validity disclosure for accounts denied panel access on login page Low
CVE-2026-84307 was published for filament/filament (Composer) Sep 1, 2026
danharrin Credited to danharrin
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled High
CVE-2026-77567 was published for filament/filament (Composer) Sep 1, 2026
Orrison Credited to Orrison and danharrin danharrin danharrin
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension High
GHSA-8rr7-cvq3-gmfh was published for league/commonmark (Composer) Sep 1, 2026
manus-use Credited to manus-use
league/commonmark: Denial of service in the SmartPunct and Attributes extensions High
GHSA-jjv6-8j6v-6j52 was published for league/commonmark (Composer) Sep 1, 2026
colinodell Credited to colinodell
league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed High
GHSA-f8fg-pg57-v4j8 was published for league/commonmark (Composer) Sep 1, 2026
StarPlatinu Credited to StarPlatinu
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters High
GHSA-j8pm-gj4c-rq4x was published for league/commonmark (Composer) Sep 1, 2026
colinodell Credited to colinodell
Smarty: SSRF via redirect bypass of trusted_uri using {fetch} Moderate
CVE-2026-62993 was published for smarty/smarty (Composer) Sep 1, 2026
Kirby: System path exposure from error messages in the REST API Moderate
CVE-2026-69127 was published for getkirby/cms (Composer) Sep 1, 2026
petersevera Credited to petersevera
Kirby: File upload permissions are not checked during processing of chunk data High
CVE-2026-71415 was published for getkirby/cms (Composer) Aug 31, 2026
alcls01111 Credited to alcls01111
Pig-Tail Credited to Pig-Tail
elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback High
CVE-2026-81889 was published for studio-42/elfinder (Composer) Aug 31, 2026
Marco198333 Credited to Marco198333
TYPO3 CMS - Unrestricted File Upload in Form Framework Moderate
CVE-2026-15305 was published for typo3/cms-form (Composer) Aug 31, 2026
brosua Credited to brosua
Snipe-IT has an Improper Privilege Management issue High
CVE-2026-55843 was published for snipe/snipe-it (Composer) Aug 28, 2026
mattimustang Credited to mattimustang
silverstripe/versioned has XSS in archive admin restore Moderate
CVE-2026-55779 was published for silverstripe/versioned (Composer) Aug 28, 2026
PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI Low
CVE-2026-55891 was published for privatebin/privatebin (Composer) Aug 28, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team, elrido, and rugk elrido elrido
rugk rugk
EvidentObscurity Credited to EvidentObscurity, rugk, and elrido rugk rugk
elrido elrido
Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name Critical
CVE-2026-55634 was published for pimcore/pimcore (Composer) Aug 28, 2026
Yanchon918s Credited to Yanchon918s
tonghuaroot Credited to tonghuaroot
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation High
CVE-2026-55212 was published for pimcore/studio-backend-bundle (Composer) Aug 28, 2026
dhairya7760 Credited to dhairya7760
byteoverride Credited to byteoverride
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass High
CVE-2026-55207 was published for pimcore/studio-backend-bundle (Composer) Aug 28, 2026
byteoverride Credited to byteoverride
phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For / Client-IP headers High
CVE-2026-55584 was published for phpsysinfo/phpsysinfo (Composer) Aug 28, 2026
mirackayikci Credited to mirackayikci
Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update High
CVE-2026-55516 was published for snipe/snipe-it (Composer) Aug 28, 2026
5h1kh4r Credited to 5h1kh4r and builtbybrayden builtbybrayden builtbybrayden
ProTip! Advisories are also available from the GraphQL API