Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,553 advisories

Loading
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module Low
CVE-2026-57232 was published for contao/contao (Composer) Sep 24, 2026
Para213 Credited to Para213
zbateson/mail-mime-parser has CRLF header injection via attachment filename High
CVE-2026-61815 was published for zbateson/mail-mime-parser (Composer) Sep 24, 2026
iliaal Credited to iliaal
zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME High
CVE-2026-61816 was published for zbateson/mail-mime-parser (Composer) Sep 24, 2026
phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion High
CVE-2026-56738 was published for phpmyfaq/phpmyfaq (Composer) Sep 24, 2026
DomainXTech Credited to DomainXTech
phpMyFAQ's two-factor authentication login bypasses the password factor High
CVE-2026-56737 was published for phpmyfaq/phpmyfaq (Composer) Sep 24, 2026
waseem-cve Credited to waseem-cve
phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission High
CVE-2026-56736 was published for phpmyfaq/phpmyfaq (Composer) Sep 24, 2026
JosanGeorge Credited to JosanGeorge
Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API High
CVE-2026-63498 was published for snipe/snipe-it (Composer) Sep 24, 2026
B1gN0Se Credited to B1gN0Se, Rajib-Mahmud, and snipe Rajib-Mahmud Rajib-Mahmud
snipe snipe
Snipe-IT: Stored XSS via Custom Field name in asset-list column headers High
CVE-2026-62368 was published for snipe/snipe-it (Composer) Sep 24, 2026
Mickey777777 Credited to Mickey777777
Snipe-IT: 2FA bypass via the API token flow High
CVE-2026-63493 was published for snipe/snipe-it (Composer) Sep 24, 2026
colinthebomb1 Credited to colinthebomb1
REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration Moderate
CVE-2026-62998 was published for redaxo/source (Composer) Sep 24, 2026
de3erve-hunter Credited to de3erve-hunter
Formie: Missing authorization on sent notification resend modal exposes submission PII High
CVE-2026-76089 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Formie: Unauthenticated users can overwrite incomplete submissions via submit action High
CVE-2026-76087 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials High
CVE-2026-76086 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated) Moderate
CVE-2026-92692 was published for sulu/sulu (Composer) Sep 23, 2026
Solspace Freeform: Limited Twig template injection via submitted field values Moderate
CVE-2026-73858 was published for solspace/craft-freeform (Composer) Sep 23, 2026
wakedxy Credited to wakedxy
WPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePost Moderate
CVE-2026-88974 was published for wp-graphql/wp-graphql (Composer) Sep 23, 2026
rajukani100 Credited to rajukani100
REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates Moderate
CVE-2026-63000 was published for redaxo/source (Composer) Sep 23, 2026
de3erve-hunter Credited to de3erve-hunter
REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames Moderate
CVE-2026-63002 was published for redaxo/source (Composer) Sep 23, 2026
de3erve-hunter Credited to de3erve-hunter
REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()` Moderate
CVE-2026-63001 was published for redaxo/source (Composer) Sep 23, 2026
de3erve Credited to de3erve
Paymenter has a credit-refund double-spend race condition in service downgrade (doUpgrade) Moderate
CVE-2026-71537 was published for paymenter/paymenter (Composer) Sep 18, 2026
Pig-Tail Credited to Pig-Tail and CorwinDev CorwinDev CorwinDev
Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks High
GHSA-jr78-w6w5-m8f8 was published for mediawiki/semantic-media-wiki (Composer) Sep 18, 2026
Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354) Moderate
GHSA-9rcc-pmj8-ffhr was published for mediawiki/semantic-media-wiki (Composer) Sep 18, 2026
arpitjain099 Credited to arpitjain099
Semantic MediaWiki affected by reflected XSS in `Special:Ask` via a forged cursor pagination token Moderate
CVE-2026-77616 was published for mediawiki/semantic-media-wiki (Composer) Sep 18, 2026
Semantic MediaWiki has a query debug output XSS (`DebugFormatter`) Moderate
CVE-2026-77610 was published for mediawiki/semantic-media-wiki (Composer) Sep 18, 2026
krabina Credited to krabina
Semantic MediaWiki has an open redirect in Special:URIResolver Moderate
CVE-2026-77609 was published for mediawiki/semantic-media-wiki (Composer) Sep 18, 2026
krabina Credited to krabina
ProTip! Advisories are also available from the GraphQL API