Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

445 advisories

Loading
Craft CMS has a potential information disclosure vulnerability in preview tokens Low
CVE-2026-29113 was published for craftcms/cms (Composer) Mar 10, 2026
singetu0096 Credited to singetu0096 and nikpivkin nikpivkin nikpivkin
Filament: Password validity disclosure for accounts denied panel access on login page Low
CVE-2026-84307 was published for filament/filament (Composer) Sep 1, 2026
danharrin Credited to danharrin
Craft CMS: Incorrect path validation could potentially lead to path traversal Low
CVE-2026-72783 was published for craftcms/cms (Composer) Aug 6, 2026
PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI Low
CVE-2026-55891 was published for privatebin/privatebin (Composer) Aug 28, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team, elrido, and rugk elrido elrido
rugk rugk
Snipe-IT has a path traversal vulnerability via CSV import `image` field Low
CVE-2026-55469 was published for snipe/snipe-it (Composer) Aug 28, 2026
Vasco0x4 Credited to Vasco0x4
cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions Low
CVE-2026-54713 was published for cakephp/queue (Composer) Aug 27, 2026
OpenSTAManager has HTML Injection in modules/utenti/edit.php Low
CVE-2026-44701 was published for devcode-it/openstamanager (Composer) Aug 26, 2026
ilmercu Credited to ilmercu
Subrion CMS vulnerable to Cross-site Scripting Low
CVE-2026-12202 was published for intelliants/subrion (Composer) Jun 15, 2026
Winter: Stored XSS through Backend List widget image columns Low
GHSA-7mpf-4465-7fc2 was published for winter/wn-backend-module (Composer) Aug 20, 2026
Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read Low
CVE-2026-56394 was published for craftcms/cms (Composer) Jul 9, 2026
GCXWLP Credited to GCXWLP
GCXWLP Credited to GCXWLP
Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options Low
CVE-2026-56393 was published for craftcms/cms (Composer) Mar 3, 2026
mHe4am Credited to mHe4am
Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page Low
CVE-2026-56381 was published for craftcms/cms (Composer) Mar 11, 2026
mHe4am Credited to mHe4am
Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type Low
CVE-2026-56383 was published for craftcms/cms (Composer) Feb 25, 2026
mHe4am Credited to mHe4am
Contao: Possible path traversal in job download URIs Low
CVE-2026-55825 was published for contao/contao (Composer) Aug 6, 2026
0x1saac Credited to 0x1saac
Contao crawler leaks auth credentials to external hosts Low
CVE-2026-55824 was published for contao/contao (Composer) Aug 6, 2026
0x1saac Credited to 0x1saac
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS Low
CVE-2026-52838 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync Low
CVE-2026-52841 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
Dredsen Credited to Dredsen
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass Low
CVE-2026-52839 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network Low
CVE-2026-52840 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
Dredsen Credited to Dredsen
Dompdf: File existence oracle via font-face stylesheet declaration Low
CVE-2026-55555 was published for dompdf/dompdf (Composer) Jul 22, 2026
g4nkd Credited to g4nkd
Dompdf: Chroot Validation Bypass Low
CVE-2026-55554 was published for dompdf/dompdf (Composer) Jul 22, 2026
vxhex Credited to vxhex and snoopysecurity snoopysecurity snoopysecurity
Dolibarr ERP CRM is vulnerable to Improper Authorization through its Leave Request REST API Low
CVE-2026-10215 was published for dolibarr/dolibarr (Composer) Jun 1, 2026
ProTip! Advisories are also available from the GraphQL API