Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

9,360 advisories

Loading
The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform any... Moderate Unreviewed
CVE-2026-88845 was published Sep 24, 2026
A flaw was found in the Ansible Automation Platform automation-controller. When a... Critical Unreviewed
CVE-2026-84719 was published Sep 23, 2026
Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions. High Unreviewed
CVE-2026-95604 was published Sep 23, 2026
Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions. Moderate Unreviewed
CVE-2026-95527 was published Sep 23, 2026
Subscriber Broken Access Control in Fluent Support <= 2.3.2 versions. Moderate Unreviewed
CVE-2026-94679 was published Sep 23, 2026
Unauthenticated Broken Access Control in AppMySite <= 3.15.4 versions. Moderate Unreviewed
CVE-2026-94498 was published Sep 23, 2026
Unauthenticated Broken Access Control in MarketKing <= 2.1.70 versions. Moderate Unreviewed
CVE-2026-94080 was published Sep 23, 2026
Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions. Moderate Unreviewed
CVE-2026-94079 was published Sep 23, 2026
Unauthenticated Broken Access Control in PayPlus Payment Gateway <= 8.2.5 versions. Moderate Unreviewed
CVE-2026-93620 was published Sep 23, 2026
Contributor Broken Access Control in WSP MCP &#8211; AI Agents Connector <= 2.7.0 versions. Moderate Unreviewed
CVE-2026-93529 was published Sep 23, 2026
JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission... Moderate Unreviewed
CVE-2026-71459 was published Sep 23, 2026
/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number,... Moderate Unreviewed
CVE-2026-71460 was published Sep 23, 2026
Formie: Missing authorization on sent notification resend modal exposes submission PII High
CVE-2026-76089 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Formie: Unauthenticated users can overwrite incomplete submissions via submit action High
CVE-2026-76087 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials High
CVE-2026-76086 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
ProTip! Advisories are also available from the GraphQL API