Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,464 advisories

Loading
CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure() Moderate
CVE-2026-63220 was published for codeigniter4/framework (Composer) Aug 7, 2026
gr8man Credited to gr8man
alexandre-daubois Credited to alexandre-daubois
Smarty Security stream restriction bypass through stream: resource Moderate
CVE-2026-62996 was published for smarty/smarty (Composer) Aug 7, 2026
Faze-up Credited to Faze-up
Smarty: Symlink path traversal out of trusted directories Moderate
CVE-2026-62992 was published for smarty/smarty (Composer) Aug 7, 2026
Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts Moderate
GHSA-957r-qf9p-67xw was published for craftcms/cms (Composer) Aug 6, 2026
je-lv Credited to je-lv
Craft CMS: Authenticated leak of secret environment variables Moderate
GHSA-596p-6jv8-775v was published for craftcms/cms (Composer) Aug 6, 2026
Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element Moderate
GHSA-xxpx-f366-4xpq was published for craftcms/cms (Composer) Aug 6, 2026
smakarim Credited to smakarim
Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics Moderate
GHSA-rvmm-v933-jgxq was published for craftcms/cms (Composer) Aug 6, 2026
Craft CMS: Stored XSS in the control panel via unescaped draft name Moderate
GHSA-2rp4-x2j7-qmcc was published for craftcms/cms (Composer) Aug 6, 2026
je-lv Credited to je-lv
Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets Moderate
CVE-2026-14793 was published for craftcms/cms (Composer) Aug 6, 2026
league/commonmark: Denial of service via deeply nested XML output Moderate
GHSA-mj63-m3rc-8ppr was published for league/commonmark (Composer) Aug 6, 2026
GrahamCampbell Credited to GrahamCampbell
league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes Moderate
CVE-2026-71478 was published for league/commonmark (Composer) Aug 6, 2026
TungNGo02 Credited to TungNGo02
Silverstripe: XSS in breadcrumbs in page list view Moderate
CVE-2026-54717 was published for silverstripe/cms (Composer) Aug 6, 2026
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template Moderate
CVE-2026-71435 was published for statamic/cms (Composer) Aug 6, 2026
ya3raj Credited to ya3raj
Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types Moderate
CVE-2026-71434 was published for statamic/cms (Composer) Aug 6, 2026
ya3raj Credited to ya3raj
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries Moderate
CVE-2026-64662 was published for statamic/cms (Composer) Aug 6, 2026
Pig-Tail Credited to Pig-Tail and luuhung1217 luuhung1217 luuhung1217
Statamic: Unsafe method invocation via Antlers template resolution allows data destruction Moderate
CVE-2026-64663 was published for statamic/cms (Composer) Aug 6, 2026
manus-use Credited to manus-use
Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence Moderate
CVE-2026-64664 was published for statamic/cms (Composer) Aug 6, 2026
ya3raj Credited to ya3raj
Guzzle: Noncanonical cookie domain keeps subdomain scope Moderate
CVE-2026-69245 was published for guzzlehttp/guzzle (Composer) Aug 3, 2026
GrahamCampbell Credited to GrahamCampbell
Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service Moderate
GHSA-3fvr-2jw6-crq4 was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers Moderate
GHSA-32rq-jhr7-m3hh was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
lukegranto23 Credited to lukegranto23
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII Moderate
CVE-2026-68501 was published for sylius/mollie-plugin (Composer) Jul 31, 2026
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page Moderate
CVE-2026-52837 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
peoplstar Credited to peoplstar
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem Moderate
CVE-2026-59943 was published for dompdf/dompdf (Composer) Jul 22, 2026
w4tchd0ge Credited to w4tchd0ge
ProTip! Advisories are also available from the GraphQL API