Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

115 advisories

Loading
Sulu: Fix authorization bypass when creating preview links Moderate
CVE-2026-82394 was published for sulu/sulu (Composer) Sep 2, 2026
Sulu: Media move/update authorization bypass (IDOR) Moderate
CVE-2026-82395 was published for sulu/sulu (Composer) Sep 2, 2026
Snipe-IT has incorrect permission for legacy license checkin API Moderate
CVE-2026-55479 was published for snipe/snipe-it (Composer) Aug 28, 2026
Mitchell45 Credited to Mitchell45
Snipe-IT's import created_by can be overwritten Moderate
CVE-2026-55475 was published for snipe/snipe-it (Composer) Aug 28, 2026
ashrexon Credited to ashrexon
Snipe-IT's API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation Moderate
CVE-2026-55472 was published for snipe/snipe-it (Composer) Aug 28, 2026
Mitchell45 Credited to Mitchell45
Snipe-IT has an authorization bypass on print inventory page Moderate
CVE-2026-55462 was published for snipe/snipe-it (Composer) Aug 28, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
phpMyFAQ public FAQ APIs expose inactive FAQ content Moderate
GHSA-mf8r-wm2w-f8c5 was published for phpmyfaq/phpmyfaq (Composer) Aug 25, 2026
YHalo-wyh Credited to YHalo-wyh
smakarim Credited to smakarim
offset Credited to offset
Sylius: Channel-based payment method restriction bypass on shop account orders API endpoint Moderate
CVE-2026-53638 was published for sylius/sylius (Composer) Jul 9, 2026
FredrikEV Credited to FredrikEV
Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface` Moderate
CVE-2026-48808 was published for twig/twig (Composer) Jun 30, 2026
fabpot Credited to fabpot
Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters Moderate
CVE-2026-48807 was published for twig/twig (Composer) Jun 30, 2026
fabpot Credited to fabpot
Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys Moderate
CVE-2026-48806 was published for twig/twig (Composer) Jun 30, 2026
fabpot Credited to fabpot
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources Moderate
CVE-2026-49288 was published for statamic/cms (Composer) Jun 26, 2026
offset Credited to offset, Eszh, and geo-chen Eszh Eszh
geo-chen geo-chen
Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment Moderate
CVE-2026-48493 was published for snipe/snipe-it (Composer) Jun 23, 2026
tienneR Credited to tienneR and iltosec iltosec iltosec
Admidio: IDOR in documents-files.php allows cross-folder file rename and description changes by unauthorized uploaders Moderate
CVE-2026-47230 was published for admidio/admidio (Composer) May 29, 2026
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
Pimcore has a WordExport Authorization Bypass for Unauthorized Document Export Moderate
CVE-2026-45703 was published for pimcore/pimcore (Composer) May 27, 2026
HuajiHD Credited to HuajiHD and kingjia90 kingjia90 kingjia90
Duplicate Advisory: phpMyFAQ: Ordinary Authenticated User Can Access Admin-Only API Endpoints Due to Insufficient Authorization Check Moderate
GHSA-9r8r-x3vg-6xh4 was published for phpMyFAQ/phpMyFAQ (Composer) May 15, 2026 withdrawn
MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API Moderate
CVE-2026-42070 was published for mantisbt/mantisbt (Composer) May 11, 2026
shukla304 Credited to shukla304, TristanInSec, and dregad TristanInSec TristanInSec
dregad dregad
kitu232 Credited to kitu232
phpMyFAQ has an Authorization Bypass in All Admin Pages Due to Non-Terminating Permission Check Moderate
CVE-2026-46362 was published for phpmyfaq/phpmyfaq (Composer) May 6, 2026
offset Credited to offset
Kimai has Missing Voter Check that Allows Cross-Team Timesheet Manipulation Moderate
GHSA-9g2q-w3w2-vf7q was published for kimai/kimai (Composer) May 6, 2026
nullvector1 Credited to nullvector1
Grav Vulnerable to Sensitive Information Disclosure via Accounts Service Bypass Moderate
CVE-2026-42610 was published for getgrav/grav (Composer) May 5, 2026
Samer666569 Credited to Samer666569
Admidio Exposes Cross-Organization Member Data via Permission Check Mismatch in contacts_data.php Moderate
CVE-2026-41657 was published for admidio/admidio (Composer) Apr 29, 2026
offset Credited to offset
ProTip! Advisories are also available from the GraphQL API