Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7 advisories

Loading
Insufficient type validation in pocketmine/pocketmine-mp High
GHSA-g5rr-p69h-7v3g was published for pocketmine/pocketmine-mp (Composer) Apr 22, 2022
kurt-r2c Credited to kurt-r2c
phpCAS vulnerable to Service Hostname Discovery Exploitation High
CVE-2022-39369 was published for apereo/phpcas (Composer) Nov 1, 2022
Moodle has arbitrary file read risk through pdfTeX Moderate
CVE-2024-43426 was published for moodle/moodle (Composer) Nov 7, 2024
TSPortal: Any user can forge self-deletion requests for any account High
CVE-2026-29788 was published for miraheze/ts-portal (Composer) Mar 27, 2026
pskyechology Credited to pskyechology and Universal-Omega Universal-Omega Universal-Omega
Concrete CMS: OAuth 2.0 Authorization-Code Handler Bypasses Account Status Low
CVE-2026-7887 was published for concrete5/concrete5 (Composer) May 22, 2026
Symfony's OidcTokenHandler Accepts JWTs Missing aud/iss/exp Claims Moderate
CVE-2026-45069 was published for symfony/security-http (Composer) May 27, 2026
YesWiki: SQL injection via the `recentchanges` action `period` argument leads to arbitrary DB read Moderate
CVE-2026-52763 was published for yeswiki/yeswiki (Composer) Jul 9, 2026
CosmicCrusader23 Credited to CosmicCrusader23
ProTip! Advisories are also available from the GraphQL API