Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

239 advisories

Loading
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() High
CVE-2026-64850 was published for getgrav/grav (Composer) Sep 2, 2026
YuvalMil Credited to YuvalMil, MatiHub25, and LeonKaya MatiHub25 MatiHub25
LeonKaya LeonKaya
Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name Critical
CVE-2026-55634 was published for pimcore/pimcore (Composer) Aug 28, 2026
Yanchon918s Credited to Yanchon918s
silverstripe/userforms vulnerable to remote code execution via userforms email subject High
CVE-2026-54721 was published for silverstripe/userforms (Composer) Aug 27, 2026
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE) Critical
CVE-2026-59989 was published for phalcon/cphalcon (Composer) Aug 21, 2026
nikkoenggaliano Credited to nikkoenggaliano
jmespath.php has CompilerRuntime code injection via unescaped function names Critical
CVE-2026-54133 was published for mtdowling/jmespath.php (Composer) Aug 18, 2026
edorian Credited to edorian
YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service Critical
CVE-2026-52778 was published for yeswiki/yeswiki (Composer) Jul 9, 2026
N0tFix3d Credited to N0tFix3d
Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview High
CVE-2026-56382 was published for craftcms/cms (Composer) Jul 9, 2026
q1uf3ng Credited to q1uf3ng
EGroupware has a Remote Code Execution Vulnerability Critical
CVE-2026-27823 was published for egroupware/egroupware (Composer) Jul 7, 2026
realalphaman Credited to realalphaman
Craft CMS: Potential authenticated Remote Code Execution via referrer redirect High
CVE-2026-55794 was published for craftcms/cms (Composer) Jul 6, 2026
Duplicate Advisory: Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview High
GHSA-pmm4-v8f6-4vpp was published for craftcms/cms (Composer) Jun 21, 2026 withdrawn
Dolibarr ERP CRM contains a remote code evaluation vulnerability Critical
CVE-2018-25357 was published for dolibarr/dolibarr (Composer) May 26, 2026
Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation High
CVE-2026-46640 was published for twig/twig (Composer) May 21, 2026
vladko312 Credited to vladko312
Twig: PHP code injection via `{% use %}` template name Critical
CVE-2026-46633 was published for twig/twig (Composer) May 21, 2026
Formie: Pre-authenticated server-side template injection in Hidden fields Critical
CVE-2026-45697 was published for verbb/formie (Composer) May 18, 2026
pwnsauc3 Credited to pwnsauc3
CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration High
CVE-2026-41249 was published for coreshop/core-shop (Composer) May 14, 2026
smiotani-aeyesec Credited to smiotani-aeyesec
FacturaScripts Vulnerable to Authenticated Remote Code Execution (RCE) via GIF Image Upload in Product Images Moderate
CVE-2026-42879 was published for facturascripts/facturascripts (Composer) May 7, 2026
guzrex Credited to guzrex
Scramble vulnerable to remote code execution via evaluation of user-controlled input in validation rules Critical
CVE-2026-44262 was published for dedoc/scramble (Composer) May 6, 2026
FORIMOC Credited to FORIMOC
Grav Vulnerable to Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Feature Critical
CVE-2026-42607 was published for getgrav/grav (Composer) May 5, 2026
akgul7990 Credited to akgul7990
offset Credited to offset
Krayin CRM allows a remote attacker to execute arbitrary code via compose email function High
CVE-2026-36340 was published for krayin/laravel-crm (Composer) Apr 30, 2026
Cockpit is vulnerable to arbitrary code execution Critical
CVE-2026-38992 was published for cockpit-hq/cockpit (Composer) Apr 29, 2026
Dolibarr Allows Code Injection through its Website Module High
CVE-2026-31018 was published for dolibarr/dolibarr (Composer) Apr 21, 2026
Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API) Critical
CVE-2026-41229 was published for froxlor/froxlor (Composer) Apr 16, 2026
offset Credited to offset
offset Credited to offset
ProTip! Advisories are also available from the GraphQL API