Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,562 advisories

Loading
league/commonmark: DisallowedRawHtml bypassed when a disallowed tag name ends the raw-HTML literal Moderate
GHSA-97jj-33gv-5xf9 was published for league/commonmark (Composer) Sep 30, 2026
4n86rakam1 Credited to 4n86rakam1
league/commonmark: Quadratic-time denial of service in the GitHub Flavored Markdown Table extension block-start scan High
GHSA-3q6v-r5mr-hxv8 was published for league/commonmark (Composer) Sep 30, 2026
manus-pi Credited to manus-pi
Laravel: XSS in Debug Page Information Low
CVE-2026-102279 was published for laravel/framework (Composer) Sep 29, 2026
Rikuxx0 Credited to Rikuxx0
iaohkut Credited to iaohkut and Unifex Unifex Unifex
PHPCSUtils: Remote code execution via eval() in AbstractArrayDeclarationSniff::getActualArrayKey() High
CVE-2026-65954 was published for phpcsstandards/phpcsutils (Composer) Sep 29, 2026
rodrigoprimo Credited to rodrigoprimo, FORIMOC, edorian, and jrfnl FORIMOC FORIMOC
edorian edorian jrfnl jrfnl
FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider Critical
CVE-2026-92161 was published for fof/oauth (Composer) Sep 25, 2026
faran1512 Credited to faran1512
Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled High
CVE-2026-57440 was published for starcitizenwiki/embedvideo (Composer) Sep 25, 2026
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute High
CVE-2026-61823 was published for code16/sharp (Composer) Sep 25, 2026
nova-aryan Credited to nova-aryan
code16/sharp has a stored XSS via data-html-content Sanitizer Bypass High
CVE-2026-61825 was published for code16/sharp (Composer) Sep 25, 2026
nova-aryan Credited to nova-aryan
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module Low
CVE-2026-57232 was published for contao/contao (Composer) Sep 24, 2026
Para213 Credited to Para213
zbateson/mail-mime-parser has CRLF header injection via attachment filename High
CVE-2026-61815 was published for zbateson/mail-mime-parser (Composer) Sep 24, 2026
iliaal Credited to iliaal
zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME High
CVE-2026-61816 was published for zbateson/mail-mime-parser (Composer) Sep 24, 2026
phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion High
CVE-2026-56738 was published for phpmyfaq/phpmyfaq (Composer) Sep 24, 2026
DomainXTech Credited to DomainXTech
phpMyFAQ's two-factor authentication login bypasses the password factor High
CVE-2026-56737 was published for phpmyfaq/phpmyfaq (Composer) Sep 24, 2026
waseem-cve Credited to waseem-cve
phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission High
CVE-2026-56736 was published for phpmyfaq/phpmyfaq (Composer) Sep 24, 2026
JosanGeorge Credited to JosanGeorge
Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API High
CVE-2026-63498 was published for snipe/snipe-it (Composer) Sep 24, 2026
B1gN0Se Credited to B1gN0Se, Rajib-Mahmud, and snipe Rajib-Mahmud Rajib-Mahmud
snipe snipe
Snipe-IT: Stored XSS via Custom Field name in asset-list column headers High
CVE-2026-62368 was published for snipe/snipe-it (Composer) Sep 24, 2026
Mickey777777 Credited to Mickey777777
Snipe-IT: 2FA bypass via the API token flow High
CVE-2026-63493 was published for snipe/snipe-it (Composer) Sep 24, 2026
colinthebomb1 Credited to colinthebomb1
REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration Moderate
CVE-2026-62998 was published for redaxo/source (Composer) Sep 24, 2026
de3erve-hunter Credited to de3erve-hunter
Formie: Missing authorization on sent notification resend modal exposes submission PII High
CVE-2026-76089 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Formie: Unauthenticated users can overwrite incomplete submissions via submit action High
CVE-2026-76087 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials High
CVE-2026-76086 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated) Moderate
CVE-2026-92692 was published for sulu/sulu (Composer) Sep 23, 2026
Solspace Freeform: Limited Twig template injection via submitted field values Moderate
CVE-2026-73858 was published for solspace/craft-freeform (Composer) Sep 23, 2026
wakedxy Credited to wakedxy
WPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePost Moderate
CVE-2026-88974 was published for wp-graphql/wp-graphql (Composer) Sep 23, 2026
rajukani100 Credited to rajukani100
ProTip! Advisories are also available from the GraphQL API