Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,455 advisories

Loading
Statamic: Unsafe method invocation via Antlers template resolution allows data destruction Moderate
CVE-2026-64663 was published for statamic/cms (Composer) Aug 6, 2026
manus-use Credited to manus-use
Statamic: Account takeover via OAuth email matching without email-verification check High
CVE-2026-64665 was published for statamic/cms (Composer) Aug 6, 2026
luuhung1217 Credited to luuhung1217
Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence Moderate
CVE-2026-64664 was published for statamic/cms (Composer) Aug 6, 2026
ya3raj Credited to ya3raj
Statamic CMS exposes two-factor recovery codes through dynamic Antlers rendering Moderate
CVE-2026-71293 was published for statamic/cms (Composer) Aug 5, 2026
Guzzle: Noncanonical host can bypass host-based checks High
CVE-2026-69246 was published for guzzlehttp/guzzle (Composer) Aug 3, 2026
bilguunbicktivism Credited to bilguunbicktivism
Guzzle: Noncanonical cookie domain keeps subdomain scope Moderate
CVE-2026-69245 was published for guzzlehttp/guzzle (Composer) Aug 3, 2026
GrahamCampbell Credited to GrahamCampbell
Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers High
GHSA-mqq9-gxg5-m58g was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service Moderate
GHSA-3fvr-2jw6-crq4 was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved High
GHSA-mjrx-74jh-7xgw was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers Moderate
GHSA-32rq-jhr7-m3hh was published for guzzlehttp/guzzle (Composer) Aug 1, 2026 withdrawn
lukegranto23 Credited to lukegranto23
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII Moderate
CVE-2026-68501 was published for sylius/mollie-plugin (Composer) Jul 31, 2026
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook High
CVE-2026-68500 was published for sylius/mollie-plugin (Composer) Jul 31, 2026
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS Low
CVE-2026-52838 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync Low
CVE-2026-52841 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
Dredsen Credited to Dredsen
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page Moderate
CVE-2026-52837 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
peoplstar Credited to peoplstar
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass Low
CVE-2026-52839 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network Low
CVE-2026-52840 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
Dredsen Credited to Dredsen
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure High
CVE-2026-55651 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
0xmupa Credited to 0xmupa
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction. Critical
CVE-2026-54588 was published for poweradmin/poweradmin (Composer) Jul 28, 2026
mike197312 Credited to mike197312
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions High
CVE-2026-54593 was published for github.com/pterodactyl/wings (Composer) Jul 28, 2026
TrixterTheTux Credited to TrixterTheTux
0x7d8 Credited to 0x7d8
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability High
CVE-2026-45293 was published for wp-coding-standards/wpcs (Composer) Jul 28, 2026
FORIMOC Credited to FORIMOC, rodrigoprimo, and jrfnl rodrigoprimo rodrigoprimo
jrfnl jrfnl
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop High
CVE-2026-43871 was published for apache/thrift (Composer) Jul 27, 2026
carlosfunk Credited to carlosfunk and oscerd oscerd oscerd
ProTip! Advisories are also available from the GraphQL API