Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

200 advisories

Loading
Formie: Missing authorization on sent notification resend modal exposes submission PII High
CVE-2026-76089 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Formie: Unauthenticated users can overwrite incomplete submissions via submit action High
CVE-2026-76087 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials High
CVE-2026-76086 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks High
GHSA-jr78-w6w5-m8f8 was published for mediawiki/semantic-media-wiki (Composer) Sep 18, 2026
manus-use Credited to manus-use
Shopper: Missing authorization on product removal actions in CollectionProducts component High
CVE-2026-56825 was published for shopper/framework (Composer) Sep 11, 2026
therawdev Credited to therawdev
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph) Moderate
CVE-2026-56830 was published for shopper/framework (Composer) Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component High
CVE-2026-56829 was published for shopper/framework (Composer) Sep 11, 2026
therawdev Credited to therawdev
Shopper: privilege escalation via improper Livewire admin component authorization High
CVE-2026-56828 was published for shopper/framework (Composer) Sep 11, 2026
therawdev Credited to therawdev
Shopping privilege escalation through missing authorization in Settings components Moderate
CVE-2026-56826 was published for shopper/framework (Composer) Sep 11, 2026
baradika Credited to baradika
Sulu: Fix authorization bypass when creating preview links Moderate
CVE-2026-82394 was published for sulu/sulu (Composer) Sep 2, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes High
CVE-2026-81892 was published for easycorp/easyadmin-bundle (Composer) Sep 2, 2026
TungNGo02 Credited to TungNGo02
Kirby: File upload permissions are not checked during processing of chunk data High
CVE-2026-71415 was published for getkirby/cms (Composer) Aug 31, 2026
alcls01111 Credited to alcls01111
Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter Moderate
CVE-2026-55476 was published for snipe/snipe-it (Composer) Aug 28, 2026
iltosec Credited to iltosec and Mitchell45 Mitchell45 Mitchell45
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate High
GHSA-fm29-4mq3-phg6 was published for winter/wn-backend-module (Composer) Aug 20, 2026
manus-use Credited to manus-use
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET Moderate
CVE-2026-55703 was published for snipe/snipe-it (Composer) Aug 19, 2026
SakusenSec Credited to SakusenSec
Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics Moderate
CVE-2026-14794 was published for craftcms/cms (Composer) Aug 6, 2026
Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets Moderate
CVE-2026-14793 was published for craftcms/cms (Composer) Aug 6, 2026
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries Moderate
CVE-2026-64662 was published for statamic/cms (Composer) Aug 6, 2026
Pig-Tail Credited to Pig-Tail and luuhung1217 luuhung1217 luuhung1217
Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence Moderate
CVE-2026-64664 was published for statamic/cms (Composer) Aug 6, 2026
ya3raj Credited to ya3raj
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass Low
CVE-2026-52839 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account High
GHSA-h4hf-v6w5-897x was published for poweradmin/poweradmin (Composer) Jul 24, 2026
SaifSalah Credited to SaifSalah
Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration Moderate
GHSA-cvpc-hccg-wmw4 was published for verbb/formie (Composer) Jul 17, 2026
chaitanyagarware Credited to chaitanyagarware
ProTip! Advisories are also available from the GraphQL API