Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,842 advisories

Loading
Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge High
CVE-2026-62669 was published for getgrav/grav (Composer) Sep 2, 2026
nicl4ssic Credited to nicl4ssic
elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE) High
CVE-2026-81891 was published for Studio-42/elFinder (Composer) Sep 2, 2026
jdh5202 Credited to jdh5202
Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed High
CVE-2026-11407 was published for pimcore/pimcore (Composer) Jun 17, 2026
astapc Credited to astapc
Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode High
CVE-2026-55643 was published for snipe/snipe-it (Composer) Aug 19, 2026
Rajib-Mahmud Credited to Rajib-Mahmud
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() High
CVE-2026-64850 was published for getgrav/grav (Composer) Sep 2, 2026
YuvalMil Credited to YuvalMil, MatiHub25, and LeonKaya MatiHub25 MatiHub25
LeonKaya LeonKaya
EasyAdmin custom-action dispatcher bypasses access_control on other routes High
CVE-2026-81892 was published for easycorp/easyadmin-bundle (Composer) Sep 2, 2026
TungNGo02 Credited to TungNGo02
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop High
CVE-2026-43871 was published for apache/thrift (Composer) Jul 27, 2026
carlosfunk Credited to carlosfunk and oscerd oscerd oscerd
AVideo has Authenticated Server-Side Request Forgery via downloadURL in aVideoEncoder.json.php High
CVE-2026-27732 was published for wwbn/avideo (Composer) Feb 25, 2026
arkmarta Credited to arkmarta and kgnio kgnio kgnio
TYPO3 CMS - Broken Access Control in Backend and Install Tool High
CVE-2026-19418 was published for typo3/cms-backend (Composer) Sep 1, 2026
Duplicate Advisory: TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool High
GHSA-4f2f-jr2m-j7p4 was published for typo3/cms-core (Composer) Aug 11, 2026 withdrawn
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled High
CVE-2026-77567 was published for filament/filament (Composer) Sep 1, 2026
Orrison Credited to Orrison and danharrin danharrin danharrin
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass High
CVE-2026-72778 was published for craftcms/cms (Composer) Aug 6, 2026
saladin0x1 Credited to saladin0x1
Duplicate Advisory: Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass High
GHSA-w36c-qxrq-v7fw was published for craftcms/cms (Composer) Aug 11, 2026 withdrawn
Duplicate Advisory: Craft CMS: Authenticated leak of secret environment variables High
GHSA-cc2g-26rw-g997 was published for craftcms/cms (Composer) Aug 11, 2026 withdrawn
Craft CMS: Authenticated RCE through Twig sandbox escape High
CVE-2026-72781 was published for craftcms/cms (Composer) Aug 6, 2026
Duplicate Advisory: Craft CMS: Authenticated RCE through Twig sandbox escape High
GHSA-h784-hpjp-2rrm was published for craftcms/cms (Composer) Aug 11, 2026 withdrawn
Duplicate Advisory: Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts High
GHSA-2p2v-3mjg-gfpf was published for craftcms/cms (Composer) Aug 11, 2026 withdrawn
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension High
GHSA-8rr7-cvq3-gmfh was published for league/commonmark (Composer) Sep 1, 2026
manus-use Credited to manus-use
league/commonmark: Denial of service in the SmartPunct and Attributes extensions High
GHSA-jjv6-8j6v-6j52 was published for league/commonmark (Composer) Sep 1, 2026
colinodell Credited to colinodell
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters High
GHSA-j8pm-gj4c-rq4x was published for league/commonmark (Composer) Sep 1, 2026
colinodell Credited to colinodell
league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed High
GHSA-f8fg-pg57-v4j8 was published for league/commonmark (Composer) Sep 1, 2026
StarPlatinu Credited to StarPlatinu
tonghuaroot Credited to tonghuaroot and soyuka soyuka soyuka
Kirby: File upload permissions are not checked during processing of chunk data High
CVE-2026-71415 was published for getkirby/cms (Composer) Aug 31, 2026
alcls01111 Credited to alcls01111
Pig-Tail Credited to Pig-Tail
elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback High
CVE-2026-81889 was published for studio-42/elfinder (Composer) Aug 31, 2026
Marco198333 Credited to Marco198333
ProTip! Advisories are also available from the GraphQL API