Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

49 advisories

Loading
Formie: Missing authorization on sent notification resend modal exposes submission PII High
CVE-2026-76089 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Formie: Unauthenticated users can overwrite incomplete submissions via submit action High
CVE-2026-76087 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials High
CVE-2026-76086 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks High
GHSA-jr78-w6w5-m8f8 was published for mediawiki/semantic-media-wiki (Composer) Sep 18, 2026
manus-use Credited to manus-use
Shopper: Missing authorization on product removal actions in CollectionProducts component High
CVE-2026-56825 was published for shopper/framework (Composer) Sep 11, 2026
therawdev Credited to therawdev
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component High
CVE-2026-56829 was published for shopper/framework (Composer) Sep 11, 2026
therawdev Credited to therawdev
Shopper: privilege escalation via improper Livewire admin component authorization High
CVE-2026-56828 was published for shopper/framework (Composer) Sep 11, 2026
therawdev Credited to therawdev
EasyAdmin custom-action dispatcher bypasses access_control on other routes High
CVE-2026-81892 was published for easycorp/easyadmin-bundle (Composer) Sep 2, 2026
TungNGo02 Credited to TungNGo02
Kirby: File upload permissions are not checked during processing of chunk data High
CVE-2026-71415 was published for getkirby/cms (Composer) Aug 31, 2026
alcls01111 Credited to alcls01111
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate High
GHSA-fm29-4mq3-phg6 was published for winter/wn-backend-module (Composer) Aug 20, 2026
manus-use Credited to manus-use
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account High
GHSA-h4hf-v6w5-897x was published for poweradmin/poweradmin (Composer) Jul 24, 2026
SaifSalah Credited to SaifSalah
Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves High
CVE-2026-50282 was published for craftcms/cms (Composer) Jul 2, 2026
davidbors-snyk Credited to davidbors-snyk and cataliniovita-snyk cataliniovita-snyk cataliniovita-snyk
offset Credited to offset
SolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings High
GHSA-7vfx-4246-jcfh was published for solidinvoice/solidinvoice (Composer) Jun 26, 2026
Kirby: `pages.access` permission is not checked in the `site/find` REST API route High
CVE-2026-54005 was published for getkirby/cms (Composer) Jun 18, 2026
EvidentObscurity Credited to EvidentObscurity
TYPO3 CMS has Broken Access Control in its Form Framework High
CVE-2026-11607 was published for typo3/cms-core (Composer) Jun 12, 2026
TYPO3 CMS: Destructive Actions on File Mount Folders High
CVE-2026-47343 was published for typo3/cms-core (Composer) Jun 12, 2026
TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework High
CVE-2026-49741 was published for typo3/cms-core (Composer) Jun 12, 2026
TYPO3 CMS has Broken Access Control in its Form Framework High
CVE-2026-47346 was published for typo3/cms-core (Composer) Jun 12, 2026
Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling High
CVE-2026-45260 was published for pimcore/pimcore (Composer) May 27, 2026
larlarua Credited to larlarua and kingjia90 kingjia90 kingjia90
phpMyFAQ: IDOR Account Takeover High
CVE-2026-35671 was published for phpmyfaq/phpmyfaq (Composer) May 20, 2026
cyberHunter127 Credited to cyberHunter127
shopper/framework: Authorization bypass in multiple Livewire admin components High
CVE-2026-47740 was published for shopper/framework (Composer) May 18, 2026
baradika Credited to baradika
ProTip! Advisories are also available from the GraphQL API