Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

190 advisories

Loading
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate High
GHSA-fm29-4mq3-phg6 was published for winter/wn-backend-module (Composer) Aug 20, 2026
manus-use Credited to manus-use
tabacitu Credited to tabacitu
Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element Moderate
GHSA-xxpx-f366-4xpq was published for craftcms/cms (Composer) Aug 6, 2026
smakarim Credited to smakarim
offset Credited to offset
Sylius: Channel-based payment method restriction bypass on shop account orders API endpoint Moderate
CVE-2026-53638 was published for sylius/sylius (Composer) Jul 9, 2026
FredrikEV Credited to FredrikEV
Mautic has an Authorization Bypass in API v2 Endpoints High
CVE-2026-9808 was published for mautic/core (Composer) Jul 2, 2026
zerlyer Credited to zerlyer, pavelkohout396, escopecz, patrykgruszka, and LeuchtfeuerDigitalMarketing pavelkohout396 pavelkohout396
escopecz escopecz patrykgruszka patrykgruszka LeuchtfeuerDigitalMarketing LeuchtfeuerDigitalMarketing
fabpot Credited to fabpot
Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface` Moderate
CVE-2026-48808 was published for twig/twig (Composer) Jun 30, 2026
fabpot Credited to fabpot
Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters Moderate
CVE-2026-48807 was published for twig/twig (Composer) Jun 30, 2026
fabpot Credited to fabpot
Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys Moderate
CVE-2026-48806 was published for twig/twig (Composer) Jun 30, 2026
fabpot Credited to fabpot
Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors Low
CVE-2026-54244 was published for statamic/cms (Composer) Jun 26, 2026
jqr1449186277 Credited to jqr1449186277
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources Moderate
CVE-2026-49288 was published for statamic/cms (Composer) Jun 26, 2026
offset Credited to offset, Eszh, and geo-chen Eszh Eszh
geo-chen geo-chen
Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users High
CVE-2026-48507 was published for snipe/snipe-it (Composer) Jun 23, 2026
louissanchez-vokecyber Credited to louissanchez-vokecyber and whatisproblem whatisproblem whatisproblem
Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment Moderate
CVE-2026-48493 was published for snipe/snipe-it (Composer) Jun 23, 2026
tienneR Credited to tienneR and iltosec iltosec iltosec
a-tt-om Credited to a-tt-om, teebow1e, and nicolas-grekas teebow1e teebow1e
nicolas-grekas nicolas-grekas
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
Admidio: IDOR in documents-files.php allows cross-folder file rename and description changes by unauthorized uploaders Moderate
CVE-2026-47230 was published for admidio/admidio (Composer) May 29, 2026
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement High
CVE-2026-41235 was published for froxlor/froxlor (Composer) May 29, 2026
larlarua Credited to larlarua
Pimcore has a CustomReports Share Bypass High
CVE-2026-45704 was published for pimcore/pimcore (Composer) May 27, 2026
HuajiHD Credited to HuajiHD and kingjia90 kingjia90 kingjia90
Pimcore has a WordExport Authorization Bypass for Unauthorized Document Export Moderate
CVE-2026-45703 was published for pimcore/pimcore (Composer) May 27, 2026
HuajiHD Credited to HuajiHD and kingjia90 kingjia90 kingjia90
Symfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid] High
CVE-2026-45075 was published for symfony/http-kernel (Composer) May 27, 2026
alexandre-daubois Credited to alexandre-daubois and connorshea connorshea connorshea
Concrete CMS is vulnerable to missing authorization in the bulk_user_assignment.php High
CVE-2026-8350 was published for concrete5/concrete5 (Composer) May 21, 2026
Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects) Low
CVE-2026-46635 was published for twig/twig (Composer) May 21, 2026
Duplicate Advisory: phpMyFAQ: Ordinary Authenticated User Can Access Admin-Only API Endpoints Due to Insufficient Authorization Check Moderate
GHSA-9r8r-x3vg-6xh4 was published for phpMyFAQ/phpMyFAQ (Composer) May 15, 2026 withdrawn
ProTip! Advisories are also available from the GraphQL API