Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,455 advisories

Loading
Snipe-IT has an authorization bypass on bulk editing users High
CVE-2026-55460 was published for snipe/snipe-it (Composer) Aug 28, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
Snipe-IT has CSV formula injection in Activity Report export Moderate
CVE-2026-55452 was published for snipe/snipe-it (Composer) Aug 28, 2026
geo-chen Credited to geo-chen
Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS High
CVE-2026-57584 was published for phalcon/cphalcon (Composer) Aug 28, 2026
nikkoenggaliano Credited to nikkoenggaliano
Phalcon: Non-constant-time HMAC verification in `Encryption\Crypt::decrypt` (timing side-channel) High
CVE-2026-54736 was published for phalcon/cphalcon (Composer) Aug 28, 2026
nikkoenggaliano Credited to nikkoenggaliano
silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template High
CVE-2026-54718 was published for symbiote/silverstripe-advancedworkflow (Composer) Aug 27, 2026
cakephp/queue's Incomplete Comparison in getUniqueId vulnerable to collisions Low
CVE-2026-54713 was published for cakephp/queue (Composer) Aug 27, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject High
CVE-2026-54721 was published for silverstripe/userforms (Composer) Aug 27, 2026
Silverstripe Framework: Possible XSS attack through media embed Moderate
CVE-2026-54720 was published for silverstripe/framework (Composer) Aug 27, 2026
OpenSTAManager has HTML Injection in modules/utenti/edit.php Low
CVE-2026-44701 was published for devcode-it/openstamanager (Composer) Aug 26, 2026
ilmercu Credited to ilmercu
LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates High
GHSA-7w8c-qgxg-m7jx was published for librenms/librenms (Composer) Aug 26, 2026
TristanInSec Credited to TristanInSec
cakephp/debug_kit: MailPreview contains unsafe reflection Moderate
CVE-2026-54614 was published for cakephp/debug_kit (Composer) Aug 26, 2026
edorian Credited to edorian
phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold High
GHSA-pg62-f8g4-4wqh was published for phpmyfaq/phpmyfaq (Composer) Aug 25, 2026
Yanchon918s Credited to Yanchon918s
phpMyFAQ public FAQ APIs expose inactive FAQ content Moderate
GHSA-mf8r-wm2w-f8c5 was published for phpmyfaq/phpmyfaq (Composer) Aug 25, 2026
YHalo-wyh Credited to YHalo-wyh
phpMyFAQ has Potential Authenticated Path Traversal in PDF Export Moderate
GHSA-88g4-74f3-63x9 was published for phpmyfaq/phpmyfaq (Composer) Aug 25, 2026
DomainXTech Credited to DomainXTech
YOURLS has stored XSS in referrer statistics chart via crafted Referer header High
CVE-2026-63135 was published for yourls/yourls (Composer) Aug 21, 2026
sondt99 Credited to sondt99, dgw, ozh, and LeoColomb dgw dgw
ozh ozh LeoColomb LeoColomb
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE) Critical
CVE-2026-59989 was published for phalcon/cphalcon (Composer) Aug 21, 2026
nikkoenggaliano Credited to nikkoenggaliano
skeletonsec Credited to skeletonsec
Winter: Reflected XSS through the search query parameter in the backend Table widget Moderate
GHSA-hq84-x37p-j6q5 was published for winter/wn-backend-module (Composer) Aug 20, 2026
NRAwwad Credited to NRAwwad
Winter: CSRF through AJAX handler names reachable as backend page actions Moderate
GHSA-p2ch-c2c3-4xm5 was published for winter/wn-backend-module (Composer) Aug 20, 2026
NRAwwad Credited to NRAwwad
Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles Moderate
GHSA-5cwr-5jxg-pcf6 was published for winter/wn-backend-module (Composer) Aug 20, 2026
NRAwwad Credited to NRAwwad
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate High
GHSA-fm29-4mq3-phg6 was published for winter/wn-backend-module (Composer) Aug 20, 2026
manus-use Credited to manus-use
Winter: My Account preview exposes another backend user's profile by record ID Moderate
GHSA-mpmw-f6h6-3g26 was published for winter/wn-backend-module (Composer) Aug 20, 2026
NRAwwad Credited to NRAwwad
Winter: Stored XSS through Backend List widget image columns Low
GHSA-7mpf-4465-7fc2 was published for winter/wn-backend-module (Composer) Aug 20, 2026
Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149) High
GHSA-8cfw-pcwh-v63w was published for winter/wn-system-module (Composer) Aug 20, 2026
M9nx Credited to M9nx
Winter: Local File Inclusion through =include directives in JavaScript asset compilation Moderate
GHSA-2223-f22x-24cq was published for winter/wn-system-module (Composer) Aug 20, 2026
elmahy111 Credited to elmahy111
ProTip! Advisories are also available from the GraphQL API