{"advisories":{"prestashop\/ps_facetedsearch":[{"advisoryId":"PKSA-36b6-kgzr-fpm3","packageName":"prestashop\/ps_facetedsearch","remoteId":"GHSA-m5f5-28qr-9g9r","title":"prestashop\/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE","link":"https:\/\/github.com\/advisories\/GHSA-m5f5-28qr-9g9r","cve":"CVE-2026-54159","affectedVersions":"\u003E=3.0.0,\u003C4.0.4","source":"GitHub","reportedAt":"2026-07-10 20:36:56","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-m5f5-28qr-9g9r"}]}],"notrinos\/notrinos-erp":[{"advisoryId":"PKSA-6c2y-dycw-7c38","packageName":"notrinos\/notrinos-erp","remoteId":"GHSA-qv4m-m73m-8hj7","title":"NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee \u0022Documents\u0022 (doc_file)","link":"https:\/\/github.com\/advisories\/GHSA-qv4m-m73m-8hj7","cve":null,"affectedVersions":"\u003C=1.0.0","source":"GitHub","reportedAt":"2026-07-10 19:34:03","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qv4m-m73m-8hj7"}]}],"kimai\/kimai":[{"advisoryId":"PKSA-j8yw-pd54-qb9k","packageName":"kimai\/kimai","remoteId":"GHSA-pj8j-p4g4-4vw8","title":"Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs","link":"https:\/\/github.com\/advisories\/GHSA-pj8j-p4g4-4vw8","cve":"CVE-2026-49865","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-10 16:04:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pj8j-p4g4-4vw8"}]},{"advisoryId":"PKSA-c4rt-jt98-gvs8","packageName":"kimai\/kimai","remoteId":"GHSA-j5mc-p8qg-39j7","title":"Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation","link":"https:\/\/github.com\/advisories\/GHSA-j5mc-p8qg-39j7","cve":null,"affectedVersions":"\u003C=2.56.0","source":"GitHub","reportedAt":"2026-07-02 20:44:05","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-j5mc-p8qg-39j7"}]},{"advisoryId":"PKSA-rxqm-xvx5-ktw1","packageName":"kimai\/kimai","remoteId":"GHSA-m492-gv72-xvxj","title":"Kimai Password Reset Link Remains Valid After Password Change","link":"https:\/\/github.com\/advisories\/GHSA-m492-gv72-xvxj","cve":null,"affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-01 19:49:24","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-m492-gv72-xvxj"}]},{"advisoryId":"PKSA-hzjv-c975-xrgc","packageName":"kimai\/kimai","remoteId":"GHSA-h5fh-7hwr-97mw","title":"Kimai has an arbitrary file read in its invoice PDF renderer (admin)","link":"https:\/\/github.com\/advisories\/GHSA-h5fh-7hwr-97mw","cve":"CVE-2026-44298","affectedVersions":"\u003E=2.32.0,\u003C=2.55","source":"GitHub","reportedAt":"2026-05-08 22:22:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h5fh-7hwr-97mw"}]},{"advisoryId":"PKSA-zy2k-4hm5-25gd","packageName":"kimai\/kimai","remoteId":"GHSA-vrqv-52x7-rm4v","title":"Kimai\u0027s Twig function config() leaks server-wide secrets (LDAP bind password, SAML SP private key) via invoice\/export templates","link":"https:\/\/github.com\/advisories\/GHSA-vrqv-52x7-rm4v","cve":null,"affectedVersions":"\u003C=2.55.0","source":"GitHub","reportedAt":"2026-05-06 18:42:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vrqv-52x7-rm4v"}]},{"advisoryId":"PKSA-5g91-2cyx-w1s8","packageName":"kimai\/kimai","remoteId":"GHSA-9g2q-w3w2-vf7q","title":"Kimai has Missing Voter Check that Allows Cross-Team Timesheet Manipulation","link":"https:\/\/github.com\/advisories\/GHSA-9g2q-w3w2-vf7q","cve":null,"affectedVersions":"\u003C=2.55.0","source":"GitHub","reportedAt":"2026-05-06 18:28:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9g2q-w3w2-vf7q"}]},{"advisoryId":"PKSA-z4ky-h9pc-hn66","packageName":"kimai\/kimai","remoteId":"GHSA-3xc2-h5r3-wv3r","title":"Kimai vulnerable to formula Injection via tag names in XLSX export","link":"https:\/\/github.com\/advisories\/GHSA-3xc2-h5r3-wv3r","cve":"CVE-2026-42267","affectedVersions":"\u003E=2.27.0,\u003C=2.53.0","source":"GitHub","reportedAt":"2026-05-05 20:53:38","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3xc2-h5r3-wv3r"}]},{"advisoryId":"PKSA-hb9p-xyj3-gfyj","packageName":"kimai\/kimai","remoteId":"GHSA-jv9x-w4gm-hwcm","title":"Kimai has Missing Object-Level Authorization in the Team API","link":"https:\/\/github.com\/advisories\/GHSA-jv9x-w4gm-hwcm","cve":"CVE-2026-41498","affectedVersions":"\u003C2.54.0","source":"GitHub","reportedAt":"2026-04-24 16:17:35","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-jv9x-w4gm-hwcm"}]},{"advisoryId":"PKSA-v9zg-kkkv-rs7x","packageName":"kimai\/kimai","remoteId":"GHSA-jrc6-fmhw-fpq2","title":"Kimai: Username enumeration via timing on X-AUTH-USER","link":"https:\/\/github.com\/advisories\/GHSA-jrc6-fmhw-fpq2","cve":null,"affectedVersions":"\u003C=2.53.0","source":"GitHub","reportedAt":"2026-04-17 22:30:59","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-jrc6-fmhw-fpq2"}]},{"advisoryId":"PKSA-ws9h-wxv9-tvcq","packageName":"kimai\/kimai","remoteId":"GHSA-g82g-m9vx-vhjg","title":"Kimai has Stored XSS via Incomplete HTML Attribute Escaping in Team Member Widget","link":"https:\/\/github.com\/advisories\/GHSA-g82g-m9vx-vhjg","cve":"CVE-2026-40479","affectedVersions":"\u003C2.53.0","source":"GitHub","reportedAt":"2026-04-15 19:46:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g82g-m9vx-vhjg"}]},{"advisoryId":"PKSA-td5w-h5y4-9w1v","packageName":"kimai\/kimai","remoteId":"GHSA-qh43-xrjm-4ggp","title":"Kimai\u0027s User Preferences API allows standard users to modify restricted attributes: hourly_rate, internal_rate","link":"https:\/\/github.com\/advisories\/GHSA-qh43-xrjm-4ggp","cve":"CVE-2026-40486","affectedVersions":"\u003C=2.52.0","source":"GitHub","reportedAt":"2026-04-15 19:46:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qh43-xrjm-4ggp"}]},{"advisoryId":"PKSA-7mgs-q4t6-z3xx","packageName":"kimai\/kimai","remoteId":"GHSA-3jp4-mhh4-gcgr","title":"Kimai has an Open Redirect via Unvalidated RelayState in SAML ACS Handler","link":"https:\/\/github.com\/advisories\/GHSA-3jp4-mhh4-gcgr","cve":null,"affectedVersions":"\u003C=2.52.0","source":"GitHub","reportedAt":"2026-04-14 01:06:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-3jp4-mhh4-gcgr"}]},{"advisoryId":"PKSA-k88g-1gqq-x96c","packageName":"kimai\/kimai","remoteId":"GHSA-rh42-6rj2-xwmc","title":"Kimai leaks API Token Hash via Invoice Twig Template","link":"https:\/\/github.com\/advisories\/GHSA-rh42-6rj2-xwmc","cve":null,"affectedVersions":"\u003C=2.52.0","source":"GitHub","reportedAt":"2026-04-14 01:06:25","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-rh42-6rj2-xwmc"}]},{"advisoryId":"PKSA-j5f5-11n1-y3zr","packageName":"kimai\/kimai","remoteId":"GHSA-v33r-r6h2-8wr7","title":"Kimai\u0027s API invoice endpoint missing customer-level access control (IDOR)","link":"https:\/\/github.com\/advisories\/GHSA-v33r-r6h2-8wr7","cve":"CVE-2026-28685","affectedVersions":"\u003C=2.50.0","source":"GitHub","reportedAt":"2026-03-04 20:43:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-v33r-r6h2-8wr7"}]},{"advisoryId":"PKSA-kh61-fncz-s7b4","packageName":"kimai\/kimai","remoteId":"GHSA-cv8h-r7r5-vwj9","title":"Kimai contains a SameSite cookie vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-cv8h-r7r5-vwj9","cve":"CVE-2023-53957","affectedVersions":"\u003C=1.30.10","source":"GitHub","reportedAt":"2025-12-19 21:30:20","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-cv8h-r7r5-vwj9"}]},{"advisoryId":"PKSA-2hk7-7wzk-4rts","packageName":"kimai\/kimai","remoteId":"GHSA-9278-6hcj-2p4j","title":"Kimai 2 vulnerable to persistent cross-site scripting in the timesheet descriptions","link":"https:\/\/github.com\/advisories\/GHSA-9278-6hcj-2p4j","cve":"CVE-2019-25317","affectedVersions":"\u003C1.1","source":"GitHub","reportedAt":"2026-02-11 15:30:27","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9278-6hcj-2p4j"}]},{"advisoryId":"PKSA-pn9p-tcw8-rbpj","packageName":"kimai\/kimai","remoteId":"GHSA-jg2j-2w24-54cg","title":"Kimai has an Authenticated Server-Side Template Injection (SSTI)","link":"https:\/\/github.com\/advisories\/GHSA-jg2j-2w24-54cg","cve":"CVE-2026-23626","affectedVersions":"\u003C2.46.0","source":"GitHub","reportedAt":"2026-01-20 17:07:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jg2j-2w24-54cg"}]}],"api-platform\/core":[{"advisoryId":"PKSA-3ncz-km6v-5vjr","packageName":"api-platform\/core","remoteId":"GHSA-pjhx-3c3w-9v23","title":"API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate","link":"https:\/\/github.com\/advisories\/GHSA-pjhx-3c3w-9v23","cve":"CVE-2026-49858","affectedVersions":"\u003E=4.3.0,\u003C4.3.8|\u003E=4.2.0,\u003C4.2.25|\u003E=2.6.0,\u003C4.1.29","source":"GitHub","reportedAt":"2026-07-10 14:32:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pjhx-3c3w-9v23"}]}],"api-platform\/json-api":[{"advisoryId":"PKSA-scrq-f2mk-7bhq","packageName":"api-platform\/json-api","remoteId":"GHSA-pjhx-3c3w-9v23","title":"API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate","link":"https:\/\/github.com\/advisories\/GHSA-pjhx-3c3w-9v23","cve":"CVE-2026-49858","affectedVersions":"\u003E=4.3.0,\u003C4.3.8|\u003E=4.2.0,\u003C4.2.25|\u003E=4.0.0,\u003C4.1.29","source":"GitHub","reportedAt":"2026-07-10 14:32:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pjhx-3c3w-9v23"}]}],"api-platform\/hal":[{"advisoryId":"PKSA-9wr7-4vnk-wwmr","packageName":"api-platform\/hal","remoteId":"GHSA-pjhx-3c3w-9v23","title":"API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate","link":"https:\/\/github.com\/advisories\/GHSA-pjhx-3c3w-9v23","cve":"CVE-2026-49858","affectedVersions":"\u003E=4.3.0,\u003C4.3.8|\u003E=4.2.0,\u003C4.2.25|\u003E=4.0.0,\u003C4.1.29","source":"GitHub","reportedAt":"2026-07-10 14:32:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pjhx-3c3w-9v23"}]}],"yeswiki\/yeswiki":[{"advisoryId":"PKSA-7yf2-c2g9-7fm6","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-qg78-vmvc-fhjw","title":"YesWiki: SQL Injection possible through public Bazar entry-listing APIs via numeric `query`\/`queries` filters","link":"https:\/\/github.com\/advisories\/GHSA-qg78-vmvc-fhjw","cve":"CVE-2026-52770","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 21:00:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qg78-vmvc-fhjw"}]},{"advisoryId":"PKSA-tw5z-d3fj-nkdp","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-8f2v-2qhj-gfwg","title":"YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)","link":"https:\/\/github.com\/advisories\/GHSA-8f2v-2qhj-gfwg","cve":"CVE-2026-52771","affectedVersions":"\u003E=4.2.0,\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 21:00:14","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8f2v-2qhj-gfwg"}]},{"advisoryId":"PKSA-p24r-4kjm-tm2m","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-xc7j-3g8q-9vh4","title":"YesWiki has stored XSS in Bazar form-field templates via unescaped field.label \/ field.hint (|raw(\u0027html\u0027))","link":"https:\/\/github.com\/advisories\/GHSA-xc7j-3g8q-9vh4","cve":"CVE-2026-52772","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 21:00:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xc7j-3g8q-9vh4"}]},{"advisoryId":"PKSA-g6jt-6wds-pck7","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-35f3-pg38-486f","title":"YesWiki Vulnerable to Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers\/page\/show.php`","link":"https:\/\/github.com\/advisories\/GHSA-35f3-pg38-486f","cve":"CVE-2026-52773","affectedVersions":"\u003E=4.1.0,\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 21:00:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-35f3-pg38-486f"}]},{"advisoryId":"PKSA-2dyc-2zkh-wzqj","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-r5xw-gcgw-hwp5","title":"YesWiki Vulnerable to Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes","link":"https:\/\/github.com\/advisories\/GHSA-r5xw-gcgw-hwp5","cve":"CVE-2026-52774","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 21:01:10","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r5xw-gcgw-hwp5"}]},{"advisoryId":"PKSA-d3nh-2b2t-1vs7","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-4pf7-cc4r-g63h","title":"YesWiki has Authenticated SQL Injection via ReactionManager ","link":"https:\/\/github.com\/advisories\/GHSA-4pf7-cc4r-g63h","cve":"CVE-2026-52775","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 21:02:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4pf7-cc4r-g63h"}]},{"advisoryId":"PKSA-24cb-kfcr-z2kg","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-9369-69wj-7m2f","title":"YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserialize","link":"https:\/\/github.com\/advisories\/GHSA-9369-69wj-7m2f","cve":"CVE-2026-52777","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 21:02:58","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-9369-69wj-7m2f"}]},{"advisoryId":"PKSA-hr3h-z8mz-dxgy","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-px5m-h76g-p7p8","title":"YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution \u0026 Denial of Service","link":"https:\/\/github.com\/advisories\/GHSA-px5m-h76g-p7p8","cve":"CVE-2026-52778","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 21:03:04","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-px5m-h76g-p7p8"}]},{"advisoryId":"PKSA-yfkg-9hwq-f446","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-65p8-9433-jpcp","title":"YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates","link":"https:\/\/github.com\/advisories\/GHSA-65p8-9433-jpcp","cve":"CVE-2026-52762","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 20:54:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-65p8-9433-jpcp"}]},{"advisoryId":"PKSA-qtt4-qmsv-g7gm","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-89v6-j5x6-cmj3","title":"YesWiki: SQL injection via the `recentchanges` action `period` argument leads to arbitrary DB read","link":"https:\/\/github.com\/advisories\/GHSA-89v6-j5x6-cmj3","cve":"CVE-2026-52763","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 20:54:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-89v6-j5x6-cmj3"}]},{"advisoryId":"PKSA-yjhk-d83g-23md","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-6x7x-gcmf-7r8x","title":"YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action","link":"https:\/\/github.com\/advisories\/GHSA-6x7x-gcmf-7r8x","cve":"CVE-2026-52766","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 20:57:25","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-6x7x-gcmf-7r8x"}]},{"advisoryId":"PKSA-cyw7-d17n-rdq5","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-mv28-wj57-f57g","title":"YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`","link":"https:\/\/github.com\/advisories\/GHSA-mv28-wj57-f57g","cve":"CVE-2026-52767","affectedVersions":"\u003E=4.6.2,\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 20:58:12","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mv28-wj57-f57g"}]},{"advisoryId":"PKSA-hr6j-d2dr-68v5","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-vw42-752g-5mrp","title":"YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`","link":"https:\/\/github.com\/advisories\/GHSA-vw42-752g-5mrp","cve":"CVE-2026-52769","affectedVersions":"\u003E=4.6.2,\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 20:58:33","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vw42-752g-5mrp"}]},{"advisoryId":"PKSA-2myt-jw5p-f7jn","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-jwvv-qr7q-cv8j","title":"YesWiki: Unauthenticated SQL Injection","link":"https:\/\/github.com\/advisories\/GHSA-jwvv-qr7q-cv8j","cve":"CVE-2026-46670","affectedVersions":"\u003C4.6.4","source":"GitHub","reportedAt":"2026-05-22 15:39:07","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-jwvv-qr7q-cv8j"}]},{"advisoryId":"PKSA-n7s9-fhkk-29wv","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-f58v-p6j9-24c2","title":"YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave()","link":"https:\/\/github.com\/advisories\/GHSA-f58v-p6j9-24c2","cve":"CVE-2026-41143","affectedVersions":"\u003C=4.6.0","source":"GitHub","reportedAt":"2026-04-18 01:00:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f58v-p6j9-24c2"}]},{"advisoryId":"PKSA-v42k-yy3p-gtyh","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-5724-x3rh-5qqq","title":"YesWiki has Multiple Reflected Cross-site Scripting Vulnerabilities","link":"https:\/\/github.com\/advisories\/GHSA-5724-x3rh-5qqq","cve":null,"affectedVersions":"\u003C4.6.0","source":"GitHub","reportedAt":"2026-04-01 00:24:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5724-x3rh-5qqq"}]},{"advisoryId":"PKSA-wfcs-d3sq-n6dj","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-37fq-47qj-6j5j","title":"YesWiki has Persistent Blind XSS at \u0022\/?BazaR\u0026vue=consulter\u0022","link":"https:\/\/github.com\/advisories\/GHSA-37fq-47qj-6j5j","cve":"CVE-2026-34598","affectedVersions":"\u003C4.6.0","source":"GitHub","reportedAt":"2026-04-01 00:13:57","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-37fq-47qj-6j5j"}]}],"sylius\/sylius":[{"advisoryId":"PKSA-kjm4-5dkr-g6q7","packageName":"sylius\/sylius","remoteId":"GHSA-5597-7rmh-97q5","title":"Sylius: Cart FormComponent allows modification or deletion of an already-completed order","link":"https:\/\/github.com\/advisories\/GHSA-5597-7rmh-97q5","cve":"CVE-2026-53637","affectedVersions":"\u003E=2.2.0,\u003C2.2.6|\u003E=2.1.0,\u003C2.1.15|\u003E=2.0.0,\u003C2.0.18","source":"GitHub","reportedAt":"2026-07-09 21:03:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5597-7rmh-97q5"}]},{"advisoryId":"PKSA-jgww-gsqm-zy1m","packageName":"sylius\/sylius","remoteId":"GHSA-6955-hrm5-c4qp","title":"Sylius: Channel-based payment method restriction bypass on shop account orders API endpoint","link":"https:\/\/github.com\/advisories\/GHSA-6955-hrm5-c4qp","cve":"CVE-2026-53638","affectedVersions":"\u003E=2.2.0,\u003C2.2.6|\u003E=2.1.0,\u003C2.1.15|\u003E=2.0.0,\u003C2.0.18","source":"GitHub","reportedAt":"2026-07-09 21:03:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6955-hrm5-c4qp"}]},{"advisoryId":"PKSA-6331-fbb1-grmz","packageName":"sylius\/sylius","remoteId":"GHSA-mr9r-h354-966r","title":"Sylius: IDOR on Shop Payment Request API endpoints","link":"https:\/\/github.com\/advisories\/GHSA-mr9r-h354-966r","cve":"CVE-2026-53639","affectedVersions":"\u003E=2.2.0,\u003C2.2.6|\u003E=2.1.0,\u003C2.1.15|\u003E=2.0.0,\u003C2.0.18","source":"GitHub","reportedAt":"2026-07-09 21:03:51","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mr9r-h354-966r"}]},{"advisoryId":"PKSA-6vgh-6nsj-96p4","packageName":"sylius\/sylius","remoteId":"GHSA-9ffx-f77r-756w","title":"Sylius has an Open Redirect via Referer Header","link":"https:\/\/github.com\/advisories\/GHSA-9ffx-f77r-756w","cve":"CVE-2026-31819","affectedVersions":"\u003E=2.2.0,\u003C=2.2.2|\u003E=2.1.0,\u003C=2.1.11|\u003E=2.0.0,\u003C=2.0.15|\u003E=1.14.0,\u003C=1.14.17|\u003E=1.13.0,\u003C=1.13.14|\u003E=1.12.0,\u003C=1.12.22|\u003E=1.11.0,\u003C=1.11.16|\u003E=1.10.0,\u003C=1.10.15|\u003C=1.9.11","source":"GitHub","reportedAt":"2026-03-11 00:12:29","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9ffx-f77r-756w"}]},{"advisoryId":"PKSA-x831-kfr2-97xs","packageName":"sylius\/sylius","remoteId":"GHSA-2xc6-348p-c2x6","title":"Sylius affected by IDOR in Cart and Checkout LiveComponents","link":"https:\/\/github.com\/advisories\/GHSA-2xc6-348p-c2x6","cve":"CVE-2026-31820","affectedVersions":"\u003E=2.2.0,\u003C=2.2.2|\u003E=2.1.0,\u003C=2.1.11|\u003E=2.0.0,\u003C=2.0.15","source":"GitHub","reportedAt":"2026-03-11 00:12:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2xc6-348p-c2x6"}]},{"advisoryId":"PKSA-mmpz-f966-fz1y","packageName":"sylius\/sylius","remoteId":"GHSA-wjmg-4cq5-m8hg","title":"Sylius is Missing Authorization in API v2 Add Item Endpoint","link":"https:\/\/github.com\/advisories\/GHSA-wjmg-4cq5-m8hg","cve":"CVE-2026-31821","affectedVersions":"\u003E=2.2.0,\u003C=2.2.2|\u003E=2.1.0,\u003C=2.1.11|\u003E=2.0.0,\u003C=2.0.15","source":"GitHub","reportedAt":"2026-03-11 00:12:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wjmg-4cq5-m8hg"}]},{"advisoryId":"PKSA-n7z6-xgmt-1wzb","packageName":"sylius\/sylius","remoteId":"GHSA-vgh8-c6fp-7gcg","title":"Sylius has a XSS vulnerability in checkout login form","link":"https:\/\/github.com\/advisories\/GHSA-vgh8-c6fp-7gcg","cve":"CVE-2026-31822","affectedVersions":"\u003E=2.2.0,\u003C=2.2.2|\u003E=2.1.0,\u003C=2.1.11|\u003E=2.0.0,\u003C=2.0.15","source":"GitHub","reportedAt":"2026-03-11 00:13:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vgh8-c6fp-7gcg"}]},{"advisoryId":"PKSA-w86z-tc6z-1np1","packageName":"sylius\/sylius","remoteId":"GHSA-mx4q-xxc9-pf5q","title":"Sylius Vulnerable to Authenticated Stored XSS","link":"https:\/\/github.com\/advisories\/GHSA-mx4q-xxc9-pf5q","cve":"CVE-2026-31823","affectedVersions":"\u003E=2.2.0,\u003C=2.2.2|\u003E=2.1.0,\u003C=2.1.11|\u003E=2.0.0,\u003C=2.0.15","source":"GitHub","reportedAt":"2026-03-11 00:13:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mx4q-xxc9-pf5q"}]},{"advisoryId":"PKSA-xqwf-3qbb-njd6","packageName":"sylius\/sylius","remoteId":"GHSA-7mp4-25j8-hp5q","title":"Sylius has a Promotion Usage Limit Bypass via Race Condition","link":"https:\/\/github.com\/advisories\/GHSA-7mp4-25j8-hp5q","cve":"CVE-2026-31824","affectedVersions":"\u003E=2.2.0,\u003C=2.2.2|\u003E=2.1.0,\u003C=2.1.11|\u003E=2.0.0,\u003C=2.0.15|\u003E=1.14.0,\u003C=1.14.17|\u003E=1.13.0,\u003C=1.13.14|\u003E=1.12.0,\u003C=1.12.22|\u003E=1.11.0,\u003C=1.11.16|\u003E=1.10.0,\u003C=1.10.15|\u003C=1.9.11","source":"GitHub","reportedAt":"2026-03-11 00:13:29","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7mp4-25j8-hp5q"}]},{"advisoryId":"PKSA-6fr5-nks6-h5j2","packageName":"sylius\/sylius","remoteId":"GHSA-xcwx-r2gw-w93m","title":"Sylius has a DQL Injection via API Order Filters","link":"https:\/\/github.com\/advisories\/GHSA-xcwx-r2gw-w93m","cve":"CVE-2026-31825","affectedVersions":"\u003E=2.2.0,\u003C=2.2.2|\u003E=2.1.0,\u003C=2.1.11|\u003E=2.0.0,\u003C=2.0.15|\u003E=1.14.0,\u003C=1.14.17|\u003E=1.13.0,\u003C=1.13.14|\u003E=1.12.0,\u003C=1.12.22|\u003E=1.11.0,\u003C=1.11.16|\u003E=1.10.0,\u003C=1.10.15|\u003C=1.9.11","source":"GitHub","reportedAt":"2026-03-11 00:13:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xcwx-r2gw-w93m"}]},{"advisoryId":"PKSA-b1q1-2jf6-pqt9","packageName":"sylius\/sylius","remoteId":"GHSA-55rf-8q29-4g43","title":"Sylius has a security vulnerability via adjustments API endpoint","link":"https:\/\/github.com\/advisories\/GHSA-55rf-8q29-4g43","cve":"CVE-2024-40633","affectedVersions":"\u003E=1.11.0-alpha.1,\u003C=1.11.16|\u003E=1.10.0-alpha.1,\u003C=1.10.15|\u003C1.9.12|\u003E=1.12.0-alpha.1,\u003C1.12.19|\u003E=1.13.0-alpha.1,\u003C1.13.4","source":"GitHub","reportedAt":"2024-07-17 14:32:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-55rf-8q29-4g43"}]},{"advisoryId":"PKSA-dg69-7wty-b2d6","packageName":"sylius\/sylius","remoteId":"GHSA-v2f9-rv6w-vw8r","title":"Sylius potentially vulnerable to Cross Site Scripting via \u0022Name\u0022 field (Taxons, Products, Options, Variants) in Admin Panel","link":"https:\/\/github.com\/advisories\/GHSA-v2f9-rv6w-vw8r","cve":"CVE-2024-34349","affectedVersions":"\u003E=1.11.0-alpha.1,\u003C1.11.17|\u003E=1.10.0-alpha.1,\u003C1.10.16|\u003C1.9.12|\u003E=1.13.0-alpha.1,\u003C1.13.1|\u003E=1.12.0-alpha.1,\u003C1.12.16","source":"GitHub","reportedAt":"2024-05-10 15:33:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-v2f9-rv6w-vw8r"}]},{"advisoryId":"PKSA-nsc4-mbdg-1r18","packageName":"sylius\/sylius","remoteId":"GHSA-7prj-9ccr-hr3q","title":"Sylius has potential Cross Site Scripting vulnerability via the \u0022Province\u0022 field in the Checkout and Address Book","link":"https:\/\/github.com\/advisories\/GHSA-7prj-9ccr-hr3q","cve":"CVE-2024-29376","affectedVersions":"\u003E=1.11.0-alpha.1,\u003C1.11.17|\u003E=1.10.0-alpha.1,\u003C1.10.16|\u003C1.9.12|\u003E=1.13.0-alpha.1,\u003C1.13.1|\u003E=1.12.0-alpha.1,\u003C1.12.16","source":"GitHub","reportedAt":"2024-05-10 15:33:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7prj-9ccr-hr3q"}]}],"wnx\/laravel-backup-restore":[{"advisoryId":"PKSA-c7fx-vfvm-h6fn","packageName":"wnx\/laravel-backup-restore","remoteId":"GHSA-w9mx-xmg4-gc4r","title":"laravel-backup-restore has an OS Command Injection during database restore","link":"https:\/\/github.com\/advisories\/GHSA-w9mx-xmg4-gc4r","cve":"CVE-2026-53932","affectedVersions":"\u003C=1.9.3","source":"GitHub","reportedAt":"2026-07-09 20:52:57","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w9mx-xmg4-gc4r"}]}],"craftcms\/cms":[{"advisoryId":"PKSA-5x6f-x35f-73db","packageName":"craftcms\/cms","remoteId":"GHSA-c43v-4cr8-6mvp","title":"Craft CMS has authenticated path traversal in `assets\/icon`, allowing local `.svg` file read","link":"https:\/\/github.com\/advisories\/GHSA-c43v-4cr8-6mvp","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.12|\u003E=4.0.0-RC1,\u003C=4.17.6","source":"GitHub","reportedAt":"2026-07-09 13:44:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-c43v-4cr8-6mvp"}]},{"advisoryId":"PKSA-r87g-h2pd-9vq1","packageName":"craftcms\/cms","remoteId":"GHSA-86vw-x4ww-x467","title":"Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview","link":"https:\/\/github.com\/advisories\/GHSA-86vw-x4ww-x467","cve":null,"affectedVersions":"\u003E=5.5.0,\u003C=5.9.13","source":"GitHub","reportedAt":"2026-07-09 13:44:12","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-86vw-x4ww-x467"}]},{"advisoryId":"PKSA-z4vj-1h29-pkrc","packageName":"craftcms\/cms","remoteId":"GHSA-xrqc-p465-2xvg","title":"Craft CMS: Stored XSS via Structure entry title in table view","link":"https:\/\/github.com\/advisories\/GHSA-xrqc-p465-2xvg","cve":"CVE-2026-55793","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.9.22","source":"GitHub","reportedAt":"2026-07-06 21:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xrqc-p465-2xvg"}]},{"advisoryId":"PKSA-hvdm-8k9p-kcdw","packageName":"craftcms\/cms","remoteId":"GHSA-f74w-488g-8x5r","title":"Craft CMS: Potential authenticated Remote Code Execution via referrer redirect","link":"https:\/\/github.com\/advisories\/GHSA-f74w-488g-8x5r","cve":"CVE-2026-55794","affectedVersions":"\u003E=5.9.0,\u003C5.10.0","source":"GitHub","reportedAt":"2026-07-06 21:37:06","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f74w-488g-8x5r"}]},{"advisoryId":"PKSA-hm4p-n9yk-nz2c","packageName":"craftcms\/cms","remoteId":"GHSA-24x4-j6x9-rfw5","title":"Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget","link":"https:\/\/github.com\/advisories\/GHSA-24x4-j6x9-rfw5","cve":"CVE-2026-55790","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.15|\u003E=5.0.0-RC1,\u003C5.9.22","source":"GitHub","reportedAt":"2026-07-06 21:29:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-24x4-j6x9-rfw5"}]},{"advisoryId":"PKSA-rvh7-y4k6-cn59","packageName":"craftcms\/cms","remoteId":"GHSA-287w-mxq6-x2cp","title":"Craft CMS: Sensitive File Disclosure \/ Server-Side File Read","link":"https:\/\/github.com\/advisories\/GHSA-287w-mxq6-x2cp","cve":"CVE-2026-55792","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.0|\u003E=4.0.0-RC1,\u003C4.18.0","source":"GitHub","reportedAt":"2026-07-06 21:29:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-287w-mxq6-x2cp"}]},{"advisoryId":"PKSA-pqnm-5q4k-cx7j","packageName":"craftcms\/cms","remoteId":"GHSA-x76w-8c62-48mg","title":"Craft CMS: Authenticated \u0022assets\/preview-thumb\u0022 discloses signed fallback transform preview link to CP users without asset-view permission","link":"https:\/\/github.com\/advisories\/GHSA-x76w-8c62-48mg","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.13|\u003E=4.0.0-RC1,\u003C=4.17.7","source":"GitHub","reportedAt":"2026-07-06 20:28:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x76w-8c62-48mg"}]},{"advisoryId":"PKSA-zn8p-45f7-kgv1","packageName":"craftcms\/cms","remoteId":"GHSA-x5m4-g2cq-52pq","title":"Craft CMS\u0027s mass assignment via id in newAttributes during bulk duplicate overwrites existing elements","link":"https:\/\/github.com\/advisories\/GHSA-x5m4-g2cq-52pq","cve":"CVE-2026-50281","affectedVersions":"\u003E=5.7.0,\u003C5.9.21","source":"GitHub","reportedAt":"2026-07-02 20:03:36","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-x5m4-g2cq-52pq"}]},{"advisoryId":"PKSA-9z7r-2kcf-76cf","packageName":"craftcms\/cms","remoteId":"GHSA-3w32-23wj-rxg3","title":"Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves","link":"https:\/\/github.com\/advisories\/GHSA-3w32-23wj-rxg3","cve":"CVE-2026-50282","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.14|\u003E=5.0.0-RC1,\u003C5.9.21","source":"GitHub","reportedAt":"2026-07-02 20:03:58","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3w32-23wj-rxg3"}]},{"advisoryId":"PKSA-rg3c-2r2k-sf93","packageName":"craftcms\/cms","remoteId":"GHSA-qq2c-2q8j-jh27","title":"Craft CMS: Authorship spoofing in `entries\/save-entry` via pre-check\/post-mutation authorization gap","link":"https:\/\/github.com\/advisories\/GHSA-qq2c-2q8j-jh27","cve":"CVE-2026-50279","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.9.21","source":"GitHub","reportedAt":"2026-07-02 18:45:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qq2c-2q8j-jh27"}]},{"advisoryId":"PKSA-nhns-q2yx-ct2v","packageName":"craftcms\/cms","remoteId":"GHSA-43cq-c2gq-pfpw","title":"Craft CMS: Authorization bypass in `entries\/move-to-section` via missing target-section save check","link":"https:\/\/github.com\/advisories\/GHSA-43cq-c2gq-pfpw","cve":"CVE-2026-50280","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.9.21","source":"GitHub","reportedAt":"2026-07-02 18:47:37","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-43cq-c2gq-pfpw"}]},{"advisoryId":"PKSA-68rr-18x7-w4gg","packageName":"craftcms\/cms","remoteId":"GHSA-qh45-9g5p-m2v4","title":"Craft CMS: Unauthorized Deletion of Source Assets During File Replacement","link":"https:\/\/github.com\/advisories\/GHSA-qh45-9g5p-m2v4","cve":"CVE-2026-50283","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.14|\u003E=5.0.0-RC1,\u003C5.9.21","source":"GitHub","reportedAt":"2026-07-02 18:48:27","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qh45-9g5p-m2v4"}]},{"advisoryId":"PKSA-fd42-dyd4-g3dq","packageName":"craftcms\/cms","remoteId":"GHSA-7h62-6v23-v8fm","title":"Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users\u0027 assets","link":"https:\/\/github.com\/advisories\/GHSA-7h62-6v23-v8fm","cve":"CVE-2026-50284","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.15|\u003E=5.0.0-RC1,\u003C5.9.22","source":"GitHub","reportedAt":"2026-07-02 18:49:04","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7h62-6v23-v8fm"}]},{"advisoryId":"PKSA-5xds-5mf3-ckxn","packageName":"craftcms\/cms","remoteId":"GHSA-c55v-343g-5xff","title":"Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs","link":"https:\/\/github.com\/advisories\/GHSA-c55v-343g-5xff","cve":"CVE-2026-55791","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18|\u003E=5.0.0-RC1,\u003C5.10","source":"GitHub","reportedAt":"2026-06-19 21:15:19","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-c55v-343g-5xff"}]},{"advisoryId":"PKSA-7b21-z11x-97gc","packageName":"craftcms\/cms","remoteId":"GHSA-qrgm-p9w5-rrfw","title":"Craft CMS has Potential Authenticated Remote Code Execution via Malicious Attached Behavior","link":"https:\/\/github.com\/advisories\/GHSA-qrgm-p9w5-rrfw","cve":"CVE-2026-44011","affectedVersions":"\u003E=5.0.0,\u003C5.9.18|\u003E=4.0.0,\u003C4.17.12","source":"GitHub","reportedAt":"2026-05-06 17:54:06","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qrgm-p9w5-rrfw"}]},{"advisoryId":"PKSA-tj2m-c963-6jtt","packageName":"craftcms\/cms","remoteId":"GHSA-33m5-hqp9-97pw","title":"Craft CMS\u0027s Missing Volume Permission Check in AssetsController::actionShowInFolder Allows Information Disclosure","link":"https:\/\/github.com\/advisories\/GHSA-33m5-hqp9-97pw","cve":"CVE-2026-44012","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.9.18","source":"GitHub","reportedAt":"2026-05-06 17:54:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-33m5-hqp9-97pw"}]},{"advisoryId":"PKSA-sxz1-z4jg-2vhh","packageName":"craftcms\/cms","remoteId":"GHSA-gj2p-p9m4-c8gw","title":"Craft CMS\u0027s Missing Authorization in GraphQL Address Resolver Allows Cross-Scope PII Disclosure","link":"https:\/\/github.com\/advisories\/GHSA-gj2p-p9m4-c8gw","cve":"CVE-2026-44010","affectedVersions":"\u003E=4.0.0,\u003C4.17.12|\u003E=5.0.0,\u003C5.9.18","source":"GitHub","reportedAt":"2026-05-06 17:49:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gj2p-p9m4-c8gw"}]},{"advisoryId":"PKSA-dmwd-n76s-m3f9","packageName":"craftcms\/cms","remoteId":"GHSA-jq2f-59pj-p3m3","title":"Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action","link":"https:\/\/github.com\/advisories\/GHSA-jq2f-59pj-p3m3","cve":"CVE-2026-41128","affectedVersions":"\u003E=5.6.0,\u003C5.9.15","source":"GitHub","reportedAt":"2026-04-14 23:34:52","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jq2f-59pj-p3m3"}]},{"advisoryId":"PKSA-wb3t-ts8t-d4cj","packageName":"craftcms\/cms","remoteId":"GHSA-3m9m-24vh-39wx","title":"Server-Side Request Forgery (SSRF) in Craft CMS with Asset Uploads Mutations","link":"https:\/\/github.com\/advisories\/GHSA-3m9m-24vh-39wx","cve":"CVE-2026-41129","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.17.8|\u003E=5.0.0-RC1,\u003C=5.9.14","source":"GitHub","reportedAt":"2026-04-14 23:35:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3m9m-24vh-39wx"}]},{"advisoryId":"PKSA-ntd3-69q5-4cfy","packageName":"craftcms\/cms","remoteId":"GHSA-95wr-3f2v-v2wh","title":"Craft CMS has a host header injection leading to SSRF via resource-js endpoint","link":"https:\/\/github.com\/advisories\/GHSA-95wr-3f2v-v2wh","cve":"CVE-2026-41130","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.17.8|\u003E=5.0.0-RC1,\u003C=5.9.14","source":"GitHub","reportedAt":"2026-04-14 23:36:09","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-95wr-3f2v-v2wh"}]},{"advisoryId":"PKSA-hq3k-cthz-b9zn","packageName":"craftcms\/cms","remoteId":"GHSA-44px-qjjc-xrhq","title":"Craft CMS: Authorized asset \u0022preview file\u0022 requests bypass allows users without asset access to retrieve private preview metadata","link":"https:\/\/github.com\/advisories\/GHSA-44px-qjjc-xrhq","cve":null,"affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.17.7|\u003E=5.0.0-RC1,\u003C=5.9.13","source":"GitHub","reportedAt":"2026-03-26 17:12:21","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-44px-qjjc-xrhq"}]},{"advisoryId":"PKSA-w984-dygq-7ryn","packageName":"craftcms\/cms","remoteId":"GHSA-vgjg-248p-rfm2","title":"Craft CMS\u0027 anonymous \u0022assets\/image-editor\u0022 calls return private asset editor metadata to unauthorized users","link":"https:\/\/github.com\/advisories\/GHSA-vgjg-248p-rfm2","cve":"CVE-2026-33161","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.17.7|\u003E=5.0.0-RC1,\u003C=5.9.13","source":"GitHub","reportedAt":"2026-03-24 17:27:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-vgjg-248p-rfm2"}]},{"advisoryId":"PKSA-7c6f-2hwc-ptwd","packageName":"craftcms\/cms","remoteId":"GHSA-f582-6gf6-gx4g","title":"Craft CMS has an authorization bypass which allows any control panel user to move entries without permissions","link":"https:\/\/github.com\/advisories\/GHSA-f582-6gf6-gx4g","cve":"CVE-2026-33162","affectedVersions":"\u003E=5.3.0,\u003C=5.9.13","source":"GitHub","reportedAt":"2026-03-24 17:28:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f582-6gf6-gx4g"}]},{"advisoryId":"PKSA-twkq-r2c1-87qq","packageName":"craftcms\/cms","remoteId":"GHSA-2fph-6v5w-89hh","title":"Craft CMS is Vulnerable to Authenticated Remote Code Execution via Malicious Attached Behavior","link":"https:\/\/github.com\/advisories\/GHSA-2fph-6v5w-89hh","cve":"CVE-2026-33157","affectedVersions":"\u003E=5.6.0,\u003C=5.9.12","source":"GitHub","reportedAt":"2026-03-24 16:50:42","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2fph-6v5w-89hh"}]},{"advisoryId":"PKSA-548y-fsbg-y9t7","packageName":"craftcms\/cms","remoteId":"GHSA-3pvf-vxrv-hh9c","title":"Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)","link":"https:\/\/github.com\/advisories\/GHSA-3pvf-vxrv-hh9c","cve":"CVE-2026-33158","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.13|\u003E=4.0.0-RC1,\u003C=4.17.7","source":"GitHub","reportedAt":"2026-03-24 16:53:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3pvf-vxrv-hh9c"}]},{"advisoryId":"PKSA-rxrx-pcy1-2csw","packageName":"craftcms\/cms","remoteId":"GHSA-6mrr-q3pj-h53w","title":"Craft CMS: Unauthenticated Users Can Perform Restricted Project Config Sync Operations","link":"https:\/\/github.com\/advisories\/GHSA-6mrr-q3pj-h53w","cve":"CVE-2026-33159","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.17.7|\u003E=5.0.0-RC1,\u003C=5.9.13","source":"GitHub","reportedAt":"2026-03-24 16:57:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6mrr-q3pj-h53w"}]},{"advisoryId":"PKSA-swp1-ty4d-gpzy","packageName":"craftcms\/cms","remoteId":"GHSA-5pgf-h923-m958","title":"Craft CMS may expose private assets through anonymous \u0022generate transform\u0022 calls via transform URL","link":"https:\/\/github.com\/advisories\/GHSA-5pgf-h923-m958","cve":"CVE-2026-33160","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.17.7|\u003E=5.0.0-RC1,\u003C=5.9.13","source":"GitHub","reportedAt":"2026-03-24 16:59:58","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-5pgf-h923-m958"}]},{"advisoryId":"PKSA-1n7m-zdqf-4n15","packageName":"craftcms\/cms","remoteId":"GHSA-3x4w-mxpf-fhqq","title":"Craft CMS Vulnerable to Stored XSS in Revision Context Menu","link":"https:\/\/github.com\/advisories\/GHSA-3x4w-mxpf-fhqq","cve":"CVE-2026-33051","affectedVersions":"\u003E=5.9.0-beta.1,\u003C=5.9.10","source":"GitHub","reportedAt":"2026-03-18 12:58:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3x4w-mxpf-fhqq"}]},{"advisoryId":"PKSA-s8c8-j6wr-t4ds","packageName":"craftcms\/cms","remoteId":"GHSA-cc7p-2j3x-x7xf","title":"Craft CMS Vulnerable to Privilege Escalation\/Bypass through UsersController-\u003EactionImpersonateWithToken()","link":"https:\/\/github.com\/advisories\/GHSA-cc7p-2j3x-x7xf","cve":"CVE-2026-32267","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.11|\u003E=4.0.0-RC1,\u003C=4.17.5","source":"GitHub","reportedAt":"2026-03-16 18:44:20","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-cc7p-2j3x-x7xf"}]},{"advisoryId":"PKSA-y7v4-m2bd-8h2y","packageName":"craftcms\/cms","remoteId":"GHSA-472v-j2g4-g9h2","title":"Craft CMS has a Path Traversal Vulnerability in AssetsController","link":"https:\/\/github.com\/advisories\/GHSA-472v-j2g4-g9h2","cve":"CVE-2026-32262","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.10|\u003E=4.0.0-RC1,\u003C=4.17.4","source":"GitHub","reportedAt":"2026-03-16 18:11:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-472v-j2g4-g9h2"}]},{"advisoryId":"PKSA-1n2n-7k4d-96rt","packageName":"craftcms\/cms","remoteId":"GHSA-qx2q-q59v-wf3j","title":"Craft CMS vulnerable to behavior injection RCE via EntryTypesController","link":"https:\/\/github.com\/advisories\/GHSA-qx2q-q59v-wf3j","cve":"CVE-2026-32263","affectedVersions":"\u003E=5.6.0,\u003C=5.9.10","source":"GitHub","reportedAt":"2026-03-16 18:12:32","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qx2q-q59v-wf3j"}]},{"advisoryId":"PKSA-1qxd-z2sm-yssc","packageName":"craftcms\/cms","remoteId":"GHSA-4484-8v2f-5748","title":"Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController","link":"https:\/\/github.com\/advisories\/GHSA-4484-8v2f-5748","cve":"CVE-2026-32264","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.10|\u003E=4.0.0-RC1,\u003C=4.17.4","source":"GitHub","reportedAt":"2026-03-16 18:13:15","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4484-8v2f-5748"}]},{"advisoryId":"PKSA-w79g-q9vy-mw7b","packageName":"craftcms\/cms","remoteId":"GHSA-fp5j-j7j4-mcxc","title":"CraftCMS has an RCE vulnerability via relational conditionals in the control panel","link":"https:\/\/github.com\/advisories\/GHSA-fp5j-j7j4-mcxc","cve":"CVE-2026-31857","affectedVersions":"\u003E=4.0.0-beta.1,\u003C=4.17.3|\u003E=5.0.0-RC1,\u003C=5.9.8","source":"GitHub","reportedAt":"2026-03-11 14:56:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fp5j-j7j4-mcxc"}]},{"advisoryId":"PKSA-sc5m-6n1y-h7vz","packageName":"craftcms\/cms","remoteId":"GHSA-g3hp-vvqf-8vw6","title":"Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page","link":"https:\/\/github.com\/advisories\/GHSA-g3hp-vvqf-8vw6","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.8.21","source":"GitHub","reportedAt":"2026-03-11 14:56:59","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-g3hp-vvqf-8vw6"}]},{"advisoryId":"PKSA-t9v1-2frg-d2wy","packageName":"craftcms\/cms","remoteId":"GHSA-fvwq-45qv-xvhv","title":"CraftCMS vulnerable to reflective XSS via incomplete return URL sanitization","link":"https:\/\/github.com\/advisories\/GHSA-fvwq-45qv-xvhv","cve":"CVE-2026-31859","affectedVersions":"\u003E=5.7.5,\u003C=5.9.6|\u003E=4.15.3,\u003C=4.17.2","source":"GitHub","reportedAt":"2026-03-11 00:26:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fvwq-45qv-xvhv"}]},{"advisoryId":"PKSA-2bdn-bpjn-j9q4","packageName":"craftcms\/cms","remoteId":"GHSA-g7j6-fmwx-7vp8","title":"CraftCMS\u0027s `ElementSearchController` Affected by Blind SQL Injection","link":"https:\/\/github.com\/advisories\/GHSA-g7j6-fmwx-7vp8","cve":"CVE-2026-31858","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.8","source":"GitHub","reportedAt":"2026-03-11 00:27:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g7j6-fmwx-7vp8"}]},{"advisoryId":"PKSA-24yr-dkzm-n9v5","packageName":"craftcms\/cms","remoteId":"GHSA-vg3j-hpm9-8v5v","title":"Craft CMS has a potential information disclosure vulnerability in preview tokens","link":"https:\/\/github.com\/advisories\/GHSA-vg3j-hpm9-8v5v","cve":"CVE-2026-29113","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.9.6|\u003E=4.0.0-RC1,\u003C4.17.3","source":"GitHub","reportedAt":"2026-03-10 18:22:02","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-vg3j-hpm9-8v5v"}]},{"advisoryId":"PKSA-s2xd-twzp-9yz7","packageName":"craftcms\/cms","remoteId":"GHSA-234q-vvw3-mrfq","title":"Craft CMS has unauthenticated activation email trigger with potential user enumeration","link":"https:\/\/github.com\/advisories\/GHSA-234q-vvw3-mrfq","cve":"CVE-2026-29069","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.0-beta.2|\u003E=5.0.0-RC1,\u003C5.9.0-beta.2","source":"GitHub","reportedAt":"2026-03-04 20:52:31","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-234q-vvw3-mrfq"}]},{"advisoryId":"PKSA-jqb9-4xf5-mdn1","packageName":"craftcms\/cms","remoteId":"GHSA-v47q-jxvr-p68x","title":"Craft CMS Vulnerable to Authenticated RCE via \u0022craft.app.fs.write()\u0022 in Twig Templates","link":"https:\/\/github.com\/advisories\/GHSA-v47q-jxvr-p68x","cve":"CVE-2026-28697","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.0-beta.1|\u003E=5.0.0-RC1,\u003C5.9.0-beta.1","source":"GitHub","reportedAt":"2026-03-03 21:00:16","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-v47q-jxvr-p68x"}]},{"advisoryId":"PKSA-zp4z-c8gp-zpww","packageName":"craftcms\/cms","remoteId":"GHSA-2xfc-g69j-x2mp","title":"Craft CMS: Entries Authorship Spoofing via Mass Assignment","link":"https:\/\/github.com\/advisories\/GHSA-2xfc-g69j-x2mp","cve":"CVE-2026-28781","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.0-beta.1|\u003E=5.0.0-RC1,\u003C5.9.0-beta.1","source":"GitHub","reportedAt":"2026-03-03 21:00:51","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2xfc-g69j-x2mp"}]},{"advisoryId":"PKSA-x1f7-3vrt-jvfj","packageName":"craftcms\/cms","remoteId":"GHSA-5fvc-7894-ghp4","title":"Craft CMS has Twig Function Blocklist Bypass","link":"https:\/\/github.com\/advisories\/GHSA-5fvc-7894-ghp4","cve":"CVE-2026-28783","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.0-beta.1|\u003E=5.0.0-RC1,\u003C5.9.0-beta.1","source":"GitHub","reportedAt":"2026-03-03 21:01:27","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5fvc-7894-ghp4"}]},{"advisoryId":"PKSA-c1gj-84dj-vvh3","packageName":"craftcms\/cms","remoteId":"GHSA-jxm3-pmm2-9gf6","title":"Craft CMS has Permission Bypass and IDOR in Duplicate Entry Action","link":"https:\/\/github.com\/advisories\/GHSA-jxm3-pmm2-9gf6","cve":"CVE-2026-28782","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.0-beta.1|\u003E=5.0.0-RC1,\u003C5.9.0-beta.1","source":"GitHub","reportedAt":"2026-03-03 21:05:12","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jxm3-pmm2-9gf6"}]},{"advisoryId":"PKSA-q22m-n7fg-cqgy","packageName":"craftcms\/cms","remoteId":"GHSA-qc86-q28f-ggww","title":"Craft CMS has potential authenticated Remote Code Execution via Twig SSTI","link":"https:\/\/github.com\/advisories\/GHSA-qc86-q28f-ggww","cve":"CVE-2026-28784","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.0-beta.1|\u003E=5.0.0-RC1,\u003C5.9.0-beta.1","source":"GitHub","reportedAt":"2026-03-03 21:06:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qc86-q28f-ggww"}]},{"advisoryId":"PKSA-skz7-x8dk-h7t1","packageName":"craftcms\/cms","remoteId":"GHSA-4mgv-366x-qxvx","title":"Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options","link":"https:\/\/github.com\/advisories\/GHSA-4mgv-366x-qxvx","cve":null,"affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.0-beta.1|\u003E=5.0.0-RC1,\u003C5.9.0-beta.1","source":"GitHub","reportedAt":"2026-03-03 20:58:07","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-4mgv-366x-qxvx"}]},{"advisoryId":"PKSA-n7dz-mnbq-y23y","packageName":"craftcms\/cms","remoteId":"GHSA-94rc-cqvm-m4pw","title":"Craft CMS Vulnerable to Authenticated RCE via Twig SSTI - create() function + Symfony Process gadget","link":"https:\/\/github.com\/advisories\/GHSA-94rc-cqvm-m4pw","cve":"CVE-2026-28695","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.0-beta.1|\u003E=5.8.7,\u003C5.9.0-beta.1","source":"GitHub","reportedAt":"2026-03-03 20:30:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-94rc-cqvm-m4pw"}]},{"advisoryId":"PKSA-ts3n-khxn-xyvm","packageName":"craftcms\/cms","remoteId":"GHSA-7x43-mpfg-r9wj","title":"Craft CMS has IDOR via GraphQL @parseRefs","link":"https:\/\/github.com\/advisories\/GHSA-7x43-mpfg-r9wj","cve":"CVE-2026-28696","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.9.0-beta.1|\u003E=4.0.0-RC1,\u003C4.17.0-beta.1","source":"GitHub","reportedAt":"2026-03-03 20:38:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7x43-mpfg-r9wj"}]},{"advisoryId":"PKSA-cf9h-wtzj-5nwd","packageName":"craftcms\/cms","remoteId":"GHSA-6j87-m5qx-9fqp","title":"Craft CMS has Stored XSS in Table Field in its \u0022Row Heading\u0022 Column Type","link":"https:\/\/github.com\/advisories\/GHSA-6j87-m5qx-9fqp","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.8.22|\u003E=4.5.0-beta.1,\u003C=4.16.18","source":"GitHub","reportedAt":"2026-02-25 19:11:31","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-6j87-m5qx-9fqp"}]},{"advisoryId":"PKSA-qgft-95tr-t5vt","packageName":"craftcms\/cms","remoteId":"GHSA-v2gc-rm6g-wrw9","title":"Craft CMS: Cloud Metadata SSRF Protection Bypass via IPv6 Resolution","link":"https:\/\/github.com\/advisories\/GHSA-v2gc-rm6g-wrw9","cve":"CVE-2026-27129","affectedVersions":"\u003E=3.5.0,\u003C=4.16.18|\u003E=5.0.0-RC1,\u003C=5.8.22","source":"GitHub","reportedAt":"2026-02-24 15:51:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-v2gc-rm6g-wrw9"}]},{"advisoryId":"PKSA-knkq-h2rk-yc48","packageName":"craftcms\/cms","remoteId":"GHSA-3jh3-prx3-w6wc","title":"Craft CMS has Stored XSS in Table Field via \u0022HTML\u0022 Column Type","link":"https:\/\/github.com\/advisories\/GHSA-3jh3-prx3-w6wc","cve":"CVE-2026-27126","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.8.22|\u003E=4.5.0-RC1,\u003C=4.16.18","source":"GitHub","reportedAt":"2026-02-23 22:15:03","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3jh3-prx3-w6wc"}]},{"advisoryId":"PKSA-ycmx-j7s8-wyxz","packageName":"craftcms\/cms","remoteId":"GHSA-gp2f-7wcm-5fhx","title":"Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding","link":"https:\/\/github.com\/advisories\/GHSA-gp2f-7wcm-5fhx","cve":"CVE-2026-27127","affectedVersions":"\u003E=3.5.0,\u003C=4.16.18|\u003E=5.0.0-RC1,\u003C=5.8.22","source":"GitHub","reportedAt":"2026-02-23 22:16:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gp2f-7wcm-5fhx"}]},{"advisoryId":"PKSA-k33k-b5qw-yqgp","packageName":"craftcms\/cms","remoteId":"GHSA-6fx5-5cw5-4897","title":"Craft CMS Race condition in Token Service potentially allows for token usage greater than the token limit","link":"https:\/\/github.com\/advisories\/GHSA-6fx5-5cw5-4897","cve":"CVE-2026-27128","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.8.22|\u003E=4.5.0-RC1,\u003C=4.16.18","source":"GitHub","reportedAt":"2026-02-23 22:16:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6fx5-5cw5-4897"}]},{"advisoryId":"PKSA-v2dw-c4ss-13bw","packageName":"craftcms\/cms","remoteId":"GHSA-7pr4-wx9w-mqwr","title":"Craft CMS Vulnerable to Stored XSS in Entry Types Name","link":"https:\/\/github.com\/advisories\/GHSA-7pr4-wx9w-mqwr","cve":"CVE-2026-25491","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.8.21","source":"GitHub","reportedAt":"2026-02-09 20:35:10","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7pr4-wx9w-mqwr"}]},{"advisoryId":"PKSA-1dbt-xzgs-7gw8","packageName":"craftcms\/cms","remoteId":"GHSA-8jr8-7hr4-vhfx","title":"Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via HTTP Redirect","link":"https:\/\/github.com\/advisories\/GHSA-8jr8-7hr4-vhfx","cve":"CVE-2026-25493","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.16.17|\u003E=5.0.0-RC1,\u003C=5.8.21","source":"GitHub","reportedAt":"2026-02-09 20:35:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8jr8-7hr4-vhfx"}]},{"advisoryId":"PKSA-jsy4-k6z3-fcjb","packageName":"craftcms\/cms","remoteId":"GHSA-m5r2-8p9x-hp5m","title":"Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via Alternative IP Notation","link":"https:\/\/github.com\/advisories\/GHSA-m5r2-8p9x-hp5m","cve":"CVE-2026-25494","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.16.17|\u003E=5.0.0-RC1,\u003C=5.8.21","source":"GitHub","reportedAt":"2026-02-09 20:35:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m5r2-8p9x-hp5m"}]},{"advisoryId":"PKSA-9dtd-sv51-7pmx","packageName":"craftcms\/cms","remoteId":"GHSA-2453-mppf-46cj","title":"Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`","link":"https:\/\/github.com\/advisories\/GHSA-2453-mppf-46cj","cve":"CVE-2026-25495","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.16.17|\u003E=5.0.0-RC1,\u003C=5.8.21","source":"GitHub","reportedAt":"2026-02-09 20:35:41","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2453-mppf-46cj"}]},{"advisoryId":"PKSA-5pj5-nxp6-547h","packageName":"craftcms\/cms","remoteId":"GHSA-9f5h-mmq6-2x78","title":"Craft CMS Vulnerable to Stored XSS in Number Prefix \u0026 Suffix Fields","link":"https:\/\/github.com\/advisories\/GHSA-9f5h-mmq6-2x78","cve":"CVE-2026-25496","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.16.17|\u003E=5.0.0-RC1,\u003C=5.8.21","source":"GitHub","reportedAt":"2026-02-09 20:35:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9f5h-mmq6-2x78"}]},{"advisoryId":"PKSA-zjy6-pdtw-mck8","packageName":"craftcms\/cms","remoteId":"GHSA-fxp3-g6gw-4r4v","title":"Craft CMS: GraphQL Asset Mutation Privilege Escalation","link":"https:\/\/github.com\/advisories\/GHSA-fxp3-g6gw-4r4v","cve":"CVE-2026-25497","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.0-beta.1|\u003E=5.0.0-RC1,\u003C5.9.0-beta.1","source":"GitHub","reportedAt":"2026-02-09 20:36:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fxp3-g6gw-4r4v"}]},{"advisoryId":"PKSA-g2n6-j3mn-x8xf","packageName":"craftcms\/cms","remoteId":"GHSA-7jx7-3846-m7w7","title":"Craft CMS Vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior","link":"https:\/\/github.com\/advisories\/GHSA-7jx7-3846-m7w7","cve":"CVE-2026-25498","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.16.17|\u003E=5.0.0-RC1,\u003C=5.8.21","source":"GitHub","reportedAt":"2026-02-09 20:36:43","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7jx7-3846-m7w7"}]},{"advisoryId":"PKSA-hcvs-d728-5zyw","packageName":"craftcms\/cms","remoteId":"GHSA-255j-qw47-wjh5","title":"Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior","link":"https:\/\/github.com\/advisories\/GHSA-255j-qw47-wjh5","cve":"CVE-2025-68455","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.16.16|\u003E=5.0.0-RC1,\u003C=5.8.20","source":"GitHub","reportedAt":"2026-01-05 18:50:14","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-255j-qw47-wjh5"}]},{"advisoryId":"PKSA-17hr-tk5g-ht8k","packageName":"craftcms\/cms","remoteId":"GHSA-v64r-7wg9-23pr","title":"Unauthenticated Craft CMS users can trigger a database backup","link":"https:\/\/github.com\/advisories\/GHSA-v64r-7wg9-23pr","cve":"CVE-2025-68456","affectedVersions":"\u003E=3.0.0,\u003C=4.16.16|\u003E=5.0.0-RC1,\u003C=5.8.20","source":"GitHub","reportedAt":"2026-01-05 18:49:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v64r-7wg9-23pr"}]},{"advisoryId":"PKSA-9rbz-gy92-qjtd","packageName":"craftcms\/cms","remoteId":"GHSA-742x-x762-7383","title":"Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI","link":"https:\/\/github.com\/advisories\/GHSA-742x-x762-7383","cve":"CVE-2025-68454","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.16.16|\u003E=5.0.0-RC1,\u003C=5.8.20","source":"GitHub","reportedAt":"2026-01-05 18:10:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-742x-x762-7383"}]},{"advisoryId":"PKSA-4gr3-459g-ssmq","packageName":"craftcms\/cms","remoteId":"GHSA-x27p-wfqw-hfcc","title":"Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation","link":"https:\/\/github.com\/advisories\/GHSA-x27p-wfqw-hfcc","cve":"CVE-2025-68437","affectedVersions":"\u003E=3.5.0,\u003C=4.16.16|\u003E=5.0.0-RC1,\u003C=5.8.20","source":"GitHub","reportedAt":"2026-01-05 18:02:37","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x27p-wfqw-hfcc"}]},{"advisoryId":"PKSA-yj3g-znh5-93sd","packageName":"craftcms\/cms","remoteId":"GHSA-53vf-c43h-j2x9","title":"Craft CMS vulnerable to potential information disclosure via unchecked asset relocation","link":"https:\/\/github.com\/advisories\/GHSA-53vf-c43h-j2x9","cve":"CVE-2025-68436","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.16.16|\u003E=5.0.0-RC1,\u003C=5.8.20","source":"GitHub","reportedAt":"2026-01-05 17:42:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-53vf-c43h-j2x9"}]}],"admidio\/admidio":[{"advisoryId":"PKSA-84pc-hcqd-7brb","packageName":"admidio\/admidio","remoteId":"GHSA-hm42-q32m-vj4f","title":"Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET Requests","link":"https:\/\/github.com\/advisories\/GHSA-hm42-q32m-vj4f","cve":"CVE-2026-53760","affectedVersions":"\u003C=5.0.11","source":"GitHub","reportedAt":"2026-07-09 13:44:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hm42-q32m-vj4f"}]},{"advisoryId":"PKSA-7hzm-szv2-dny3","packageName":"admidio\/admidio","remoteId":"GHSA-xg76-5qj2-2hhv","title":"Admidio: CSRF in SSO client `enable` action toggles SAML\/OIDC clients without token validation","link":"https:\/\/github.com\/advisories\/GHSA-xg76-5qj2-2hhv","cve":"CVE-2026-47229","affectedVersions":"\u003C=5.0.9","source":"GitHub","reportedAt":"2026-05-29 22:01:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xg76-5qj2-2hhv"}]},{"advisoryId":"PKSA-hs5n-pnrm-d3b9","packageName":"admidio\/admidio","remoteId":"GHSA-q6w3-hpfv-rg36","title":"Admidio: IDOR in documents-files.php allows cross-folder file rename and description changes by unauthorized uploaders","link":"https:\/\/github.com\/advisories\/GHSA-q6w3-hpfv-rg36","cve":"CVE-2026-47230","affectedVersions":"\u003C=5.0.9","source":"GitHub","reportedAt":"2026-05-29 22:05:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q6w3-hpfv-rg36"}]},{"advisoryId":"PKSA-3qmd-8hcr-xs96","packageName":"admidio\/admidio","remoteId":"GHSA-x628-457g-2pw9","title":"Admidio has IDOR in `documents-files.php` `mode=move_save` that lets any folder-uploader exfiltrate files from private folders","link":"https:\/\/github.com\/advisories\/GHSA-x628-457g-2pw9","cve":"CVE-2026-47231","affectedVersions":"\u003C=5.0.9","source":"GitHub","reportedAt":"2026-05-29 22:06:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-x628-457g-2pw9"}]},{"advisoryId":"PKSA-94fb-rmqx-1b5r","packageName":"admidio\/admidio","remoteId":"GHSA-4rgq-38mh-9xqg","title":"Admidio PKCS#12 private key export action lacks CSRF protection","link":"https:\/\/github.com\/advisories\/GHSA-4rgq-38mh-9xqg","cve":"CVE-2026-47232","affectedVersions":"\u003C=5.0.9","source":"GitHub","reportedAt":"2026-05-29 22:07:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4rgq-38mh-9xqg"}]},{"advisoryId":"PKSA-rcfv-x5hj-zr3k","packageName":"admidio\/admidio","remoteId":"GHSA-mch8-wf3h-6x88","title":"Admidio writes session IDs and auto-login cookie values to application logs","link":"https:\/\/github.com\/advisories\/GHSA-mch8-wf3h-6x88","cve":"CVE-2026-47234","affectedVersions":"\u003C=5.0.9","source":"GitHub","reportedAt":"2026-05-29 22:07:52","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mch8-wf3h-6x88"}]},{"advisoryId":"PKSA-k742-4y2v-1nnc","packageName":"admidio\/admidio","remoteId":"GHSA-xw54-c3mx-9pm3","title":"Admidio: Any logged-in user can delete inventory fields via `mode=field_delete` \u2014 incomplete fix of #2024","link":"https:\/\/github.com\/advisories\/GHSA-xw54-c3mx-9pm3","cve":"CVE-2026-47233","affectedVersions":"\u003C=5.0.9","source":"GitHub","reportedAt":"2026-05-29 22:09:38","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xw54-c3mx-9pm3"}]},{"advisoryId":"PKSA-wkrr-fx7h-y1x9","packageName":"admidio\/admidio","remoteId":"GHSA-qc4c-hrmc-4f78","title":"Admidio: Authorization bypass in file_delete enables cross-folder file removal by authenticated users without delete privileges","link":"https:\/\/github.com\/advisories\/GHSA-qc4c-hrmc-4f78","cve":"CVE-2026-47226","affectedVersions":"\u003C=5.0.9","source":"GitHub","reportedAt":"2026-05-29 21:54:09","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qc4c-hrmc-4f78"}]},{"advisoryId":"PKSA-34vw-5145-vh4w","packageName":"admidio\/admidio","remoteId":"GHSA-rwjr-qjj3-mq2f","title":"Admidio module-administrator can delete or reorder categories owned by other modules via dead authorization check in `modules\/categories.php`","link":"https:\/\/github.com\/advisories\/GHSA-rwjr-qjj3-mq2f","cve":"CVE-2026-47227","affectedVersions":"\u003C=5.0.9","source":"GitHub","reportedAt":"2026-05-29 21:57:05","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rwjr-qjj3-mq2f"}]},{"advisoryId":"PKSA-z3z8-m2ny-zj6b","packageName":"admidio\/admidio","remoteId":"GHSA-mx25-j3rc-6w2w","title":"Admidio\u0027s CSRF in registration `send_login` mode resets arbitrary user passwords","link":"https:\/\/github.com\/advisories\/GHSA-mx25-j3rc-6w2w","cve":"CVE-2026-47228","affectedVersions":"\u003C=5.0.9","source":"GitHub","reportedAt":"2026-05-29 21:58:44","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mx25-j3rc-6w2w"}]},{"advisoryId":"PKSA-k2cf-4hh1-rf1y","packageName":"admidio\/admidio","remoteId":"GHSA-hcjj-chvw-fmw9","title":"Admidio has an incomplete fix for CVE-2026-32812 (SSRF)","link":"https:\/\/github.com\/advisories\/GHSA-hcjj-chvw-fmw9","cve":"CVE-2026-42194","affectedVersions":"\u003C=5.0.8","source":"GitHub","reportedAt":"2026-05-05 20:03:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hcjj-chvw-fmw9"}]},{"advisoryId":"PKSA-n418-ymkg-hg9x","packageName":"admidio\/admidio","remoteId":"GHSA-gq27-fc8w-vcmp","title":"Admidio vulnerable to reflected XSS in msg_window.php via Square Bracket to HTML Tag Conversion","link":"https:\/\/github.com\/advisories\/GHSA-gq27-fc8w-vcmp","cve":"CVE-2026-41661","affectedVersions":"\u003C=5.0.8","source":"GitHub","reportedAt":"2026-04-29 21:51:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gq27-fc8w-vcmp"}]},{"advisoryId":"PKSA-c3x4-7b97-m7w3","packageName":"admidio\/admidio","remoteId":"GHSA-c7xm-r6vj-8vg6","title":"Admidio Missing Minimum Administrator Check in Role Membership Removal","link":"https:\/\/github.com\/advisories\/GHSA-c7xm-r6vj-8vg6","cve":"CVE-2026-41662","affectedVersions":"\u003C=5.0.8","source":"GitHub","reportedAt":"2026-04-29 21:53:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c7xm-r6vj-8vg6"}]},{"advisoryId":"PKSA-j859-828r-5ckz","packageName":"admidio\/admidio","remoteId":"GHSA-rw74-vc9h-534j","title":"Admidio has CSRF on Admin Preferences that Triggers Unauthorized Backup, .htaccess Write, and Email Send","link":"https:\/\/github.com\/advisories\/GHSA-rw74-vc9h-534j","cve":"CVE-2026-41663","affectedVersions":"\u003C=5.0.8","source":"GitHub","reportedAt":"2026-04-29 21:54:30","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-rw74-vc9h-534j"}]},{"advisoryId":"PKSA-mwvm-8f5c-nh8q","packageName":"admidio\/admidio","remoteId":"GHSA-25cw-98hg-g3cg","title":"Admidio Ignores SAML Signature Validation Result, Processes Forged AuthnRequests and LogoutRequests","link":"https:\/\/github.com\/advisories\/GHSA-25cw-98hg-g3cg","cve":"CVE-2026-41669","affectedVersions":"\u003C=5.0.8","source":"GitHub","reportedAt":"2026-04-29 21:56:13","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-25cw-98hg-g3cg"}]},{"advisoryId":"PKSA-k4tr-44q9-mfgg","packageName":"admidio\/admidio","remoteId":"GHSA-p9w9-87c8-m235","title":"Admidio Sends SAML Response to Unvalidated Assertion Consumer Service URL from AuthnRequest","link":"https:\/\/github.com\/advisories\/GHSA-p9w9-87c8-m235","cve":"CVE-2026-41670","affectedVersions":"\u003C=5.0.8","source":"GitHub","reportedAt":"2026-04-29 21:57:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-p9w9-87c8-m235"}]},{"advisoryId":"PKSA-n1pt-kptp-xq6q","packageName":"admidio\/admidio","remoteId":"GHSA-9xx5-cv6j-x533","title":"Admidio: OIDC Token Introspection Endpoint Returns Active for All Tokens Without Validation","link":"https:\/\/github.com\/advisories\/GHSA-9xx5-cv6j-x533","cve":"CVE-2026-41671","affectedVersions":"\u003C=5.0.8","source":"GitHub","reportedAt":"2026-04-29 21:58:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9xx5-cv6j-x533"}]},{"advisoryId":"PKSA-dmht-7tmz-kr72","packageName":"admidio\/admidio","remoteId":"GHSA-m9h6-8pqm-xrhf","title":"Admidio has Path Traversal via Unvalidated `name` Parameter in Document Add Mode that Enables Arbitrary Server File Read","link":"https:\/\/github.com\/advisories\/GHSA-m9h6-8pqm-xrhf","cve":"CVE-2026-41656","affectedVersions":"\u003C=5.0.8","source":"GitHub","reportedAt":"2026-04-29 21:42:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m9h6-8pqm-xrhf"}]},{"advisoryId":"PKSA-9g4b-9vzm-tggf","packageName":"admidio\/admidio","remoteId":"GHSA-g8p8-94f2-28gr","title":"Admidio Exposes Cross-Organization Member Data via Permission Check Mismatch in contacts_data.php","link":"https:\/\/github.com\/advisories\/GHSA-g8p8-94f2-28gr","cve":"CVE-2026-41657","affectedVersions":"\u003C=5.0.8","source":"GitHub","reportedAt":"2026-04-29 21:44:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g8p8-94f2-28gr"}]},{"advisoryId":"PKSA-rj3x-dwht-5vgg","packageName":"admidio\/admidio","remoteId":"GHSA-xqv4-xm7h-52cv","title":"Admidio\u0027s Missing Authorization on Inventory Module Destructive Endpoints Allows Any Authenticated User to Delete Items","link":"https:\/\/github.com\/advisories\/GHSA-xqv4-xm7h-52cv","cve":"CVE-2026-41658","affectedVersions":"\u003C=5.0.8","source":"GitHub","reportedAt":"2026-04-29 21:46:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xqv4-xm7h-52cv"}]},{"advisoryId":"PKSA-f5x6-www4-q362","packageName":"admidio\/admidio","remoteId":"GHSA-68pr-7prh-mpv4","title":"Admidio Leaks Hidden Profile Field Values via Blind Search Oracle in Member Assignment","link":"https:\/\/github.com\/advisories\/GHSA-68pr-7prh-mpv4","cve":"CVE-2026-41659","affectedVersions":"\u003C=5.0.8","source":"GitHub","reportedAt":"2026-04-29 21:47:29","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-68pr-7prh-mpv4"}]},{"advisoryId":"PKSA-z1nh-b6vq-4kjj","packageName":"admidio\/admidio","remoteId":"GHSA-rh3w-4ccx-prf9","title":"Admidio has Inverted 2FA Reset Authorization Check that Lets Group Leaders Strip Admin TOTP","link":"https:\/\/github.com\/advisories\/GHSA-rh3w-4ccx-prf9","cve":"CVE-2026-41660","affectedVersions":"\u003C=5.0.8","source":"GitHub","reportedAt":"2026-04-29 21:49:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-rh3w-4ccx-prf9"}]},{"advisoryId":"PKSA-cp5f-g188-kj61","packageName":"admidio\/admidio","remoteId":"GHSA-m3vp-3jjm-gpmx","title":"Admidio has Path Traversal in ECard Preview that Allows Reading Arbitrary Server Files Including Database Credentials","link":"https:\/\/github.com\/advisories\/GHSA-m3vp-3jjm-gpmx","cve":"CVE-2026-41655","affectedVersions":"\u003C=5.0.8","source":"GitHub","reportedAt":"2026-04-29 21:37:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m3vp-3jjm-gpmx"}]},{"advisoryId":"PKSA-xdc9-2g6y-xpdf","packageName":"admidio\/admidio","remoteId":"GHSA-7fh7-8xqm-3g88","title":"Admidio allows Unauthenticated Access to Role-Restricted documents via neutralized .htaccess","link":"https:\/\/github.com\/advisories\/GHSA-7fh7-8xqm-3g88","cve":"CVE-2026-34381","affectedVersions":"\u003E=5.0.0,\u003C5.0.8","source":"GitHub","reportedAt":"2026-03-31 23:10:03","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7fh7-8xqm-3g88"}]},{"advisoryId":"PKSA-rjbb-v642-bmj1","packageName":"admidio\/admidio","remoteId":"GHSA-g3mx-8jm6-rc85","title":"Admidio has Missing CSRF Protections on Custom List Deletion in mylist_function.php","link":"https:\/\/github.com\/advisories\/GHSA-g3mx-8jm6-rc85","cve":"CVE-2026-34382","affectedVersions":"\u003E=5.0.0,\u003C=5.0.7","source":"GitHub","reportedAt":"2026-03-31 23:10:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g3mx-8jm6-rc85"}]},{"advisoryId":"PKSA-rs6z-52fv-dzjt","packageName":"admidio\/admidio","remoteId":"GHSA-ph84-r98x-2j22","title":"Admidio has Missing CSRF Protection on Registration Approval Actions","link":"https:\/\/github.com\/advisories\/GHSA-ph84-r98x-2j22","cve":"CVE-2026-34384","affectedVersions":"\u003C5.0.8","source":"GitHub","reportedAt":"2026-03-31 23:11:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-ph84-r98x-2j22"}]},{"advisoryId":"PKSA-ksvx-vqkf-t9m4","packageName":"admidio\/admidio","remoteId":"GHSA-4rwm-c5mj-wh7x","title":"Admidio has CSRF and Form Validation Bypass in Inventory Item Save via `imported` Parameter","link":"https:\/\/github.com\/advisories\/GHSA-4rwm-c5mj-wh7x","cve":"CVE-2026-34383","affectedVersions":"\u003C=5.0.7","source":"GitHub","reportedAt":"2026-03-31 23:11:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4rwm-c5mj-wh7x"}]},{"advisoryId":"PKSA-z3z9-x952-96sj","packageName":"admidio\/admidio","remoteId":"GHSA-95cq-p4w2-32w5","title":"File Upload(RCE) Vulnerability in admidio","link":"https:\/\/github.com\/advisories\/GHSA-95cq-p4w2-32w5","cve":"CVE-2026-32756","affectedVersions":"\u003C=5.0.6","source":"GitHub","reportedAt":"2026-03-16 21:16:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-95cq-p4w2-32w5"}]},{"advisoryId":"PKSA-1wgg-nst3-ctpz","packageName":"admidio\/admidio","remoteId":"GHSA-wwg8-6ffr-h4q2","title":"Admidio is Missing CSRF Validation on Role Delete, Activate, and Deactivate Actions","link":"https:\/\/github.com\/advisories\/GHSA-wwg8-6ffr-h4q2","cve":"CVE-2026-32816","affectedVersions":"\u003E=5.0.0,\u003C=5.0.6","source":"GitHub","reportedAt":"2026-03-16 21:17:09","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wwg8-6ffr-h4q2"}]},{"advisoryId":"PKSA-ym3s-c4g7-mjjc","packageName":"admidio\/admidio","remoteId":"GHSA-h8gr-qwr6-m9gx","title":"Admidio is Missing CSRF Protection on Role Membership Date Changes","link":"https:\/\/github.com\/advisories\/GHSA-h8gr-qwr6-m9gx","cve":"CVE-2026-32755","affectedVersions":"\u003C=5.0.6","source":"GitHub","reportedAt":"2026-03-16 21:17:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h8gr-qwr6-m9gx"}]},{"advisoryId":"PKSA-k5pv-h718-ynrx","packageName":"admidio\/admidio","remoteId":"GHSA-6j68-gcc3-mq73","title":"Admidio Vulnerable to SSRF and Local File Read via Unrestricted URL Fetch in SSO Metadata Endpoint","link":"https:\/\/github.com\/advisories\/GHSA-6j68-gcc3-mq73","cve":"CVE-2026-32812","affectedVersions":"\u003E=5.0.0,\u003C=5.0.6","source":"GitHub","reportedAt":"2026-03-16 21:17:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6j68-gcc3-mq73"}]},{"advisoryId":"PKSA-stt3-wv6m-657m","packageName":"admidio\/admidio","remoteId":"GHSA-rmpj-3x5m-9m5f","title":"Admidio is Missing Authorization and CSRF Protection on Document and Folder Deletion","link":"https:\/\/github.com\/advisories\/GHSA-rmpj-3x5m-9m5f","cve":"CVE-2026-32817","affectedVersions":"\u003E=5.0.0,\u003C=5.0.6","source":"GitHub","reportedAt":"2026-03-16 21:18:10","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-rmpj-3x5m-9m5f"}]},{"advisoryId":"PKSA-sgr9-nmmb-pbwy","packageName":"admidio\/admidio","remoteId":"GHSA-4wr4-f2qf-x5wj","title":"Admidio has an HTMLPurifier Bypass in eCard Message Allows HTML Email Injection","link":"https:\/\/github.com\/advisories\/GHSA-4wr4-f2qf-x5wj","cve":"CVE-2026-32757","affectedVersions":"\u003C=5.0.6","source":"GitHub","reportedAt":"2026-03-16 21:18:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4wr4-f2qf-x5wj"}]},{"advisoryId":"PKSA-vs7x-4q3q-rbsp","packageName":"admidio\/admidio","remoteId":"GHSA-g375-5wmp-xr78","title":"Admidio is Missing Authorization on Forum Topic and Post Deletion","link":"https:\/\/github.com\/advisories\/GHSA-g375-5wmp-xr78","cve":"CVE-2026-32818","affectedVersions":"\u003E=5.0.0,\u003C=5.0.6","source":"GitHub","reportedAt":"2026-03-16 21:18:53","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g375-5wmp-xr78"}]},{"advisoryId":"PKSA-gmjw-r3kp-z9vp","packageName":"admidio\/admidio","remoteId":"GHSA-3x67-4c2c-w45m","title":"Admidio has a Second-Order SQL Injection via List Configuration (lsc_special_field, lsc_sort, lsc_filter)","link":"https:\/\/github.com\/advisories\/GHSA-3x67-4c2c-w45m","cve":"CVE-2026-32813","affectedVersions":"\u003C=5.0.6","source":"GitHub","reportedAt":"2026-03-16 21:19:09","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3x67-4c2c-w45m"}]},{"advisoryId":"PKSA-m5mq-p62f-xpq3","packageName":"admidio\/admidio","remoteId":"GHSA-7pfv-hr63-h7cw","title":"Admidio: Event participation IDOR - non-leaders can register other users for events via user_uuid parameter","link":"https:\/\/github.com\/advisories\/GHSA-7pfv-hr63-h7cw","cve":"CVE-2026-30927","affectedVersions":"\u003C5.0.6","source":"GitHub","reportedAt":"2026-03-09 19:45:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7pfv-hr63-h7cw"}]},{"advisoryId":"PKSA-4zpm-2kww-7r27","packageName":"admidio\/admidio","remoteId":"GHSA-2v5m-cq9w-fc33","title":"Admidio Vulnerable to Authenticated SQL Injection in Member Assignment Functionality","link":"https:\/\/github.com\/advisories\/GHSA-2v5m-cq9w-fc33","cve":"CVE-2025-62617","affectedVersions":"\u003C=4.3.16","source":"GitHub","reportedAt":"2025-10-22 16:46:03","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2v5m-cq9w-fc33"}]}],"code16\/sharp":[{"advisoryId":"PKSA-krdf-j5zz-ky6v","packageName":"code16\/sharp","remoteId":"GHSA-vmwx-m75v-qvch","title":"Sharp Missing Authorization Check in Quick Creation Command Endpoints","link":"https:\/\/github.com\/advisories\/GHSA-vmwx-m75v-qvch","cve":"CVE-2026-53634","affectedVersions":"\u003E=9.0.0,\u003C9.22.3","source":"GitHub","reportedAt":"2026-07-08 20:24:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vmwx-m75v-qvch"}]},{"advisoryId":"PKSA-h9kt-ss6k-xq4z","packageName":"code16\/sharp","remoteId":"GHSA-748w-hm6r-qc7v","title":"Authenticated Sharp users can download unrelated Laravel Storage objects through the generic download endpoint","link":"https:\/\/github.com\/advisories\/GHSA-748w-hm6r-qc7v","cve":"CVE-2026-44692","affectedVersions":"\u003C9.22.0","source":"GitHub","reportedAt":"2026-05-15 18:01:03","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-748w-hm6r-qc7v"}]},{"advisoryId":"PKSA-74vs-2hzw-xc7y","packageName":"code16\/sharp","remoteId":"GHSA-fr76-5637-w3g9","title":"Sharp has Unrestricted File Upload via Client-Controlled Validation Rules","link":"https:\/\/github.com\/advisories\/GHSA-fr76-5637-w3g9","cve":"CVE-2026-33687","affectedVersions":"\u003C9.20.0","source":"GitHub","reportedAt":"2026-03-25 20:00:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fr76-5637-w3g9"}]},{"advisoryId":"PKSA-48kw-4xx3-wpfb","packageName":"code16\/sharp","remoteId":"GHSA-9ffq-6457-8958","title":"Sharp is Vulnerable to Path Traversal via Unsanitized Extension in FileUtil","link":"https:\/\/github.com\/advisories\/GHSA-9ffq-6457-8958","cve":"CVE-2026-33686","affectedVersions":"\u003C9.20.0","source":"GitHub","reportedAt":"2026-03-25 20:01:04","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9ffq-6457-8958"}]},{"advisoryId":"PKSA-w3x4-3yd5-pjjx","packageName":"code16\/sharp","remoteId":"GHSA-9f58-4465-23c7","title":"Sharp user-provided input can be evaluated in a SharpShowTextField with Vue template syntax","link":"https:\/\/github.com\/advisories\/GHSA-9f58-4465-23c7","cve":"CVE-2025-62798","affectedVersions":"\u003C9.11.1","source":"GitHub","reportedAt":"2025-10-29 10:52:08","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9f58-4465-23c7"}]},{"advisoryId":"PKSA-9m12-t4dn-mzg2","packageName":"code16\/sharp","remoteId":"GHSA-9778-v769-qvjf","title":"code16 Sharp vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/github.com\/advisories\/GHSA-9778-v769-qvjf","cve":"CVE-2025-61457","affectedVersions":"\u003C9.7.0","source":"GitHub","reportedAt":"2025-10-21 21:33:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9778-v769-qvjf"}]}],"dolibarr\/dolibarr":[{"advisoryId":"PKSA-199z-kb1w-7qjg","packageName":"dolibarr\/dolibarr","remoteId":"GHSA-7fg5-vc77-69fp","title":"Dolibarr ERP CRM is vulnerable to Improper Authorization through its Leave Request REST API","link":"https:\/\/github.com\/advisories\/GHSA-7fg5-vc77-69fp","cve":"CVE-2026-10215","affectedVersions":"\u003C=15.0.3","source":"GitHub","reportedAt":"2026-06-01 03:30:26","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7fg5-vc77-69fp"}]},{"advisoryId":"PKSA-t829-nm92-5bvj","packageName":"dolibarr\/dolibarr","remoteId":"GHSA-hxmh-2xc4-c894","title":"Dolibarr ERP CRM contains a remote code evaluation vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-hxmh-2xc4-c894","cve":"CVE-2018-25357","affectedVersions":"\u003C6.0.8|\u003E=7.0.0,\u003C=7.0.3","source":"GitHub","reportedAt":"2026-05-26 13:30:27","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-hxmh-2xc4-c894"}]},{"advisoryId":"PKSA-zbps-xm91-whkn","packageName":"dolibarr\/dolibarr","remoteId":"GHSA-rvwr-q5hj-wq7g","title":"Dolibarr has an Injection issue","link":"https:\/\/github.com\/advisories\/GHSA-rvwr-q5hj-wq7g","cve":"CVE-2026-7688","affectedVersions":"\u003C=23.0.2","source":"GitHub","reportedAt":"2026-05-03 12:30:26","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-rvwr-q5hj-wq7g"}]},{"advisoryId":"PKSA-dxkr-sbbp-889v","packageName":"dolibarr\/dolibarr","remoteId":"GHSA-jggh-5rmh-r6h5","title":"Dolibarr has Insufficient Verification of Data Authenticity ","link":"https:\/\/github.com\/advisories\/GHSA-jggh-5rmh-r6h5","cve":"CVE-2026-7689","affectedVersions":"\u003C=15.0.3","source":"GitHub","reportedAt":"2026-05-03 12:30:26","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-jggh-5rmh-r6h5"}]},{"advisoryId":"PKSA-pnx2-khzh-yv6p","packageName":"dolibarr\/dolibarr","remoteId":"GHSA-j2g9-rprv-hrhc","title":"Dolibarr user with permission to edit PHP content can bypass filtering to restrict dangerous PHP functions","link":"https:\/\/github.com\/advisories\/GHSA-j2g9-rprv-hrhc","cve":"CVE-2026-31019","affectedVersions":"\u003C=22.0.4","source":"GitHub","reportedAt":"2026-04-21 15:32:22","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j2g9-rprv-hrhc"}]},{"advisoryId":"PKSA-ntds-z6nr-8hyf","packageName":"dolibarr\/dolibarr","remoteId":"GHSA-676v-wh57-p375","title":"Dolibarr Allows Code Injection through its Website Module","link":"https:\/\/github.com\/advisories\/GHSA-676v-wh57-p375","cve":"CVE-2026-31018","affectedVersions":"\u003C=15.0.3","source":"GitHub","reportedAt":"2026-04-21 15:32:22","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-676v-wh57-p375"}]},{"advisoryId":"PKSA-5yjp-cmsh-j9sp","packageName":"dolibarr\/dolibarr","remoteId":"GHSA-xxxg-x793-7fq3","title":"Dolibarr has SQL injection vulnerability in the rowid parameter of the admin dict.php","link":"https:\/\/github.com\/advisories\/GHSA-xxxg-x793-7fq3","cve":"CVE-2019-25710","affectedVersions":"\u003C=8.0.4","source":"GitHub","reportedAt":"2026-04-12 15:30:27","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xxxg-x793-7fq3"}]},{"advisoryId":"PKSA-ncsd-s9tq-7bj2","packageName":"dolibarr\/dolibarr","remoteId":"GHSA-w5j3-8fcr-h87w","title":"Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration","link":"https:\/\/github.com\/advisories\/GHSA-w5j3-8fcr-h87w","cve":"CVE-2026-23500","affectedVersions":"\u003C=22.0.4","source":"GitHub","reportedAt":"2026-04-17 21:24:48","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-w5j3-8fcr-h87w"}]},{"advisoryId":"PKSA-bc6q-cg7z-6rnf","packageName":"dolibarr\/dolibarr","remoteId":"GHSA-2mfj-r695-5h9r","title":"Dolibarr Core Discloses Sensitive Data via Authenticated Local File Inclusion in selectobject.php ","link":"https:\/\/github.com\/advisories\/GHSA-2mfj-r695-5h9r","cve":"CVE-2026-34036","affectedVersions":"\u003C=22.0.4","source":"GitHub","reportedAt":"2026-03-27 18:04:19","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2mfj-r695-5h9r"}]},{"advisoryId":"PKSA-shmy-ndn8-n6b3","packageName":"dolibarr\/dolibarr","remoteId":"GHSA-27hj-48r9-x2vx","title":"Dolibarr vulnerable to RCE via the computed field parameter","link":"https:\/\/github.com\/advisories\/GHSA-27hj-48r9-x2vx","cve":"CVE-2025-56588","affectedVersions":"\u003C21.0.3","source":"GitHub","reportedAt":"2025-10-01 21:31:22","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-27hj-48r9-x2vx"}]},{"advisoryId":"PKSA-pt1m-6pf4-t9z4","packageName":"dolibarr\/dolibarr","remoteId":"GHSA-7947-48q7-cp5m","title":"Dolibarr Application Home Page has HTML injection vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-7947-48q7-cp5m","cve":"CVE-2024-23817","affectedVersions":"\u003E=18.0.4,\u003C18.0.7","source":"GitHub","reportedAt":"2024-04-18 16:42:32","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7947-48q7-cp5m"}]}],"web-auth\/webauthn-lib":[{"advisoryId":"PKSA-zk1n-qbm6-d3rq","packageName":"web-auth\/webauthn-lib","remoteId":"GHSA-gq4g-fpc9-vjfq","title":"Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection","link":"https:\/\/github.com\/advisories\/GHSA-gq4g-fpc9-vjfq","cve":null,"affectedVersions":"\u003E=4.9.0,\u003C5.3.5","source":"GitHub","reportedAt":"2026-07-07 23:39:43","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-gq4g-fpc9-vjfq"}]},{"advisoryId":"PKSA-n72g-8zd8-6dm2","packageName":"web-auth\/webauthn-lib","remoteId":"GHSA-f7pm-6hr8-7ggm","title":"Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validation","link":"https:\/\/github.com\/advisories\/GHSA-f7pm-6hr8-7ggm","cve":"CVE-2026-30964","affectedVersions":"\u003E=5.2.0,\u003C5.2.4","source":"GitHub","reportedAt":"2026-03-10 01:19:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f7pm-6hr8-7ggm"}]}],"egroupware\/egroupware":[{"advisoryId":"PKSA-3pf5-qtx8-njsg","packageName":"egroupware\/egroupware","remoteId":"GHSA-h9qx-v5xp-ph8p","title":"EGroupware has a Remote Code Execution Vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-h9qx-v5xp-ph8p","cve":"CVE-2026-27823","affectedVersions":"\u003C23.1.20260224|\u003E=26.0.20251208,\u003C26.2.20260224","source":"GitHub","reportedAt":"2026-07-07 13:01:01","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-h9qx-v5xp-ph8p"}]},{"advisoryId":"PKSA-s1pv-qcq4-r5jv","packageName":"egroupware\/egroupware","remoteId":"GHSA-8737-2x9g-xjj7","title":"EGroupware has Authenticated RCE via Malicious eTemplate Upload","link":"https:\/\/github.com\/advisories\/GHSA-8737-2x9g-xjj7","cve":"CVE-2026-40187","affectedVersions":"\u003C23.1.20260601|\u003E=26.0.20251208,\u003C26.0.20260113","source":"GitHub","reportedAt":"2026-07-07 13:01:31","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8737-2x9g-xjj7"}]},{"advisoryId":"PKSA-pvm8-1tm1-jhwt","packageName":"egroupware\/egroupware","remoteId":"GHSA-c8m7-r2jv-rw63","title":"EGroupware Vulnerable to Local File Inclusion via file:\/\/ URI in Mail Compose","link":"https:\/\/github.com\/advisories\/GHSA-c8m7-r2jv-rw63","cve":"CVE-2026-45016","affectedVersions":"\u003C23.1.20260601|\u003E=26.0.20251208,\u003C26.5.20260507","source":"GitHub","reportedAt":"2026-07-07 13:02:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c8m7-r2jv-rw63"}]},{"advisoryId":"PKSA-jdcn-qrct-7cv7","packageName":"egroupware\/egroupware","remoteId":"GHSA-rvxj-7f72-mhrx","title":"EGroupware has SQL Injection in Nextmatch Filter Processing","link":"https:\/\/github.com\/advisories\/GHSA-rvxj-7f72-mhrx","cve":"CVE-2026-22243","affectedVersions":"\u003E=26.0.20251208,\u003C26.0.20260113|\u003C23.1.20260113","source":"GitHub","reportedAt":"2026-01-28 20:39:27","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-rvxj-7f72-mhrx"}]}],"verbb\/formie":[{"advisoryId":"PKSA-rm1g-8q6b-7djk","packageName":"verbb\/formie","remoteId":"GHSA-565m-g33j-jq96","title":"Formie Hidden field defaults vulnerable to Server-Side Template Injection","link":"https:\/\/github.com\/advisories\/GHSA-565m-g33j-jq96","cve":"CVE-2026-52889","affectedVersions":"\u003C3.1.27","source":"GitHub","reportedAt":"2026-07-06 16:52:16","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-565m-g33j-jq96"}]},{"advisoryId":"PKSA-2h9w-qq3j-93vt","packageName":"verbb\/formie","remoteId":"GHSA-pgxq-p76c-x9cg","title":"formie\u0027s unauthenticated front-end submission editing can overwrite existing submissions","link":"https:\/\/github.com\/advisories\/GHSA-pgxq-p76c-x9cg","cve":"CVE-2026-47266","affectedVersions":"\u003C2.2.21|\u003E=3.0.0,\u003C3.1.26","source":"GitHub","reportedAt":"2026-05-29 22:19:19","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pgxq-p76c-x9cg"}]},{"advisoryId":"PKSA-snft-3cv8-v5p5","packageName":"verbb\/formie","remoteId":"GHSA-x7m9-mwc2-g6w2","title":"Formie: Pre-authenticated server-side template injection in Hidden fields","link":"https:\/\/github.com\/advisories\/GHSA-x7m9-mwc2-g6w2","cve":"CVE-2026-45697","affectedVersions":"\u003C2.2.20|\u003E=3.0.0-beta.1,\u003C3.1.24","source":"GitHub","reportedAt":"2026-05-18 17:23:39","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-x7m9-mwc2-g6w2"}]}],"web-token\/jwt-bundle":[{"advisoryId":"PKSA-5yb6-pjs2-zg93","packageName":"web-token\/jwt-bundle","remoteId":"GHSA-jc38-x7x8-2xc8","title":"PHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks","link":"https:\/\/github.com\/advisories\/GHSA-jc38-x7x8-2xc8","cve":null,"affectedVersions":"\u003E=4.1.0,\u003C4.1.7|\u003E=4.0.0,\u003C4.0.7|\u003C3.4.10","source":"GitHub","reportedAt":"2026-06-18 21:09:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jc38-x7x8-2xc8"}]}],"web-token\/jwt-experimental":[{"advisoryId":"PKSA-rq51-8s6h-13tp","packageName":"web-token\/jwt-experimental","remoteId":"GHSA-jc38-x7x8-2xc8","title":"PHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks","link":"https:\/\/github.com\/advisories\/GHSA-jc38-x7x8-2xc8","cve":null,"affectedVersions":"\u003E=4.1.0,\u003C4.1.7|\u003E=4.0.0,\u003C4.0.7|\u003C3.4.10","source":"GitHub","reportedAt":"2026-06-18 21:09:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jc38-x7x8-2xc8"}]},{"advisoryId":"PKSA-z37k-njn7-w125","packageName":"web-token\/jwt-experimental","remoteId":"GHSA-6vvh-pxr4-25r7","title":"PHP JWT Framework: Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption","link":"https:\/\/github.com\/advisories\/GHSA-6vvh-pxr4-25r7","cve":null,"affectedVersions":"\u003C=4.1.6","source":"GitHub","reportedAt":"2026-06-18 21:08:15","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6vvh-pxr4-25r7"}]}],"spatie\/laravel-medialibrary":[{"advisoryId":"PKSA-88bj-c5ky-3pr6","packageName":"spatie\/laravel-medialibrary","remoteId":"GHSA-fggg-964j-3j7h","title":"Spatie Laravel Media Library contains a server-side request forgery vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-fggg-964j-3j7h","cve":"CVE-2026-48555","affectedVersions":"\u003C11.23.0","source":"GitHub","reportedAt":"2026-05-29 21:31:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fggg-964j-3j7h"}]},{"advisoryId":"PKSA-mrgr-9pdf-y591","packageName":"spatie\/laravel-medialibrary","remoteId":"GHSA-3ggm-c5m7-hfv5","title":"Spatie Laravel Media Library contains a file upload restriction bypass","link":"https:\/\/github.com\/advisories\/GHSA-3ggm-c5m7-hfv5","cve":"CVE-2026-48557","affectedVersions":"\u003C11.23.0","source":"GitHub","reportedAt":"2026-05-29 21:31:25","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3ggm-c5m7-hfv5"}]}],"simplesamlphp\/simplesamlphp":[{"advisoryId":"PKSA-569h-6vqh-5xr3","packageName":"simplesamlphp\/simplesamlphp","remoteId":"GHSA-q8r6-xj3f-wrrm","title":"SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response\/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData\/InResponseTo`","link":"https:\/\/github.com\/advisories\/GHSA-q8r6-xj3f-wrrm","cve":"CVE-2026-49284","affectedVersions":"\u003C=2.4.6|\u003E=2.5.0,\u003C=2.5.1","source":"GitHub","reportedAt":"2026-07-02 20:47:21","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-q8r6-xj3f-wrrm"}]}],"simplesamlphp\/saml2":[{"advisoryId":"PKSA-yk3g-3g3t-ts6q","packageName":"simplesamlphp\/saml2","remoteId":"GHSA-6929-8p9f-26jx","title":"SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass","link":"https:\/\/github.com\/advisories\/GHSA-6929-8p9f-26jx","cve":"CVE-2026-49283","affectedVersions":"\u003C4.20.2|\u003E=5.0.0,\u003C5.0.6|\u003E=6.0.0,\u003C6.2.1","source":"GitHub","reportedAt":"2026-07-02 20:25:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6929-8p9f-26jx"}]},{"advisoryId":"PKSA-1fc7-xrz7-vw78","packageName":"simplesamlphp\/saml2","remoteId":"GHSA-5cjr-mxj5-wmrx","title":"SimpleSAMLphp has Possible DoS via XPath Transform","link":"https:\/\/github.com\/advisories\/GHSA-5cjr-mxj5-wmrx","cve":"CVE-2026-49289","affectedVersions":"\u003C=4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:27:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5cjr-mxj5-wmrx"}]}],"simplesamlphp\/saml2-legacy":[{"advisoryId":"PKSA-4y26-97zb-p98g","packageName":"simplesamlphp\/saml2-legacy","remoteId":"GHSA-6929-8p9f-26jx","title":"SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass","link":"https:\/\/github.com\/advisories\/GHSA-6929-8p9f-26jx","cve":"CVE-2026-49283","affectedVersions":"\u003C4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:25:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6929-8p9f-26jx"}]},{"advisoryId":"PKSA-11bv-m3wk-h9sn","packageName":"simplesamlphp\/saml2-legacy","remoteId":"GHSA-5cjr-mxj5-wmrx","title":"SimpleSAMLphp has Possible DoS via XPath Transform","link":"https:\/\/github.com\/advisories\/GHSA-5cjr-mxj5-wmrx","cve":"CVE-2026-49289","affectedVersions":"\u003C=4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:27:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5cjr-mxj5-wmrx"}]}],"mautic\/core":[{"advisoryId":"PKSA-tmx3-5zmv-624c","packageName":"mautic\/core","remoteId":"GHSA-jmv8-8j9j-rcpc","title":"Mautic Focus component Vulnerable to SSRF","link":"https:\/\/github.com\/advisories\/GHSA-jmv8-8j9j-rcpc","cve":"CVE-2026-9557","affectedVersions":"\u003E=7.0.0,\u003C7.1.2|\u003E=6.0.0,\u003C6.0.9|\u003E=5.0.0,\u003C5.2.11|\u003E=4.0.0,\u003C=4.4.13","source":"GitHub","reportedAt":"2026-07-02 19:47:38","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jmv8-8j9j-rcpc"}]},{"advisoryId":"PKSA-5wpq-7gbm-cqxv","packageName":"mautic\/core","remoteId":"GHSA-9fx4-7cmj-47vg","title":"Mautic has Server-Side Template Injection (SSTI) in Theme Templates","link":"https:\/\/github.com\/advisories\/GHSA-9fx4-7cmj-47vg","cve":"CVE-2026-9558","affectedVersions":"\u003E=7.0.0,\u003C7.1.2|\u003E=6.0.0,\u003C6.0.9|\u003E=5.0.0,\u003C5.2.11|\u003E=1.3.0,\u003C4.4.13","source":"GitHub","reportedAt":"2026-07-02 19:48:08","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-9fx4-7cmj-47vg"}]},{"advisoryId":"PKSA-743g-7dzv-xbzg","packageName":"mautic\/core","remoteId":"GHSA-6r9h-4h75-7q4x","title":"Mautic vulnerable to Path Traversal via Campaign Import","link":"https:\/\/github.com\/advisories\/GHSA-6r9h-4h75-7q4x","cve":"CVE-2026-9559","affectedVersions":"\u003E=7.0.0,\u003C7.1.2","source":"GitHub","reportedAt":"2026-07-02 19:48:50","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-6r9h-4h75-7q4x"}]},{"advisoryId":"PKSA-199x-g3sb-2vrd","packageName":"mautic\/core","remoteId":"GHSA-2jrw-c95w-h43g","title":"Mautic has an Authorization Bypass in API v2 Endpoints","link":"https:\/\/github.com\/advisories\/GHSA-2jrw-c95w-h43g","cve":"CVE-2026-9808","affectedVersions":"\u003E=7.0.0,\u003C7.1.2","source":"GitHub","reportedAt":"2026-07-02 19:49:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2jrw-c95w-h43g"}]},{"advisoryId":"PKSA-xbvd-zmn4-s43b","packageName":"mautic\/core","remoteId":"GHSA-7h65-whp7-rgqf","title":"Mautic has Stored Cross-Site Scripting (XSS) in Projects Component","link":"https:\/\/github.com\/advisories\/GHSA-7h65-whp7-rgqf","cve":"CVE-2026-9809","affectedVersions":"\u003E=7.0.0,\u003C7.1.2","source":"GitHub","reportedAt":"2026-07-02 19:49:14","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7h65-whp7-rgqf"}]},{"advisoryId":"PKSA-mhxb-h64m-td2q","packageName":"mautic\/core","remoteId":"GHSA-5hvg-w58j-545m","title":"Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector","link":"https:\/\/github.com\/advisories\/GHSA-5hvg-w58j-545m","cve":"CVE-2026-9811","affectedVersions":"\u003E=7.0.0,\u003C7.1.2","source":"GitHub","reportedAt":"2026-07-02 19:49:27","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5hvg-w58j-545m"}]},{"advisoryId":"PKSA-pdn1-217f-vc3y","packageName":"mautic\/core","remoteId":"GHSA-fcmw-wx57-9p75","title":"Mautic has SQL Injection in API Contact Filtering","link":"https:\/\/github.com\/advisories\/GHSA-fcmw-wx57-9p75","cve":"CVE-2026-4776","affectedVersions":"\u003E=7.0.0,\u003C7.1.2|\u003E=6.0.0,\u003C6.0.9|\u003E=5.0.0,\u003C5.2.11|\u003E=2.6.0,\u003C=4.4.13","source":"GitHub","reportedAt":"2026-07-02 19:25:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fcmw-wx57-9p75"}]},{"advisoryId":"PKSA-frhs-vjy5-hffg","packageName":"mautic\/core","remoteId":"GHSA-r5j5-q42h-fc93","title":"Mautic is Vulnerable to SQL Injection through Contact Activity API Sorting","link":"https:\/\/github.com\/advisories\/GHSA-r5j5-q42h-fc93","cve":"CVE-2026-3105","affectedVersions":"\u003E=7.0.0-alpha,\u003C7.0.1|\u003E=6.0.0-alpha,\u003C6.0.8|\u003E=2.10.0,\u003C5.2.10","source":"GitHub","reportedAt":"2026-02-25 19:28:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r5j5-q42h-fc93"}]},{"advisoryId":"PKSA-j693-8gvk-sx7v","packageName":"mautic\/core","remoteId":"GHSA-3fq7-c5m8-g86x","title":"Mautic user without privileged access to the Marketplace can install and uninstall composer packages","link":"https:\/\/github.com\/advisories\/GHSA-3fq7-c5m8-g86x","cve":"CVE-2025-13828","affectedVersions":"\u003E=6.0.0,\u003C6.0.7|\u003E=5.0.0,\u003C5.2.9|\u003E=4.0.0,\u003C4.4.18","source":"GitHub","reportedAt":"2025-12-02 21:10:39","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-3fq7-c5m8-g86x"}]}],"froxlor\/froxlor":[{"advisoryId":"PKSA-q6mw-b5rg-dy2q","packageName":"froxlor\/froxlor","remoteId":"GHSA-mr9h-45p9-fg8h","title":"Froxlor: Authenticated customers can read other customers\u0027 allowed sender aliases","link":"https:\/\/github.com\/advisories\/GHSA-mr9h-45p9-fg8h","cve":null,"affectedVersions":"\u003C=2.3.6","source":"GitHub","reportedAt":"2026-07-02 19:23:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mr9h-45p9-fg8h"}]},{"advisoryId":"PKSA-54z7-97sf-f9k2","packageName":"froxlor\/froxlor","remoteId":"GHSA-q4rm-m6xh-5pv7","title":"Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API","link":"https:\/\/github.com\/advisories\/GHSA-q4rm-m6xh-5pv7","cve":null,"affectedVersions":"\u003C=2.3.6","source":"GitHub","reportedAt":"2026-07-02 19:23:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q4rm-m6xh-5pv7"}]},{"advisoryId":"PKSA-bhjh-v6gp-f43f","packageName":"froxlor\/froxlor","remoteId":"GHSA-f9rx-7wf7-jr36","title":"Froxlor\u0027s API Authentication bypasses 2FA Authentication","link":"https:\/\/github.com\/advisories\/GHSA-f9rx-7wf7-jr36","cve":"CVE-2026-52793","affectedVersions":"\u003C2.3.7","source":"GitHub","reportedAt":"2026-06-03 21:41:12","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f9rx-7wf7-jr36"}]},{"advisoryId":"PKSA-jryy-96vk-jczz","packageName":"froxlor\/froxlor","remoteId":"GHSA-37m5-m4q3-fc6x","title":"Froxlor: BIND Zone File Injection via TXT Record Content","link":"https:\/\/github.com\/advisories\/GHSA-37m5-m4q3-fc6x","cve":"CVE-2026-41234","affectedVersions":"\u003C=2.3.6","source":"GitHub","reportedAt":"2026-06-03 21:02:12","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-37m5-m4q3-fc6x"}]},{"advisoryId":"PKSA-vtjk-w45q-7qyz","packageName":"froxlor\/froxlor","remoteId":"GHSA-mq5v-pxpm-8jw2","title":"Froxlor has privilege escalation in SSH key synchronization via symlinked `authorized_keys` path","link":"https:\/\/github.com\/advisories\/GHSA-mq5v-pxpm-8jw2","cve":"CVE-2026-41236","affectedVersions":"=2.3.6","source":"GitHub","reportedAt":"2026-05-29 15:40:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mq5v-pxpm-8jw2"}]},{"advisoryId":"PKSA-sn72-k1q6-w5r5","packageName":"froxlor\/froxlor","remoteId":"GHSA-j6fm-9rfm-j5hx","title":"Froxlor has an incomplete fix for CVE-2026-30932","link":"https:\/\/github.com\/advisories\/GHSA-j6fm-9rfm-j5hx","cve":"CVE-2026-41237","affectedVersions":"\u003C=2.3.6","source":"GitHub","reportedAt":"2026-05-29 15:45:31","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j6fm-9rfm-j5hx"}]},{"advisoryId":"PKSA-yjh3-nghh-xpft","packageName":"froxlor\/froxlor","remoteId":"GHSA-gcv3-5v9q-fmhh","title":"Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement","link":"https:\/\/github.com\/advisories\/GHSA-gcv3-5v9q-fmhh","cve":"CVE-2026-41235","affectedVersions":"=2.3.6","source":"GitHub","reportedAt":"2026-05-29 15:36:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gcv3-5v9q-fmhh"}]},{"advisoryId":"PKSA-t427-p3m6-gf3c","packageName":"froxlor\/froxlor","remoteId":"GHSA-w59f-67xm-rxx7","title":"Froxlor has Local File Inclusion via path traversal in API `def_language` parameter leads to Remote Code Execution","link":"https:\/\/github.com\/advisories\/GHSA-w59f-67xm-rxx7","cve":"CVE-2026-41228","affectedVersions":"\u003C=2.3.5","source":"GitHub","reportedAt":"2026-04-16 01:02:12","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-w59f-67xm-rxx7"}]},{"advisoryId":"PKSA-ghdy-xf1y-wsyx","packageName":"froxlor\/froxlor","remoteId":"GHSA-jvx4-xv3m-hrj4","title":"Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add()","link":"https:\/\/github.com\/advisories\/GHSA-jvx4-xv3m-hrj4","cve":"CVE-2026-41233","affectedVersions":"\u003C=2.3.5","source":"GitHub","reportedAt":"2026-04-16 00:46:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jvx4-xv3m-hrj4"}]},{"advisoryId":"PKSA-mym1-2cj8-f6cp","packageName":"froxlor\/froxlor","remoteId":"GHSA-vmjj-qr7v-pxm6","title":"Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index Allows Cross-Customer Email Spoofing","link":"https:\/\/github.com\/advisories\/GHSA-vmjj-qr7v-pxm6","cve":"CVE-2026-41232","affectedVersions":"\u003C2.3.6","source":"GitHub","reportedAt":"2026-04-16 00:47:05","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vmjj-qr7v-pxm6"}]},{"advisoryId":"PKSA-jy2x-d5vf-ycwz","packageName":"froxlor\/froxlor","remoteId":"GHSA-75h4-c557-j89r","title":"Froxlor has Incomplete Symlink Validation in DataDump.add() Allows Arbitrary Directory Ownership Takeover via Cron","link":"https:\/\/github.com\/advisories\/GHSA-75h4-c557-j89r","cve":"CVE-2026-41231","affectedVersions":"\u003C2.3.6","source":"GitHub","reportedAt":"2026-04-16 00:47:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-75h4-c557-j89r"}]},{"advisoryId":"PKSA-zvbr-5xtx-pwd7","packageName":"froxlor\/froxlor","remoteId":"GHSA-47hf-23pw-3m8c","title":"Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()","link":"https:\/\/github.com\/advisories\/GHSA-47hf-23pw-3m8c","cve":"CVE-2026-41230","affectedVersions":"\u003C2.3.6","source":"GitHub","reportedAt":"2026-04-16 00:47:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-47hf-23pw-3m8c"}]},{"advisoryId":"PKSA-s4pz-z4hm-5n7x","packageName":"froxlor\/froxlor","remoteId":"GHSA-gc9w-cc93-rjv8","title":"Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)","link":"https:\/\/github.com\/advisories\/GHSA-gc9w-cc93-rjv8","cve":"CVE-2026-41229","affectedVersions":"\u003C=2.3.5","source":"GitHub","reportedAt":"2026-04-16 00:50:00","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-gc9w-cc93-rjv8"}]},{"advisoryId":"PKSA-8kv2-v86v-pjxv","packageName":"froxlor\/froxlor","remoteId":"GHSA-x6w6-2xwp-3jh6","title":"Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones API","link":"https:\/\/github.com\/advisories\/GHSA-x6w6-2xwp-3jh6","cve":"CVE-2026-30932","affectedVersions":"\u003C=2.3.4","source":"GitHub","reportedAt":"2026-03-24 16:49:21","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-x6w6-2xwp-3jh6"}]},{"advisoryId":"PKSA-b24n-4864-6pc2","packageName":"froxlor\/froxlor","remoteId":"GHSA-33mp-8p67-xj7c","title":"Froxlor has Admin-to-Root Privilege Escalation via Input Validation Bypass + OS Command Injection","link":"https:\/\/github.com\/advisories\/GHSA-33mp-8p67-xj7c","cve":"CVE-2026-26279","affectedVersions":"\u003C=2.3.3","source":"GitHub","reportedAt":"2026-03-03 17:40:19","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-33mp-8p67-xj7c"}]}],"mediawiki\/maps":[{"advisoryId":"PKSA-hjtx-83wm-5fvj","packageName":"mediawiki\/maps","remoteId":"GHSA-4h7g-5542-v3fc","title":"mediawiki\/maps has stored XSS through the overlays parameter in the display_map parser function","link":"https:\/\/github.com\/advisories\/GHSA-4h7g-5542-v3fc","cve":"CVE-2026-52854","affectedVersions":"\u003C12.1.3","source":"GitHub","reportedAt":"2026-07-02 17:51:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4h7g-5542-v3fc"}]}],"twig\/twig":[{"advisoryId":"PKSA-8zx5-v2nz-58pb","packageName":"twig\/twig","remoteId":"GHSA-529h-vh3j-85hq","title":"Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`","link":"https:\/\/github.com\/advisories\/GHSA-529h-vh3j-85hq","cve":"CVE-2026-49981","affectedVersions":"\u003C=3.26.0","source":"GitHub","reportedAt":"2026-07-01 18:55:49","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-529h-vh3j-85hq"}]},{"advisoryId":"PKSA-fbvq-z33h-r2np","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2026-48808.yaml","title":"Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`","link":"https:\/\/symfony.com\/blog\/cve-2026-48808-sandbox-property-allowlist-bypass-via-the-column-filter-under-sourcepolicyinterface","cve":"CVE-2026-48808","affectedVersions":"\u003E=1.0.0,\u003C2.0.0|\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C3.27.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-27 15:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h8vq-8gpg-mhcg"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2026-48808.yaml"}]},{"advisoryId":"PKSA-g9zw-qxh8-pq8w","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2026-48805.yaml","title":"Sandbox state regression in deprecated internal wrappers in `src\/Resources\/core.php`","link":"https:\/\/symfony.com\/blog\/cve-2026-48805-sandbox-state-regression-in-deprecated-internal-wrappers-in-src-resources-core-php","cve":"CVE-2026-48805","affectedVersions":"\u003E=1.0.0,\u003C2.0.0|\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C3.27.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-27 15:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-p42q-9prx-q5wq"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2026-48805.yaml"}]},{"advisoryId":"PKSA-yd6k-t2gh-1m43","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2026-46636.yaml","title":"Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders","link":"https:\/\/symfony.com\/blog\/cve-2026-46636-sandbox-filter-tag-and-function-allow-list-bypass-when-sandbox-state-changes-between-renders","cve":"CVE-2026-46636","affectedVersions":"\u003E=1.0.0,\u003C2.0.0|\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C3.27.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-27 15:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2026-46636.yaml"}]},{"advisoryId":"PKSA-1tmc-rt7x-12w6","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2026-48806.yaml","title":"Sandbox `__toString()` policy bypass via dynamic mapping keys","link":"https:\/\/symfony.com\/blog\/cve-2026-48806-sandbox-tostring-policy-bypass-via-dynamic-mapping-keys","cve":"CVE-2026-48806","affectedVersions":"\u003E=1.0.0,\u003C2.0.0|\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C3.27.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-27 15:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5v5v-ww74-355v"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2026-48806.yaml"}]},{"advisoryId":"PKSA-xx6c-6d96-db2w","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2026-48807.yaml","title":"Sandbox `__toString()` policy bypass via `Traversable` in `join`\/`replace` and `in`\/`not in` operators","link":"https:\/\/symfony.com\/blog\/cve-2026-48807-sandbox-tostring-policy-bypass-via-traversable-in-join-replace-and-in-not-in-operators","cve":"CVE-2026-48807","affectedVersions":"\u003E=1.0.0,\u003C2.0.0|\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C3.27.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-27 15:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8x9c-rmqh-456c"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2026-48807.yaml"}]},{"advisoryId":"PKSA-5k7f-wvjj-jrgw","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2026-46640.yaml","title":"Arbitrary PHP code execution via `_self.(\u003Cstring\u003E)` macro-reference compilation","link":"https:\/\/symfony.com\/cve-2026-46640","cve":"CVE-2026-46640","affectedVersions":"\u003E=3.15.0,\u003C3.26.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-45vw-wh46-2vx8"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2026-46640.yaml"}]},{"advisoryId":"PKSA-sjvz-tbbr-vwth","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2026-46628.yaml","title":"The `spaceless` filter implicitly marks its output as safe","link":"https:\/\/symfony.com\/cve-2026-46628","cve":"CVE-2026-46628","affectedVersions":"\u003E=1.0.0,\u003C2.0.0|\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C3.26.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-4j38-f5cw-54h7"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2026-46628.yaml"}]},{"advisoryId":"PKSA-h8hf-ytnd-5t9q","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2026-46633.yaml","title":"PHP code injection via `{% use %}` template name","link":"https:\/\/symfony.com\/cve-2026-46633","cve":"CVE-2026-46633","affectedVersions":"\u003E=1.0.0,\u003C2.0.0|\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C3.26.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-7p85-w9px-jpjp"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2026-46633.yaml"}]},{"advisoryId":"PKSA-wwb1-81rc-pd65","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2026-47730.yaml","title":"XSS in profiler HtmlDumper via unescaped template and profile names","link":"https:\/\/symfony.com\/cve-2026-47730","cve":"CVE-2026-47730","affectedVersions":"\u003E=3.0.0,\u003C3.26.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-2g2g-8p8h-fgwm"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2026-47730.yaml"}]},{"advisoryId":"PKSA-hgmw-wn4d-hpcy","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2026-46639.yaml","title":"Sandbox property and method bypass via object-destructuring assignment","link":"https:\/\/symfony.com\/cve-2026-46639","cve":"CVE-2026-46639","affectedVersions":"\u003E=3.24.0,\u003C3.26.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mm6w-gr99-p3jj"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2026-46639.yaml"}]},{"advisoryId":"PKSA-kvv6-36cr-fkzb","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2026-46627.yaml","title":"Sandbox does not protect against resource exhaustion","link":"https:\/\/symfony.com\/cve-2026-46627","cve":"CVE-2026-46627","affectedVersions":"\u003E=1.0.0,\u003C2.0.0|\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C3.26.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2026-46627.yaml"}]},{"advisoryId":"PKSA-n14z-jjjg-g8vd","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2026-46635.yaml","title":"Sandbox property allowlist bypass via the `column` filter (array_column on objects)","link":"https:\/\/symfony.com\/cve-2026-46635","cve":"CVE-2026-46635","affectedVersions":"\u003E=1.0.0,\u003C2.0.0|\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C3.26.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-vcc8-phrv-43wj"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2026-46635.yaml"}]},{"advisoryId":"PKSA-3mcc-k66d-pydb","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2026-46638.yaml","title":"`{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)","link":"https:\/\/symfony.com\/cve-2026-46638","cve":"CVE-2026-46638","affectedVersions":"\u003E=1.0.0,\u003C2.0.0|\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C3.26.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7fxw-r6jv-74c8"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2026-46638.yaml"}]},{"advisoryId":"PKSA-gw7n-z4yx-7xjt","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2026-24425.yaml","title":"Possible sandbox bypass when using a source policy","link":"https:\/\/symfony.com\/cve-2026-24425","cve":"CVE-2026-24425","affectedVersions":"\u003E=2.16.0,\u003C3.0.0|\u003E=3.9.0,\u003C3.26.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2q52-x2ff-qgfr"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2026-24425.yaml"}]},{"advisoryId":"PKSA-dpx1-78wg-1kqs","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2026-47732.yaml","title":"Sandbox: multiple `__toString()` policy bypasses via unguarded string coercion points","link":"https:\/\/symfony.com\/cve-2026-47732","cve":"CVE-2026-47732","affectedVersions":"\u003E=1.0.0,\u003C2.0.0|\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C3.26.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pr2w-4gpj-cpq4"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2026-47732.yaml"}]},{"advisoryId":"PKSA-21g2-dzjv-sky5","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2026-46634.yaml","title":"`template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name","link":"https:\/\/symfony.com\/cve-2026-46634","cve":"CVE-2026-46634","affectedVersions":"\u003E=3.9.0,\u003C3.26.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-24x9-r6q4-q93w"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2026-46634.yaml"}]},{"advisoryId":"PKSA-yhcn-xrg3-68b1","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2024-51754.yaml","title":"Unguarded calls to __toString() when nesting an object into an array","link":"https:\/\/symfony.com\/blog\/cve-2024-51754-unguarded-calls-to-tostring-in-a-sandbox-when-an-object-is-in-an-array-or-an-argument-list","cve":"CVE-2024-51754","affectedVersions":"\u003E=1.0.0,\u003C2.0.0|\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C3.11.2|\u003E=3.12.0,\u003C3.14.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2024-11-06 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-6377-hfv9-hqf6"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2024-51754.yaml"}]},{"advisoryId":"PKSA-2wrf-1xmk-1pky","packageName":"twig\/twig","remoteId":"twig\/twig\/CVE-2024-51755.yaml","title":"Unguarded calls to __isset() and to array-accesses when the sandbox is enabled","link":"https:\/\/symfony.com\/blog\/cve-2024-51755-unguarded-calls-to-isset-and-to-array-accesses-in-a-sandbox","cve":"CVE-2024-51755","affectedVersions":"\u003E=1.0.0,\u003C2.0.0|\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C3.11.2|\u003E=3.12.0,\u003C3.14.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2024-11-06 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-jjxq-ff2g-95vh"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/twig\/CVE-2024-51755.yaml"}]}],"paymenter\/paymenter":[{"advisoryId":"PKSA-rhsq-g9d6-k3wy","packageName":"paymenter\/paymenter","remoteId":"GHSA-pgcq-8grm-5rx9","title":"Paymenter has race condition in payWithCredit() that enables credit double-spend","link":"https:\/\/github.com\/advisories\/GHSA-pgcq-8grm-5rx9","cve":"CVE-2026-55219","affectedVersions":"\u003C=1.5.4","source":"GitHub","reportedAt":"2026-06-30 19:11:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pgcq-8grm-5rx9"}]},{"advisoryId":"PKSA-6pn7-by4p-qj8v","packageName":"paymenter\/paymenter","remoteId":"GHSA-5q4q-834j-g8g4","title":"Paymenter has URL parameter injection that bypasses paid plan limits at checkout","link":"https:\/\/github.com\/advisories\/GHSA-5q4q-834j-g8g4","cve":"CVE-2026-47198","affectedVersions":"\u003C1.5.1","source":"GitHub","reportedAt":"2026-06-30 16:44:31","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5q4q-834j-g8g4"}]},{"advisoryId":"PKSA-c1p6-fvgz-yw29","packageName":"paymenter\/paymenter","remoteId":"GHSA-x93q-x9pc-w5hw","title":"Paymenter has broken object level authorization via service reference manipulation on ticket creation","link":"https:\/\/github.com\/advisories\/GHSA-x93q-x9pc-w5hw","cve":"CVE-2026-44585","affectedVersions":"\u003C1.5.0","source":"GitHub","reportedAt":"2026-06-22 20:30:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x93q-x9pc-w5hw"}]},{"advisoryId":"PKSA-scs3-cd2n-yh78","packageName":"paymenter\/paymenter","remoteId":"GHSA-7wwh-xcc3-9fcg","title":"Paymenter has Blind Unauthenticated SSRF on the Paypal gateway module","link":"https:\/\/github.com\/advisories\/GHSA-7wwh-xcc3-9fcg","cve":"CVE-2026-44583","affectedVersions":"\u003C1.5.0","source":"GitHub","reportedAt":"2026-06-22 20:28:29","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7wwh-xcc3-9fcg"}]},{"advisoryId":"PKSA-db93-h5mg-r9z4","packageName":"paymenter\/paymenter","remoteId":"GHSA-rv89-wch8-c574","title":"Paymenter doesn\u0027t reset email verification status after email change","link":"https:\/\/github.com\/advisories\/GHSA-rv89-wch8-c574","cve":"CVE-2026-44584","affectedVersions":"\u003C1.5.0","source":"GitHub","reportedAt":"2026-06-22 20:29:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rv89-wch8-c574"}]},{"advisoryId":"PKSA-7yx9-82k3-n51f","packageName":"paymenter\/paymenter","remoteId":"GHSA-5pm9-r2m8-rcmj","title":"Paymenter vulnerable to Remote Code Execution via public file uploads","link":"https:\/\/github.com\/advisories\/GHSA-5pm9-r2m8-rcmj","cve":"CVE-2025-58048","affectedVersions":"\u003C1.2.11","source":"GitHub","reportedAt":"2026-06-22 16:53:59","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-5pm9-r2m8-rcmj"}]}],"concrete5\/concrete5":[{"advisoryId":"PKSA-btjd-g8jc-d7j1","packageName":"concrete5\/concrete5","remoteId":"GHSA-jqvq-gv67-3567","title":"Concrete CMS is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog","link":"https:\/\/github.com\/advisories\/GHSA-jqvq-gv67-3567","cve":"CVE-2026-8347","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-26 13:30:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-jqvq-gv67-3567"}]},{"advisoryId":"PKSA-ft53-g53d-bkdk","packageName":"concrete5\/concrete5","remoteId":"GHSA-xjg6-5v39-v7fc","title":"Concrete CMS is vulnerable to CSRF via Backend\\File::approveVersion","link":"https:\/\/github.com\/advisories\/GHSA-xjg6-5v39-v7fc","cve":"CVE-2026-8340","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-26 13:30:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xjg6-5v39-v7fc"}]},{"advisoryId":"PKSA-7k3m-1wvv-hrns","packageName":"concrete5\/concrete5","remoteId":"GHSA-q9fm-mpg8-8jqm","title":"Concrete CMS is vulnerable to Stored XSS via page name in the Atomik theme","link":"https:\/\/github.com\/advisories\/GHSA-q9fm-mpg8-8jqm","cve":"CVE-2026-8353","affectedVersions":"\u003E=9.0.0RC.1,\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-26 13:30:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-q9fm-mpg8-8jqm"}]},{"advisoryId":"PKSA-9s3m-thqq-9cfd","packageName":"concrete5\/concrete5","remoteId":"GHSA-xj25-753j-wgp9","title":"Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete\/controllers\/dialog\/express\/association\/reorder","link":"https:\/\/github.com\/advisories\/GHSA-xj25-753j-wgp9","cve":"CVE-2026-8415","affectedVersions":"\u003E=9.0.0RC1,\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xj25-753j-wgp9"}]},{"advisoryId":"PKSA-4vdj-385c-kbs8","packageName":"concrete5\/concrete5","remoteId":"GHSA-qj94-6rx6-27fr","title":"Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete\/controllers\/backend\/file addFavoriteFolder($id)","link":"https:\/\/github.com\/advisories\/GHSA-qj94-6rx6-27fr","cve":"CVE-2026-8416","affectedVersions":"\u003E=9.0.0RC1,\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-qj94-6rx6-27fr"}]},{"advisoryId":"PKSA-d6mg-vz5r-sfbf","packageName":"concrete5\/concrete5","remoteId":"GHSA-67hj-8239-cmf5","title":"Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete\/controllers\/backend\/file removeFavoriteFolder($id)","link":"https:\/\/github.com\/advisories\/GHSA-67hj-8239-cmf5","cve":"CVE-2026-8427","affectedVersions":"\u003E=9.0.0RC1,\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-67hj-8239-cmf5"}]},{"advisoryId":"PKSA-q99w-2v6k-kwsc","packageName":"concrete5\/concrete5","remoteId":"GHSA-97jw-gr4m-c5v8","title":"Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete\/controllers\/backend\/file star()","link":"https:\/\/github.com\/advisories\/GHSA-97jw-gr4m-c5v8","cve":"CVE-2026-8432","affectedVersions":"\u003E=9.0.0RC1,\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-97jw-gr4m-c5v8"}]},{"advisoryId":"PKSA-1cn3-6pmf-71hx","packageName":"concrete5\/concrete5","remoteId":"GHSA-6fxm-r8p3-mx5c","title":"Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete\/controllers\/backend\/file rescan()","link":"https:\/\/github.com\/advisories\/GHSA-6fxm-r8p3-mx5c","cve":"CVE-2026-8433","affectedVersions":"\u003E=9.0.0RC1,\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-6fxm-r8p3-mx5c"}]},{"advisoryId":"PKSA-15g8-fcvm-qwvy","packageName":"concrete5\/concrete5","remoteId":"GHSA-6qjh-p324-694f","title":"Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete\/controllers\/backend\/file rescanMultiple()","link":"https:\/\/github.com\/advisories\/GHSA-6qjh-p324-694f","cve":"CVE-2026-8434","affectedVersions":"\u003E=9.0.0RC1,\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-6qjh-p324-694f"}]},{"advisoryId":"PKSA-54fw-f2r8-pxcd","packageName":"concrete5\/concrete5","remoteId":"GHSA-44q4-354f-c826","title":"Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete\/controllers\/backend\/file approveVersion()","link":"https:\/\/github.com\/advisories\/GHSA-44q4-354f-c826","cve":"CVE-2026-8435","affectedVersions":"\u003E=9.0.0RC1,\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-44q4-354f-c826"}]},{"advisoryId":"PKSA-5dbv-8tcv-hjg5","packageName":"concrete5\/concrete5","remoteId":"GHSA-wmw3-3fv3-h54w","title":"Concrete CMS has a session-hardening bypass and allows password change without reauthorization","link":"https:\/\/github.com\/advisories\/GHSA-wmw3-3fv3-h54w","cve":"CVE-2026-8327","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wmw3-3fv3-h54w"}]},{"advisoryId":"PKSA-9rx2-25z1-q5pv","packageName":"concrete5\/concrete5","remoteId":"GHSA-f73j-pm2c-rxvr","title":"Concrete CMS is Vulnerable to Reflected XSS in Legacy Pagination","link":"https:\/\/github.com\/advisories\/GHSA-f73j-pm2c-rxvr","cve":"CVE-2026-8245","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f73j-pm2c-rxvr"}]},{"advisoryId":"PKSA-td7z-y5jc-79yq","packageName":"concrete5\/concrete5","remoteId":"GHSA-f54h-78c9-c24h","title":"Concrete CMS: OAuth 2.0 Authorization-Code Handler Bypasses Account Status","link":"https:\/\/github.com\/advisories\/GHSA-f54h-78c9-c24h","cve":"CVE-2026-7887","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:16","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-f54h-78c9-c24h"}]},{"advisoryId":"PKSA-wqcg-9fxw-b667","packageName":"concrete5\/concrete5","remoteId":"GHSA-8c7c-h7px-267g","title":"Concrete CMS is vulnerable to IDOR in surveys","link":"https:\/\/github.com\/advisories\/GHSA-8c7c-h7px-267g","cve":"CVE-2026-8337","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8c7c-h7px-267g"}]},{"advisoryId":"PKSA-qzg4-w3py-ddfh","packageName":"concrete5\/concrete5","remoteId":"GHSA-56c9-xq5g-xrf9","title":"Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete\/controllers\/dialog\/logs\/delete","link":"https:\/\/github.com\/advisories\/GHSA-56c9-xq5g-xrf9","cve":"CVE-2026-8409","affectedVersions":"\u003E=9.0.0RC1,\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-56c9-xq5g-xrf9"}]},{"advisoryId":"PKSA-x9hx-5ky4-cyz2","packageName":"concrete5\/concrete5","remoteId":"GHSA-v7c7-658v-hh7v","title":"Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete\/controllers\/dialog\/logs\/bulk\/delete","link":"https:\/\/github.com\/advisories\/GHSA-v7c7-658v-hh7v","cve":"CVE-2026-8410","affectedVersions":"\u003E=9.0.0RC1,\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-v7c7-658v-hh7v"}]},{"advisoryId":"PKSA-ngsw-3psq-jryj","packageName":"concrete5\/concrete5","remoteId":"GHSA-752x-23hp-jmv6","title":"Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete\/controllers\/dialog\/page\/bulk\/delete","link":"https:\/\/github.com\/advisories\/GHSA-752x-23hp-jmv6","cve":"CVE-2026-8411","affectedVersions":"\u003E=9.0.0RC1,\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-752x-23hp-jmv6"}]},{"advisoryId":"PKSA-ks9q-hdsh-jhd2","packageName":"concrete5\/concrete5","remoteId":"GHSA-rv3q-xmfw-mcjv","title":"Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete\/controllers\/dialog\/page\/bulk\/cache","link":"https:\/\/github.com\/advisories\/GHSA-rv3q-xmfw-mcjv","cve":"CVE-2026-8412","affectedVersions":"\u003E=9.0.0RC1,\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-rv3q-xmfw-mcjv"}]},{"advisoryId":"PKSA-9yjm-r5x4-kcxv","packageName":"concrete5\/concrete5","remoteId":"GHSA-98qf-jvwj-2r5f","title":"Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete\/controllers\/dialog\/event\/duplicate","link":"https:\/\/github.com\/advisories\/GHSA-98qf-jvwj-2r5f","cve":"CVE-2026-8414","affectedVersions":"\u003E=9.0.0RC1,\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-98qf-jvwj-2r5f"}]},{"advisoryId":"PKSA-jszb-q2pk-2pw4","packageName":"concrete5\/concrete5","remoteId":"GHSA-mpq2-mv8p-9wm6","title":"Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete\/controllers\/dialog\/page\/bulk\/design","link":"https:\/\/github.com\/advisories\/GHSA-mpq2-mv8p-9wm6","cve":"CVE-2026-8413","affectedVersions":"\u003E=9.0.0RC1,\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-mpq2-mv8p-9wm6"}]},{"advisoryId":"PKSA-9c7x-8d4g-nf5y","packageName":"concrete5\/concrete5","remoteId":"GHSA-gjwq-9v8p-47w7","title":"Concrete CMS\u0027s RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation","link":"https:\/\/github.com\/advisories\/GHSA-gjwq-9v8p-47w7","cve":"CVE-2026-7890","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:16","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-gjwq-9v8p-47w7"}]},{"advisoryId":"PKSA-5hj9-8591-58xc","packageName":"concrete5\/concrete5","remoteId":"GHSA-pcrh-gj77-j4mw","title":"Concrete CMS is vulnerable to Stored XSS via external-link page cvName","link":"https:\/\/github.com\/advisories\/GHSA-pcrh-gj77-j4mw","cve":"CVE-2026-8139","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:16","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-pcrh-gj77-j4mw"}]},{"advisoryId":"PKSA-c22k-ckrz-mqyc","packageName":"concrete5\/concrete5","remoteId":"GHSA-58c8-vvqw-cm7m","title":"Concrete CMS is vulnerable to IDOR combined with a missing authentication gate","link":"https:\/\/github.com\/advisories\/GHSA-58c8-vvqw-cm7m","cve":"CVE-2026-8236","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-58c8-vvqw-cm7m"}]},{"advisoryId":"PKSA-xbvd-x9c6-831x","packageName":"concrete5\/concrete5","remoteId":"GHSA-xpgc-7vc2-8725","title":"Concrete CMS is vulnerable to IDOR","link":"https:\/\/github.com\/advisories\/GHSA-xpgc-7vc2-8725","cve":"CVE-2026-8237","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xpgc-7vc2-8725"}]},{"advisoryId":"PKSA-5sc7-fzk2-kdbh","packageName":"concrete5\/concrete5","remoteId":"GHSA-qv3x-mffx-9gw8","title":"Concrete CMS is vulnerable to IDOR","link":"https:\/\/github.com\/advisories\/GHSA-qv3x-mffx-9gw8","cve":"CVE-2026-8238","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qv3x-mffx-9gw8"}]},{"advisoryId":"PKSA-7cdm-s319-44x4","packageName":"concrete5\/concrete5","remoteId":"GHSA-2xp7-rpvc-pjwc","title":"Concrete CMS is vulnerable to IDOR","link":"https:\/\/github.com\/advisories\/GHSA-2xp7-rpvc-pjwc","cve":"CVE-2026-8239","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2xp7-rpvc-pjwc"}]},{"advisoryId":"PKSA-d421-dyhx-r37b","packageName":"concrete5\/concrete5","remoteId":"GHSA-vpgr-cwfx-pwfw","title":"Concrete CMS is\u00a0vulnerable to unauthenticated page metadata disclosure","link":"https:\/\/github.com\/advisories\/GHSA-vpgr-cwfx-pwfw","cve":"CVE-2026-8240","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vpgr-cwfx-pwfw"}]},{"advisoryId":"PKSA-bbrg-6bt9-f5br","packageName":"concrete5\/concrete5","remoteId":"GHSA-chfm-cm6h-q5x7","title":"Concrete CMS is subject to\u00a0Insecure Direct Object Reference\u00a0(IDOR) in the Express Entry Detail block","link":"https:\/\/github.com\/advisories\/GHSA-chfm-cm6h-q5x7","cve":"CVE-2026-7881","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-chfm-cm6h-q5x7"}]},{"advisoryId":"PKSA-frbf-6y2c-qxdh","packageName":"concrete5\/concrete5","remoteId":"GHSA-p8p9-5953-h9jw","title":"Concrete CMS is vulnerable to\u00a0IDOR in AddMessage\/UpdateMessage","link":"https:\/\/github.com\/advisories\/GHSA-p8p9-5953-h9jw","cve":"CVE-2026-7886","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:16","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-p8p9-5953-h9jw"}]},{"advisoryId":"PKSA-ppz6-swp7-nf1t","packageName":"concrete5\/concrete5","remoteId":"GHSA-fqg3-8w8r-8g94","title":"Concrete CMS has an unauthorized file access issue","link":"https:\/\/github.com\/advisories\/GHSA-fqg3-8w8r-8g94","cve":"CVE-2026-7879","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fqg3-8w8r-8g94"}]},{"advisoryId":"PKSA-fxgv-rp7s-m994","packageName":"concrete5\/concrete5","remoteId":"GHSA-66rg-92q4-6m8q","title":"Concrete CMS is vulnerable to unauthorized file deletion","link":"https:\/\/github.com\/advisories\/GHSA-66rg-92q4-6m8q","cve":"CVE-2026-7882","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-22 00:31:16","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-66rg-92q4-6m8q"}]},{"advisoryId":"PKSA-ftn7-4ynj-kvdm","packageName":"concrete5\/concrete5","remoteId":"GHSA-4c8m-6fwx-m7xq","title":"Concrete CMS contains a CSRF vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-4c8m-6fwx-m7xq","cve":"CVE-2026-8421","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-21 21:30:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4c8m-6fwx-m7xq"}]},{"advisoryId":"PKSA-fqsc-qq8z-j29z","packageName":"concrete5\/concrete5","remoteId":"GHSA-prxr-vjgc-2cq9","title":"Concrete CMS is Vulnerable to Cross-Site Request Forgery","link":"https:\/\/github.com\/advisories\/GHSA-prxr-vjgc-2cq9","cve":"CVE-2026-8428","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-21 21:30:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-prxr-vjgc-2cq9"}]},{"advisoryId":"PKSA-8c12-5257-gxrx","packageName":"concrete5\/concrete5","remoteId":"GHSA-jr5g-qv3g-rxxx","title":"Concrete does not validate a CSRF token before processing requests to `\/dashboard\/extend\/update\/do_update\/\u003CpkgHandle\u003E`","link":"https:\/\/github.com\/advisories\/GHSA-jr5g-qv3g-rxxx","cve":"CVE-2026-8417","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-21 21:30:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jr5g-qv3g-rxxx"}]},{"advisoryId":"PKSA-4c8s-p3cg-97tt","packageName":"concrete5\/concrete5","remoteId":"GHSA-9v2g-37mp-qpxf","title":"Concrete CMS has Stored XSS through its height parameter","link":"https:\/\/github.com\/advisories\/GHSA-9v2g-37mp-qpxf","cve":"CVE-2026-8203","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-21 21:30:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9v2g-37mp-qpxf"}]},{"advisoryId":"PKSA-vtsr-51yz-qsq4","packageName":"concrete5\/concrete5","remoteId":"GHSA-x2fp-hj8c-mmxh","title":"Concrete CMS is vulnerable to authorization bypass in the Calendar Event Frontend Dialog","link":"https:\/\/github.com\/advisories\/GHSA-x2fp-hj8c-mmxh","cve":"CVE-2026-8204","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-21 21:30:38","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x2fp-hj8c-mmxh"}]},{"advisoryId":"PKSA-tftp-4vyz-vsqv","packageName":"concrete5\/concrete5","remoteId":"GHSA-46xh-7854-f568","title":"Concrete CMS is vulnerable to authorization bypass in the Calendar Block","link":"https:\/\/github.com\/advisories\/GHSA-46xh-7854-f568","cve":"CVE-2026-8205","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-21 21:30:38","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-46xh-7854-f568"}]},{"advisoryId":"PKSA-bks2-z4jr-2jcs","packageName":"concrete5\/concrete5","remoteId":"GHSA-g7xp-jf3x-wcx4","title":"Concrete CMS is vulnerable to missing authorization in the bulk_user_assignment.php","link":"https:\/\/github.com\/advisories\/GHSA-g7xp-jf3x-wcx4","cve":"CVE-2026-8350","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-21 21:30:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g7xp-jf3x-wcx4"}]},{"advisoryId":"PKSA-61mc-443r-dbcf","packageName":"concrete5\/concrete5","remoteId":"GHSA-5rj5-gfmr-hrc3","title":"Concrete CMS does not validate a CSRF token before processing requests to `\/dashboard\/extend\/update\/prepare_remote_upgrade\/\u003CremoteMPID\u003E`","link":"https:\/\/github.com\/advisories\/GHSA-5rj5-gfmr-hrc3","cve":"CVE-2026-8426","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-21 21:30:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5rj5-gfmr-hrc3"}]},{"advisoryId":"PKSA-k9dr-8j28-xxx4","packageName":"concrete5\/concrete5","remoteId":"GHSA-h72c-xx3w-w8h7","title":"Concrete CMS is vulnerable to Stored XSS via OAuth integration name","link":"https:\/\/github.com\/advisories\/GHSA-h72c-xx3w-w8h7","cve":"CVE-2026-8197","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-21 21:30:37","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h72c-xx3w-w8h7"}]},{"advisoryId":"PKSA-sqtt-5khz-wksh","packageName":"concrete5\/concrete5","remoteId":"GHSA-645j-cm4x-3xvw","title":"Concrete CMS Vulnerable to Relative Path Traversal","link":"https:\/\/github.com\/advisories\/GHSA-645j-cm4x-3xvw","cve":"CVE-2026-8134","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-21 21:30:37","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-645j-cm4x-3xvw"}]},{"advisoryId":"PKSA-xn4v-f846-x248","packageName":"concrete5\/concrete5","remoteId":"GHSA-4g7q-44qp-cc5c","title":"Concrete CMS is vulnerable to\u00a0unauthenticated file usage disclosure","link":"https:\/\/github.com\/advisories\/GHSA-4g7q-44qp-cc5c","cve":"CVE-2026-6826","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-21 21:30:37","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4g7q-44qp-cc5c"}]},{"advisoryId":"PKSA-wrt6-mxyh-dqd1","packageName":"concrete5\/concrete5","remoteId":"GHSA-pv2v-6w2v-97x6","title":"Concrete CMS Vulnerable to Deserialization of Untrusted Data","link":"https:\/\/github.com\/advisories\/GHSA-pv2v-6w2v-97x6","cve":"CVE-2026-8135","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-21 21:30:37","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pv2v-6w2v-97x6"}]},{"advisoryId":"PKSA-krdd-qg62-29s4","packageName":"concrete5\/concrete5","remoteId":"GHSA-r42c-3rr2-jrfp","title":"Concrete CMS is Vulnerable to Cross-Site Request Forgery","link":"https:\/\/github.com\/advisories\/GHSA-r42c-3rr2-jrfp","cve":"CVE-2026-8140","affectedVersions":"\u003C9.5.1","source":"GitHub","reportedAt":"2026-05-21 21:30:37","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r42c-3rr2-jrfp"}]},{"advisoryId":"PKSA-xvm3-fqgr-dzxw","packageName":"concrete5\/concrete5","remoteId":"GHSA-p68c-rmfh-j48h","title":"ConcreteCMS is vulnerable to Denial of Service During Bulk Downloads","link":"https:\/\/github.com\/advisories\/GHSA-p68c-rmfh-j48h","cve":"CVE-2026-30662","affectedVersions":"\u003C=9.4.7","source":"GitHub","reportedAt":"2026-03-24 15:30:29","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-p68c-rmfh-j48h"}]},{"advisoryId":"PKSA-k8s6-ntjk-g2wy","packageName":"concrete5\/concrete5","remoteId":"GHSA-f4vq-pj32-gr4q","title":"Concrete CMS has a stored Cross-site Scripting (XSS) vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-f4vq-pj32-gr4q","cve":"CVE-2026-3241","affectedVersions":"\u003C9.4.8","source":"GitHub","reportedAt":"2026-03-04 03:31:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f4vq-pj32-gr4q"}]},{"advisoryId":"PKSA-nnjv-c4gq-wny8","packageName":"concrete5\/concrete5","remoteId":"GHSA-w9qg-chfh-g3q9","title":"Concrete CMS has a stored Cross-site Scripting (XSS) vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-w9qg-chfh-g3q9","cve":"CVE-2026-3242","affectedVersions":"\u003C9.4.8","source":"GitHub","reportedAt":"2026-03-04 03:31:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w9qg-chfh-g3q9"}]},{"advisoryId":"PKSA-79x2-hpny-rxg9","packageName":"concrete5\/concrete5","remoteId":"GHSA-gj26-w59c-29mf","title":"Concrete CMS vulnerable to\u00a0Remote Code Execution by\u00a0stored PHP object injection","link":"https:\/\/github.com\/advisories\/GHSA-gj26-w59c-29mf","cve":"CVE-2026-3452","affectedVersions":"\u003C9.4.8","source":"GitHub","reportedAt":"2026-03-04 03:31:34","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gj26-w59c-29mf"}]},{"advisoryId":"PKSA-r7c6-pnck-sspr","packageName":"concrete5\/concrete5","remoteId":"GHSA-mm5f-5rqw-574f","title":"Concrete CMS has a stored Cross-site Scripting (XSS) vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-mm5f-5rqw-574f","cve":"CVE-2026-3244","affectedVersions":"\u003C9.4.8","source":"GitHub","reportedAt":"2026-03-04 03:31:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mm5f-5rqw-574f"}]},{"advisoryId":"PKSA-46yc-bd63-xkv6","packageName":"concrete5\/concrete5","remoteId":"GHSA-6mxw-2vhf-42g5","title":"Concrete CMS vulnerable to Cross-Site Request Forgery (CSRF)","link":"https:\/\/github.com\/advisories\/GHSA-6mxw-2vhf-42g5","cve":"CVE-2026-2994","affectedVersions":"\u003C9.4.8","source":"GitHub","reportedAt":"2026-03-04 03:31:34","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-6mxw-2vhf-42g5"}]},{"advisoryId":"PKSA-gwgb-qhcr-dkk9","packageName":"concrete5\/concrete5","remoteId":"GHSA-45fj-fvmm-xcc5","title":"Concrete CMS has a stored Cross-site Scripting (XSS) vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-45fj-fvmm-xcc5","cve":"CVE-2026-3240","affectedVersions":"\u003C9.4.8","source":"GitHub","reportedAt":"2026-03-04 03:31:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-45fj-fvmm-xcc5"}]},{"advisoryId":"PKSA-6rjc-txvn-sxnp","packageName":"concrete5\/concrete5","remoteId":"GHSA-r7vr-wg3f-8hr9","title":"Concrete5 CMS contains an XPath injection vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-r7vr-wg3f-8hr9","cve":"CVE-2022-50807","affectedVersions":"=9.1.3","source":"GitHub","reportedAt":"2026-01-14 00:31:27","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r7vr-wg3f-8hr9"}]}],"statamic\/cms":[{"advisoryId":"PKSA-9stt-y5w8-fn5y","packageName":"statamic\/cms","remoteId":"GHSA-7mqq-4v55-88gh","title":"Statamic CMS\u0027s incorrect authorization lets view-only users submit Live Preview content reserved for editors","link":"https:\/\/github.com\/advisories\/GHSA-7mqq-4v55-88gh","cve":"CVE-2026-54244","affectedVersions":"\u003E=6.0.0,\u003C6.20.3|\u003C5.74.0","source":"GitHub","reportedAt":"2026-06-26 23:10:37","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7mqq-4v55-88gh"}]},{"advisoryId":"PKSA-9vds-c3yh-rq22","packageName":"statamic\/cms","remoteId":"GHSA-v5c4-wcpj-x73m","title":"Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)","link":"https:\/\/github.com\/advisories\/GHSA-v5c4-wcpj-x73m","cve":"CVE-2026-54242","affectedVersions":"\u003E=6.0.0,\u003C6.20.1|\u003C5.73.24","source":"GitHub","reportedAt":"2026-06-26 23:03:28","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-v5c4-wcpj-x73m"}]},{"advisoryId":"PKSA-q7zp-ytbf-kmf9","packageName":"statamic\/cms","remoteId":"GHSA-h77m-qrj7-jxcw","title":"Statamic Vulnerable to CSV formula injection in form submission exports","link":"https:\/\/github.com\/advisories\/GHSA-h77m-qrj7-jxcw","cve":"CVE-2026-54243","affectedVersions":"\u003C5.73.24|\u003E=6.0.0,\u003C6.20.1","source":"GitHub","reportedAt":"2026-06-26 23:03:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h77m-qrj7-jxcw"}]},{"advisoryId":"PKSA-ykrx-2shq-vs9n","packageName":"statamic\/cms","remoteId":"GHSA-2497-6pwj-pwg7","title":"Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources","link":"https:\/\/github.com\/advisories\/GHSA-2497-6pwj-pwg7","cve":"CVE-2026-49288","affectedVersions":"\u003E=6.0.0,\u003C6.20.0|\u003C5.73.23","source":"GitHub","reportedAt":"2026-06-26 22:12:21","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2497-6pwj-pwg7"}]},{"advisoryId":"PKSA-fhw5-pm86-31ff","packageName":"statamic\/cms","remoteId":"GHSA-m92m-r54r-x8r2","title":"Statamic CMS\u0027s unsafe method invocation via collection sorting allows data destruction","link":"https:\/\/github.com\/advisories\/GHSA-m92m-r54r-x8r2","cve":"CVE-2026-49287","affectedVersions":"\u003E=6.0.0,\u003C6.20.0|\u003C5.73.23","source":"GitHub","reportedAt":"2026-06-26 22:15:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-m92m-r54r-x8r2"}]},{"advisoryId":"PKSA-7fht-jznj-7mgv","packageName":"statamic\/cms","remoteId":"GHSA-pf9c-ch8r-2958","title":"Statamic CMS: Server-Side Request Forgery via Glide","link":"https:\/\/github.com\/advisories\/GHSA-pf9c-ch8r-2958","cve":"CVE-2026-45660","affectedVersions":"\u003E=6.0.0-alpha.1,\u003C6.18.1|\u003C5.73.22","source":"GitHub","reportedAt":"2026-05-18 15:32:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pf9c-ch8r-2958"}]},{"advisoryId":"PKSA-ynr1-y6st-8cwm","packageName":"statamic\/cms","remoteId":"GHSA-m24v-f7g5-gq67","title":"Statamic CMS vulnerable to email enumeration via forgot password endpoint","link":"https:\/\/github.com\/advisories\/GHSA-m24v-f7g5-gq67","cve":"CVE-2026-44306","affectedVersions":"\u003E=6.0.0,\u003C6.15.0|\u003C5.73.21","source":"GitHub","reportedAt":"2026-05-06 20:54:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m24v-f7g5-gq67"}]},{"advisoryId":"PKSA-yx2m-bjk3-fnky","packageName":"statamic\/cms","remoteId":"GHSA-4jjr-vmv7-wh4w","title":"Statamic: Unsafe method invocation via query value resolution allows data destruction","link":"https:\/\/github.com\/advisories\/GHSA-4jjr-vmv7-wh4w","cve":"CVE-2026-41175","affectedVersions":"\u003E=6.0.0-alpha.1,\u003C6.13.0|\u003C5.73.20","source":"GitHub","reportedAt":"2026-04-16 21:25:35","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4jjr-vmv7-wh4w"}]},{"advisoryId":"PKSA-8f4x-d8sb-16sq","packageName":"statamic\/cms","remoteId":"GHSA-cvh3-23vq-w7h4","title":"Statamic\u0027s Markdown preview endpoint exposes sensitive user data","link":"https:\/\/github.com\/advisories\/GHSA-cvh3-23vq-w7h4","cve":"CVE-2026-33882","affectedVersions":"\u003E=6.0.0-alpha.1,\u003C6.7.2|\u003C5.73.16","source":"GitHub","reportedAt":"2026-03-26 19:03:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cvh3-23vq-w7h4"}]},{"advisoryId":"PKSA-ffqw-wkbr-m6bg","packageName":"statamic\/cms","remoteId":"GHSA-3jg4-p23x-p4qx","title":"Statamic has Reflected XSS via unescaped redirect parameter in its password reset form tag","link":"https:\/\/github.com\/advisories\/GHSA-3jg4-p23x-p4qx","cve":"CVE-2026-33883","affectedVersions":"\u003E=6.0.0-alpha.1,\u003C6.7.2|\u003C5.73.16","source":"GitHub","reportedAt":"2026-03-26 19:05:27","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3jg4-p23x-p4qx"}]},{"advisoryId":"PKSA-tg1h-vfwx-wzp9","packageName":"statamic\/cms","remoteId":"GHSA-8vwx-ccf6-5wg2","title":"Statamic\u0027s live preview token bypasses content protection for unrelated entries","link":"https:\/\/github.com\/advisories\/GHSA-8vwx-ccf6-5wg2","cve":"CVE-2026-33884","affectedVersions":"\u003E=6.0.0-alpha.1,\u003C6.7.2|\u003C5.73.16","source":"GitHub","reportedAt":"2026-03-26 19:05:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8vwx-ccf6-5wg2"}]},{"advisoryId":"PKSA-3yh1-q236-qg5b","packageName":"statamic\/cms","remoteId":"GHSA-7f74-7q5w-hj4r","title":"Statamic has an Open Redirect on unauthenticated endpoints via URL parsing differential","link":"https:\/\/github.com\/advisories\/GHSA-7f74-7q5w-hj4r","cve":"CVE-2026-33885","affectedVersions":"\u003E=6.0.0.alpha.1,\u003C6.7.2|\u003C5.73.16","source":"GitHub","reportedAt":"2026-03-26 19:05:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7f74-7q5w-hj4r"}]},{"advisoryId":"PKSA-74j5-mc2z-3jj1","packageName":"statamic\/cms","remoteId":"GHSA-gcqf-5x9f-hq7f","title":"Statamic\u0027s sensitive configuration values are exposed to content editors via Antlers-enabled fields","link":"https:\/\/github.com\/advisories\/GHSA-gcqf-5x9f-hq7f","cve":"CVE-2026-33886","affectedVersions":"\u003E=6.5.0,\u003C6.7.2|\u003E=5.73.12,\u003C5.73.16","source":"GitHub","reportedAt":"2026-03-26 19:06:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gcqf-5x9f-hq7f"}]},{"advisoryId":"PKSA-yd5q-tqxd-dxfr","packageName":"statamic\/cms","remoteId":"GHSA-4hp7-3wxg-cv9q","title":"Statamic allows unauthorized content access through missing authorization in its revision controllers ","link":"https:\/\/github.com\/advisories\/GHSA-4hp7-3wxg-cv9q","cve":"CVE-2026-33887","affectedVersions":"\u003E=6.0.0-alpha.1,\u003C6.7.2|\u003C5.73.16","source":"GitHub","reportedAt":"2026-03-26 19:07:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4hp7-3wxg-cv9q"}]},{"advisoryId":"PKSA-4mnq-vkqt-4wqf","packageName":"statamic\/cms","remoteId":"GHSA-qm7r-wwq7-6f85","title":"Statamic has a path traversal in file dictionary fieldtype","link":"https:\/\/github.com\/advisories\/GHSA-qm7r-wwq7-6f85","cve":"CVE-2026-33171","affectedVersions":"\u003C5.73.14|\u003E=6.0.0-alpha.1,\u003C6.7.0","source":"GitHub","reportedAt":"2026-03-18 20:00:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qm7r-wwq7-6f85"}]},{"advisoryId":"PKSA-ymb8-dx7z-7137","packageName":"statamic\/cms","remoteId":"GHSA-wh3h-gvc4-cc2g","title":"Statamic is missing authorization check on taxonomy term creation via fieldtype","link":"https:\/\/github.com\/advisories\/GHSA-wh3h-gvc4-cc2g","cve":"CVE-2026-33177","affectedVersions":"\u003C5.73.14|\u003E=6.0.0-alpha.1,\u003C6.7.0","source":"GitHub","reportedAt":"2026-03-18 20:00:51","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wh3h-gvc4-cc2g"}]},{"advisoryId":"PKSA-8wnz-z9p8-kd44","packageName":"statamic\/cms","remoteId":"GHSA-7rcv-55mj-chg7","title":"Statamic has Stored XSS via SVG Sanitization Bypass","link":"https:\/\/github.com\/advisories\/GHSA-7rcv-55mj-chg7","cve":"CVE-2026-33172","affectedVersions":"\u003C5.73.14|\u003E=6.0.0-alpha.1,\u003C6.7.0","source":"GitHub","reportedAt":"2026-03-18 19:54:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7rcv-55mj-chg7"}]},{"advisoryId":"PKSA-thnk-qh3m-ttzb","packageName":"statamic\/cms","remoteId":"GHSA-hcch-w73c-jp4m","title":"Statamic vulnerable to privilege escalation via stored cross-site scripting","link":"https:\/\/github.com\/advisories\/GHSA-hcch-w73c-jp4m","cve":"CVE-2026-32612","affectedVersions":"\u003E=6.0.0,\u003C6.6.2","source":"GitHub","reportedAt":"2026-03-13 20:50:51","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hcch-w73c-jp4m"}]},{"advisoryId":"PKSA-n7ys-rxzm-bn18","packageName":"statamic\/cms","remoteId":"GHSA-cwpp-325q-2cvp","title":"Statamic Vulnerable to Server-Side Request Forgery via Glide","link":"https:\/\/github.com\/advisories\/GHSA-cwpp-325q-2cvp","cve":"CVE-2026-28423","affectedVersions":"\u003E=6.0.0-alpha.1,\u003C6.4.0|\u003C5.73.11","source":"GitHub","reportedAt":"2026-03-01 01:30:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cwpp-325q-2cvp"}]},{"advisoryId":"PKSA-hycr-3628-cp88","packageName":"statamic\/cms","remoteId":"GHSA-w878-f8c6-7r63","title":"Statamic\u0027s missing authorization allows access to email addresses","link":"https:\/\/github.com\/advisories\/GHSA-w878-f8c6-7r63","cve":"CVE-2026-28424","affectedVersions":"\u003E=6.0.0-alpha.1,\u003C6.4.0|\u003C5.73.11","source":"GitHub","reportedAt":"2026-03-01 01:30:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w878-f8c6-7r63"}]},{"advisoryId":"PKSA-skzr-by55-tmc5","packageName":"statamic\/cms","remoteId":"GHSA-cpv7-q2wx-m8rw","title":"Statamic vulnerable to remote code execution via Antlers-enabled control panel inputs","link":"https:\/\/github.com\/advisories\/GHSA-cpv7-q2wx-m8rw","cve":"CVE-2026-28425","affectedVersions":"\u003E=6.0.0-alpha.1,\u003C6.7.2|\u003C5.73.16","source":"GitHub","reportedAt":"2026-03-01 01:30:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-cpv7-q2wx-m8rw"}]},{"advisoryId":"PKSA-81wb-3yhb-txs4","packageName":"statamic\/cms","remoteId":"GHSA-5vrj-wf7v-5wr7","title":"Statamic vulnerable to privilege escalation via stored cross-site scripting","link":"https:\/\/github.com\/advisories\/GHSA-5vrj-wf7v-5wr7","cve":"CVE-2026-28426","affectedVersions":"\u003E=6.0.0-alpha.1,\u003C6.4.0|\u003C5.73.11","source":"GitHub","reportedAt":"2026-03-01 01:31:09","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5vrj-wf7v-5wr7"}]},{"advisoryId":"PKSA-7n8y-6n2j-9v3z","packageName":"statamic\/cms","remoteId":"GHSA-rw9x-pxqx-q789","title":"Statamic allows Authenticated Control Panel users to escalate privileges via elevated session bypass","link":"https:\/\/github.com\/advisories\/GHSA-rw9x-pxqx-q789","cve":"CVE-2026-27939","affectedVersions":"\u003E=6.0.0,\u003C6.4.0","source":"GitHub","reportedAt":"2026-02-27 21:35:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-rw9x-pxqx-q789"}]},{"advisoryId":"PKSA-w3y4-x9d3-9t28","packageName":"statamic\/cms","remoteId":"GHSA-jxq9-79vj-rgvw","title":"Statamic is vulnerable to account takeover via password reset link injection","link":"https:\/\/github.com\/advisories\/GHSA-jxq9-79vj-rgvw","cve":"CVE-2026-27593","affectedVersions":"\u003E=6.0.0-alpha.1,\u003C6.7.1|\u003C5.73.10","source":"GitHub","reportedAt":"2026-02-24 21:09:23","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-jxq9-79vj-rgvw"}]},{"advisoryId":"PKSA-vfrr-bp4n-314v","packageName":"statamic\/cms","remoteId":"GHSA-8r7r-f4gm-wcpq","title":"Statamic affected by privilege escalation via stored cross-site scripting","link":"https:\/\/github.com\/advisories\/GHSA-8r7r-f4gm-wcpq","cve":"CVE-2026-27196","affectedVersions":"\u003C5.73.9|\u003E=6.0.0-alpha.1,\u003C6.3.2","source":"GitHub","reportedAt":"2026-02-19 20:30:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8r7r-f4gm-wcpq"}]},{"advisoryId":"PKSA-fst8-xgkz-31tn","packageName":"statamic\/cms","remoteId":"GHSA-ff9r-ww9c-43x8","title":"Statamic CMS vulnerable to privilege escalation via stored cross-site scripting","link":"https:\/\/github.com\/advisories\/GHSA-ff9r-ww9c-43x8","cve":"CVE-2026-25759","affectedVersions":"\u003E=6.0.0,\u003C6.2.3","source":"GitHub","reportedAt":"2026-02-11 18:17:58","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-ff9r-ww9c-43x8"}]},{"advisoryId":"PKSA-nr63-r5tp-xby1","packageName":"statamic\/cms","remoteId":"GHSA-gwmx-9gcj-332h","title":"Statamic CMS\u0027s missing authorization allows access to assets","link":"https:\/\/github.com\/advisories\/GHSA-gwmx-9gcj-332h","cve":"CVE-2026-25633","affectedVersions":"\u003E=6.0.0-alpha.1,\u003C6.2.5|\u003C5.73.6","source":"GitHub","reportedAt":"2026-02-11 16:53:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gwmx-9gcj-332h"}]},{"advisoryId":"PKSA-mmp9-wb2h-d8gy","packageName":"statamic\/cms","remoteId":"GHSA-g59r-24g3-h7cm","title":"Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validation","link":"https:\/\/github.com\/advisories\/GHSA-g59r-24g3-h7cm","cve":"CVE-2025-64112","affectedVersions":"\u003C=5.22.0","source":"GitHub","reportedAt":"2025-10-30 17:22:53","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g59r-24g3-h7cm"}]}],"solidinvoice\/solidinvoice":[{"advisoryId":"PKSA-djbd-8ghh-z678","packageName":"solidinvoice\/solidinvoice","remoteId":"GHSA-7vfx-4246-jcfh","title":"SolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings","link":"https:\/\/github.com\/advisories\/GHSA-7vfx-4246-jcfh","cve":null,"affectedVersions":"\u003C=2.3.15","source":"GitHub","reportedAt":"2026-06-26 22:20:50","composerRepository":null,"severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7vfx-4246-jcfh"}]}],"pontedilana\/php-weasyprint":[{"advisoryId":"PKSA-xz12-xgjc-r2wn","packageName":"pontedilana\/php-weasyprint","remoteId":"GHSA-2fmj-p74r-3wjm","title":"PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)","link":"https:\/\/github.com\/advisories\/GHSA-2fmj-p74r-3wjm","cve":"CVE-2026-49286","affectedVersions":"\u003C=2.5.1","source":"GitHub","reportedAt":"2026-06-26 22:10:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2fmj-p74r-3wjm"}]},{"advisoryId":"PKSA-69w1-spwq-4gvw","packageName":"pontedilana\/php-weasyprint","remoteId":"GHSA-5g9f-cwwg-4p8g","title":"PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles","link":"https:\/\/github.com\/advisories\/GHSA-5g9f-cwwg-4p8g","cve":"CVE-2026-49358","affectedVersions":"\u003C=2.5.1","source":"GitHub","reportedAt":"2026-06-26 22:10:51","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-5g9f-cwwg-4p8g"}]},{"advisoryId":"PKSA-q4hm-4pvf-f13w","packageName":"pontedilana\/php-weasyprint","remoteId":"GHSA-x8g9-h984-pc36","title":"PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option","link":"https:\/\/github.com\/advisories\/GHSA-x8g9-h984-pc36","cve":"CVE-2026-49359","affectedVersions":"\u003C=2.5.1","source":"GitHub","reportedAt":"2026-06-26 22:11:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x8g9-h984-pc36"}]},{"advisoryId":"PKSA-p9k4-v53c-c7zd","packageName":"pontedilana\/php-weasyprint","remoteId":"GHSA-f5gc-qxf8-mh9g","title":"php-weasyprint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs\/snappy GHSA-vpr4-p6fq-85jc)","link":"https:\/\/github.com\/advisories\/GHSA-f5gc-qxf8-mh9g","cve":"CVE-2026-49260","affectedVersions":"\u003C=2.5.0","source":"GitHub","reportedAt":"2026-06-26 21:46:27","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f5gc-qxf8-mh9g"}]}],"aimeos\/pagible":[{"advisoryId":"PKSA-85r2-kyxr-cpv8","packageName":"aimeos\/pagible","remoteId":"GHSA-mmj8-wcvw-6789","title":"Aimeos Pagible CMS vulnerable to Server Side Request Forgery (SSRF) via DNS rebinding in admin proxy","link":"https:\/\/github.com\/advisories\/GHSA-mmj8-wcvw-6789","cve":"CVE-2026-49262","affectedVersions":"\u003C0.10.4","source":"GitHub","reportedAt":"2026-06-26 21:50:10","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-mmj8-wcvw-6789"}]}],"thorsten\/phpmyfaq":[{"advisoryId":"PKSA-bgmm-r5q1-dvfj","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-985r-q3qp-299h","title":"phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 \u2014 editUser() and updateUserRights() lack authorization guards","link":"https:\/\/github.com\/advisories\/GHSA-985r-q3qp-299h","cve":null,"affectedVersions":"\u003C=4.1.3","source":"GitHub","reportedAt":"2026-06-26 21:23:37","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-985r-q3qp-299h"}]},{"advisoryId":"PKSA-wn7x-tbkv-cqqp","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-8c6h-7g6x-m5x4","title":"phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)","link":"https:\/\/github.com\/advisories\/GHSA-8c6h-7g6x-m5x4","cve":"CVE-2026-49205","affectedVersions":"\u003C4.1.4","source":"GitHub","reportedAt":"2026-06-23 22:27:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8c6h-7g6x-m5x4"}]},{"advisoryId":"PKSA-p1ky-vdyf-6r6j","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-58fg-62fg-3fcj","title":"phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing","link":"https:\/\/github.com\/advisories\/GHSA-58fg-62fg-3fcj","cve":"CVE-2026-48488","affectedVersions":"\u003C=4.1.3","source":"GitHub","reportedAt":"2026-06-23 22:02:25","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-58fg-62fg-3fcj"}]},{"advisoryId":"PKSA-64xv-jbdm-pg2q","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-9qv9-8xv6-5p35","title":"phpMyFAQ: Unauthenticated Password Reset Endpoint Allows User Enumeration and Forced Password Change Without Token Validation","link":"https:\/\/github.com\/advisories\/GHSA-9qv9-8xv6-5p35","cve":"CVE-2026-35676","affectedVersions":"\u003C4.1.3","source":"GitHub","reportedAt":"2026-05-20 15:45:53","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9qv9-8xv6-5p35"}]},{"advisoryId":"PKSA-ttcw-fg74-jv2w","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-xvp4-phqj-cjr3","title":"phpMyFAQ: IDOR Account Takeover ","link":"https:\/\/github.com\/advisories\/GHSA-xvp4-phqj-cjr3","cve":"CVE-2026-35671","affectedVersions":"\u003C4.1.3","source":"GitHub","reportedAt":"2026-05-20 15:46:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xvp4-phqj-cjr3"}]},{"advisoryId":"PKSA-jk8b-rmby-gztg","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-gp95-j463-vv28","title":"phpMyFAQ: Default Empty API Token Authentication Bypass","link":"https:\/\/github.com\/advisories\/GHSA-gp95-j463-vv28","cve":"CVE-2026-35672","affectedVersions":"\u003C=4.1.2","source":"GitHub","reportedAt":"2026-05-20 15:46:42","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gp95-j463-vv28"}]},{"advisoryId":"PKSA-x1b3-f9q9-1brm","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-w9xh-5f39-vq89","title":"phpMyFAQ: Missing Password Reset Token Allows Account Takeover via Username\/Email Enumeration","link":"https:\/\/github.com\/advisories\/GHSA-w9xh-5f39-vq89","cve":"CVE-2026-35675","affectedVersions":"\u003C4.1.3","source":"GitHub","reportedAt":"2026-05-20 15:46:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w9xh-5f39-vq89"}]},{"advisoryId":"PKSA-q6mm-vp1w-mgjs","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-9pq7-mfwh-xx2j","title":"phpMyFAQ enables unauthenticated 2FA brute-force attack via \/admin\/check acceptance of arbitrary user-id","link":"https:\/\/github.com\/advisories\/GHSA-9pq7-mfwh-xx2j","cve":"CVE-2026-45010","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:42:54","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-9pq7-mfwh-xx2j"}]},{"advisoryId":"PKSA-n87n-9t5q-zcf5","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-pm8c-3qq3-72w7","title":"phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields","link":"https:\/\/github.com\/advisories\/GHSA-pm8c-3qq3-72w7","cve":"CVE-2026-46359","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:44:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pm8c-3qq3-72w7"}]},{"advisoryId":"PKSA-k9ft-9rnh-h8dn","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-99qv-g4x9-mgc3","title":"phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query","link":"https:\/\/github.com\/advisories\/GHSA-99qv-g4x9-mgc3","cve":"CVE-2026-46366","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:45:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-99qv-g4x9-mgc3"}]},{"advisoryId":"PKSA-djzh-dx9x-j5hd","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-gh9p-q46p-57g2","title":"phpMyFAQ: Path Traversal in Client::deleteClientFolder enables arbitrary directory deletion by non-super-admin admins","link":"https:\/\/github.com\/advisories\/GHSA-gh9p-q46p-57g2","cve":"CVE-2026-45008","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:47:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gh9p-q46p-57g2"}]},{"advisoryId":"PKSA-trv8-7xnx-t8d9","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-289f-fq7w-6q2w","title":"phpMyFAQ has unauthenticated SQL injection via User-Agent header in BuiltinCaptcha","link":"https:\/\/github.com\/advisories\/GHSA-289f-fq7w-6q2w","cve":"CVE-2026-46364","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:49:15","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-289f-fq7w-6q2w"}]},{"advisoryId":"PKSA-198b-7kr6-ksdh","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-pqh6-8fxf-jx22","title":"phpMyFAQ has stored XSS via | raw Filter in search.twig \u2014 html_entity_decode(strip_tags()) Bypass in Search Result Rendering","link":"https:\/\/github.com\/advisories\/GHSA-pqh6-8fxf-jx22","cve":"CVE-2026-46361","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:31:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pqh6-8fxf-jx22"}]},{"advisoryId":"PKSA-42b7-bh2b-d7nn","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-jrc5-w569-h7h5","title":"phpMyFAQ: Ordinary Authenticated User Can Access Admin-Only API Endpoints Due to Insufficient Authorization Check in phpMyFAQ","link":"https:\/\/github.com\/advisories\/GHSA-jrc5-w569-h7h5","cve":"CVE-2026-45009","affectedVersions":"=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:37:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jrc5-w569-h7h5"}]},{"advisoryId":"PKSA-pmsp-dtdj-k1f9","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-rm98-82fr-mcfx","title":"phpMyFAQ\u0027s Missing CONFIGURATION_EDIT Permission Check on 12 Admin API Configuration Tab Endpoints Allows Information Disclosure by Any Authenticated User","link":"https:\/\/github.com\/advisories\/GHSA-rm98-82fr-mcfx","cve":"CVE-2026-45007","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:24:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rm98-82fr-mcfx"}]},{"advisoryId":"PKSA-1zxw-krpv-74xh","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-9525-27vj-c8r8","title":"phpMyFAQ has stored XSS via Utils::parseUrl() in comment rendering","link":"https:\/\/github.com\/advisories\/GHSA-9525-27vj-c8r8","cve":"CVE-2026-46367","affectedVersions":"=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:10:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9525-27vj-c8r8"}]},{"advisoryId":"PKSA-b77f-s5cd-b1qh","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-hpgw-ww76-c68r","title":"phpMyFAQ has an Authorization Bypass in All Admin Pages Due to Non-Terminating Permission Check","link":"https:\/\/github.com\/advisories\/GHSA-hpgw-ww76-c68r","cve":"CVE-2026-46362","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:11:52","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hpgw-ww76-c68r"}]},{"advisoryId":"PKSA-p58s-jb5m-qycz","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-7cx3-2qx2-3g6w","title":"phpMyFAQ\u0027s Missing Authorization on Tag Deletion Allows Any Authenticated User to Delete Tags","link":"https:\/\/github.com\/advisories\/GHSA-7cx3-2qx2-3g6w","cve":null,"affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:12:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7cx3-2qx2-3g6w"}]},{"advisoryId":"PKSA-jr2y-dd2x-qtks","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-f5p7-2c9q-8896","title":"phpMyFAQ has Stored XSS in FAQ Question\/Answer via Encode-Decode Bypass of removeAttributes() Sanitization","link":"https:\/\/github.com\/advisories\/GHSA-f5p7-2c9q-8896","cve":"CVE-2026-46363","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:18:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f5p7-2c9q-8896"}]},{"advisoryId":"PKSA-sw8q-jkxw-m11r","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-whqh-9pq5-c7r3","title":"phpMyFAQ has a SVG Sanitizer Entity Decoding Depth Limit Bypass Leading to Stored XSS","link":"https:\/\/github.com\/advisories\/GHSA-whqh-9pq5-c7r3","cve":"CVE-2026-46360","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:18:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-whqh-9pq5-c7r3"}]},{"advisoryId":"PKSA-fk9h-qz7y-fk1q","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-gcp9-5jc8-976x","title":"phpMyFAQ has a LIKE Wildcard Injection in Search.php \u2014 Unescaped % and _ Metacharacters Enable Broad Content Disclosure","link":"https:\/\/github.com\/advisories\/GHSA-gcp9-5jc8-976x","cve":"CVE-2026-34973","affectedVersions":"\u003C4.1.1","source":"GitHub","reportedAt":"2026-04-01 23:41:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gcp9-5jc8-976x"}]},{"advisoryId":"PKSA-yy2b-x6vy-wsx2","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-5crx-pfhq-4hgg","title":"phpMyFAQ: SVG Sanitizer Bypass via HTML Entity Encoding Leads to Stored XSS and Privilege Escalation","link":"https:\/\/github.com\/advisories\/GHSA-5crx-pfhq-4hgg","cve":"CVE-2026-34974","affectedVersions":"\u003C=4.1.0","source":"GitHub","reportedAt":"2026-04-01 23:42:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5crx-pfhq-4hgg"}]},{"advisoryId":"PKSA-t2yv-wns1-2p5c","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-98gw-w575-h2ph","title":"phpMyFAQ is Vulnerable to Stored XSS via Unsanitized Email Field in Admin FAQ Editor","link":"https:\/\/github.com\/advisories\/GHSA-98gw-w575-h2ph","cve":"CVE-2026-32629","affectedVersions":"\u003C=4.1.0","source":"GitHub","reportedAt":"2026-03-31 22:48:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-98gw-w575-h2ph"}]},{"advisoryId":"PKSA-y9f6-42c9-xggs","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-w22q-m2fm-x9f4","title":"phpMyFAQ Allows Unauthenticated Account Creation via WebAuthn Prepare Endpoint","link":"https:\/\/github.com\/advisories\/GHSA-w22q-m2fm-x9f4","cve":"CVE-2026-27836","affectedVersions":"\u003C4.0.18","source":"GitHub","reportedAt":"2026-02-27 21:01:58","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w22q-m2fm-x9f4"}]},{"advisoryId":"PKSA-mvwk-xn5v-s54b","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-7p9h-m7m8-vhhv","title":"phpMyFAQ: Attachment download allowed without dlattachment right (broken access control)","link":"https:\/\/github.com\/advisories\/GHSA-7p9h-m7m8-vhhv","cve":"CVE-2026-24420","affectedVersions":"\u003C=4.0.16","source":"GitHub","reportedAt":"2026-01-23 20:17:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7p9h-m7m8-vhhv"}]},{"advisoryId":"PKSA-fgvt-rx8y-b52y","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-wm8h-26fv-mg7g","title":"phpMyFAQ: \/api\/setup\/backup accessible to any authenticated user (authz missing)","link":"https:\/\/github.com\/advisories\/GHSA-wm8h-26fv-mg7g","cve":"CVE-2026-24421","affectedVersions":"\u003C=4.0.16","source":"GitHub","reportedAt":"2026-01-23 20:17:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wm8h-26fv-mg7g"}]},{"advisoryId":"PKSA-2sk9-r8yw-1gc5","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-j4rc-96xj-gvqc","title":"phpMyFAQ: Public API endpoints expose emails and invisible questions","link":"https:\/\/github.com\/advisories\/GHSA-j4rc-96xj-gvqc","cve":"CVE-2026-24422","affectedVersions":"\u003C=4.0.16","source":"GitHub","reportedAt":"2026-01-23 20:17:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j4rc-96xj-gvqc"}]},{"advisoryId":"PKSA-hxrq-cj69-vm9f","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-x2v3-9p22-w3x6","title":"phpMyFAQ contains a CSV injection vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-x2v3-9p22-w3x6","cve":"CVE-2023-53929","affectedVersions":"\u003C=3.1.12","source":"GitHub","reportedAt":"2025-12-18 00:34:08","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x2v3-9p22-w3x6"}]},{"advisoryId":"PKSA-w8m6-73n2-zbk6","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-9cg9-4h4f-j6fg","title":"phpMyFAQ has unauthenticated config backup download via \/api\/setup\/backup","link":"https:\/\/github.com\/advisories\/GHSA-9cg9-4h4f-j6fg","cve":"CVE-2025-69200","affectedVersions":"\u003E=4.1.0-alpha,\u003C=4.1.0-beta.2|\u003C4.0.16","source":"GitHub","reportedAt":"2025-12-30 15:31:19","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9cg9-4h4f-j6fg"}]},{"advisoryId":"PKSA-hj4y-1t5r-b8zy","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-jv8r-hv7q-p6vc","title":"phpMyFAQ has Stored XSS in user list via admin-managed display_name","link":"https:\/\/github.com\/advisories\/GHSA-jv8r-hv7q-p6vc","cve":"CVE-2025-68951","affectedVersions":"\u003E=4.0.14,\u003C4.0.16","source":"GitHub","reportedAt":"2025-12-29 22:12:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jv8r-hv7q-p6vc"}]},{"advisoryId":"PKSA-zh4p-vq78-zndy","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-fxm2-cmwj-qvx4","title":"phpMyFAQ has Authenticated SQL Injection in Configuration Update Functionality","link":"https:\/\/github.com\/advisories\/GHSA-fxm2-cmwj-qvx4","cve":"CVE-2025-62519","affectedVersions":"\u003C=4.0.13","source":"GitHub","reportedAt":"2025-11-17 17:37:37","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fxm2-cmwj-qvx4"}]},{"advisoryId":"PKSA-pzch-4td8-nkvb","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-9wj2-4hcm-r74j","title":"phpMyFAQ duplicate email registration allows multiple accounts with the same email","link":"https:\/\/github.com\/advisories\/GHSA-9wj2-4hcm-r74j","cve":"CVE-2025-59943","affectedVersions":"\u003E=4.0.7,\u003C4.0.13","source":"GitHub","reportedAt":"2025-10-03 14:52:33","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9wj2-4hcm-r74j"}]}],"phpmyfaq\/phpmyfaq":[{"advisoryId":"PKSA-nnfw-464q-679b","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-985r-q3qp-299h","title":"phpMyFAQ has an incomplete fix for GHSA-xvp4-phqj-cjr3 \u2014 editUser() and updateUserRights() lack authorization guards","link":"https:\/\/github.com\/advisories\/GHSA-985r-q3qp-299h","cve":null,"affectedVersions":"\u003C=4.1.3","source":"GitHub","reportedAt":"2026-06-26 21:23:37","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-985r-q3qp-299h"}]},{"advisoryId":"PKSA-ncdr-61sw-52cy","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-8c6h-7g6x-m5x4","title":"phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)","link":"https:\/\/github.com\/advisories\/GHSA-8c6h-7g6x-m5x4","cve":"CVE-2026-49205","affectedVersions":"\u003C4.1.4","source":"GitHub","reportedAt":"2026-06-23 22:27:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8c6h-7g6x-m5x4"}]},{"advisoryId":"PKSA-rr72-yd9q-kc5n","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-58fg-62fg-3fcj","title":"phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing","link":"https:\/\/github.com\/advisories\/GHSA-58fg-62fg-3fcj","cve":"CVE-2026-48488","affectedVersions":"\u003C=4.1.3","source":"GitHub","reportedAt":"2026-06-23 22:02:25","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-58fg-62fg-3fcj"}]},{"advisoryId":"PKSA-1ckg-7bmf-xkmp","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-9qv9-8xv6-5p35","title":"phpMyFAQ: Unauthenticated Password Reset Endpoint Allows User Enumeration and Forced Password Change Without Token Validation","link":"https:\/\/github.com\/advisories\/GHSA-9qv9-8xv6-5p35","cve":"CVE-2026-35676","affectedVersions":"\u003C4.1.3","source":"GitHub","reportedAt":"2026-05-20 15:45:53","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9qv9-8xv6-5p35"}]},{"advisoryId":"PKSA-vdjw-v652-d3d9","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-xvp4-phqj-cjr3","title":"phpMyFAQ: IDOR Account Takeover ","link":"https:\/\/github.com\/advisories\/GHSA-xvp4-phqj-cjr3","cve":"CVE-2026-35671","affectedVersions":"\u003C4.1.3","source":"GitHub","reportedAt":"2026-05-20 15:46:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xvp4-phqj-cjr3"}]},{"advisoryId":"PKSA-xr26-9czp-vbgk","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-gp95-j463-vv28","title":"phpMyFAQ: Default Empty API Token Authentication Bypass","link":"https:\/\/github.com\/advisories\/GHSA-gp95-j463-vv28","cve":"CVE-2026-35672","affectedVersions":"\u003C=4.1.2","source":"GitHub","reportedAt":"2026-05-20 15:46:42","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gp95-j463-vv28"}]},{"advisoryId":"PKSA-527c-n963-c1j5","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-w9xh-5f39-vq89","title":"phpMyFAQ: Missing Password Reset Token Allows Account Takeover via Username\/Email Enumeration","link":"https:\/\/github.com\/advisories\/GHSA-w9xh-5f39-vq89","cve":"CVE-2026-35675","affectedVersions":"\u003C4.1.3","source":"GitHub","reportedAt":"2026-05-20 15:46:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w9xh-5f39-vq89"}]},{"advisoryId":"PKSA-6pt5-mfr3-5b72","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-9pq7-mfwh-xx2j","title":"phpMyFAQ enables unauthenticated 2FA brute-force attack via \/admin\/check acceptance of arbitrary user-id","link":"https:\/\/github.com\/advisories\/GHSA-9pq7-mfwh-xx2j","cve":"CVE-2026-45010","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:42:54","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-9pq7-mfwh-xx2j"}]},{"advisoryId":"PKSA-r4gq-dd3d-gxrj","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-pm8c-3qq3-72w7","title":"phpMyFAQ has SQL Injection in CurrentUser::setTokenData through unescaped OAuth token fields","link":"https:\/\/github.com\/advisories\/GHSA-pm8c-3qq3-72w7","cve":"CVE-2026-46359","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:44:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pm8c-3qq3-72w7"}]},{"advisoryId":"PKSA-76kk-7mdh-r8h5","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-99qv-g4x9-mgc3","title":"phpMyFAQ has unauthenticated FAQ permission bypass via getFaqBySolutionId fallback query","link":"https:\/\/github.com\/advisories\/GHSA-99qv-g4x9-mgc3","cve":"CVE-2026-46366","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:45:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-99qv-g4x9-mgc3"}]},{"advisoryId":"PKSA-tvkw-wcnm-h63h","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-gh9p-q46p-57g2","title":"phpMyFAQ: Path Traversal in Client::deleteClientFolder enables arbitrary directory deletion by non-super-admin admins","link":"https:\/\/github.com\/advisories\/GHSA-gh9p-q46p-57g2","cve":"CVE-2026-45008","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:47:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gh9p-q46p-57g2"}]},{"advisoryId":"PKSA-6nrc-qfr1-rds3","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-289f-fq7w-6q2w","title":"phpMyFAQ has unauthenticated SQL injection via User-Agent header in BuiltinCaptcha","link":"https:\/\/github.com\/advisories\/GHSA-289f-fq7w-6q2w","cve":"CVE-2026-46364","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:49:15","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-289f-fq7w-6q2w"}]},{"advisoryId":"PKSA-7dk8-b5d5-n9bf","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-pqh6-8fxf-jx22","title":"phpMyFAQ has stored XSS via | raw Filter in search.twig \u2014 html_entity_decode(strip_tags()) Bypass in Search Result Rendering","link":"https:\/\/github.com\/advisories\/GHSA-pqh6-8fxf-jx22","cve":"CVE-2026-46361","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:31:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pqh6-8fxf-jx22"}]},{"advisoryId":"PKSA-v8r2-1321-xzpp","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-jrc5-w569-h7h5","title":"phpMyFAQ: Ordinary Authenticated User Can Access Admin-Only API Endpoints Due to Insufficient Authorization Check in phpMyFAQ","link":"https:\/\/github.com\/advisories\/GHSA-jrc5-w569-h7h5","cve":"CVE-2026-45009","affectedVersions":"=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:37:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jrc5-w569-h7h5"}]},{"advisoryId":"PKSA-n88j-cgtd-2fvg","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-rm98-82fr-mcfx","title":"phpMyFAQ\u0027s Missing CONFIGURATION_EDIT Permission Check on 12 Admin API Configuration Tab Endpoints Allows Information Disclosure by Any Authenticated User","link":"https:\/\/github.com\/advisories\/GHSA-rm98-82fr-mcfx","cve":"CVE-2026-45007","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:24:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rm98-82fr-mcfx"}]},{"advisoryId":"PKSA-vm8f-6283-2vfw","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-9525-27vj-c8r8","title":"phpMyFAQ has stored XSS via Utils::parseUrl() in comment rendering","link":"https:\/\/github.com\/advisories\/GHSA-9525-27vj-c8r8","cve":"CVE-2026-46367","affectedVersions":"=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:10:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9525-27vj-c8r8"}]},{"advisoryId":"PKSA-8syh-w2cp-tqks","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-hpgw-ww76-c68r","title":"phpMyFAQ has an Authorization Bypass in All Admin Pages Due to Non-Terminating Permission Check","link":"https:\/\/github.com\/advisories\/GHSA-hpgw-ww76-c68r","cve":"CVE-2026-46362","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:11:52","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hpgw-ww76-c68r"}]},{"advisoryId":"PKSA-117q-9kx2-kjzm","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-7cx3-2qx2-3g6w","title":"phpMyFAQ\u0027s Missing Authorization on Tag Deletion Allows Any Authenticated User to Delete Tags","link":"https:\/\/github.com\/advisories\/GHSA-7cx3-2qx2-3g6w","cve":null,"affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:12:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7cx3-2qx2-3g6w"}]},{"advisoryId":"PKSA-6zc3-3brt-ftsh","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-f5p7-2c9q-8896","title":"phpMyFAQ has Stored XSS in FAQ Question\/Answer via Encode-Decode Bypass of removeAttributes() Sanitization","link":"https:\/\/github.com\/advisories\/GHSA-f5p7-2c9q-8896","cve":"CVE-2026-46363","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:18:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f5p7-2c9q-8896"}]},{"advisoryId":"PKSA-jn65-sph2-9wn9","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-whqh-9pq5-c7r3","title":"phpMyFAQ has a SVG Sanitizer Entity Decoding Depth Limit Bypass Leading to Stored XSS","link":"https:\/\/github.com\/advisories\/GHSA-whqh-9pq5-c7r3","cve":"CVE-2026-46360","affectedVersions":"\u003C=4.1.1","source":"GitHub","reportedAt":"2026-05-06 20:18:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-whqh-9pq5-c7r3"}]},{"advisoryId":"PKSA-n57d-sn2t-c46g","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-38m8-xrfj-v38x","title":"phpMyFAQ: Path Traversal - Arbitrary File Deletion in MediaBrowserController","link":"https:\/\/github.com\/advisories\/GHSA-38m8-xrfj-v38x","cve":"CVE-2026-34728","affectedVersions":"\u003C=4.1.0","source":"GitHub","reportedAt":"2026-04-01 22:30:32","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-38m8-xrfj-v38x"}]},{"advisoryId":"PKSA-yq8b-v8fg-rvf8","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-cv2g-8cj8-vgc7","title":"phpMyFAQ: Stored XSS via Regex Bypass in Filter::removeAttributes()","link":"https:\/\/github.com\/advisories\/GHSA-cv2g-8cj8-vgc7","cve":"CVE-2026-34729","affectedVersions":"\u003C=4.1.0","source":"GitHub","reportedAt":"2026-04-01 22:31:44","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cv2g-8cj8-vgc7"}]},{"advisoryId":"PKSA-25jh-4r4k-gpj5","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-98gw-w575-h2ph","title":"phpMyFAQ is Vulnerable to Stored XSS via Unsanitized Email Field in Admin FAQ Editor","link":"https:\/\/github.com\/advisories\/GHSA-98gw-w575-h2ph","cve":"CVE-2026-32629","affectedVersions":"\u003C=4.1.0","source":"GitHub","reportedAt":"2026-03-31 22:48:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-98gw-w575-h2ph"}]},{"advisoryId":"PKSA-bn6v-4n7v-4dtq","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-7p9h-m7m8-vhhv","title":"phpMyFAQ: Attachment download allowed without dlattachment right (broken access control)","link":"https:\/\/github.com\/advisories\/GHSA-7p9h-m7m8-vhhv","cve":"CVE-2026-24420","affectedVersions":"\u003C=4.0.16","source":"GitHub","reportedAt":"2026-01-23 20:17:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7p9h-m7m8-vhhv"}]},{"advisoryId":"PKSA-kw83-ss3b-tqsv","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-wm8h-26fv-mg7g","title":"phpMyFAQ: \/api\/setup\/backup accessible to any authenticated user (authz missing)","link":"https:\/\/github.com\/advisories\/GHSA-wm8h-26fv-mg7g","cve":"CVE-2026-24421","affectedVersions":"\u003C=4.0.16","source":"GitHub","reportedAt":"2026-01-23 20:17:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wm8h-26fv-mg7g"}]},{"advisoryId":"PKSA-g4rh-637x-8kby","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-j4rc-96xj-gvqc","title":"phpMyFAQ: Public API endpoints expose emails and invisible questions","link":"https:\/\/github.com\/advisories\/GHSA-j4rc-96xj-gvqc","cve":"CVE-2026-24422","affectedVersions":"\u003C=4.0.16","source":"GitHub","reportedAt":"2026-01-23 20:17:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j4rc-96xj-gvqc"}]},{"advisoryId":"PKSA-1cq7-dh6p-78w8","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-x2v3-9p22-w3x6","title":"phpMyFAQ contains a CSV injection vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-x2v3-9p22-w3x6","cve":"CVE-2023-53929","affectedVersions":"\u003C=3.1.12","source":"GitHub","reportedAt":"2025-12-18 00:34:08","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x2v3-9p22-w3x6"}]},{"advisoryId":"PKSA-mvvf-b3jn-bt43","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-fxm2-cmwj-qvx4","title":"phpMyFAQ has Authenticated SQL Injection in Configuration Update Functionality","link":"https:\/\/github.com\/advisories\/GHSA-fxm2-cmwj-qvx4","cve":"CVE-2025-62519","affectedVersions":"\u003C=4.0.13","source":"GitHub","reportedAt":"2025-11-17 17:37:37","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fxm2-cmwj-qvx4"}]}],"cakephp\/cakephp":[{"advisoryId":"PKSA-wx2k-k564-z67n","packageName":"cakephp\/cakephp","remoteId":"GHSA-wpvj-hjcr-h3p2","title":"CakePHP: View::element() is missing a path containment check","link":"https:\/\/github.com\/advisories\/GHSA-wpvj-hjcr-h3p2","cve":"CVE-2026-48820","affectedVersions":"\u003C4.5.11|\u003E=4.6.0,\u003C4.6.4|\u003E=5.0.0,\u003C5.1.7|\u003E=5.2.0,\u003C5.2.13|\u003E=5.3.0,\u003C5.3.6","source":"GitHub","reportedAt":"2026-06-26 21:00:10","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wpvj-hjcr-h3p2"}]},{"advisoryId":"PKSA-y889-wbb2-rsdf","packageName":"cakephp\/cakephp","remoteId":"GHSA-qh8m-9qxx-53m5","title":"CakePHP PaginatorHelper::limitControl() vulnerable to reflected cross-site-scripting","link":"https:\/\/github.com\/advisories\/GHSA-qh8m-9qxx-53m5","cve":"CVE-2026-23643","affectedVersions":"=5.3.0|\u003E=5.2.10,\u003C5.2.12","source":"GitHub","reportedAt":"2026-01-16 21:00:44","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qh8m-9qxx-53m5"}]}],"web-auth\/webauthn-symfony-bundle":[{"advisoryId":"PKSA-by78-v7zw-v73g","packageName":"web-auth\/webauthn-symfony-bundle","remoteId":"GHSA-q683-8468-r6h6","title":"WebauthnAuthenticator leaks sensitive HTTP headers through INFO-level logs","link":"https:\/\/github.com\/advisories\/GHSA-q683-8468-r6h6","cve":null,"affectedVersions":"\u003C5.3.4","source":"GitHub","reportedAt":"2026-06-26 21:00:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q683-8468-r6h6"}]},{"advisoryId":"PKSA-mvry-7c68-swp2","packageName":"web-auth\/webauthn-symfony-bundle","remoteId":"GHSA-f7pm-6hr8-7ggm","title":"Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validation","link":"https:\/\/github.com\/advisories\/GHSA-f7pm-6hr8-7ggm","cve":"CVE-2026-30964","affectedVersions":"\u003E=5.2.0,\u003C5.2.4","source":"GitHub","reportedAt":"2026-03-10 01:19:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f7pm-6hr8-7ggm"}]}],"pterodactyl\/panel":[{"advisoryId":"PKSA-mzmz-41cv-9dtv","packageName":"pterodactyl\/panel","remoteId":"GHSA-j7f5-gfqm-pcx3","title":"Pterodactyl Panel: Client email change endpoint allows enumeration of accounts in system","link":"https:\/\/github.com\/advisories\/GHSA-j7f5-gfqm-pcx3","cve":null,"affectedVersions":"\u003C1.12.3","source":"GitHub","reportedAt":"2026-06-26 20:54:38","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j7f5-gfqm-pcx3"}]},{"advisoryId":"PKSA-d16c-6bkx-pfvs","packageName":"pterodactyl\/panel","remoteId":"GHSA-fgmm-w5cx-vrfw","title":"Pterodactyl has a database resource limit bypass via race condition in Client API","link":"https:\/\/github.com\/advisories\/GHSA-fgmm-w5cx-vrfw","cve":"CVE-2026-35202","affectedVersions":"\u003C1.12.3","source":"GitHub","reportedAt":"2026-05-26 19:30:02","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-fgmm-w5cx-vrfw"}]},{"advisoryId":"PKSA-773t-3wms-bb2z","packageName":"pterodactyl\/panel","remoteId":"GHSA-g7vw-f8p5-c728","title":"Pterodactyl Panel Allows Cross-Node Server Configuration Disclosure via Remote API Missing Authorization","link":"https:\/\/github.com\/advisories\/GHSA-g7vw-f8p5-c728","cve":"CVE-2026-26016","affectedVersions":"\u003C1.12.1","source":"GitHub","reportedAt":"2026-02-17 18:54:49","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-g7vw-f8p5-c728"}]},{"advisoryId":"PKSA-khps-r6nm-3z7r","packageName":"pterodactyl\/panel","remoteId":"GHSA-hr7j-63v7-vj7g","title":"Pterodactyl Panel\u0027s SFTP sessions remain active after user account deletion or password change","link":"https:\/\/github.com\/advisories\/GHSA-hr7j-63v7-vj7g","cve":null,"affectedVersions":"\u003C1.12.1","source":"GitHub","reportedAt":"2026-02-17 17:15:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hr7j-63v7-vj7g"}]},{"advisoryId":"PKSA-hm8z-9vp5-kfyz","packageName":"pterodactyl\/panel","remoteId":"GHSA-jw2v-cq5x-q68g","title":"Pterodactyl improperly locks resources allowing raced queries to create more resources than alloted","link":"https:\/\/github.com\/advisories\/GHSA-jw2v-cq5x-q68g","cve":"CVE-2025-69198","affectedVersions":"\u003C1.12.0","source":"GitHub","reportedAt":"2026-01-20 16:30:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jw2v-cq5x-q68g"}]},{"advisoryId":"PKSA-nk76-8zr3-7ywp","packageName":"pterodactyl\/panel","remoteId":"GHSA-rgmp-4873-r683","title":"Pterodactyl TOTPs can be reused during validity window","link":"https:\/\/github.com\/advisories\/GHSA-rgmp-4873-r683","cve":"CVE-2025-69197","affectedVersions":"\u003C1.12.0","source":"GitHub","reportedAt":"2026-01-06 17:20:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rgmp-4873-r683"}]},{"advisoryId":"PKSA-zfwd-jx3t-62gc","packageName":"pterodactyl\/panel","remoteId":"GHSA-8c39-xppg-479c","title":"Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced","link":"https:\/\/github.com\/advisories\/GHSA-8c39-xppg-479c","cve":"CVE-2025-68954","affectedVersions":"\u003C1.12.0","source":"GitHub","reportedAt":"2026-01-06 17:18:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8c39-xppg-479c"}]},{"advisoryId":"PKSA-5dmg-k8vm-rbb6","packageName":"pterodactyl\/panel","remoteId":"GHSA-mgr9-6c2j-jxrq","title":"Pterodactyl has a Reflected XSS vulnerability in \u201cCreate New Database Host\u201d","link":"https:\/\/github.com\/advisories\/GHSA-mgr9-6c2j-jxrq","cve":null,"affectedVersions":"\u003C1.12.0","source":"GitHub","reportedAt":"2025-12-30 15:13:52","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-mgr9-6c2j-jxrq"}]}],"php-standard-library\/h2":[{"advisoryId":"PKSA-wz5t-5b2y-qjqk","packageName":"php-standard-library\/h2","remoteId":"GHSA-pw9p-jvrm-f7rm","title":"PHP Standard Library: HTTP\/2 server-side missing content-length validation enables request smuggling","link":"https:\/\/github.com\/advisories\/GHSA-pw9p-jvrm-f7rm","cve":"CVE-2026-48979","affectedVersions":"\u003E=6.2.0,\u003C6.2.1|\u003E=6.1.0,\u003C6.1.2","source":"GitHub","reportedAt":"2026-06-26 20:55:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pw9p-jvrm-f7rm"}]}],"php-standard-library\/php-standard-library":[{"advisoryId":"PKSA-9rcn-mnby-44gp","packageName":"php-standard-library\/php-standard-library","remoteId":"GHSA-pw9p-jvrm-f7rm","title":"PHP Standard Library: HTTP\/2 server-side missing content-length validation enables request smuggling","link":"https:\/\/github.com\/advisories\/GHSA-pw9p-jvrm-f7rm","cve":"CVE-2026-48979","affectedVersions":"\u003E=6.2.0,\u003C6.2.1|\u003E=6.1.0,\u003C6.1.2","source":"GitHub","reportedAt":"2026-06-26 20:55:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pw9p-jvrm-f7rm"}]}],"filament\/filament":[{"advisoryId":"PKSA-nsry-m1tp-jzr9","packageName":"filament\/filament","remoteId":"GHSA-mc5j-f6wx-h9qh","title":"Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission","link":"https:\/\/github.com\/advisories\/GHSA-mc5j-f6wx-h9qh","cve":"CVE-2026-48505","affectedVersions":"\u003E=5.0.0,\u003C5.6.5|\u003E=4.0.0,\u003C4.11.5","source":"GitHub","reportedAt":"2026-06-25 18:45:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mc5j-f6wx-h9qh"}]},{"advisoryId":"PKSA-317j-243v-z7tc","packageName":"filament\/filament","remoteId":"GHSA-44wp-g8f4-f4v5","title":"Filament: Unauthenticated temporary file upload on auth pages","link":"https:\/\/github.com\/advisories\/GHSA-44wp-g8f4-f4v5","cve":"CVE-2026-48500","affectedVersions":"\u003E=3.0.0,\u003C=3.3.51|\u003E=5.0.0,\u003C=5.6.4|\u003E=4.0.0,\u003C=4.11.4","source":"GitHub","reportedAt":"2026-06-23 22:16:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-44wp-g8f4-f4v5"}]},{"advisoryId":"PKSA-3rh1-zh9g-4mq5","packageName":"filament\/filament","remoteId":"GHSA-5w46-g9pq-wh6f","title":"Filament: Timing-based user enumeration on login page","link":"https:\/\/github.com\/advisories\/GHSA-5w46-g9pq-wh6f","cve":"CVE-2026-48166","affectedVersions":"\u003E=5.0.0,\u003C=5.6.4|\u003E=4.0.0,\u003C=4.11.4","source":"GitHub","reportedAt":"2026-06-23 21:54:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5w46-g9pq-wh6f"}]},{"advisoryId":"PKSA-yb9k-ykqx-p2zw","packageName":"filament\/filament","remoteId":"GHSA-pvcv-q3q7-266g","title":"Filament multi-factor authentication (app) recovery codes can be used multiple times","link":"https:\/\/github.com\/advisories\/GHSA-pvcv-q3q7-266g","cve":"CVE-2025-67507","affectedVersions":"\u003E=4.0.0,\u003C4.3.1","source":"GitHub","reportedAt":"2025-12-09 17:19:10","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pvcv-q3q7-266g"}]}],"symbiote\/silverstripe-advancedworkflow":[{"advisoryId":"PKSA-x4kf-7gbb-fh93","packageName":"symbiote\/silverstripe-advancedworkflow","remoteId":"symbiote\/silverstripe-advancedworkflow\/CVE-2026-54718.yaml","title":"CVE-2026-54718 - Remote code execution via advanced workflow email template","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-54718","cve":"CVE-2026-54718","affectedVersions":"\u003C6.4.5|\u003E=7.0.0,\u003C7.1.3|\u003E=7.2.0,\u003C7.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 04:12:03","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"symbiote\/silverstripe-advancedworkflow\/CVE-2026-54718.yaml"}]}],"silverstripe\/cms":[{"advisoryId":"PKSA-pjvm-vnw2-n3m2","packageName":"silverstripe\/cms","remoteId":"silverstripe\/cms\/CVE-2026-54717.yaml","title":"CVE-2026-54717 - XSS in breadcrumbs in page list view","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-54717","cve":"CVE-2026-54717","affectedVersions":"\u003C6.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 02:39:20","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/cms\/CVE-2026-54717.yaml"}]},{"advisoryId":"PKSA-pvwk-bm9n-rprc","packageName":"silverstripe\/cms","remoteId":"silverstripe\/cms\/SS-2015-005-1.yaml","title":"SS-2015-005: VirtualPage XSS","link":"https:\/\/www.silverstripe.org\/software\/download\/security-releases\/ss-2015-005\/","cve":null,"affectedVersions":"\u003E=3.1.0,\u003C3.1.10","source":"FriendsOfPHP\/security-advisories","reportedAt":"2015-02-12 15:55:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3mm9-2p44-rw39"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/cms\/SS-2015-005-1.yaml"}]},{"advisoryId":"PKSA-d3xv-chbr-ng6f","packageName":"silverstripe\/cms","remoteId":"silverstripe\/cms\/SS-2015-003-1.yaml","title":"SS-2015-003: History XSS Vulnerability","link":"https:\/\/www.silverstripe.org\/software\/download\/security-releases\/ss-2015-003\/","cve":null,"affectedVersions":"\u003E=3.1.0,\u003C3.1.10","source":"FriendsOfPHP\/security-advisories","reportedAt":"2015-02-12 15:55:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r97r-64vp-fghm"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/cms\/SS-2015-003-1.yaml"}]},{"advisoryId":"PKSA-tbcz-9q2k-1r4f","packageName":"silverstripe\/cms","remoteId":"silverstripe\/cms\/SS-2015-008-1.yaml","title":"SS-2015-008: SiteTree Creation Permission Vulnerability","link":"https:\/\/www.silverstripe.org\/software\/download\/security-releases\/ss-2015-008-sitetree-creation-permission-vulnerability\/","cve":null,"affectedVersions":"\u003E=3.0.0,\u003C3.0.12|\u003E=3.1.0,\u003C3.1.11","source":"FriendsOfPHP\/security-advisories","reportedAt":"2015-03-19 16:54:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6hh6-59j2-qrxw"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/cms\/SS-2015-008-1.yaml"}]}],"silverstripe\/versioned":[{"advisoryId":"PKSA-nksq-cxj8-zb32","packageName":"silverstripe\/versioned","remoteId":"silverstripe\/versioned\/CVE-2026-55779.yaml","title":"CVE-2026-55779 - XSS in archive admin restore","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-55779","cve":"CVE-2026-55779","affectedVersions":"\u003C3.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 02:53:49","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/versioned\/CVE-2026-55779.yaml"}]}],"silverstripe\/framework":[{"advisoryId":"PKSA-x6tz-s6v3-ynk3","packageName":"silverstripe\/framework","remoteId":"silverstripe\/framework\/CVE-2026-54720.yaml","title":"CVE-2026-54720 - XSS attack through media embed","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-54720","cve":"CVE-2026-54720","affectedVersions":"\u003C6.2.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 02:45:19","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/framework\/CVE-2026-54720.yaml"}]},{"advisoryId":"PKSA-wt32-ns28-f45d","packageName":"silverstripe\/framework","remoteId":"silverstripe\/framework\/SS-2015-014-1.yaml","title":"SS-2015-014: Vulnerability on \u0027isDev\u0027, \u0027isTest\u0027 and \u0027flush\u0027 $_GET validation","link":"https:\/\/www.silverstripe.org\/software\/download\/security-releases\/ss-2015-014\/","cve":null,"affectedVersions":"\u003E=3.0.0,\u003C3.0.14|\u003E=3.1.0,\u003C3.1.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2015-05-28 13:05:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-ph62-fv59-vf9h"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/framework\/SS-2015-014-1.yaml"}]},{"advisoryId":"PKSA-td9q-mf48-mqpm","packageName":"silverstripe\/framework","remoteId":"silverstripe\/framework\/SS-2015-012-1.yaml","title":"SS-2015-012: External redirection risk in Security?ReturnURL","link":"https:\/\/www.silverstripe.org\/software\/download\/security-releases\/ss-2015-012\/","cve":null,"affectedVersions":"\u003E=3.0.0,\u003C3.0.14|\u003E=3.1.0,\u003C3.1.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2015-05-25 14:52:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xx4r-5265-48j6"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/framework\/SS-2015-012-1.yaml"}]},{"advisoryId":"PKSA-bkm6-5mwx-3kd3","packageName":"silverstripe\/framework","remoteId":"silverstripe\/framework\/SS-2015-011-1.yaml","title":"SS-2015-011: Potential SQL Injection Vulnerability","link":"https:\/\/www.silverstripe.org\/software\/download\/security-releases\/ss-2015-011\/","cve":null,"affectedVersions":"\u003E=3.0.0,\u003C3.0.14|\u003E=3.1.0,\u003C3.1.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2015-05-25 10:52:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7m2v-x7rg-5hm5"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/framework\/SS-2015-011-1.yaml"}]},{"advisoryId":"PKSA-bnbw-tbzq-5ykk","packageName":"silverstripe\/framework","remoteId":"silverstripe\/framework\/SS-2016-003-1.yaml","title":"SS-2016-003: Hostname, IP and Protocol Spoofing through HTTP Headers","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/ss-2016-003\/","cve":null,"affectedVersions":"\u003E=3.1.0,\u003C3.1.17|\u003E=3.2.0,\u003C3.2.2|\u003E3.2,\u003C3.3.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2016-02-18 11:05:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r85g-7jpv-8xrx"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/framework\/SS-2016-003-1.yaml"}]},{"advisoryId":"PKSA-gg94-wpcm-tbtp","packageName":"silverstripe\/framework","remoteId":"silverstripe\/framework\/SS-2016-002-1.yaml","title":"SS-2016-002: CSRF vulnerability in GridFieldAddExistingAutocompleter","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/ss-2016-002\/","cve":null,"affectedVersions":"\u003E=3.1.0,\u003C3.1.17|\u003E=3.2.0,\u003C3.2.2|\u003E3.2,\u003C3.3.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2016-02-17 17:50:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g84q-cq55-xwgp"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/framework\/SS-2016-002-1.yaml"}]},{"advisoryId":"PKSA-z1m7-vnpc-524q","packageName":"silverstripe\/framework","remoteId":"silverstripe\/framework\/SS-2015-009-1.yaml","title":"SS-2015-009: XSS In rewritten hash links","link":"https:\/\/www.silverstripe.org\/software\/download\/security-releases\/ss-2015-009-xss-in-rewritten-hash-links\/","cve":null,"affectedVersions":"\u003E=3.0.0,\u003C3.0.13|\u003E=3.1.0,\u003C3.1.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2015-03-20 14:57:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-5r8w-66hq-rc39"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/framework\/SS-2015-009-1.yaml"}]},{"advisoryId":"PKSA-xhsq-x1jb-f31d","packageName":"silverstripe\/framework","remoteId":"silverstripe\/framework\/SS-2014-017-1.yaml","title":"SS-2014-017: XML Quadratic Blowup Attack","link":"https:\/\/www.silverstripe.org\/software\/download\/security-releases\/ss-2014-017-xml-quadratic-blowup-attack\/","cve":null,"affectedVersions":"\u003E=3.1.0,\u003C3.1.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2014-08-12 11:50:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-87pf-7x99-5xc4"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/framework\/SS-2014-017-1.yaml"}]},{"advisoryId":"PKSA-4b5m-tw4q-3fmq","packageName":"silverstripe\/framework","remoteId":"silverstripe\/framework\/SS-2015-004-1.yaml","title":"SS-2015-004: TreeDropdownField and TreeMultiSelectField XSS","link":"https:\/\/www.silverstripe.org\/software\/download\/security-releases\/ss-2015-004\/","cve":null,"affectedVersions":"\u003E=3.1.0,\u003C3.1.10","source":"FriendsOfPHP\/security-advisories","reportedAt":"2015-02-12 15:55:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qp29-wcc2-vmpc"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/framework\/SS-2015-004-1.yaml"}]},{"advisoryId":"PKSA-dwpn-yczp-hpvw","packageName":"silverstripe\/framework","remoteId":"silverstripe\/framework\/SS-2014-015-1.yaml","title":"SS-2014-015: IE requests not properly behaving with rewritehashlinks","link":"https:\/\/www.silverstripe.org\/software\/download\/security-releases\/ss-2014-015-ie-requests-not-properly-behaving-with-rewritehashlinks\/","cve":null,"affectedVersions":"\u003E=3.0.0,\u003C3.0.13|\u003E=3.1.0,\u003C3.1.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2015-03-20 12:10:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-34q6-xqxh-gq39"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/framework\/SS-2014-015-1.yaml"}]},{"advisoryId":"PKSA-tdvc-fx4y-y9yf","packageName":"silverstripe\/framework","remoteId":"silverstripe\/framework\/SS-2015-028-1.yaml","title":"SS-2015-028: Missing security check on dev\/build\/defaults","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/ss-2015-028\/","cve":null,"affectedVersions":"\u003E=3.1.0,\u003C3.1.17|\u003E=3.2.0,\u003C3.2.2|\u003E3.2,\u003C3.3.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2016-02-17 17:55:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4h54-vwx9-3vr3"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/framework\/SS-2015-028-1.yaml"}]},{"advisoryId":"PKSA-r8bz-4tyw-cqq7","packageName":"silverstripe\/framework","remoteId":"silverstripe\/framework\/SS-2015-007-1.yaml","title":"SS-2015-007: XSS In FormAction","link":"https:\/\/www.silverstripe.org\/software\/download\/security-releases\/ss-2015-007\/","cve":null,"affectedVersions":"\u003E=3.1.0,\u003C3.1.10","source":"FriendsOfPHP\/security-advisories","reportedAt":"2015-02-12 15:55:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-88jp-9jrv-6368"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/framework\/SS-2015-007-1.yaml"}]}],"silverstripe\/userforms":[{"advisoryId":"PKSA-g6zg-78xs-c8r8","packageName":"silverstripe\/userforms","remoteId":"silverstripe\/userforms\/CVE-2026-54721.yaml","title":"CVE-2026-54721 - Remote code execution via userforms email subject","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-54721","cve":"CVE-2026-54721","affectedVersions":"\u003C6.4.9|\u003E=7.0.0,\u003C7.0.7|\u003E=7.1.0,\u003C7.1.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 04:05:09","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/userforms\/CVE-2026-54721.yaml"}]}],"snipe\/snipe-it":[{"advisoryId":"PKSA-k6ph-vwdz-djyn","packageName":"snipe\/snipe-it","remoteId":"GHSA-6mmj-jhqj-6c6q","title":"Snipe-IT\u0027s S3 signature image retrieval lacks authorization before temporary URL ","link":"https:\/\/github.com\/advisories\/GHSA-6mmj-jhqj-6c6q","cve":"CVE-2026-55542","affectedVersions":"\u003C=8.5.0","source":"GitHub","reportedAt":"2026-06-23 23:11:26","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-6mmj-jhqj-6c6q"}]},{"advisoryId":"PKSA-2tsw-c1yg-xhyc","packageName":"snipe\/snipe-it","remoteId":"GHSA-pwpj-p52h-q484","title":"Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection","link":"https:\/\/github.com\/advisories\/GHSA-pwpj-p52h-q484","cve":"CVE-2026-54329","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-06-23 23:12:04","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pwpj-p52h-q484"}]},{"advisoryId":"PKSA-sr4q-gvr6-k14n","packageName":"snipe\/snipe-it","remoteId":"GHSA-p68w-rgmg-3c2v","title":"Snipe-IT Vulnerable to User Account Escalation via CSV Import","link":"https:\/\/github.com\/advisories\/GHSA-p68w-rgmg-3c2v","cve":"CVE-2026-49976","affectedVersions":"\u003C8.6.0","source":"GitHub","reportedAt":"2026-06-23 23:02:03","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-p68w-rgmg-3c2v"}]},{"advisoryId":"PKSA-xjxm-8vz6-vf8y","packageName":"snipe\/snipe-it","remoteId":"GHSA-6x4j-8954-5hxm","title":"Snipe-IT has a 2FA reset privilege bypass","link":"https:\/\/github.com\/advisories\/GHSA-6x4j-8954-5hxm","cve":"CVE-2026-50550","affectedVersions":"\u003C8.5.0","source":"GitHub","reportedAt":"2026-06-23 23:03:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6x4j-8954-5hxm"}]},{"advisoryId":"PKSA-44m9-kxcv-rmgf","packageName":"snipe\/snipe-it","remoteId":"GHSA-33g4-646g-qwmm","title":"Snipe-IT has Multi-Tenancy Bypass via Bulk Asset Update","link":"https:\/\/github.com\/advisories\/GHSA-33g4-646g-qwmm","cve":"CVE-2026-55482","affectedVersions":"\u003C=8.4.1","source":"GitHub","reportedAt":"2026-06-23 23:03:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-33g4-646g-qwmm"}]},{"advisoryId":"PKSA-nhdc-dm5c-gkjd","packageName":"snipe\/snipe-it","remoteId":"GHSA-hf68-g98v-wp9g","title":"Snipe-IT Vulnerable to Privilege Escalation via Missing admin Permission Check in User Creation","link":"https:\/\/github.com\/advisories\/GHSA-hf68-g98v-wp9g","cve":"CVE-2026-55483","affectedVersions":"\u003C8.6.0","source":"GitHub","reportedAt":"2026-06-23 23:06:18","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hf68-g98v-wp9g"}]},{"advisoryId":"PKSA-dfjb-vj14-j26x","packageName":"snipe\/snipe-it","remoteId":"GHSA-x667-r589-43m7","title":"Snipe-IT has Improper Authorization in File Deletion (IDOR)","link":"https:\/\/github.com\/advisories\/GHSA-x667-r589-43m7","cve":"CVE-2026-55519","affectedVersions":"\u003C=8.4.0","source":"GitHub","reportedAt":"2026-06-23 23:06:59","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-x667-r589-43m7"}]},{"advisoryId":"PKSA-35bw-hh2v-5kbx","packageName":"snipe\/snipe-it","remoteId":"GHSA-mr8g-2mj4-pcq2","title":"Snipe-IT\u0027s TOTP is Brute-Forceable Due to Missing Rate Limiting on `POST \/two-factor`","link":"https:\/\/github.com\/advisories\/GHSA-mr8g-2mj4-pcq2","cve":"CVE-2026-49870","affectedVersions":"\u003C8.6.0","source":"GitHub","reportedAt":"2026-06-23 22:32:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mr8g-2mj4-pcq2"}]},{"advisoryId":"PKSA-czh5-xdx3-8gjh","packageName":"snipe\/snipe-it","remoteId":"GHSA-6f75-x745-xcpr","title":"Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users","link":"https:\/\/github.com\/advisories\/GHSA-6f75-x745-xcpr","cve":"CVE-2026-48507","affectedVersions":"\u003C8.6.0","source":"GitHub","reportedAt":"2026-06-23 22:24:59","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6f75-x745-xcpr"}]},{"advisoryId":"PKSA-bd8t-dph3-gby8","packageName":"snipe\/snipe-it","remoteId":"GHSA-f3c5-6cw8-fg57","title":"Snipe-IT\u0027s selectlist visibility is too permissive","link":"https:\/\/github.com\/advisories\/GHSA-f3c5-6cw8-fg57","cve":"CVE-2026-48492","affectedVersions":"\u003C8.5.1","source":"GitHub","reportedAt":"2026-06-23 22:11:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f3c5-6cw8-fg57"}]},{"advisoryId":"PKSA-7srb-sjc8-3k98","packageName":"snipe\/snipe-it","remoteId":"GHSA-52fw-7fw2-fmv5","title":"Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment","link":"https:\/\/github.com\/advisories\/GHSA-52fw-7fw2-fmv5","cve":"CVE-2026-48493","affectedVersions":"\u003C8.6.0","source":"GitHub","reportedAt":"2026-06-23 22:12:11","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-52fw-7fw2-fmv5"}]},{"advisoryId":"PKSA-rnj3-1mvy-45m9","packageName":"snipe\/snipe-it","remoteId":"GHSA-mghp-5cq4-v6mg","title":"Snipe-IT has an open redirect vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-mghp-5cq4-v6mg","cve":"CVE-2026-44833","affectedVersions":"\u003C8.4.1","source":"GitHub","reportedAt":"2026-05-08 23:25:37","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mghp-5cq4-v6mg"}]},{"advisoryId":"PKSA-p5z5-yvbr-44mr","packageName":"snipe\/snipe-it","remoteId":"GHSA-xg82-2hrv-hf64","title":"Snipe-IT has insecure permissions in file uploads","link":"https:\/\/github.com\/advisories\/GHSA-xg82-2hrv-hf64","cve":"CVE-2026-37709","affectedVersions":"\u003C8.4.1","source":"GitHub","reportedAt":"2026-05-08 23:04:36","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-xg82-2hrv-hf64"}]},{"advisoryId":"PKSA-t5t8-ptsk-b8c5","packageName":"snipe\/snipe-it","remoteId":"GHSA-r42m-953q-6vjx","title":"Snipe-IT has Stored XSS via Component Checkout Notes (v8.4.0)","link":"https:\/\/github.com\/advisories\/GHSA-r42m-953q-6vjx","cve":"CVE-2026-44831","affectedVersions":"\u003C8.4.1","source":"GitHub","reportedAt":"2026-05-08 22:23:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r42m-953q-6vjx"}]},{"advisoryId":"PKSA-3w8f-xykp-s5ps","packageName":"snipe\/snipe-it","remoteId":"GHSA-hq28-crg7-95pr","title":"Snipe-IT has Privilege Escalation via API Permissions Assignment","link":"https:\/\/github.com\/advisories\/GHSA-hq28-crg7-95pr","cve":"CVE-2026-44832","affectedVersions":"\u003C8.4.1","source":"GitHub","reportedAt":"2026-05-08 22:24:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hq28-crg7-95pr"}]},{"advisoryId":"PKSA-b19f-d499-7h75","packageName":"snipe\/snipe-it","remoteId":"GHSA-5448-v74m-7mv7","title":"Snipe-IT has sensitive user attributes related to account privileges that are insufficiently protected against mass assignment","link":"https:\/\/github.com\/advisories\/GHSA-5448-v74m-7mv7","cve":"CVE-2025-15602","affectedVersions":"\u003C8.3.7","source":"GitHub","reportedAt":"2026-03-06 18:31:13","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5448-v74m-7mv7"}]},{"advisoryId":"PKSA-wtqq-tf96-nxmc","packageName":"snipe\/snipe-it","remoteId":"GHSA-4g25-wj72-chxg","title":"Snipe-IT allows stored XSS via the Locations \u0022Country\u0022 field","link":"https:\/\/github.com\/advisories\/GHSA-4g25-wj72-chxg","cve":"CVE-2025-65622","affectedVersions":"\u003C8.3.4","source":"GitHub","reportedAt":"2025-12-02 00:31:12","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4g25-wj72-chxg"}]},{"advisoryId":"PKSA-czzq-6v8k-876d","packageName":"snipe\/snipe-it","remoteId":"GHSA-fww5-m9wc-jcjc","title":"Snipe-IT is vulnerable to stored cross-site scripting","link":"https:\/\/github.com\/advisories\/GHSA-fww5-m9wc-jcjc","cve":"CVE-2025-65621","affectedVersions":"\u003C8.3.4","source":"GitHub","reportedAt":"2025-12-01 21:30:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fww5-m9wc-jcjc"}]},{"advisoryId":"PKSA-c9tc-ctjb-ht9h","packageName":"snipe\/snipe-it","remoteId":"GHSA-8x9v-8qgj-945x","title":"Snipe-IT has Cross-site Scripting vulnerability in CSV import workflow","link":"https:\/\/github.com\/advisories\/GHSA-8x9v-8qgj-945x","cve":"CVE-2025-64027","affectedVersions":"\u003C=8.3.4","source":"GitHub","reportedAt":"2025-11-20 18:31:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8x9v-8qgj-945x"}]}],"slim\/slim":[{"advisoryId":"PKSA-ftt4-t9sz-mwn5","packageName":"slim\/slim","remoteId":"GHSA-53h4-8rc4-f539","title":"Slim has Reflected XSS in the HtmlErrorRenderer","link":"https:\/\/github.com\/advisories\/GHSA-53h4-8rc4-f539","cve":"CVE-2026-48157","affectedVersions":"\u003E=4.4.0,\u003C=4.15.1","source":"GitHub","reportedAt":"2026-06-23 21:54:06","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-53h4-8rc4-f539"}]}],"filament\/infolists":[{"advisoryId":"PKSA-jm9c-w1fc-4m3p","packageName":"filament\/infolists","remoteId":"GHSA-3fc8-8hp6-6jr4","title":"Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS","link":"https:\/\/github.com\/advisories\/GHSA-3fc8-8hp6-6jr4","cve":"CVE-2026-48167","affectedVersions":"\u003E=5.0.0,\u003C=5.6.4|\u003E=4.0.0,\u003C=4.11.4","source":"GitHub","reportedAt":"2026-06-23 21:57:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3fc8-8hp6-6jr4"}]},{"advisoryId":"PKSA-jyd3-2srm-pfqd","packageName":"filament\/infolists","remoteId":"GHSA-9h9q-qhxg-89xr","title":"Filament has unvalidated ColorColumn and ColorEntry values that can be used for Cross-site Scripting","link":"https:\/\/github.com\/advisories\/GHSA-9h9q-qhxg-89xr","cve":"CVE-2024-47186","affectedVersions":"\u003E=3.0.0,\u003C3.2.115","source":"GitHub","reportedAt":"2024-09-27 20:51:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9h9q-qhxg-89xr"}]}],"filament\/tables":[{"advisoryId":"PKSA-qx8b-yc1b-44yc","packageName":"filament\/tables","remoteId":"GHSA-3fc8-8hp6-6jr4","title":"Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS","link":"https:\/\/github.com\/advisories\/GHSA-3fc8-8hp6-6jr4","cve":"CVE-2026-48167","affectedVersions":"\u003E=5.0.0,\u003C=5.6.4|\u003E=4.0.0,\u003C=4.11.4","source":"GitHub","reportedAt":"2026-06-23 21:57:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3fc8-8hp6-6jr4"}]},{"advisoryId":"PKSA-w941-zhwq-2wbm","packageName":"filament\/tables","remoteId":"GHSA-7q3w-xqjw-g3cr","title":"Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields","link":"https:\/\/github.com\/advisories\/GHSA-7q3w-xqjw-g3cr","cve":"CVE-2026-48067","affectedVersions":"\u003E=3.0.0,\u003C=3.3.50","source":"GitHub","reportedAt":"2026-06-11 20:26:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7q3w-xqjw-g3cr"}]},{"advisoryId":"PKSA-5bdf-2x61-v43c","packageName":"filament\/tables","remoteId":"GHSA-vv3x-j2x5-36jc","title":"Filament Unvalidated Range and Values summarizer values can be used for XSS","link":"https:\/\/github.com\/advisories\/GHSA-vv3x-j2x5-36jc","cve":"CVE-2026-33080","affectedVersions":"\u003E=5.0.0,\u003C5.3.5|\u003E=4.0.0,\u003C4.8.5","source":"GitHub","reportedAt":"2026-03-18 20:07:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vv3x-j2x5-36jc"}]},{"advisoryId":"PKSA-2xmv-8f99-rg33","packageName":"filament\/tables","remoteId":"GHSA-9h9q-qhxg-89xr","title":"Filament has unvalidated ColorColumn and ColorEntry values that can be used for Cross-site Scripting","link":"https:\/\/github.com\/advisories\/GHSA-9h9q-qhxg-89xr","cve":"CVE-2024-47186","affectedVersions":"\u003E=3.0.0,\u003C3.2.115","source":"GitHub","reportedAt":"2024-09-27 20:51:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9h9q-qhxg-89xr"}]}],"wwbn\/avideo":[{"advisoryId":"PKSA-m974-q1kf-q6bz","packageName":"wwbn\/avideo","remoteId":"GHSA-7cqp-7cfv-6c3q","title":"AVideo Meet plugin: anonymous-to-admin stored XSS via unescaped participant User-Agent in getMeetInfo.json.php Participants panel","link":"https:\/\/github.com\/advisories\/GHSA-7cqp-7cfv-6c3q","cve":null,"affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-06-23 19:11:27","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7cqp-7cfv-6c3q"}]},{"advisoryId":"PKSA-kyny-4znw-msn6","packageName":"wwbn\/avideo","remoteId":"GHSA-wc3f-xc32-435f","title":"AVideo has an incomplete fix of CVE-2026-33482: sanitizeFFmpegCommand still allows a single \u0027\u0026\u0027 (background operator), giving OS command execution at the same execAsync sh -c sink","link":"https:\/\/github.com\/advisories\/GHSA-wc3f-xc32-435f","cve":"CVE-2026-55173","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-06-23 17:42:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wc3f-xc32-435f"}]},{"advisoryId":"PKSA-6ggv-tpsf-fgk3","packageName":"wwbn\/avideo","remoteId":"GHSA-wf69-r4mx-43rr","title":"AVideo Vulnerable to Unauthenticated .env File Exposure via Official Docker Compose Configuration","link":"https:\/\/github.com\/advisories\/GHSA-wf69-r4mx-43rr","cve":"CVE-2026-33692","affectedVersions":"\u003C29.0","source":"GitHub","reportedAt":"2026-06-22 19:54:15","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wf69-r4mx-43rr"}]},{"advisoryId":"PKSA-pwzs-6qqr-1tpq","packageName":"wwbn\/avideo","remoteId":"GHSA-95jh-7r58-xmxw","title":"AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data","link":"https:\/\/github.com\/advisories\/GHSA-95jh-7r58-xmxw","cve":"CVE-2026-33731","affectedVersions":"\u003C=28.0","source":"GitHub","reportedAt":"2026-06-22 19:58:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-95jh-7r58-xmxw"}]},{"advisoryId":"PKSA-k458-rr3w-813f","packageName":"wwbn\/avideo","remoteId":"GHSA-8j8m-p79x-g4jm","title":"AVideo\u0027s Privilege Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload\/Stream\/Meet Permissions","link":"https:\/\/github.com\/advisories\/GHSA-8j8m-p79x-g4jm","cve":"CVE-2026-33684","affectedVersions":"\u003C29.0","source":"GitHub","reportedAt":"2026-06-22 17:25:03","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8j8m-p79x-g4jm"}]},{"advisoryId":"PKSA-k9kk-fbnx-923m","packageName":"wwbn\/avideo","remoteId":"GHSA-2fhx-q92v-5fhv","title":"WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass)","link":"https:\/\/github.com\/advisories\/GHSA-2fhx-q92v-5fhv","cve":"CVE-2026-49279","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-06-04 18:55:04","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2fhx-q92v-5fhv"}]},{"advisoryId":"PKSA-s76b-xf2h-zmsc","packageName":"wwbn\/avideo","remoteId":"GHSA-hgjh-6wj8-gcgf","title":"WWBN AVideo: Unauthenticated Reflected XSS via $_GET[\u0027search\u0027] in AVideo YouTubeAPI Gallery Pagination","link":"https:\/\/github.com\/advisories\/GHSA-hgjh-6wj8-gcgf","cve":"CVE-2026-50182","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-06-04 18:55:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hgjh-6wj8-gcgf"}]},{"advisoryId":"PKSA-qfq6-tncf-8grt","packageName":"wwbn\/avideo","remoteId":"GHSA-66q5-cj5g-wrfx","title":"WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI Gallery Section","link":"https:\/\/github.com\/advisories\/GHSA-66q5-cj5g-wrfx","cve":"CVE-2026-50183","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-06-04 18:56:53","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-66q5-cj5g-wrfx"}]},{"advisoryId":"PKSA-rftd-5wbt-6qx1","packageName":"wwbn\/avideo","remoteId":"GHSA-8whc-2wmv-ww35","title":"WWBN AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin","link":"https:\/\/github.com\/advisories\/GHSA-8whc-2wmv-ww35","cve":"CVE-2026-54458","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-06-04 18:57:50","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-8whc-2wmv-ww35"}]},{"advisoryId":"PKSA-4cz6-6cfv-8gy3","packageName":"wwbn\/avideo","remoteId":"GHSA-c8h8-vq34-9fw2","title":"WWBN AVideo: Stored XSS via unescaped Gallery category description","link":"https:\/\/github.com\/advisories\/GHSA-c8h8-vq34-9fw2","cve":"CVE-2026-47694","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-06-04 18:46:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c8h8-vq34-9fw2"}]},{"advisoryId":"PKSA-59k2-q697-bf8x","packageName":"wwbn\/avideo","remoteId":"GHSA-9392-pj54-qqf8","title":"WWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPayment endpoint","link":"https:\/\/github.com\/advisories\/GHSA-9392-pj54-qqf8","cve":"CVE-2026-47696","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-06-04 18:47:35","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9392-pj54-qqf8"}]},{"advisoryId":"PKSA-2zy4-bynz-m2w3","packageName":"wwbn\/avideo","remoteId":"GHSA-w4qq-74h6-58wq","title":"AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view\/img\/image404Raw.php`","link":"https:\/\/github.com\/advisories\/GHSA-w4qq-74h6-58wq","cve":"CVE-2026-46337","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-19 16:25:27","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w4qq-74h6-58wq"}]},{"advisoryId":"PKSA-qsmt-54t8-4cfb","packageName":"wwbn\/avideo","remoteId":"GHSA-3mjv-375j-6h92","title":"AVideo: Authenticated Arbitrary File Read in view\/update.php","link":"https:\/\/github.com\/advisories\/GHSA-3mjv-375j-6h92","cve":"CVE-2026-45731","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-18 19:01:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3mjv-375j-6h92"}]},{"advisoryId":"PKSA-23zk-pg8x-sksb","packageName":"wwbn\/avideo","remoteId":"GHSA-vpfx-pxqw-2w79","title":"AVideo CVE-2026-43881 incomplete fix - `objects\/mention.json.php:17` is an unauthenticated user enumeration sibling that survives `d9cdc7024`","link":"https:\/\/github.com\/advisories\/GHSA-vpfx-pxqw-2w79","cve":"CVE-2026-45620","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-18 13:30:05","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vpfx-pxqw-2w79"}]},{"advisoryId":"PKSA-rjrh-w2j8-5qv7","packageName":"wwbn\/avideo","remoteId":"GHSA-xw67-cg5f-4m2r","title":"AVideo: OS command injection in on_publish.php execAsync via unescaped m3u8 URL","link":"https:\/\/github.com\/advisories\/GHSA-xw67-cg5f-4m2r","cve":"CVE-2026-45578","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-15 18:32:36","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xw67-cg5f-4m2r"}]},{"advisoryId":"PKSA-wfgs-zzz2-wqdc","packageName":"wwbn\/avideo","remoteId":"GHSA-m5j4-7r85-2cj2","title":"AVideo: stored XSS via unescaped stream key in modeYoutubeLive.php class attribute","link":"https:\/\/github.com\/advisories\/GHSA-m5j4-7r85-2cj2","cve":"CVE-2026-45580","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-15 18:33:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m5j4-7r85-2cj2"}]},{"advisoryId":"PKSA-p6p4-r212-wdgb","packageName":"wwbn\/avideo","remoteId":"GHSA-3mv2-vmwh-rwfx","title":"AVideo: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim\u0027s 2FA","link":"https:\/\/github.com\/advisories\/GHSA-3mv2-vmwh-rwfx","cve":"CVE-2026-45610","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-15 18:34:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3mv2-vmwh-rwfx"}]},{"advisoryId":"PKSA-fc5p-jrjx-1jy4","packageName":"wwbn\/avideo","remoteId":"GHSA-c3ch-22rq-xfwr","title":"AVideo CVE-2026-43884 incomplete fix - six (or more) `isSSRFSafeURL()` call sites still discard the `$resolvedIP` out-param at master HEAD post-`603e7bf`","link":"https:\/\/github.com\/advisories\/GHSA-c3ch-22rq-xfwr","cve":"CVE-2026-45619","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-15 18:35:38","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c3ch-22rq-xfwr"}]},{"advisoryId":"PKSA-psg4-6wzm-s4q8","packageName":"wwbn\/avideo","remoteId":"GHSA-qxvm-r42f-5p8j","title":"AVideo\u0027s Meet plugin: `uploadRecordedVideo.json.php` derives `users_id` from the uploaded filename and calls passwordless `User-\u003Elogin()`, allowing any caller with the Meet shared secret to obtain a session as arbitrary users including admin","link":"https:\/\/github.com\/advisories\/GHSA-qxvm-r42f-5p8j","cve":null,"affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-15 18:17:19","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qxvm-r42f-5p8j"}]},{"advisoryId":"PKSA-fx66-ws43-zr1x","packageName":"wwbn\/avideo","remoteId":"GHSA-xr49-f4rh-qcjf","title":"AVideo Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization","link":"https:\/\/github.com\/advisories\/GHSA-xr49-f4rh-qcjf","cve":"CVE-2026-43885","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-05 22:20:42","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xr49-f4rh-qcjf"}]},{"advisoryId":"PKSA-81bf-8cfg-hbh2","packageName":"wwbn\/avideo","remoteId":"GHSA-mwgh-92m2-wvhv","title":"AVideo: Unauthenticated CRLF\/ICS Injection in Scheduler downloadICS.php Allows Calendar Event Spoofing","link":"https:\/\/github.com\/advisories\/GHSA-mwgh-92m2-wvhv","cve":"CVE-2026-43882","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-05 22:14:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mwgh-92m2-wvhv"}]},{"advisoryId":"PKSA-45d7-4cq7-wyg1","packageName":"wwbn\/avideo","remoteId":"GHSA-958h-qp3x-q4gj","title":"AVideo: IDOR in PayPalYPT Plugin Allows Any Authenticated User to Cancel Arbitrary PayPal Subscription Agreements","link":"https:\/\/github.com\/advisories\/GHSA-958h-qp3x-q4gj","cve":"CVE-2026-43883","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-05 22:16:12","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-958h-qp3x-q4gj"}]},{"advisoryId":"PKSA-458v-1gr5-bf2y","packageName":"wwbn\/avideo","remoteId":"GHSA-2hch-c97c-g99x","title":"AVideo has SSRF Protection Bypass via HTTP Redirect and DNS Rebinding in isSSRFSafeURL()","link":"https:\/\/github.com\/advisories\/GHSA-2hch-c97c-g99x","cve":"CVE-2026-43884","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-05 22:16:33","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2hch-c97c-g99x"}]},{"advisoryId":"PKSA-m1k1-6n5g-5skj","packageName":"wwbn\/avideo","remoteId":"GHSA-6rvw-7p8v-mjfq","title":"AVideo: Unauthenticated User Enumeration in objects\/users.json.php via isCompany Parameter Allows Bypass of the Admin-Only Listing Restriction","link":"https:\/\/github.com\/advisories\/GHSA-6rvw-7p8v-mjfq","cve":"CVE-2026-43881","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-05 22:02:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6rvw-7p8v-mjfq"}]},{"advisoryId":"PKSA-7c98-nyt4-qt25","packageName":"wwbn\/avideo","remoteId":"GHSA-5hgj-7gm9-cff5","title":"AVideo: Unauthenticated Arbitrary Email Sending via sendEmail.json.php Enables Phishing from the Site\u2019s Legitimate From Address","link":"https:\/\/github.com\/advisories\/GHSA-5hgj-7gm9-cff5","cve":"CVE-2026-43880","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-05 21:56:19","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5hgj-7gm9-cff5"}]},{"advisoryId":"PKSA-n1mw-ddw6-yyqd","packageName":"wwbn\/avideo","remoteId":"GHSA-wp38-whx3-xffh","title":"AVideo has Blind SSRF in YPTWallet Donation Webhook via Missing isSSRFSafeURL() Check and CURLOPT_FOLLOWLOCATION Redirect Bypass","link":"https:\/\/github.com\/advisories\/GHSA-wp38-whx3-xffh","cve":"CVE-2026-43879","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-05 21:49:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wp38-whx3-xffh"}]},{"advisoryId":"PKSA-71gv-fx3g-ynk8","packageName":"wwbn\/avideo","remoteId":"GHSA-g9cm-rxp7-6gv5","title":"AVideo: HTML Injection in notifySubscribers.json.php Allows Platform-Branded Phishing Emails to Channel Subscribers","link":"https:\/\/github.com\/advisories\/GHSA-g9cm-rxp7-6gv5","cve":"CVE-2026-43876","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-05 19:11:32","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g9cm-rxp7-6gv5"}]},{"advisoryId":"PKSA-7rzh-pwkp-t841","packageName":"wwbn\/avideo","remoteId":"GHSA-jw8g-5j46-44rp","title":"AVideo: CSRF in userSavePhoto.php Allows Cross-Origin Overwrite of Authenticated Users\u0027 Profile Photos with Arbitrary Content","link":"https:\/\/github.com\/advisories\/GHSA-jw8g-5j46-44rp","cve":"CVE-2026-43877","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-05 19:13:03","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jw8g-5j46-44rp"}]},{"advisoryId":"PKSA-x5f2-6rvc-vhkd","packageName":"wwbn\/avideo","remoteId":"GHSA-mm5f-8q57-4fc4","title":"Video: Reflected XSS in plugin\/Meet\/iframe.php via Unescaped user and pass Parameters in JavaScript String Literal","link":"https:\/\/github.com\/advisories\/GHSA-mm5f-8q57-4fc4","cve":"CVE-2026-43878","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-05 19:15:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mm5f-8q57-4fc4"}]},{"advisoryId":"PKSA-15fj-zg4r-zsnq","packageName":"wwbn\/avideo","remoteId":"GHSA-ghcv-22jf-vfxm","title":"AVideo has an Incomplete Fix for YPTSocket autoEvalCodeOnHTML Strip: Unauthenticated Cross-User JavaScript Execution via `$msg[\u0027json\u0027]` Relay Bypass","link":"https:\/\/github.com\/advisories\/GHSA-ghcv-22jf-vfxm","cve":"CVE-2026-43874","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-05 19:07:09","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-ghcv-22jf-vfxm"}]},{"advisoryId":"PKSA-dbh3-mg7m-c1nc","packageName":"wwbn\/avideo","remoteId":"GHSA-5w8w-26ch-v5cw","title":"AVideo: Password Hash Leak in MobileManager OAuth Redirect URL Enables Account Takeover","link":"https:\/\/github.com\/advisories\/GHSA-5w8w-26ch-v5cw","cve":"CVE-2026-43875","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-05 19:08:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5w8w-26ch-v5cw"}]},{"advisoryId":"PKSA-5tbj-dcxw-w2wv","packageName":"wwbn\/avideo","remoteId":"GHSA-qm9p-p5pw-jrx2","title":"AVideo: Unauthenticated Disclosure of CloneSite `myKey` via Error Echo in `cloneClient.json.php` Enables Cross-Site DB Dump of the Configured Clone Server","link":"https:\/\/github.com\/advisories\/GHSA-qm9p-p5pw-jrx2","cve":"CVE-2026-43873","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-05-05 18:58:13","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qm9p-p5pw-jrx2"}]},{"advisoryId":"PKSA-z3t4-4xbz-b3c9","packageName":"wwbn\/avideo","remoteId":"GHSA-xr6f-h4x7-r6qp","title":"WWBN AVideo: RCE cause by clonesite plugin","link":"https:\/\/github.com\/advisories\/GHSA-xr6f-h4x7-r6qp","cve":"CVE-2026-41304","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-16 21:25:19","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xr6f-h4x7-r6qp"}]},{"advisoryId":"PKSA-q934-7bnb-4bby","packageName":"wwbn\/avideo","remoteId":"GHSA-5879-4fmr-xwf2","title":"WWBN AVideo has an incomplete fix for CVE-2026-33293: Path Traversal","link":"https:\/\/github.com\/advisories\/GHSA-5879-4fmr-xwf2","cve":"CVE-2026-41058","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 23:21:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5879-4fmr-xwf2"}]},{"advisoryId":"PKSA-8cks-7g1w-tz19","packageName":"wwbn\/avideo","remoteId":"GHSA-j432-4w3j-3w8j","title":"WWBN AVideo has a SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL","link":"https:\/\/github.com\/advisories\/GHSA-j432-4w3j-3w8j","cve":"CVE-2026-41060","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 23:22:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j432-4w3j-3w8j"}]},{"advisoryId":"PKSA-gxyd-jpvf-3ngj","packageName":"wwbn\/avideo","remoteId":"GHSA-8pv3-29pp-pf8f","title":"WWBN AVideo has Stored XSS via Unanchored Duration Regex in Video Encoder Receiver","link":"https:\/\/github.com\/advisories\/GHSA-8pv3-29pp-pf8f","cve":"CVE-2026-41061","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 23:22:21","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8pv3-29pp-pf8f"}]},{"advisoryId":"PKSA-pt2z-fxr4-fvmc","packageName":"wwbn\/avideo","remoteId":"GHSA-m63r-m9jh-3vc6","title":"WWBN AVideo has an Incomplete fix: Directory traversal bypass via query string in ReceiveImage downloadURL parameters","link":"https:\/\/github.com\/advisories\/GHSA-m63r-m9jh-3vc6","cve":"CVE-2026-41062","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 23:23:14","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m63r-m9jh-3vc6"}]},{"advisoryId":"PKSA-gvmz-qdx4-njzh","packageName":"wwbn\/avideo","remoteId":"GHSA-m7r8-6q9j-m2hc","title":"WWBN AVideo has an incomplete fix for CVE-2026-33500: XSS","link":"https:\/\/github.com\/advisories\/GHSA-m7r8-6q9j-m2hc","cve":"CVE-2026-41063","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 23:25:28","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m7r8-6q9j-m2hc"}]},{"advisoryId":"PKSA-v7bq-jd15-qdrz","packageName":"wwbn\/avideo","remoteId":"GHSA-pq8p-wc4f-vg7j","title":"WWBN AVideo has an incomplete fix for CVE-2026-33502: Command Injection","link":"https:\/\/github.com\/advisories\/GHSA-pq8p-wc4f-vg7j","cve":"CVE-2026-41064","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 23:27:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pq8p-wc4f-vg7j"}]},{"advisoryId":"PKSA-nfcd-g6c3-5tff","packageName":"wwbn\/avideo","remoteId":"GHSA-vvfw-4m39-fjqf","title":"WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials","link":"https:\/\/github.com\/advisories\/GHSA-vvfw-4m39-fjqf","cve":"CVE-2026-40925","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 23:12:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vvfw-4m39-fjqf"}]},{"advisoryId":"PKSA-ttj4-18vr-tsp9","packageName":"wwbn\/avideo","remoteId":"GHSA-ffw8-fwxp-h64w","title":"WWBN AVideo has Multiple CSRF Vulnerabilities in Admin JSON Endpoints (Category CRUD, Plugin Update Script)","link":"https:\/\/github.com\/advisories\/GHSA-ffw8-fwxp-h64w","cve":"CVE-2026-40926","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 23:12:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-ffw8-fwxp-h64w"}]},{"advisoryId":"PKSA-k36z-m2m9-7f9w","packageName":"wwbn\/avideo","remoteId":"GHSA-x2pw-9c38-cp2j","title":"WWBN AVideo: Missing CSRF Protection on State-Changing JSON Endpoints Enables Forced Comment Creation, Vote Manipulation, and Category Asset Deletion","link":"https:\/\/github.com\/advisories\/GHSA-x2pw-9c38-cp2j","cve":"CVE-2026-40928","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 23:12:53","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x2pw-9c38-cp2j"}]},{"advisoryId":"PKSA-8nj2-vhcz-7bc5","packageName":"wwbn\/avideo","remoteId":"GHSA-8qm8-g55h-xmqr","title":"WWBN AVideo is missing CSRF protection in objects\/commentDelete.json.php enables mass comment deletion against moderators and content creators","link":"https:\/\/github.com\/advisories\/GHSA-8qm8-g55h-xmqr","cve":"CVE-2026-40929","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 23:13:08","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8qm8-g55h-xmqr"}]},{"advisoryId":"PKSA-k6wt-ck7m-8514","packageName":"wwbn\/avideo","remoteId":"GHSA-hg7g-56h5-5pqr","title":"CAPTCHA Bypass in WWBN\/AVideo via Attacker-Controlled Length Parameter and Missing Token Invalidation on Failure","link":"https:\/\/github.com\/advisories\/GHSA-hg7g-56h5-5pqr","cve":"CVE-2026-40935","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 23:13:21","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hg7g-56h5-5pqr"}]},{"advisoryId":"PKSA-zgmc-4215-ztzk","packageName":"wwbn\/avideo","remoteId":"GHSA-793q-xgj6-7frp","title":"WWBN AVideo has an incomplete fix for CVE-2026-33039: SSRF","link":"https:\/\/github.com\/advisories\/GHSA-793q-xgj6-7frp","cve":"CVE-2026-41055","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 23:15:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-793q-xgj6-7frp"}]},{"advisoryId":"PKSA-5c4b-gnfd-8xsq","packageName":"wwbn\/avideo","remoteId":"GHSA-ccq9-r5cw-5hwq","title":"WWBN AVideo has CORS Origin Reflection with Credentials on Sensitive API Endpoints Enables Cross-Origin Account Takeover","link":"https:\/\/github.com\/advisories\/GHSA-ccq9-r5cw-5hwq","cve":"CVE-2026-41056","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 23:18:19","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-ccq9-r5cw-5hwq"}]},{"advisoryId":"PKSA-tsyg-vszv-9tkz","packageName":"wwbn\/avideo","remoteId":"GHSA-ff5q-cc22-fgp4","title":"WWBN AVideo has a CORS Origin Reflection Bypass via plugin\/API\/router.php and allowOrigin(true) Exposes Authenticated API Responses","link":"https:\/\/github.com\/advisories\/GHSA-ff5q-cc22-fgp4","cve":"CVE-2026-41057","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 23:18:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-ff5q-cc22-fgp4"}]},{"advisoryId":"PKSA-zr2c-vrf1-x6qy","packageName":"wwbn\/avideo","remoteId":"GHSA-gph2-j4c9-vhhr","title":"WWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks","link":"https:\/\/github.com\/advisories\/GHSA-gph2-j4c9-vhhr","cve":"CVE-2026-40911","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 22:50:05","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-gph2-j4c9-vhhr"}]},{"advisoryId":"PKSA-2sy8-4q8b-cn2c","packageName":"wwbn\/avideo","remoteId":"GHSA-gpgp-w4x2-h3h7","title":"WWBN AVideo has an IDOR in Live Restreams list.json.php Exposes Other Users\u0027 Stream Keys and OAuth Tokens","link":"https:\/\/github.com\/advisories\/GHSA-gpgp-w4x2-h3h7","cve":"CVE-2026-40907","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 22:49:05","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gpgp-w4x2-h3h7"}]},{"advisoryId":"PKSA-yc9y-ydj1-h48d","packageName":"wwbn\/avideo","remoteId":"GHSA-52hf-63q4-r926","title":"WWBN AVideo has an Unauthenticated Information Disclosure via git.json.php Exposes Developer Emails and Deployed Version","link":"https:\/\/github.com\/advisories\/GHSA-52hf-63q4-r926","cve":"CVE-2026-40908","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 22:49:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-52hf-63q4-r926"}]},{"advisoryId":"PKSA-mbzn-myxk-vdz9","packageName":"wwbn\/avideo","remoteId":"GHSA-6rc6-p838-686f","title":"WWBN AVideo has a Path Traversal in Locale Save Endpoint Enables Arbitrary PHP File Write to Any Web-Accessible Directory (RCE)","link":"https:\/\/github.com\/advisories\/GHSA-6rc6-p838-686f","cve":"CVE-2026-40909","affectedVersions":"\u003C=29.0","source":"GitHub","reportedAt":"2026-04-14 22:49:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6rc6-p838-686f"}]},{"advisoryId":"PKSA-f178-s5q3-rpz6","packageName":"wwbn\/avideo","remoteId":"GHSA-687q-32c6-8x68","title":"AVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command Injection","link":"https:\/\/github.com\/advisories\/GHSA-687q-32c6-8x68","cve":"CVE-2026-33478","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-20 20:43:50","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-687q-32c6-8x68"}]},{"advisoryId":"PKSA-1dhf-r34w-p2f7","packageName":"wwbn\/avideo","remoteId":"GHSA-mmw7-wq3c-wf9p","title":"WWBN AVideo Affected by a PayPal IPN Replay Attack Enabling Wallet Balance Inflation via Missing Transaction Deduplication in ipn.php","link":"https:\/\/github.com\/advisories\/GHSA-mmw7-wq3c-wf9p","cve":"CVE-2026-39366","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-08 00:08:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mmw7-wq3c-wf9p"}]},{"advisoryId":"PKSA-zd55-pq2p-fmtz","packageName":"wwbn\/avideo","remoteId":"GHSA-rqp3-gf5h-mrqx","title":"WWBN AVideo has Stored XSS via Malicious EPG XML Program Titles in AVideo EPG Page","link":"https:\/\/github.com\/advisories\/GHSA-rqp3-gf5h-mrqx","cve":"CVE-2026-39367","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-08 00:08:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rqp3-gf5h-mrqx"}]},{"advisoryId":"PKSA-9dyr-jdcn-mr53","packageName":"wwbn\/avideo","remoteId":"GHSA-q4x6-6mm2-crg9","title":"WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal services","link":"https:\/\/github.com\/advisories\/GHSA-q4x6-6mm2-crg9","cve":"CVE-2026-39368","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-08 00:08:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q4x6-6mm2-crg9"}]},{"advisoryId":"PKSA-jrf5-73b5-1wm8","packageName":"wwbn\/avideo","remoteId":"GHSA-f4f9-627c-jh33","title":"WWBN AVideo\u0027s GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs","link":"https:\/\/github.com\/advisories\/GHSA-f4f9-627c-jh33","cve":"CVE-2026-39369","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-08 00:08:44","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f4f9-627c-jh33"}]},{"advisoryId":"PKSA-k95w-1pmg-ryfd","packageName":"wwbn\/avideo","remoteId":"GHSA-cmcr-q4jf-p6q9","title":"WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltration (Incomplete fix for CVE-2026-27732)","link":"https:\/\/github.com\/advisories\/GHSA-cmcr-q4jf-p6q9","cve":"CVE-2026-39370","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-08 00:08:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-cmcr-q4jf-p6q9"}]},{"advisoryId":"PKSA-v2fv-f7cj-pvmk","packageName":"wwbn\/avideo","remoteId":"GHSA-3v7m-qg4x-58h9","title":"AVideo: Unauthenticated Access to Payment Order Data via BlockonomicsYPT check.php","link":"https:\/\/github.com\/advisories\/GHSA-3v7m-qg4x-58h9","cve":"CVE-2026-35448","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-04 06:15:37","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-3v7m-qg4x-58h9"}]},{"advisoryId":"PKSA-8k5g-7b6v-dmzw","packageName":"wwbn\/avideo","remoteId":"GHSA-hg8q-8wqr-35xx","title":"AVideo: Unauthenticated Information Disclosure via Disabled CLI Guard in install\/test.php","link":"https:\/\/github.com\/advisories\/GHSA-hg8q-8wqr-35xx","cve":"CVE-2026-35449","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-04 06:16:18","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hg8q-8wqr-35xx"}]},{"advisoryId":"PKSA-yv5c-84v4-5kzs","packageName":"wwbn\/avideo","remoteId":"GHSA-2vg4-rrx4-qcpq","title":"AVideo: Unauthenticated FFmpeg Remote Server Status Disclosure via check.ffmpeg.json.php","link":"https:\/\/github.com\/advisories\/GHSA-2vg4-rrx4-qcpq","cve":"CVE-2026-35450","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-04 06:16:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2vg4-rrx4-qcpq"}]},{"advisoryId":"PKSA-8d75-pkrm-ryk2","packageName":"wwbn\/avideo","remoteId":"GHSA-99j6-hj87-6fcf","title":"AVideo: Unauthenticated Information Disclosure via Missing Auth on CloneSite client.log.php","link":"https:\/\/github.com\/advisories\/GHSA-99j6-hj87-6fcf","cve":"CVE-2026-35452","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-04 06:17:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-99j6-hj87-6fcf"}]},{"advisoryId":"PKSA-6czf-bc7p-h4k6","packageName":"wwbn\/avideo","remoteId":"GHSA-4q27-4rrq-fx95","title":"AVideo: CSRF on Player Skin Configuration via admin\/playerUpdate.json.php","link":"https:\/\/github.com\/advisories\/GHSA-4q27-4rrq-fx95","cve":"CVE-2026-35181","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-03 23:43:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4q27-4rrq-fx95"}]},{"advisoryId":"PKSA-9kdr-v9xz-q97d","packageName":"wwbn\/avideo","remoteId":"GHSA-x9w5-xccw-5h9w","title":"AVideo: Unauthenticated Instagram Graph API Proxy via publishInstagram.json.php","link":"https:\/\/github.com\/advisories\/GHSA-x9w5-xccw-5h9w","cve":"CVE-2026-35179","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-03 23:33:09","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x9w5-xccw-5h9w"}]},{"advisoryId":"PKSA-h129-dyyg-hqpq","packageName":"wwbn\/avideo","remoteId":"GHSA-gmpc-fxg2-vcmq","title":"AVideo has Stored XSS via Unescaped Menu Item Fields in TopMenu Plugin","link":"https:\/\/github.com\/advisories\/GHSA-gmpc-fxg2-vcmq","cve":null,"affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-01 23:25:11","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gmpc-fxg2-vcmq"}]},{"advisoryId":"PKSA-nbcf-22q2-3259","packageName":"wwbn\/avideo","remoteId":"GHSA-4jcg-jxpf-5vq3","title":"AVideo: Unauthenticated Live Stream Termination via RTMP Callback on_publish_done.php","link":"https:\/\/github.com\/advisories\/GHSA-4jcg-jxpf-5vq3","cve":"CVE-2026-34731","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-01 21:04:09","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4jcg-jxpf-5vq3"}]},{"advisoryId":"PKSA-mshg-1d1p-db19","packageName":"wwbn\/avideo","remoteId":"GHSA-g2mg-cgr6-vmv7","title":"AVideo: Missing Authentication in CreatePlugin list.json.php Template Affects 21 Endpoints","link":"https:\/\/github.com\/advisories\/GHSA-g2mg-cgr6-vmv7","cve":"CVE-2026-34732","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-01 21:05:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g2mg-cgr6-vmv7"}]},{"advisoryId":"PKSA-tjqt-v3v3-pg6b","packageName":"wwbn\/avideo","remoteId":"GHSA-wwpw-hrx8-79r5","title":"AVideo: Unauthenticated File Deletion via PHP Operator Precedence Bug in CLI Guard","link":"https:\/\/github.com\/advisories\/GHSA-wwpw-hrx8-79r5","cve":"CVE-2026-34733","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-01 21:06:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wwpw-hrx8-79r5"}]},{"advisoryId":"PKSA-jw1r-58j1-stm1","packageName":"wwbn\/avideo","remoteId":"GHSA-38rh-4v39-vfxv","title":"AVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscriptions() Bug","link":"https:\/\/github.com\/advisories\/GHSA-38rh-4v39-vfxv","cve":"CVE-2026-34737","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-01 21:06:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-38rh-4v39-vfxv"}]},{"advisoryId":"PKSA-4yg6-hdf3-cm7q","packageName":"wwbn\/avideo","remoteId":"GHSA-m577-w9j8-ch7j","title":"AVideo: Video Publishing Workflow Bypass via Unauthorized overrideStatus Request Parameter","link":"https:\/\/github.com\/advisories\/GHSA-m577-w9j8-ch7j","cve":"CVE-2026-34738","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-01 21:07:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m577-w9j8-ch7j"}]},{"advisoryId":"PKSA-trzy-nkyc-3bq1","packageName":"wwbn\/avideo","remoteId":"GHSA-jqrj-chh6-8h78","title":"AVideo: Reflected XSS via Unescaped ip Parameter in User_Location testIP.php","link":"https:\/\/github.com\/advisories\/GHSA-jqrj-chh6-8h78","cve":"CVE-2026-34739","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-01 21:08:14","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jqrj-chh6-8h78"}]},{"advisoryId":"PKSA-v4v4-994j-g46x","packageName":"wwbn\/avideo","remoteId":"GHSA-x5vx-vrpf-r45f","title":"AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation","link":"https:\/\/github.com\/advisories\/GHSA-x5vx-vrpf-r45f","cve":"CVE-2026-34740","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-01 21:08:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x5vx-vrpf-r45f"}]},{"advisoryId":"PKSA-bppj-bwtk-gjyq","packageName":"wwbn\/avideo","remoteId":"GHSA-hqxf-mhfw-rc44","title":"AVideo: CSRF on Plugin Enable\/Disable Endpoint Allows Disabling Security Plugins","link":"https:\/\/github.com\/advisories\/GHSA-hqxf-mhfw-rc44","cve":"CVE-2026-34613","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-01 20:54:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hqxf-mhfw-rc44"}]},{"advisoryId":"PKSA-nph7-q1m2-1jj5","packageName":"wwbn\/avideo","remoteId":"GHSA-w4hp-w536-jg64","title":"AVideo: DOM XSS via Unsanitized Display Name in WebSocket Call Notification","link":"https:\/\/github.com\/advisories\/GHSA-w4hp-w536-jg64","cve":"CVE-2026-34716","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-01 20:54:51","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w4hp-w536-jg64"}]},{"advisoryId":"PKSA-zmm3-dkmp-577r","packageName":"wwbn\/avideo","remoteId":"GHSA-c4xj-x7p8-3x7q","title":"AVideo: CSRF on emailAllUsers.json.php Enables Mass Phishing Email to All Users","link":"https:\/\/github.com\/advisories\/GHSA-c4xj-x7p8-3x7q","cve":"CVE-2026-34611","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-04-01 20:48:53","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c4xj-x7p8-3x7q"}]},{"advisoryId":"PKSA-9wd9-hqm1-g8vw","packageName":"wwbn\/avideo","remoteId":"GHSA-77jp-mgcw-rfmr","title":"AVideo vulnerable to Mass User PII Disclosure via Missing Authorization in YPTWallet users.json.php","link":"https:\/\/github.com\/advisories\/GHSA-77jp-mgcw-rfmr","cve":"CVE-2026-34395","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-31 23:21:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-77jp-mgcw-rfmr"}]},{"advisoryId":"PKSA-8d8v-tnwh-mvxd","packageName":"wwbn\/avideo","remoteId":"GHSA-v4h7-3x43-qqw4","title":"AVideo has Stored XSS via Unescaped Plugin Configuration Values in Admin Panel","link":"https:\/\/github.com\/advisories\/GHSA-v4h7-3x43-qqw4","cve":"CVE-2026-34396","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-31 23:22:21","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-v4h7-3x43-qqw4"}]},{"advisoryId":"PKSA-sgq7-y46w-x6wm","packageName":"wwbn\/avideo","remoteId":"GHSA-4wwr-7h7c-chqr","title":"AVideo\u0027s CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking","link":"https:\/\/github.com\/advisories\/GHSA-4wwr-7h7c-chqr","cve":"CVE-2026-34394","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-31 23:15:25","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4wwr-7h7c-chqr"}]},{"advisoryId":"PKSA-jgsk-3v13-mp5q","packageName":"wwbn\/avideo","remoteId":"GHSA-q6jj-r49p-94fh","title":"AVideo has Video Password Protection Bypass via API Endpoints Returning Full Playback Sources Without Password Verification","link":"https:\/\/github.com\/advisories\/GHSA-q6jj-r49p-94fh","cve":"CVE-2026-34369","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-30 18:03:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q6jj-r49p-94fh"}]},{"advisoryId":"PKSA-vp5k-2k3q-kh8x","packageName":"wwbn\/avideo","remoteId":"GHSA-pm37-62g7-p768","title":"AVideo Vulnerable to Reflected XSS via Unsanitized plugin Parameter in YPTWallet Stripe Payment Page","link":"https:\/\/github.com\/advisories\/GHSA-pm37-62g7-p768","cve":"CVE-2026-34375","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-30 18:08:52","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pm37-62g7-p768"}]},{"advisoryId":"PKSA-r7hg-81sr-ph3s","packageName":"wwbn\/avideo","remoteId":"GHSA-h54m-c522-h6qr","title":"AVideo Vulnerable to Wallet Balance Double-Spend via TOCTOU Race Condition in transferBalance","link":"https:\/\/github.com\/advisories\/GHSA-h54m-c522-h6qr","cve":"CVE-2026-34368","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-30 17:51:12","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h54m-c522-h6qr"}]},{"advisoryId":"PKSA-zrqg-465j-tm13","packageName":"wwbn\/avideo","remoteId":"GHSA-73gr-r64q-7jh4","title":"AVideo has User Group-Based Category Access Control Bypass via Missing and Broken Group Filtering in categories.json.php","link":"https:\/\/github.com\/advisories\/GHSA-73gr-r64q-7jh4","cve":"CVE-2026-34364","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-30 17:49:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-73gr-r64q-7jh4"}]},{"advisoryId":"PKSA-3yrj-j1ff-gsp4","packageName":"wwbn\/avideo","remoteId":"GHSA-2mg4-pfgx-64cf","title":"AVideo\u0027s WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket()","link":"https:\/\/github.com\/advisories\/GHSA-2mg4-pfgx-64cf","cve":"CVE-2026-34362","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-30 17:35:21","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2mg4-pfgx-64cf"}]},{"advisoryId":"PKSA-mhr2-p9hx-xy4j","packageName":"wwbn\/avideo","remoteId":"GHSA-wprj-9cvc-5w37","title":"AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records","link":"https:\/\/github.com\/advisories\/GHSA-wprj-9cvc-5w37","cve":null,"affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-29 15:40:52","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wprj-9cvc-5w37"}]},{"advisoryId":"PKSA-fw58-yv1p-mjjv","packageName":"wwbn\/avideo","remoteId":"GHSA-2rm7-j397-3fqg","title":"AVideo: Missing Authorization in Playlist Schedule Creation Allows Cross-User Broadcast Hijacking","link":"https:\/\/github.com\/advisories\/GHSA-2rm7-j397-3fqg","cve":"CVE-2026-34245","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-29 15:41:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2rm7-j397-3fqg"}]},{"advisoryId":"PKSA-6jcq-63hk-b922","packageName":"wwbn\/avideo","remoteId":"GHSA-g3hj-mf85-679g","title":"AVideo: IDOR in uploadPoster.php Allows Any Authenticated User to Overwrite Scheduled Live Stream Posters and Trigger False Socket Notifications","link":"https:\/\/github.com\/advisories\/GHSA-g3hj-mf85-679g","cve":"CVE-2026-34247","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-29 15:41:44","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g3hj-mf85-679g"}]},{"advisoryId":"PKSA-37q2-fmsd-htgf","packageName":"wwbn\/avideo","remoteId":"GHSA-f359-r3pv-2phf","title":"AVideo has SSRF Protection Bypass via HTTP Redirect in Image Download Endpoints","link":"https:\/\/github.com\/advisories\/GHSA-f359-r3pv-2phf","cve":"CVE-2026-33766","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-26 18:10:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f359-r3pv-2phf"}]},{"advisoryId":"PKSA-d7fp-yz92-57bz","packageName":"wwbn\/avideo","remoteId":"GHSA-fj74-qxj7-r3vc","title":"AVideo has SQL Injection via Partial Prepared Statement \u2014 videos_id Concatenated Directly into Query","link":"https:\/\/github.com\/advisories\/GHSA-fj74-qxj7-r3vc","cve":"CVE-2026-33767","affectedVersions":"\u003C26.0","source":"GitHub","reportedAt":"2026-03-26 18:12:33","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fj74-qxj7-r3vc"}]},{"advisoryId":"PKSA-d1c1-62x6-fsdv","packageName":"wwbn\/avideo","remoteId":"GHSA-584p-rpvq-35vf","title":"AVideo has SQL Injection in category.php fixCleanTitle() via Unparameterized clean_title and id Variables","link":"https:\/\/github.com\/advisories\/GHSA-584p-rpvq-35vf","cve":"CVE-2026-33770","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-26 18:15:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-584p-rpvq-35vf"}]},{"advisoryId":"PKSA-vcf8-yygk-smvm","packageName":"wwbn\/avideo","remoteId":"GHSA-363v-5rh8-23wg","title":"AVideo has Plaintext Video Password Storage","link":"https:\/\/github.com\/advisories\/GHSA-363v-5rh8-23wg","cve":"CVE-2026-33867","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-26 18:16:39","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-363v-5rh8-23wg"}]},{"advisoryId":"PKSA-kzzd-7tpm-2718","packageName":"wwbn\/avideo","remoteId":"GHSA-75qq-68m8-pvfr","title":"AVideo: Unauthenticated IDOR in playlistsVideos.json.php Exposes Private Playlist Contents","link":"https:\/\/github.com\/advisories\/GHSA-75qq-68m8-pvfr","cve":"CVE-2026-33759","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-26 18:05:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-75qq-68m8-pvfr"}]},{"advisoryId":"PKSA-t2zr-g4vs-n5nr","packageName":"wwbn\/avideo","remoteId":"GHSA-j724-5c6c-68g5","title":"AVideo: Unauthenticated Access to Scheduler Plugin Endpoints Leaks Scheduled Tasks, Email Content, and User Mappings","link":"https:\/\/github.com\/advisories\/GHSA-j724-5c6c-68g5","cve":"CVE-2026-33761","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-26 18:06:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j724-5c6c-68g5"}]},{"advisoryId":"PKSA-qmkf-gp88-ftk6","packageName":"wwbn\/avideo","remoteId":"GHSA-8prq-2jr2-cm92","title":"AVideo has an Unauthenticated Video Password Brute-Force Vulnerability via Unrate-Limited Boolean Oracle","link":"https:\/\/github.com\/advisories\/GHSA-8prq-2jr2-cm92","cve":"CVE-2026-33763","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-26 18:07:38","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8prq-2jr2-cm92"}]},{"advisoryId":"PKSA-ggc8-4vpf-v295","packageName":"wwbn\/avideo","remoteId":"GHSA-g39v-qrj6-jxrh","title":"AVideo: IDOR in AI Plugin Allows Stealing Other Users\u0027 AI-Generated Metadata and Transcriptions","link":"https:\/\/github.com\/advisories\/GHSA-g39v-qrj6-jxrh","cve":"CVE-2026-33764","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-26 18:08:12","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g39v-qrj6-jxrh"}]},{"advisoryId":"PKSA-nk6y-bx1m-kq7t","packageName":"wwbn\/avideo","remoteId":"GHSA-r64r-883r-wcwh","title":"AVideo: Unauthenticated CDN Configuration Takeover via Empty Default Key Bypass and Mass-Assignment","link":"https:\/\/github.com\/advisories\/GHSA-r64r-883r-wcwh","cve":"CVE-2026-33719","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-25 21:55:32","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r64r-883r-wcwh"}]},{"advisoryId":"PKSA-c9d6-fz2f-92mg","packageName":"wwbn\/avideo","remoteId":"GHSA-ffr8-fxhv-fv8h","title":"AVideo is Vulnerable to SQL Injection through Subscribe Endpoint via Unsanitized user_id Parameter","link":"https:\/\/github.com\/advisories\/GHSA-ffr8-fxhv-fv8h","cve":"CVE-2026-33723","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-25 21:56:12","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-ffr8-fxhv-fv8h"}]},{"advisoryId":"PKSA-7gff-yt7v-8bkx","packageName":"wwbn\/avideo","remoteId":"GHSA-9hv9-gvwm-95f2","title":"AVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.json.php","link":"https:\/\/github.com\/advisories\/GHSA-9hv9-gvwm-95f2","cve":"CVE-2026-33716","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-25 21:28:21","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-9hv9-gvwm-95f2"}]},{"advisoryId":"PKSA-xbpw-5md3-j3nz","packageName":"wwbn\/avideo","remoteId":"GHSA-8wf4-c4x3-h952","title":"AVideo: Remote Code Execution via PHP Temp File in Encoder downloadURL","link":"https:\/\/github.com\/advisories\/GHSA-8wf4-c4x3-h952","cve":"CVE-2026-33717","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-25 21:28:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8wf4-c4x3-h952"}]},{"advisoryId":"PKSA-9p99-sn38-6cwv","packageName":"wwbn\/avideo","remoteId":"GHSA-3hwv-x8g3-9qpr","title":"AVideo has Path Traversal in pluginRunDatabaseScript.json.php Enables Arbitrary SQL File Execution via Unsanitized Plugin Name","link":"https:\/\/github.com\/advisories\/GHSA-3hwv-x8g3-9qpr","cve":"CVE-2026-33681","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-25 19:51:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3hwv-x8g3-9qpr"}]},{"advisoryId":"PKSA-cx3j-v85y-y9tv","packageName":"wwbn\/avideo","remoteId":"GHSA-ghx5-7jjg-q2j7","title":"AVideo vulnerable to Stored XSS via html_entity_decode() Reversing xss_esc() Sanitization in Channel About Field","link":"https:\/\/github.com\/advisories\/GHSA-ghx5-7jjg-q2j7","cve":"CVE-2026-33683","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-25 19:52:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-ghx5-7jjg-q2j7"}]},{"advisoryId":"PKSA-rhxf-1yfy-x5fd","packageName":"wwbn\/avideo","remoteId":"GHSA-j36m-74g2-7m95","title":"AVideo Allows Unauthenticated Access to AD_Server reports.json.php that Exposes Ad Campaign Analytics and User Data","link":"https:\/\/github.com\/advisories\/GHSA-j36m-74g2-7m95","cve":"CVE-2026-33685","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-25 19:52:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j36m-74g2-7m95"}]},{"advisoryId":"PKSA-rmrd-1jny-519s","packageName":"wwbn\/avideo","remoteId":"GHSA-m99f-mmvg-3xmx","title":"AVideo has Pre-Captcha User Enumeration and Account Status Disclosure in Password Recovery Endpoint","link":"https:\/\/github.com\/advisories\/GHSA-m99f-mmvg-3xmx","cve":"CVE-2026-33688","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-25 19:53:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m99f-mmvg-3xmx"}]},{"advisoryId":"PKSA-6bhm-ppng-rh7j","packageName":"wwbn\/avideo","remoteId":"GHSA-wxjx-r2j2-96fx","title":"AVideo: Full-Read SSRF Through Unvalidated statsURL Parameter in plugin\/Live\/test.php","link":"https:\/\/github.com\/advisories\/GHSA-wxjx-r2j2-96fx","cve":null,"affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-25 19:53:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wxjx-r2j2-96fx"}]},{"advisoryId":"PKSA-x77f-z8vb-hbfr","packageName":"wwbn\/avideo","remoteId":"GHSA-8p2x-5cpm-qrqw","title":"AVideo vulnerable to IP Address Spoofing via Untrusted HTTP Headers in getRealIpAddr()","link":"https:\/\/github.com\/advisories\/GHSA-8p2x-5cpm-qrqw","cve":"CVE-2026-33690","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-25 19:54:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8p2x-5cpm-qrqw"}]},{"advisoryId":"PKSA-m663-qqs4-57t4","packageName":"wwbn\/avideo","remoteId":"GHSA-pvw4-p2jm-chjm","title":"AVideo has a Blind SQL Injection in Live Schedule Reminder via Unsanitized live_schedule_id in Scheduler_commands::getAllActiveOrToRepeat()","link":"https:\/\/github.com\/advisories\/GHSA-pvw4-p2jm-chjm","cve":"CVE-2026-33651","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-25 17:50:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pvw4-p2jm-chjm"}]},{"advisoryId":"PKSA-sv6m-nx8k-5kz3","packageName":"wwbn\/avideo","remoteId":"GHSA-wxjw-phj6-g75w","title":"AVideo Vulnerable to Remote Code Execution via MIME\/Extension Mismatch in ImageGallery File Upload","link":"https:\/\/github.com\/advisories\/GHSA-wxjw-phj6-g75w","cve":"CVE-2026-33647","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-25 17:45:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wxjw-phj6-g75w"}]},{"advisoryId":"PKSA-cpqv-3x62-47s6","packageName":"wwbn\/avideo","remoteId":"GHSA-5m4q-5cvx-36mw","title":"AVideo Vulnerable to OS Command Injection via Unsanitized `users_id` and `liveTransmitionHistory_id` in Restreamer Log File Path","link":"https:\/\/github.com\/advisories\/GHSA-5m4q-5cvx-36mw","cve":"CVE-2026-33648","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-25 17:47:21","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5m4q-5cvx-36mw"}]},{"advisoryId":"PKSA-nfgn-q1hy-xddr","packageName":"wwbn\/avideo","remoteId":"GHSA-g8x9-7mgh-7cvj","title":"AVideo\u0027s GET-Based CSRF in setPermission.json.php Enables Privilege Escalation via Arbitrary Permission Modification","link":"https:\/\/github.com\/advisories\/GHSA-g8x9-7mgh-7cvj","cve":"CVE-2026-33649","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-25 17:48:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g8x9-7mgh-7cvj"}]},{"advisoryId":"PKSA-kbvc-x3nh-bwr5","packageName":"wwbn\/avideo","remoteId":"GHSA-8x77-f38v-4m5j","title":"AVideo: Video Moderator Privilege Escalation via Ownership Transfer Enables Arbitrary Video Deletion","link":"https:\/\/github.com\/advisories\/GHSA-8x77-f38v-4m5j","cve":"CVE-2026-33650","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-25 17:49:32","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8x77-f38v-4m5j"}]},{"advisoryId":"PKSA-stv4-sw5c-pp7h","packageName":"wwbn\/avideo","remoteId":"GHSA-mwjc-5j4x-r686","title":"AVideo has an unauthenticated decrypt oracle leaking any ciphertext","link":"https:\/\/github.com\/advisories\/GHSA-mwjc-5j4x-r686","cve":"CVE-2026-33512","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-20 21:55:12","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mwjc-5j4x-r686"}]},{"advisoryId":"PKSA-2x5y-pg7k-8jx1","packageName":"wwbn\/avideo","remoteId":"GHSA-8fw8-q79c-fp9m","title":"AVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP)","link":"https:\/\/github.com\/advisories\/GHSA-8fw8-q79c-fp9m","cve":"CVE-2026-33513","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-20 21:55:31","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8fw8-q79c-fp9m"}]},{"advisoryId":"PKSA-9rhr-hzp4-skcj","packageName":"wwbn\/avideo","remoteId":"GHSA-hv36-p4w4-6vmj","title":"AVideo Affected by CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Execution via Malicious Plugin Upload","link":"https:\/\/github.com\/advisories\/GHSA-hv36-p4w4-6vmj","cve":"CVE-2026-33507","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-20 21:47:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hv36-p4w4-6vmj"}]},{"advisoryId":"PKSA-g9zg-y2pv-yf4q","packageName":"wwbn\/avideo","remoteId":"GHSA-7292-w8qp-mhq2","title":"AVideo has Reflected XSS via unlockPassword Parameter in forbiddenPage.php and warningPage.php","link":"https:\/\/github.com\/advisories\/GHSA-7292-w8qp-mhq2","cve":"CVE-2026-33499","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-20 20:56:38","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7292-w8qp-mhq2"}]},{"advisoryId":"PKSA-fjmv-8jwk-wtsg","packageName":"wwbn\/avideo","remoteId":"GHSA-72h5-39r7-r26j","title":"AVideo - Incomplete Fix for CVE-2026-27568: Stored XSS via Markdown `javascript:` URI Bypasses ParsedownSafeWithLinks Sanitization","link":"https:\/\/github.com\/advisories\/GHSA-72h5-39r7-r26j","cve":"CVE-2026-33500","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-20 20:56:52","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-72h5-39r7-r26j"}]},{"advisoryId":"PKSA-93k3-9zdh-zky7","packageName":"wwbn\/avideo","remoteId":"GHSA-96qp-8cmq-jvq8","title":"AVideo has Unauthenticated Information Disclosure of User Group Permission Mappings via Permissions Plugin","link":"https:\/\/github.com\/advisories\/GHSA-96qp-8cmq-jvq8","cve":"CVE-2026-33501","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-20 20:57:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-96qp-8cmq-jvq8"}]},{"advisoryId":"PKSA-734r-s438-vkf3","packageName":"wwbn\/avideo","remoteId":"GHSA-3fpm-8rjr-v5mc","title":"AVideo has Unauthenticated SSRF via plugin\/Live\/test.php","link":"https:\/\/github.com\/advisories\/GHSA-3fpm-8rjr-v5mc","cve":"CVE-2026-33502","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-20 20:57:56","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-3fpm-8rjr-v5mc"}]},{"advisoryId":"PKSA-4kfk-t6qg-77z2","packageName":"wwbn\/avideo","remoteId":"GHSA-xggw-g9pm-9qhh","title":"AVideo has PHP Code Injection via eval() in Gallery saveSort.json.php Exploitable Through CSRF Against Admin","link":"https:\/\/github.com\/advisories\/GHSA-xggw-g9pm-9qhh","cve":"CVE-2026-33479","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-20 20:44:02","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xggw-g9pm-9qhh"}]},{"advisoryId":"PKSA-8d9c-5xxm-8vns","packageName":"wwbn\/avideo","remoteId":"GHSA-p3gr-g84w-g8hh","title":"AVideo has a SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses in Unauthenticated LiveLinks Proxy","link":"https:\/\/github.com\/advisories\/GHSA-p3gr-g84w-g8hh","cve":"CVE-2026-33480","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-20 20:44:10","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-p3gr-g84w-g8hh"}]},{"advisoryId":"PKSA-tp22-rjkg-27h5","packageName":"wwbn\/avideo","remoteId":"GHSA-pmj8-r2j7-xg6c","title":"AVideo has an OS Command Injection via $() Shell Substitution Bypass in sanitizeFFmpegCommand()","link":"https:\/\/github.com\/advisories\/GHSA-pmj8-r2j7-xg6c","cve":"CVE-2026-33482","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-20 20:46:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pmj8-r2j7-xg6c"}]},{"advisoryId":"PKSA-f4gx-6t2c-nrd6","packageName":"wwbn\/avideo","remoteId":"GHSA-vv7w-qf5c-734w","title":"AVideo Affected by Unauthenticated Disk Space Exhaustion via Unlimited Temp File Creation in aVideoEncoderChunk.json.php","link":"https:\/\/github.com\/advisories\/GHSA-vv7w-qf5c-734w","cve":"CVE-2026-33483","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-20 20:46:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vv7w-qf5c-734w"}]},{"advisoryId":"PKSA-v7r8-5fwd-x92z","packageName":"wwbn\/avideo","remoteId":"GHSA-8p58-35c3-ccxx","title":"AVideo has an Unauthenticated Blind SQL Injection in RTMP on_publish Callback via Stream Name Parameter","link":"https:\/\/github.com\/advisories\/GHSA-8p58-35c3-ccxx","cve":"CVE-2026-33485","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-20 20:47:19","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8p58-35c3-ccxx"}]},{"advisoryId":"PKSA-qjdg-5npg-72ng","packageName":"wwbn\/avideo","remoteId":"GHSA-6m5f-j7w2-w953","title":"AVideo has a PGP 2FA Bypass via Cryptographically Broken 512-bit RSA Key Generation in LoginControl Plugin","link":"https:\/\/github.com\/advisories\/GHSA-6m5f-j7w2-w953","cve":"CVE-2026-33488","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-20 20:49:06","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6m5f-j7w2-w953"}]},{"advisoryId":"PKSA-3ybr-q6r1-fnzm","packageName":"wwbn\/avideo","remoteId":"GHSA-x3pr-vrhq-vq43","title":"AVideo has Session Fixation via GET PHPSESSID Parameter With Disabled Login Session Regeneration","link":"https:\/\/github.com\/advisories\/GHSA-x3pr-vrhq-vq43","cve":"CVE-2026-33492","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-20 20:49:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-x3pr-vrhq-vq43"}]},{"advisoryId":"PKSA-28kd-gd4j-w94p","packageName":"wwbn\/avideo","remoteId":"GHSA-83xq-8jxj-4rxm","title":"AVideo has a Path Traversal in import.json.php Allows Private Video Theft and Arbitrary File Read\/Deletion via fileURI Parameter","link":"https:\/\/github.com\/advisories\/GHSA-83xq-8jxj-4rxm","cve":"CVE-2026-33493","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-20 20:49:36","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-83xq-8jxj-4rxm"}]},{"advisoryId":"PKSA-6mc5-gbk2-4jkz","packageName":"wwbn\/avideo","remoteId":"GHSA-4jw9-5hrc-m4j6","title":"AVideo has an authenticated arbitrary local file read via `chunkFile` path injection in `aVideoEncoder.json.php`","link":"https:\/\/github.com\/advisories\/GHSA-4jw9-5hrc-m4j6","cve":"CVE-2026-33354","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-19 19:34:06","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4jw9-5hrc-m4j6"}]},{"advisoryId":"PKSA-zqc4-q9ns-kq82","packageName":"wwbn\/avideo","remoteId":"GHSA-mcj5-6qr4-95fj","title":"AVideo has an Unauthenticated SQL Injection via `doNotShowCats` Parameter (Backslash Escape Bypass)","link":"https:\/\/github.com\/advisories\/GHSA-mcj5-6qr4-95fj","cve":"CVE-2026-33352","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-19 19:25:53","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-mcj5-6qr4-95fj"}]},{"advisoryId":"PKSA-kz4k-1fdq-4jkn","packageName":"wwbn\/avideo","remoteId":"GHSA-5f7v-4f6g-74rj","title":"AVideo has Unauthenticated SSRF via `webSiteRootURL` Parameter in saveDVR.json.php, Chaining to Verification Bypass","link":"https:\/\/github.com\/advisories\/GHSA-5f7v-4f6g-74rj","cve":"CVE-2026-33351","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-19 19:13:26","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-5f7v-4f6g-74rj"}]},{"advisoryId":"PKSA-yh5p-7324-8k1n","packageName":"wwbn\/avideo","remoteId":"GHSA-hj5h-5623-gwhw","title":"AVideo has an Open Redirect via Unvalidated redirectUri in userLogin.php","link":"https:\/\/github.com\/advisories\/GHSA-hj5h-5623-gwhw","cve":"CVE-2026-33296","affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-19 17:25:28","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-hj5h-5623-gwhw"}]},{"advisoryId":"PKSA-qms8-qf5t-6w9q","packageName":"wwbn\/avideo","remoteId":"GHSA-6547-8hrg-c55m","title":"AVideo: IDOR - Any Admin Can Set Another User\u0027s Channel Password via setPassword.json.php","link":"https:\/\/github.com\/advisories\/GHSA-6547-8hrg-c55m","cve":"CVE-2026-33297","affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-19 17:25:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6547-8hrg-c55m"}]},{"advisoryId":"PKSA-61gg-79td-yp6m","packageName":"wwbn\/avideo","remoteId":"GHSA-xmjm-86qv-g226","title":"AVideo Affected by Arbitrary File Deletion via Path Traversal in CloneSite deleteDump Parameter","link":"https:\/\/github.com\/advisories\/GHSA-xmjm-86qv-g226","cve":"CVE-2026-33293","affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-19 17:12:04","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xmjm-86qv-g226"}]},{"advisoryId":"PKSA-69wq-d8c2-6qbn","packageName":"wwbn\/avideo","remoteId":"GHSA-66cw-h2mj-j39p","title":"AVideo Affected by SSRF in BulkEmbed Thumbnail Fetch Allows Reading Internal Network Resources","link":"https:\/\/github.com\/advisories\/GHSA-66cw-h2mj-j39p","cve":"CVE-2026-33294","affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-19 17:12:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-66cw-h2mj-j39p"}]},{"advisoryId":"PKSA-7zcq-fgdd-9176","packageName":"wwbn\/avideo","remoteId":"GHSA-gc3m-4mcr-h3pv","title":"AVideo Affected by Stored XSS via Unescaped Video Title in CDN downloadButtons.php","link":"https:\/\/github.com\/advisories\/GHSA-gc3m-4mcr-h3pv","cve":"CVE-2026-33295","affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-19 17:12:19","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gc3m-4mcr-h3pv"}]},{"advisoryId":"PKSA-ht27-8rcs-t939","packageName":"wwbn\/avideo","remoteId":"GHSA-pw4v-x838-w5pg","title":"AVideo has an Authorization Bypass via Path Traversal in HLS Endpoint Allows Streaming Private\/Paid Videos","link":"https:\/\/github.com\/advisories\/GHSA-pw4v-x838-w5pg","cve":"CVE-2026-33292","affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-19 16:43:03","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pw4v-x838-w5pg"}]},{"advisoryId":"PKSA-1msk-y5kh-hb4p","packageName":"wwbn\/avideo","remoteId":"GHSA-v467-g7g7-hhfh","title":"AVideo has SSRF in Scheduler Plugin via callbackURL Missing `isSSRFSafeURL()` Validation","link":"https:\/\/github.com\/advisories\/GHSA-v467-g7g7-hhfh","cve":"CVE-2026-33237","affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-19 12:43:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-v467-g7g7-hhfh"}]},{"advisoryId":"PKSA-484r-cdwt-2gm4","packageName":"wwbn\/avideo","remoteId":"GHSA-4wmm-6qxj-fpj4","title":"AVideo has a Path Traversal in listFiles.json.php Enables Server Filesystem Enumeration","link":"https:\/\/github.com\/advisories\/GHSA-4wmm-6qxj-fpj4","cve":"CVE-2026-33238","affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-19 12:43:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4wmm-6qxj-fpj4"}]},{"advisoryId":"PKSA-5drt-2yg3-m4bb","packageName":"wwbn\/avideo","remoteId":"GHSA-w5ff-2mjc-4phc","title":"AVideo has an OS Command Injection via Unescaped URL in LinkedIn Video Upload Shell Command","link":"https:\/\/github.com\/advisories\/GHSA-w5ff-2mjc-4phc","cve":"CVE-2026-33319","affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-19 12:45:38","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w5ff-2mjc-4phc"}]},{"advisoryId":"PKSA-3whn-q4tm-bwhh","packageName":"wwbn\/avideo","remoteId":"GHSA-5x2w-37xf-7962","title":"AVideo has Unauthenticated PGP Message Decryption via Public Endpoint","link":"https:\/\/github.com\/advisories\/GHSA-5x2w-37xf-7962","cve":null,"affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-19 12:46:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5x2w-37xf-7962"}]},{"advisoryId":"PKSA-spwc-tcr7-cpby","packageName":"wwbn\/avideo","remoteId":"GHSA-9x67-f2v7-63rw","title":"AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy","link":"https:\/\/github.com\/advisories\/GHSA-9x67-f2v7-63rw","cve":"CVE-2026-33039","affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-17 20:33:06","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9x67-f2v7-63rw"}]},{"advisoryId":"PKSA-qj1g-pbwp-h996","packageName":"wwbn\/avideo","remoteId":"GHSA-wfq5-qgqp-hvhv","title":"Unauthenticated Reflected XSS via innerHTML in AVideo","link":"https:\/\/github.com\/advisories\/GHSA-wfq5-qgqp-hvhv","cve":"CVE-2026-33035","affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-17 20:05:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wfq5-qgqp-hvhv"}]},{"advisoryId":"PKSA-pcdx-pg9p-v4gz","packageName":"wwbn\/avideo","remoteId":"GHSA-qc3p-398r-p59j","title":"AVideo affected by Session Hijacking via Unauthenticated Session ID Disclosure with Permissive CORS","link":"https:\/\/github.com\/advisories\/GHSA-qc3p-398r-p59j","cve":"CVE-2026-33043","affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-17 19:52:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qc3p-398r-p59j"}]},{"advisoryId":"PKSA-3jbs-pwhv-9v32","packageName":"wwbn\/avideo","remoteId":"GHSA-2f9h-23f7-8gcx","title":"AVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deployments","link":"https:\/\/github.com\/advisories\/GHSA-2f9h-23f7-8gcx","cve":"CVE-2026-33038","affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-17 19:46:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2f9h-23f7-8gcx"}]},{"advisoryId":"PKSA-v5mg-73g8-w2x4","packageName":"wwbn\/avideo","remoteId":"GHSA-px7x-gq96-rmp5","title":"AVideo has an Unauthenticated Password Hash Oracle via encryptPass.json.php","link":"https:\/\/github.com\/advisories\/GHSA-px7x-gq96-rmp5","cve":"CVE-2026-33041","affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-17 19:48:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-px7x-gq96-rmp5"}]},{"advisoryId":"PKSA-prng-jvqx-4vkt","packageName":"wwbn\/avideo","remoteId":"GHSA-6w2r-cfpc-23r5","title":"AVideo has Unauthenticated IDOR - Playlist Information Disclosure","link":"https:\/\/github.com\/advisories\/GHSA-6w2r-cfpc-23r5","cve":"CVE-2026-30885","affectedVersions":"\u003C25.0","source":"GitHub","reportedAt":"2026-03-07 02:25:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6w2r-cfpc-23r5"}]},{"advisoryId":"PKSA-876z-dgrg-zwqs","packageName":"wwbn\/avideo","remoteId":"GHSA-xxpw-32hf-q8v9","title":"AVideo: Unauthenticated PHP session store exposed to host network via published memcached port","link":"https:\/\/github.com\/advisories\/GHSA-xxpw-32hf-q8v9","cve":"CVE-2026-29093","affectedVersions":"\u003C=21.0","source":"GitHub","reportedAt":"2026-03-05 01:22:21","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xxpw-32hf-q8v9"}]},{"advisoryId":"PKSA-jc43-whmg-bn3y","packageName":"wwbn\/avideo","remoteId":"GHSA-9j26-99jh-v26q","title":"WWBN AVideo is vulnerable to unauthenticated OS Command Injection via base64Url in objects\/getImage.php","link":"https:\/\/github.com\/advisories\/GHSA-9j26-99jh-v26q","cve":"CVE-2026-29058","affectedVersions":"\u003C7.0.0","source":"GitHub","reportedAt":"2026-03-03 20:02:40","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-9j26-99jh-v26q"}]},{"advisoryId":"PKSA-p5zb-45dv-s5gy","packageName":"wwbn\/avideo","remoteId":"GHSA-v8jw-8w5p-23g3","title":"AVideo has Authenticated Remote Code Execution via Unsafe Plugin ZIP Extraction","link":"https:\/\/github.com\/advisories\/GHSA-v8jw-8w5p-23g3","cve":"CVE-2026-28502","affectedVersions":"\u003C21.0","source":"GitHub","reportedAt":"2026-03-02 20:56:52","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-v8jw-8w5p-23g3"}]},{"advisoryId":"PKSA-xtjn-tvnf-r8sj","packageName":"wwbn\/avideo","remoteId":"GHSA-pv87-r9qf-x56p","title":"AVideo has Unauthenticated SQL Injection via JSON Request Bypass in objects\/videos.json.php","link":"https:\/\/github.com\/advisories\/GHSA-pv87-r9qf-x56p","cve":"CVE-2026-28501","affectedVersions":"\u003C=21.0.0","source":"GitHub","reportedAt":"2026-03-02 20:49:43","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-pv87-r9qf-x56p"}]},{"advisoryId":"PKSA-mpqq-rw7h-r6qr","packageName":"wwbn\/avideo","remoteId":"GHSA-h39h-7cvg-q7j6","title":"AVideo has Authenticated Server-Side Request Forgery via downloadURL in aVideoEncoder.json.php","link":"https:\/\/github.com\/advisories\/GHSA-h39h-7cvg-q7j6","cve":"CVE-2026-27732","affectedVersions":"\u003C=21.0.0","source":"GitHub","reportedAt":"2026-02-25 18:57:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h39h-7cvg-q7j6"}]},{"advisoryId":"PKSA-zj1v-1r3y-vnpg","packageName":"wwbn\/avideo","remoteId":"GHSA-rcqw-6466-3mv7","title":"AVideo has Stored Cross-Site Scripting via Markdown Comment Injection","link":"https:\/\/github.com\/advisories\/GHSA-rcqw-6466-3mv7","cve":"CVE-2026-27568","affectedVersions":"\u003C21.0","source":"GitHub","reportedAt":"2026-02-20 21:15:06","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rcqw-6466-3mv7"}]}],"starcitizenwiki\/embedvideo":[{"advisoryId":"PKSA-wg3k-7dyt-r1n5","packageName":"starcitizenwiki\/embedvideo","remoteId":"GHSA-5c7p-g73q-rpg5","title":"StarCitizenWiki Extension Embed Video: Stored XSS via malformed src url with $wgEmbedVideoRequireConsent enabled","link":"https:\/\/github.com\/advisories\/GHSA-5c7p-g73q-rpg5","cve":"CVE-2026-55692","affectedVersions":"\u003C=4.0.0","source":"GitHub","reportedAt":"2026-06-19 21:41:57","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5c7p-g73q-rpg5"}]},{"advisoryId":"PKSA-bvqp-6135-khxc","packageName":"starcitizenwiki\/embedvideo","remoteId":"GHSA-c29q-5xm7-5p62","title":"StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized service name in exception text","link":"https:\/\/github.com\/advisories\/GHSA-c29q-5xm7-5p62","cve":"CVE-2026-55690","affectedVersions":"\u003C=4.0.0","source":"GitHub","reportedAt":"2026-06-19 21:14:15","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c29q-5xm7-5p62"}]},{"advisoryId":"PKSA-17vj-28c7-d53v","packageName":"starcitizenwiki\/embedvideo","remoteId":"GHSA-7h5p-637f-jfr7","title":"StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized class passed to template","link":"https:\/\/github.com\/advisories\/GHSA-7h5p-637f-jfr7","cve":"CVE-2026-55691","affectedVersions":"\u003C=4.0.0","source":"GitHub","reportedAt":"2026-06-19 21:15:03","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7h5p-637f-jfr7"}]}],"craftcms\/commerce":[{"advisoryId":"PKSA-3cyb-p9z9-9j9r","packageName":"craftcms\/commerce","remoteId":"GHSA-78vr-q6cf-c7p6","title":"Craft Commerce: Partial Payment Amount Without Lower Bound Validation","link":"https:\/\/github.com\/advisories\/GHSA-78vr-q6cf-c7p6","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C=4.11.1|\u003E=5.0.0,\u003C=5.6.4","source":"GitHub","reportedAt":"2026-06-19 21:15:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-78vr-q6cf-c7p6"}]},{"advisoryId":"PKSA-8pd1-kqxv-12wq","packageName":"craftcms\/commerce","remoteId":"GHSA-h5gm-x9wr-vhcm","title":"Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass","link":"https:\/\/github.com\/advisories\/GHSA-h5gm-x9wr-vhcm","cve":"CVE-2026-55795","affectedVersions":"\u003E=4.0.0,\u003C=4.11.1|\u003E=5.0.0,\u003C=5.6.4","source":"GitHub","reportedAt":"2026-06-19 21:15:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h5gm-x9wr-vhcm"}]},{"advisoryId":"PKSA-tnb8-k5sw-yxmk","packageName":"craftcms\/commerce","remoteId":"GHSA-3vxg-x5f8-f5qf","title":"Craft Commerce has an unauthenticated information disclosure that can leak some customer order data on anonymous payments","link":"https:\/\/github.com\/advisories\/GHSA-3vxg-x5f8-f5qf","cve":"CVE-2026-32270","affectedVersions":"\u003E=4.0.0,\u003C=4.10.2|\u003E=5.0.0,\u003C=5.5.4","source":"GitHub","reportedAt":"2026-04-14 01:01:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-3vxg-x5f8-f5qf"}]},{"advisoryId":"PKSA-nhg1-858f-sgm2","packageName":"craftcms\/commerce","remoteId":"GHSA-r54v-qq87-px5r","title":"Craft Commerce hasVariant\/hasProduct Blind SQL Injection","link":"https:\/\/github.com\/advisories\/GHSA-r54v-qq87-px5r","cve":"CVE-2026-32272","affectedVersions":"\u003E=5.0.0,\u003C5.6.0","source":"GitHub","reportedAt":"2026-04-14 00:06:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r54v-qq87-px5r"}]},{"advisoryId":"PKSA-chpm-5f12-rdnt","packageName":"craftcms\/commerce","remoteId":"GHSA-875v-7m49-8x88","title":"Craft Commerce has a SQL Injection can lead to Remote Code Execution via TotalRevenue Widget","link":"https:\/\/github.com\/advisories\/GHSA-875v-7m49-8x88","cve":"CVE-2026-32271","affectedVersions":"\u003E=5.0.0,\u003C=5.5.4|\u003E=4.0.0,\u003C=4.10.2","source":"GitHub","reportedAt":"2026-04-14 00:07:34","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-875v-7m49-8x88"}]},{"advisoryId":"PKSA-hf29-t8gq-x1bd","packageName":"craftcms\/commerce","remoteId":"GHSA-j3x5-mghf-xvfw","title":"Craft Commerce is Vulnerable to SQL Injection in Commerce Purchasables Table Sorting","link":"https:\/\/github.com\/advisories\/GHSA-j3x5-mghf-xvfw","cve":"CVE-2026-29172","affectedVersions":"\u003E=5.0.0,\u003C=5.5.2|\u003E=4.0.0,\u003C=4.10.1","source":"GitHub","reportedAt":"2026-03-10 18:23:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j3x5-mghf-xvfw"}]},{"advisoryId":"PKSA-7wm1-vvyh-k91c","packageName":"craftcms\/commerce","remoteId":"GHSA-mqxf-2998-c6cp","title":"Craft Commerce is Vulnerable to Stored XSS while updating Order Status from Orders Table","link":"https:\/\/github.com\/advisories\/GHSA-mqxf-2998-c6cp","cve":"CVE-2026-29173","affectedVersions":"\u003E=5.0.0,\u003C=5.5.2|\u003E=4.0.0,\u003C=4.10.1","source":"GitHub","reportedAt":"2026-03-10 18:23:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-mqxf-2998-c6cp"}]},{"advisoryId":"PKSA-5vsf-cyf4-k2zs","packageName":"craftcms\/commerce","remoteId":"GHSA-pmgj-gmm4-jh6j","title":"Craft Commerce is vulnerable to SQL Injection in Commerce Inventory Table Sorting","link":"https:\/\/github.com\/advisories\/GHSA-pmgj-gmm4-jh6j","cve":"CVE-2026-29174","affectedVersions":"\u003E=5.0.0,\u003C=5.5.2","source":"GitHub","reportedAt":"2026-03-10 18:23:25","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pmgj-gmm4-jh6j"}]},{"advisoryId":"PKSA-c2f2-bw98-42sz","packageName":"craftcms\/commerce","remoteId":"GHSA-cfpv-rmpf-f624","title":"Craft Commerce has multiple Stored XSS in Commerce Inventory Page, Leading to Session Hijacking","link":"https:\/\/github.com\/advisories\/GHSA-cfpv-rmpf-f624","cve":"CVE-2026-29175","affectedVersions":"\u003E=5.0.0,\u003C=5.5.2","source":"GitHub","reportedAt":"2026-03-10 18:23:42","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-cfpv-rmpf-f624"}]},{"advisoryId":"PKSA-9385-f9kj-gpgr","packageName":"craftcms\/commerce","remoteId":"GHSA-wj89-2385-gpx3","title":"Craft Commerce has stored XSS in Inventory Location Name","link":"https:\/\/github.com\/advisories\/GHSA-wj89-2385-gpx3","cve":"CVE-2026-29176","affectedVersions":"\u003E=5.0.0,\u003C=5.5.2","source":"GitHub","reportedAt":"2026-03-10 18:23:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wj89-2385-gpx3"}]},{"advisoryId":"PKSA-q6pp-5z96-2bd2","packageName":"craftcms\/commerce","remoteId":"GHSA-mj32-r678-7mvp","title":"Craft Commerce has stored XSS in Craft Commerce Order Details Slideout","link":"https:\/\/github.com\/advisories\/GHSA-mj32-r678-7mvp","cve":"CVE-2026-29177","affectedVersions":"\u003E=5.0.0,\u003C=5.5.2|\u003E=4.0.0,\u003C=4.10.1","source":"GitHub","reportedAt":"2026-03-10 18:24:18","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-mj32-r678-7mvp"}]},{"advisoryId":"PKSA-c2xz-ckr6-6mky","packageName":"craftcms\/commerce","remoteId":"GHSA-vff3-pqq8-4cpq","title":"Craft Commerce: Potential IDOR in Commerce carts","link":"https:\/\/github.com\/advisories\/GHSA-vff3-pqq8-4cpq","cve":"CVE-2026-31867","affectedVersions":"\u003E=4.0.0,\u003C4.11.0|\u003E=5.0.0,\u003C5.6.0","source":"GitHub","reportedAt":"2026-03-10 18:24:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vff3-pqq8-4cpq"}]},{"advisoryId":"PKSA-xfj6-h72k-yknr","packageName":"craftcms\/commerce","remoteId":"GHSA-v585-mf6r-rqrc","title":"Craft Commerce has Stored XSS in Tax Zones (Name \u0026 Description) Leading to Potential Privilege Escalation","link":"https:\/\/github.com\/advisories\/GHSA-v585-mf6r-rqrc","cve":"CVE-2026-25489","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.10.0|\u003E=5.0.0-RC1,\u003C=5.5.1","source":"GitHub","reportedAt":"2026-02-02 23:00:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-v585-mf6r-rqrc"}]},{"advisoryId":"PKSA-nrcm-7whq-x868","packageName":"craftcms\/commerce","remoteId":"GHSA-wq2m-r96q-crrf","title":" Craft Commerce has Stored XSS in Inventory Location Address Leading to Potential Privilege Escalation","link":"https:\/\/github.com\/advisories\/GHSA-wq2m-r96q-crrf","cve":"CVE-2026-25490","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.10.0|\u003E=5.0.0-RC1,\u003C=5.5.1","source":"GitHub","reportedAt":"2026-02-02 23:02:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wq2m-r96q-crrf"}]},{"advisoryId":"PKSA-y1rc-ctkn-mgyg","packageName":"craftcms\/commerce","remoteId":"GHSA-h9r9-2pxg-cx9m","title":"Craft Commerce has Stored XSS in Shipping Zone (Name \u0026 Description) Fields Leading to Potential Privilege Escalation","link":"https:\/\/github.com\/advisories\/GHSA-h9r9-2pxg-cx9m","cve":"CVE-2026-25522","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.10.0|\u003E=5.0.0-RC1,\u003C=5.5.1","source":"GitHub","reportedAt":"2026-02-02 23:04:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h9r9-2pxg-cx9m"}]},{"advisoryId":"PKSA-twkq-s65v-3zph","packageName":"craftcms\/commerce","remoteId":"GHSA-wqc5-485v-3hqh","title":"Craft CMS has Stored XSS in Tax Rates Name Leading to Potential Privilege Escalation","link":"https:\/\/github.com\/advisories\/GHSA-wqc5-485v-3hqh","cve":"CVE-2026-25487","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.10.0|\u003E=5.0.0-RC1,\u003C=5.5.1","source":"GitHub","reportedAt":"2026-02-02 22:51:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wqc5-485v-3hqh"}]},{"advisoryId":"PKSA-gnb2-rr3g-hcdr","packageName":"craftcms\/commerce","remoteId":"GHSA-p6w8-q63m-72c8","title":"Craft Commerce has Stored XSS in Tax Categories (Name \u0026 Description) Fields Leading to Potential Privilege Escalation","link":"https:\/\/github.com\/advisories\/GHSA-p6w8-q63m-72c8","cve":"CVE-2026-25488","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.10.0|\u003E=5.0.0-RC1,\u003C=5.5.1","source":"GitHub","reportedAt":"2026-02-02 22:51:51","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-p6w8-q63m-72c8"}]},{"advisoryId":"PKSA-m4r9-k8fn-t8bm","packageName":"craftcms\/commerce","remoteId":"GHSA-frj9-9rwc-pw9j","title":"Craft Commerce has Stored DOM XSS in Order Status Name (Reflects in \u0022Recent Orders\u0022 Dashboard Widget)","link":"https:\/\/github.com\/advisories\/GHSA-frj9-9rwc-pw9j","cve":"CVE-2026-25482","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.10.0|\u003E=5.0.0,\u003C=5.5.1","source":"GitHub","reportedAt":"2026-02-02 22:41:44","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-frj9-9rwc-pw9j"}]},{"advisoryId":"PKSA-6px2-ht8s-n19h","packageName":"craftcms\/commerce","remoteId":"GHSA-8478-rmjg-mjj5","title":"Craft Commerce has Stored XSS via Order Status Message with potential database exfiltration","link":"https:\/\/github.com\/advisories\/GHSA-8478-rmjg-mjj5","cve":"CVE-2026-25483","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.10.0|\u003E=5.0.0,\u003C=5.5.1","source":"GitHub","reportedAt":"2026-02-02 22:43:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8478-rmjg-mjj5"}]},{"advisoryId":"PKSA-tjsq-jr27-yxgb","packageName":"craftcms\/commerce","remoteId":"GHSA-2h2m-v2mg-656c","title":"Craft Commerce has Stored XSS in Product Type Name","link":"https:\/\/github.com\/advisories\/GHSA-2h2m-v2mg-656c","cve":"CVE-2026-25484","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.10.0|\u003E=5.0.0,\u003C=5.5.1","source":"GitHub","reportedAt":"2026-02-02 22:44:05","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2h2m-v2mg-656c"}]},{"advisoryId":"PKSA-vyym-2rg1-mr68","packageName":"craftcms\/commerce","remoteId":"GHSA-g92v-wpv7-6w22","title":"Craft Commerce has Stored XSS in Shipping Methods Name Field Leading to Potential Privilege Escalation","link":"https:\/\/github.com\/advisories\/GHSA-g92v-wpv7-6w22","cve":"CVE-2026-25486","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.5.1","source":"GitHub","reportedAt":"2026-02-02 22:49:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g92v-wpv7-6w22"}]}],"cotonti\/cotonti":[{"advisoryId":"PKSA-cy3k-vcz8-1k97","packageName":"cotonti\/cotonti","remoteId":"GHSA-hp3v-wp32-953h","title":"Cotonti:  Cross-Site Request Forgery in the Personal File Storage (PFS) module","link":"https:\/\/github.com\/advisories\/GHSA-hp3v-wp32-953h","cve":"CVE-2026-55745","affectedVersions":"\u003C=1.0.0","source":"GitHub","reportedAt":"2026-06-18 12:40:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hp3v-wp32-953h"}]},{"advisoryId":"PKSA-sv92-d57h-xntt","packageName":"cotonti\/cotonti","remoteId":"GHSA-7g3p-35vc-mgjr","title":"Cotonti: Cross-Site Request Forgery in the administration rights handler","link":"https:\/\/github.com\/advisories\/GHSA-7g3p-35vc-mgjr","cve":"CVE-2026-55742","affectedVersions":"\u003C=1.0.0","source":"GitHub","reportedAt":"2026-06-18 12:40:25","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-7g3p-35vc-mgjr"}]},{"advisoryId":"PKSA-4kh8-r3m8-hxqy","packageName":"cotonti\/cotonti","remoteId":"GHSA-86hp-hf3j-3m8r","title":"Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module","link":"https:\/\/github.com\/advisories\/GHSA-86hp-hf3j-3m8r","cve":"CVE-2026-55746","affectedVersions":"\u003C=1.0.0","source":"GitHub","reportedAt":"2026-06-18 12:40:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-86hp-hf3j-3m8r"}]},{"advisoryId":"PKSA-5cx6-4jyf-9qk9","packageName":"cotonti\/cotonti","remoteId":"GHSA-wx35-cv59-9gwr","title":"Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module","link":"https:\/\/github.com\/advisories\/GHSA-wx35-cv59-9gwr","cve":"CVE-2026-55744","affectedVersions":"\u003C=1.0.0","source":"GitHub","reportedAt":"2026-06-18 12:40:25","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wx35-cv59-9gwr"}]}],"pimcore\/pimcore":[{"advisoryId":"PKSA-6dhb-gq75-qpgr","packageName":"pimcore\/pimcore","remoteId":"GHSA-7p36-fq2r-4h7r","title":"Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed","link":"https:\/\/github.com\/advisories\/GHSA-7p36-fq2r-4h7r","cve":"CVE-2026-11407","affectedVersions":"\u003C=12.3.8","source":"GitHub","reportedAt":"2026-06-17 21:34:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7p36-fq2r-4h7r"}]},{"advisoryId":"PKSA-vd5r-2gyh-m6cc","packageName":"pimcore\/pimcore","remoteId":"GHSA-jwcc-gv4m-93x6","title":"Pimcore has a CustomReports Share Bypass","link":"https:\/\/github.com\/advisories\/GHSA-jwcc-gv4m-93x6","cve":"CVE-2026-45704","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.2|\u003C=11.5.16|\u003E=12.0.0-RC1,\u003C=12.3.5","source":"GitHub","reportedAt":"2026-05-27 22:34:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jwcc-gv4m-93x6"}]},{"advisoryId":"PKSA-v5bg-33q7-q8zj","packageName":"pimcore\/pimcore","remoteId":"GHSA-332x-r494-54fq","title":"Pimcore has a WordExport Authorization Bypass for Unauthorized Document Export","link":"https:\/\/github.com\/advisories\/GHSA-332x-r494-54fq","cve":"CVE-2026-45703","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.3|\u003C=11.5.16|\u003E=12.0.0-RC1,\u003C=12.3.6","source":"GitHub","reportedAt":"2026-05-27 22:27:18","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-332x-r494-54fq"}]},{"advisoryId":"PKSA-y4yc-6g1b-qfqz","packageName":"pimcore\/pimcore","remoteId":"GHSA-wc7j-g8wx-m2qx","title":"Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling","link":"https:\/\/github.com\/advisories\/GHSA-wc7j-g8wx-m2qx","cve":"CVE-2026-45260","affectedVersions":"\u003C=11.5.16|\u003E=2026.1.0,\u003C2026.1.3|\u003E=12.0.0-RC1,\u003C=12.3.6","source":"GitHub","reportedAt":"2026-05-27 17:17:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wc7j-g8wx-m2qx"}]},{"advisoryId":"PKSA-882j-k212-wjbf","packageName":"pimcore\/pimcore","remoteId":"GHSA-36fc-7wjg-mfvj","title":"Pimcore has Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction","link":"https:\/\/github.com\/advisories\/GHSA-36fc-7wjg-mfvj","cve":"CVE-2026-45162","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.3|\u003C=11.5.16|\u003E=12.0.0-RC1,\u003C=12.3.6","source":"GitHub","reportedAt":"2026-05-27 16:57:04","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-36fc-7wjg-mfvj"}]},{"advisoryId":"PKSA-kp19-xmdp-rvyj","packageName":"pimcore\/pimcore","remoteId":"GHSA-3234-gxc3-pq6f","title":"Pimcore Vulnerable to SQL Injection in Custom Reports Column Configuration","link":"https:\/\/github.com\/advisories\/GHSA-3234-gxc3-pq6f","cve":"CVE-2026-44739","affectedVersions":"\u003E=12.0.0-RC1,\u003C=12.3.5|\u003C=11.5.16|\u003E=2026.1.0,\u003C2026.1.2","source":"GitHub","reportedAt":"2026-05-27 00:35:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3234-gxc3-pq6f"}]},{"advisoryId":"PKSA-m2yg-zp8k-8hxj","packageName":"pimcore\/pimcore","remoteId":"GHSA-7gxw-q9j5-mrj4","title":"Pimcore has an authenticated Cross-site Scripting issue","link":"https:\/\/github.com\/advisories\/GHSA-7gxw-q9j5-mrj4","cve":"CVE-2026-5362","affectedVersions":"=12.3.3","source":"GitHub","reportedAt":"2026-04-27 21:31:03","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7gxw-q9j5-mrj4"}]},{"advisoryId":"PKSA-vp19-ydt7-tws9","packageName":"pimcore\/pimcore","remoteId":"GHSA-r2f4-ff2p-xc64","title":"Pimcore Platform - SQL Injection in DataObject composite index handling during class definition import\/save","link":"https:\/\/github.com\/advisories\/GHSA-r2f4-ff2p-xc64","cve":"CVE-2026-5394","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.3|\u003C=11.5.16|\u003E=12.0.0-RC1,\u003C=12.3.6","source":"GitHub","reportedAt":"2026-05-28 20:47:10","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r2f4-ff2p-xc64"}]},{"advisoryId":"PKSA-8x4n-f9v2-4s1d","packageName":"pimcore\/pimcore","remoteId":"GHSA-vxg3-v4p6-f3fp","title":"Pimcore vulnerable to SQL injection via unsanitized filter value in Dependency Dao RLIKE clause","link":"https:\/\/github.com\/advisories\/GHSA-vxg3-v4p6-f3fp","cve":"CVE-2026-27461","affectedVersions":"\u003E=12.0.0,\u003C12.3.3|\u003C=11.5.14.1","source":"GitHub","reportedAt":"2026-02-24 20:03:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vxg3-v4p6-f3fp"}]},{"advisoryId":"PKSA-9ss4-dj21-s7vh","packageName":"pimcore\/pimcore","remoteId":"GHSA-q433-j342-rp9h","title":"Pimcore ENV Variables and Cookie Informations are exposed in http_error_log","link":"https:\/\/github.com\/advisories\/GHSA-q433-j342-rp9h","cve":"CVE-2026-23493","affectedVersions":"\u003C=11.5.13|\u003E=12.0.0-RC1,\u003C=12.3","source":"GitHub","reportedAt":"2026-01-15 18:11:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-q433-j342-rp9h"}]},{"advisoryId":"PKSA-88th-p7sv-k9g4","packageName":"pimcore\/pimcore","remoteId":"GHSA-m3r2-724c-pwgf","title":"Pimcore is Vulnerable to Broken Access Control: Missing Function Level Authorization on \u0022Static Routes\u0022 Listing","link":"https:\/\/github.com\/advisories\/GHSA-m3r2-724c-pwgf","cve":"CVE-2026-23494","affectedVersions":"\u003C=11.5.13|\u003E=12.0.0-RC1,\u003C=12.3","source":"GitHub","reportedAt":"2026-01-15 18:12:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m3r2-724c-pwgf"}]},{"advisoryId":"PKSA-hpvp-zv9c-rrr4","packageName":"pimcore\/pimcore","remoteId":"GHSA-qvr7-7g55-69xj","title":"Pimcore Has an Incomplete Patch for CVE-2023-30848","link":"https:\/\/github.com\/advisories\/GHSA-qvr7-7g55-69xj","cve":"CVE-2026-23492","affectedVersions":"\u003C=11.5.13|\u003E=12.0.0-RC1,\u003C12.3.1","source":"GitHub","reportedAt":"2026-01-14 21:15:43","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qvr7-7g55-69xj"}]},{"advisoryId":"PKSA-1njj-d9p2-mxd2","packageName":"pimcore\/pimcore","remoteId":"GHSA-xr3m-6gq6-22cg","title":"Pimcore Authenticated Stored Cross-Site Scripting (XSS) Via Search Document","link":"https:\/\/github.com\/advisories\/GHSA-xr3m-6gq6-22cg","cve":"CVE-2024-11954","affectedVersions":"\u003E=11.4.2,\u003C11.5.3","source":"GitHub","reportedAt":"2025-01-28 19:12:44","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xr3m-6gq6-22cg"}]},{"advisoryId":"PKSA-7prq-96rv-5y6n","packageName":"pimcore\/pimcore","remoteId":"GHSA-h9vc-2p9g-63gp","title":"Cross-site Scripting in pimcore","link":"https:\/\/github.com\/advisories\/GHSA-h9vc-2p9g-63gp","cve":"CVE-2022-0565","affectedVersions":"\u003C10.3.1","source":"GitHub","reportedAt":"2022-02-15 00:02:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h9vc-2p9g-63gp"}]}],"guzzlehttp\/psr7":[{"advisoryId":"PKSA-7qs6-zvnz-h66r","packageName":"guzzlehttp\/psr7","remoteId":"guzzlehttp\/psr7\/CVE-2026-55766.yaml","title":"CRLF injection in HTTP start-line serialization","link":"https:\/\/github.com\/guzzle\/psr7\/security\/advisories\/GHSA-vm85-hxw5-5432","cve":"CVE-2026-55766","affectedVersions":"\u003C2.12.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-18 09:49:37","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vm85-hxw5-5432"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/psr7\/CVE-2026-55766.yaml"}]},{"advisoryId":"PKSA-gm5x-j3mz-71n9","packageName":"guzzlehttp\/psr7","remoteId":"guzzlehttp\/psr7\/CVE-2026-49214.yaml","title":"CRLF injection via URI host component","link":"https:\/\/github.com\/guzzle\/psr7\/security\/advisories\/GHSA-hq7v-mx3g-29hw","cve":"CVE-2026-49214","affectedVersions":"\u003C2.10.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-25 22:58:15","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hq7v-mx3g-29hw"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/psr7\/CVE-2026-49214.yaml"}]},{"advisoryId":"PKSA-jj5t-2zs1-dcfm","packageName":"guzzlehttp\/psr7","remoteId":"guzzlehttp\/psr7\/CVE-2026-48998.yaml","title":"Host confusion via authority reinterpretation","link":"https:\/\/github.com\/guzzle\/psr7\/security\/advisories\/GHSA-34xg-wgjx-8xph","cve":"CVE-2026-48998","affectedVersions":"\u003C2.10.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-25 22:58:15","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-34xg-wgjx-8xph"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/psr7\/CVE-2026-48998.yaml"}]},{"advisoryId":"PKSA-hn62-zkx4-1y5q","packageName":"guzzlehttp\/psr7","remoteId":"guzzlehttp\/psr7\/CVE-2023-29197.yaml","title":"Improper header validation","link":"https:\/\/github.com\/guzzle\/psr7\/security\/advisories\/GHSA-wxmh-65f7-jcvw","cve":"CVE-2023-29197","affectedVersions":"\u003E=2,\u003C2.4.5|\u003C1.9.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2023-04-17 16:00:37","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wxmh-65f7-jcvw"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/psr7\/CVE-2023-29197.yaml"}]},{"advisoryId":"PKSA-gvzg-s447-b5b5","packageName":"guzzlehttp\/psr7","remoteId":"guzzlehttp\/psr7\/CVE-2022-24775.yaml","title":"Inproper parsing of HTTP headers","link":"https:\/\/github.com\/guzzle\/psr7\/security\/advisories\/GHSA-q7rv-6hp3-vh96","cve":"CVE-2022-24775","affectedVersions":"\u003E=2,\u003C2.1.1|\u003C1.8.4","source":"FriendsOfPHP\/security-advisories","reportedAt":"2022-03-20 13:44:44","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q7rv-6hp3-vh96"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/psr7\/CVE-2022-24775.yaml"}]}],"guzzlehttp\/guzzle":[{"advisoryId":"PKSA-93qv-9n9h-6k6p","packageName":"guzzlehttp\/guzzle","remoteId":"guzzlehttp\/guzzle\/CVE-2026-55767.yaml","title":"Dot-only cookie domains match all hosts","link":"https:\/\/github.com\/guzzle\/guzzle\/security\/advisories\/GHSA-cwxw-98qj-8qjx","cve":"CVE-2026-55767","affectedVersions":"\u003C7.12.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-18 14:12:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cwxw-98qj-8qjx"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle\/CVE-2026-55767.yaml"}]},{"advisoryId":"PKSA-k22t-f949-t9g6","packageName":"guzzlehttp\/guzzle","remoteId":"guzzlehttp\/guzzle\/CVE-2026-55568.yaml","title":"Silent HTTPS proxy downgrade to cleartext","link":"https:\/\/github.com\/guzzle\/guzzle\/security\/advisories\/GHSA-wpwq-4j6v-78m3","cve":"CVE-2026-55568","affectedVersions":"\u003C7.12.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-18 14:12:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wpwq-4j6v-78m3"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle\/CVE-2026-55568.yaml"}]},{"advisoryId":"PKSA-yfw5-9gnj-n2c7","packageName":"guzzlehttp\/guzzle","remoteId":"guzzlehttp\/guzzle\/CVE-2022-31091.yaml","title":"Change in port should be considered a change in origin","link":"https:\/\/github.com\/guzzle\/guzzle\/security\/advisories\/GHSA-q559-8m2m-g699","cve":"CVE-2022-31091","affectedVersions":"\u003E=7,\u003C7.4.5|\u003E=4,\u003C6.5.8","source":"FriendsOfPHP\/security-advisories","reportedAt":"2022-06-20 22:16:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-q559-8m2m-g699"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle\/CVE-2022-31091.yaml"}]},{"advisoryId":"PKSA-k1b4-kshy-xgbh","packageName":"guzzlehttp\/guzzle","remoteId":"guzzlehttp\/guzzle\/CVE-2022-31090.yaml","title":"CURLOPT_HTTPAUTH option not cleared on change of origin","link":"https:\/\/github.com\/guzzle\/guzzle\/security\/advisories\/GHSA-25mq-v84q-4j7r","cve":"CVE-2022-31090","affectedVersions":"\u003E=7,\u003C7.4.5|\u003E=4,\u003C6.5.8","source":"FriendsOfPHP\/security-advisories","reportedAt":"2022-06-20 22:16:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-25mq-v84q-4j7r"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle\/CVE-2022-31090.yaml"}]},{"advisoryId":"PKSA-2z36-j4q9-rsfy","packageName":"guzzlehttp\/guzzle","remoteId":"guzzlehttp\/guzzle\/CVE-2022-31043.yaml","title":"Fix failure to strip Authorization header on HTTP downgrade","link":"https:\/\/github.com\/guzzle\/guzzle\/security\/advisories\/GHSA-w248-ffj2-4v5q","cve":"CVE-2022-31043","affectedVersions":"\u003E=7,\u003C7.4.4|\u003E=4,\u003C6.5.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2022-06-09 21:36:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w248-ffj2-4v5q"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle\/CVE-2022-31043.yaml"}]},{"advisoryId":"PKSA-fvw5-9t6n-nwvr","packageName":"guzzlehttp\/guzzle","remoteId":"guzzlehttp\/guzzle\/CVE-2022-31042.yaml","title":"Failure to strip the Cookie header on change in host or HTTP downgrade","link":"https:\/\/github.com\/guzzle\/guzzle\/security\/advisories\/GHSA-f2wf-25xc-69c9","cve":"CVE-2022-31042","affectedVersions":"\u003E=7,\u003C7.4.4|\u003E=4,\u003C6.5.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2022-06-09 21:36:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f2wf-25xc-69c9"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle\/CVE-2022-31042.yaml"}]},{"advisoryId":"PKSA-6d8m-6kgw-18zr","packageName":"guzzlehttp\/guzzle","remoteId":"guzzlehttp\/guzzle\/CVE-2022-29248.yaml","title":"Cross-domain cookie leakage","link":"https:\/\/github.com\/guzzle\/guzzle\/security\/advisories\/GHSA-cwmx-hcrq-mhc3","cve":"CVE-2022-29248","affectedVersions":"\u003E=7,\u003C7.4.3|\u003E=4,\u003C6.5.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2022-05-25 13:19:12","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-cwmx-hcrq-mhc3"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle\/CVE-2022-29248.yaml"}]},{"advisoryId":"PKSA-stmn-hvzq-wph6","packageName":"guzzlehttp\/guzzle","remoteId":"guzzlehttp\/guzzle\/CVE-2016-5385.yaml","title":"HTTP Proxy header vulnerability","link":"https:\/\/github.com\/guzzle\/guzzle\/releases\/tag\/6.2.1","cve":"CVE-2016-5385","affectedVersions":"\u003E=6,\u003C6.2.1|\u003E=4.0.0-rc2,\u003C4.2.4|\u003E=5,\u003C5.3.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2016-07-15 17:44:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-m6ch-gg5f-wxx3"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle\/CVE-2016-5385.yaml"}]}],"jleehr\/canto-saas-api":[{"advisoryId":"PKSA-j2jj-8zzq-m6yn","packageName":"jleehr\/canto-saas-api","remoteId":"GHSA-9qfv-wgh2-m6p8","title":"canto-saas-api: Authenticated API requests can be redirected via unencoded path variables","link":"https:\/\/github.com\/advisories\/GHSA-9qfv-wgh2-m6p8","cve":"CVE-2026-55374","affectedVersions":"\u003C=2.0.0","source":"GitHub","reportedAt":"2026-06-19 14:13:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9qfv-wgh2-m6p8"}]},{"advisoryId":"PKSA-cgpk-zpcz-kxmr","packageName":"jleehr\/canto-saas-api","remoteId":"GHSA-37pm-83g7-r22v","title":"canto-saas-api: OAuth credentials exposed in URL query string and exception messages","link":"https:\/\/github.com\/advisories\/GHSA-37pm-83g7-r22v","cve":"CVE-2026-55375","affectedVersions":"\u003C=2.0.0","source":"GitHub","reportedAt":"2026-06-19 14:16:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-37pm-83g7-r22v"}]}],"symfony\/ux-icons":[{"advisoryId":"PKSA-2rqz-j593-s85p","packageName":"symfony\/ux-icons","remoteId":"symfony\/ux-icons\/CVE-2026-55877.yaml","title":"symfony\/ux-icons XSS via unsanitized SVG content in local files and Iconify on-demand responses","link":"https:\/\/github.com\/symfony\/ux\/security\/advisories\/GHSA-6v8j-33hc-mv84","cve":"CVE-2026-55877","affectedVersions":"\u003E=2.17.0,\u003C2.36.1|\u003E=3.0.0,\u003C3.2.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-19 07:21:19","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6v8j-33hc-mv84"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/ux-icons\/CVE-2026-55877.yaml"}]}],"symfony\/ux-toolkit":[{"advisoryId":"PKSA-hmn2-9g3k-g9mr","packageName":"symfony\/ux-toolkit","remoteId":"symfony\/ux-toolkit\/CVE-2026-55878.yaml","title":"symfony\/ux-toolkit Path Traversal allows arbitrary file write and read via crafted recipe manifest","link":"https:\/\/github.com\/symfony\/ux\/security\/advisories\/GHSA-p9xj-fpr2-jf2q","cve":"CVE-2026-55878","affectedVersions":"\u003E=2.32.0,\u003C2.36.1|\u003E=3.0.0,\u003C3.2.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-19 07:21:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-p9xj-fpr2-jf2q"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/ux-toolkit\/CVE-2026-55878.yaml"}]}],"phpbb\/phpbb":[{"advisoryId":"PKSA-k9cm-sh3f-xrxt","packageName":"phpbb\/phpbb","remoteId":"GHSA-7gm6-w7mx-58cr","title":"phpBB has Password Reset Link Poisoning via Host Header injection","link":"https:\/\/github.com\/advisories\/GHSA-7gm6-w7mx-58cr","cve":"CVE-2026-29199","affectedVersions":"=4.0.0-a1|\u003E=3.0.0,\u003C3.3.16","source":"GitHub","reportedAt":"2026-05-04 09:31:09","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7gm6-w7mx-58cr"}]}],"drupal\/core":[{"advisoryId":"PKSA-h76q-q9b2-4kdc","packageName":"drupal\/core","remoteId":"GHSA-ghwc-95x2-682j","title":"Drupal Core has a SQL Injection issue","link":"https:\/\/github.com\/advisories\/GHSA-ghwc-95x2-682j","cve":"CVE-2026-9082","affectedVersions":"\u003E=11.3.0,\u003C11.3.10|\u003E=11.2.0,\u003C11.2.12|\u003E=11.0.0,\u003C11.1.10|\u003E=10.6.0,\u003C10.6.9|\u003E=10.5.0,\u003C10.5.10|\u003E=8.9.0,\u003C10.4.10","source":"GitHub","reportedAt":"2026-05-20 21:31:32","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-ghwc-95x2-682j"}]},{"advisoryId":"PKSA-787q-p7fn-mcw7","packageName":"drupal\/core","remoteId":"GHSA-pw6f-3999-xp7g","title":"Drupal core allows Cross-Site Scripting (XSS)","link":"https:\/\/github.com\/advisories\/GHSA-pw6f-3999-xp7g","cve":"CVE-2026-6367","affectedVersions":"\u003E=11.3.0,\u003C11.3.7","source":"GitHub","reportedAt":"2026-05-20 00:31:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pw6f-3999-xp7g"}]},{"advisoryId":"PKSA-7kyj-yy4m-jzhv","packageName":"drupal\/core","remoteId":"GHSA-f3cj-mjqm-fhvj","title":"Drupal core is Vulnerable to Cross-Site Scripting","link":"https:\/\/github.com\/advisories\/GHSA-f3cj-mjqm-fhvj","cve":"CVE-2026-6365","affectedVersions":"\u003E=11.3.0,\u003C11.3.7|\u003E=11.0.0,\u003C11.2.11|\u003E=10.6.0,\u003C10.6.7|\u003E=8.0.0,\u003C10.5.9","source":"GitHub","reportedAt":"2026-05-20 00:31:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f3cj-mjqm-fhvj"}]},{"advisoryId":"PKSA-j351-xv4b-pryh","packageName":"drupal\/core","remoteId":"GHSA-xmjc-63pr-2mpg","title":"Drupal core allows Object Injection","link":"https:\/\/github.com\/advisories\/GHSA-xmjc-63pr-2mpg","cve":"CVE-2026-6366","affectedVersions":"\u003E=11.3.0,\u003C11.3.7|\u003E=11.0.0,\u003C11.2.11|\u003E=10.6.0,\u003C10.6.7|\u003E=8.0.0,\u003C10.5.9","source":"GitHub","reportedAt":"2026-05-20 00:31:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xmjc-63pr-2mpg"}]},{"advisoryId":"PKSA-d8tb-wwz2-ctxk","packageName":"drupal\/core","remoteId":"GHSA-mhpg-hpj5-73r2","title":"Drupal core allows Exploiting Incorrectly Configured Access Control Security Levels","link":"https:\/\/github.com\/advisories\/GHSA-mhpg-hpj5-73r2","cve":"CVE-2025-13083","affectedVersions":"\u003E=7.0,\u003C7.103|\u003E=11.2.0,\u003C11.2.8|\u003E=11.0.0,\u003C11.1.9|\u003E=10.5.0,\u003C10.5.6|\u003E=8.0.0,\u003C10.4.9","source":"GitHub","reportedAt":"2025-11-18 18:32:53","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-mhpg-hpj5-73r2"}]},{"advisoryId":"PKSA-dh1f-zjm5-qg8y","packageName":"drupal\/core","remoteId":"GHSA-h89p-5896-f4q8","title":"Drupal core allows Content Spoofing","link":"https:\/\/github.com\/advisories\/GHSA-h89p-5896-f4q8","cve":"CVE-2025-13082","affectedVersions":"\u003E=11.2.0,\u003C11.2.8|\u003E=11.0.0,\u003C11.1.9|\u003E=10.5.0,\u003C10.5.6|\u003E=8.0.0,\u003C10.4.9","source":"GitHub","reportedAt":"2025-11-18 18:32:53","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-h89p-5896-f4q8"}]},{"advisoryId":"PKSA-bn52-vyzy-rmnm","packageName":"drupal\/core","remoteId":"GHSA-83v7-c2cf-p9c2","title":"Drupal core allows Forceful Browsing","link":"https:\/\/github.com\/advisories\/GHSA-83v7-c2cf-p9c2","cve":"CVE-2025-13080","affectedVersions":"\u003E=11.2.0,\u003C11.2.8|\u003E=11.0.0,\u003C11.1.9|\u003E=10.5.0,\u003C10.5.6|\u003E=8.0.0,\u003C10.4.9","source":"GitHub","reportedAt":"2025-11-18 18:32:53","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-83v7-c2cf-p9c2"}]},{"advisoryId":"PKSA-xj83-g6g8-41vf","packageName":"drupal\/core","remoteId":"GHSA-m6vv-vcj8-w8m7","title":"Drupal core allows Object Injection","link":"https:\/\/github.com\/advisories\/GHSA-m6vv-vcj8-w8m7","cve":"CVE-2025-13081","affectedVersions":"\u003E=11.2.0,\u003C11.2.8|\u003E=11.0.0,\u003C11.1.9|\u003E=10.5.0,\u003C10.5.6|\u003E=8.0.0,\u003C10.4.9","source":"GitHub","reportedAt":"2025-11-18 18:32:53","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m6vv-vcj8-w8m7"}]}],"getkirby\/cms":[{"advisoryId":"PKSA-4ys7-5twb-r3bn","packageName":"getkirby\/cms","remoteId":"GHSA-23q2-54qv-rq5x","title":"Kirby: `pages.access` permission is not checked in the pages picker for parent pages","link":"https:\/\/github.com\/advisories\/GHSA-23q2-54qv-rq5x","cve":"CVE-2026-49274","affectedVersions":"\u003E=5.0.0-alpha.1,\u003C=5.4.3|\u003C=4.9.3","source":"GitHub","reportedAt":"2026-06-18 15:04:14","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-23q2-54qv-rq5x"}]},{"advisoryId":"PKSA-hnr2-vddk-p4gy","packageName":"getkirby\/cms","remoteId":"GHSA-rhj6-r49h-5932","title":"Kirby: Self cross-site scripting (self-XSS) in the writer field","link":"https:\/\/github.com\/advisories\/GHSA-rhj6-r49h-5932","cve":"CVE-2026-49276","affectedVersions":"\u003E=5.0.0-alpha.1,\u003C=5.4.3|\u003C=4.9.3","source":"GitHub","reportedAt":"2026-06-18 15:04:41","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-rhj6-r49h-5932"}]},{"advisoryId":"PKSA-k11s-611y-v46q","packageName":"getkirby\/cms","remoteId":"GHSA-4v4h-m2qq-ppgw","title":"Kirby: Request header injection in `Http\\Remote`","link":"https:\/\/github.com\/advisories\/GHSA-4v4h-m2qq-ppgw","cve":"CVE-2026-50188","affectedVersions":"\u003E=5.0.0-alpha.1,\u003C=5.4.3|\u003C=4.9.3","source":"GitHub","reportedAt":"2026-06-18 15:04:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4v4h-m2qq-ppgw"}]},{"advisoryId":"PKSA-wps5-gfv8-mm6f","packageName":"getkirby\/cms","remoteId":"GHSA-wr9h-4r83-f4v6","title":"Kirby: Cross-site scripting (XSS) from incomplete HTML\/XML sanitization in `Dom::sanitize()`","link":"https:\/\/github.com\/advisories\/GHSA-wr9h-4r83-f4v6","cve":"CVE-2026-54002","affectedVersions":"\u003E=5.0.0-alpha.1,\u003C=5.4.3|\u003C=4.9.3","source":"GitHub","reportedAt":"2026-06-18 15:04:52","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wr9h-4r83-f4v6"}]},{"advisoryId":"PKSA-h8zr-vfb5-1d5r","packageName":"getkirby\/cms","remoteId":"GHSA-whxw-24jc-cwmv","title":"Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header","link":"https:\/\/github.com\/advisories\/GHSA-whxw-24jc-cwmv","cve":"CVE-2026-54003","affectedVersions":"\u003E=5.0.0-alpha.1,\u003C=5.4.3|\u003C=4.9.3","source":"GitHub","reportedAt":"2026-06-18 15:04:57","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-whxw-24jc-cwmv"}]},{"advisoryId":"PKSA-6sq2-11dh-hkdq","packageName":"getkirby\/cms","remoteId":"GHSA-89cp-7p28-jffg","title":"Kirby: Access to files of top-level drafts is not protected by permissions","link":"https:\/\/github.com\/advisories\/GHSA-89cp-7p28-jffg","cve":"CVE-2026-54004","affectedVersions":"\u003E=5.0.0-alpha.1,\u003C=5.4.3|\u003C=4.9.3","source":"GitHub","reportedAt":"2026-06-18 15:05:05","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-89cp-7p28-jffg"}]},{"advisoryId":"PKSA-jpkc-34xj-4vfy","packageName":"getkirby\/cms","remoteId":"GHSA-r3w8-2c5r-h9j9","title":"Kirby: `pages.access` permission is not checked in the `site\/find` REST API route","link":"https:\/\/github.com\/advisories\/GHSA-r3w8-2c5r-h9j9","cve":"CVE-2026-54005","affectedVersions":"\u003E=5.0.0-alpha.1,\u003C=5.4.3|\u003C=4.9.3","source":"GitHub","reportedAt":"2026-06-18 15:05:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r3w8-2c5r-h9j9"}]},{"advisoryId":"PKSA-d956-rcc1-9n2f","packageName":"getkirby\/cms","remoteId":"GHSA-qvjf-922g-pj44","title":"Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend","link":"https:\/\/github.com\/advisories\/GHSA-qvjf-922g-pj44","cve":"CVE-2026-45368","affectedVersions":"\u003E=5.0.0,\u003C=5.4.0|\u003C=4.9.0","source":"GitHub","reportedAt":"2026-05-27 17:42:03","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qvjf-922g-pj44"}]},{"advisoryId":"PKSA-q7k8-c5gf-pkgc","packageName":"getkirby\/cms","remoteId":"GHSA-39vq-49qm-r2mc","title":"Kirby CMS\u0027s content locks disclose IDs and emails of inaccessible users from `users.access\/list` permissions","link":"https:\/\/github.com\/advisories\/GHSA-39vq-49qm-r2mc","cve":"CVE-2026-45334","affectedVersions":"\u003E=5.0.0,\u003C=5.4.0|\u003C=4.9.0","source":"GitHub","reportedAt":"2026-05-27 17:23:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-39vq-49qm-r2mc"}]},{"advisoryId":"PKSA-ycvm-k4m4-tr9m","packageName":"getkirby\/cms","remoteId":"GHSA-2xw4-v2wx-hqq9","title":"Kirby CMS\u0027s `pages.access` permission is not checked during rendering of page drafts","link":"https:\/\/github.com\/advisories\/GHSA-2xw4-v2wx-hqq9","cve":"CVE-2026-44176","affectedVersions":"\u003E=5.0.0,\u003C=5.4.0|\u003C=4.9.0","source":"GitHub","reportedAt":"2026-05-26 23:55:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2xw4-v2wx-hqq9"}]},{"advisoryId":"PKSA-82wy-dsmt-xgpc","packageName":"getkirby\/cms","remoteId":"GHSA-9hx7-c53c-v6x8","title":"Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup","link":"https:\/\/github.com\/advisories\/GHSA-9hx7-c53c-v6x8","cve":"CVE-2026-44177","affectedVersions":"\u003E=5.3.0,\u003C=5.4.0","source":"GitHub","reportedAt":"2026-05-26 23:56:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9hx7-c53c-v6x8"}]},{"advisoryId":"PKSA-hhnz-p4k9-sfyd","packageName":"getkirby\/cms","remoteId":"GHSA-86rh-h242-j8xp","title":"Kirby CMS has an Arbitrary Method Call via REST API Search and Collection Query Endpoints","link":"https:\/\/github.com\/advisories\/GHSA-86rh-h242-j8xp","cve":"CVE-2026-44174","affectedVersions":"\u003E=5.0.0,\u003C=5.4.0|\u003C=4.9.0","source":"GitHub","reportedAt":"2026-05-26 23:47:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-86rh-h242-j8xp"}]},{"advisoryId":"PKSA-g7d2-4qf5-mg45","packageName":"getkirby\/cms","remoteId":"GHSA-5fhx-9q32-q257","title":"Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend","link":"https:\/\/github.com\/advisories\/GHSA-5fhx-9q32-q257","cve":"CVE-2026-44175","affectedVersions":"\u003E=5.0.0,\u003C=5.4.0|\u003C=4.9.0","source":"GitHub","reportedAt":"2026-05-26 23:49:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5fhx-9q32-q257"}]},{"advisoryId":"PKSA-wrgq-xy3s-q6nz","packageName":"getkirby\/cms","remoteId":"GHSA-2h7v-4372-f6x2","title":"Kirby CMS\u0027s read access to site, user and role information is not gated by permissions","link":"https:\/\/github.com\/advisories\/GHSA-2h7v-4372-f6x2","cve":"CVE-2026-42069","affectedVersions":"\u003E=5.0.0,\u003C=5.3.3|\u003C=4.8.0","source":"GitHub","reportedAt":"2026-05-04 19:50:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2h7v-4372-f6x2"}]},{"advisoryId":"PKSA-p78d-845h-8y84","packageName":"getkirby\/cms","remoteId":"GHSA-39cp-6679-8xv2","title":"Kirby CMS doesn\u0027t gate user avatar creation, replacement and deletion with user update permissions","link":"https:\/\/github.com\/advisories\/GHSA-39cp-6679-8xv2","cve":"CVE-2026-42174","affectedVersions":"\u003E=5.0.0,\u003C=5.3.3|\u003C=4.8.0","source":"GitHub","reportedAt":"2026-05-04 19:58:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-39cp-6679-8xv2"}]},{"advisoryId":"PKSA-d1w9-s6x2-nh6p","packageName":"getkirby\/cms","remoteId":"GHSA-x68m-c7jf-2572","title":"Kirby CMS\u0027s system API endpoint leaks installed version and license data to authenticated users","link":"https:\/\/github.com\/advisories\/GHSA-x68m-c7jf-2572","cve":"CVE-2026-42051","affectedVersions":"\u003E=5.0.0,\u003C=5.3.3|\u003C=4.8.0","source":"GitHub","reportedAt":"2026-05-04 19:59:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x68m-c7jf-2572"}]},{"advisoryId":"PKSA-bpcj-ysn7-my14","packageName":"getkirby\/cms","remoteId":"GHSA-85x2-r8xv-ww8c","title":"Kirby CMS\u0027s `pages.access\/list` and `files.access\/list` permissions are not consistently checked in the Panel and REST API","link":"https:\/\/github.com\/advisories\/GHSA-85x2-r8xv-ww8c","cve":"CVE-2026-42137","affectedVersions":"\u003E=5.0.0,\u003C=5.3.3|\u003C=4.8.0","source":"GitHub","reportedAt":"2026-04-30 21:03:20","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-85x2-r8xv-ww8c"}]},{"advisoryId":"PKSA-m1sp-3j4c-yg88","packageName":"getkirby\/cms","remoteId":"GHSA-6gqr-mx34-wh8r","title":"Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection","link":"https:\/\/github.com\/advisories\/GHSA-6gqr-mx34-wh8r","cve":"CVE-2026-41325","affectedVersions":"\u003E=5.0.0,\u003C5.4.0|\u003C4.9.0","source":"GitHub","reportedAt":"2026-04-24 20:39:36","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6gqr-mx34-wh8r"}]},{"advisoryId":"PKSA-rr97-2byk-h46m","packageName":"getkirby\/cms","remoteId":"GHSA-9wfj-c55w-j9qr","title":"Kirby has XML injection in its XML creator toolkit","link":"https:\/\/github.com\/advisories\/GHSA-9wfj-c55w-j9qr","cve":"CVE-2026-32870","affectedVersions":"\u003E=5.0.0,\u003C5.4.0|\u003C4.9.0","source":"GitHub","reportedAt":"2026-04-23 21:21:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9wfj-c55w-j9qr"}]},{"advisoryId":"PKSA-w67s-1md9-r7dk","packageName":"getkirby\/cms","remoteId":"GHSA-jcjw-58rv-c452","title":"Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering","link":"https:\/\/github.com\/advisories\/GHSA-jcjw-58rv-c452","cve":"CVE-2026-34587","affectedVersions":"\u003E=5.0.0,\u003C5.4.0|\u003C4.9.0","source":"GitHub","reportedAt":"2026-04-23 21:24:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jcjw-58rv-c452"}]},{"advisoryId":"PKSA-pyk9-2q1t-drry","packageName":"getkirby\/cms","remoteId":"GHSA-w942-j9r6-hr6r","title":"Kirby\u0027s page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter","link":"https:\/\/github.com\/advisories\/GHSA-w942-j9r6-hr6r","cve":"CVE-2026-40099","affectedVersions":"\u003E=5.0.0,\u003C5.4.0|\u003C4.9.0","source":"GitHub","reportedAt":"2026-04-23 21:24:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w942-j9r6-hr6r"}]},{"advisoryId":"PKSA-yfpp-rndk-cm9x","packageName":"getkirby\/cms","remoteId":"GHSA-4j78-4xrm-cr2f","title":"Kirby is missing permission checks in the content changes API","link":"https:\/\/github.com\/advisories\/GHSA-4j78-4xrm-cr2f","cve":"CVE-2026-21896","affectedVersions":"\u003E=5.0.0,\u003C=5.2.1","source":"GitHub","reportedAt":"2026-01-08 20:32:05","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4j78-4xrm-cr2f"}]},{"advisoryId":"PKSA-jms5-zv67-g12r","packageName":"getkirby\/cms","remoteId":"GHSA-84hf-8gh5-575j","title":"Kirby CMS has cross-site scripting (XSS) in the changes dialog","link":"https:\/\/github.com\/advisories\/GHSA-84hf-8gh5-575j","cve":"CVE-2025-65012","affectedVersions":"\u003E=5.0.0,\u003C5.1.4","source":"GitHub","reportedAt":"2025-11-18 18:01:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-84hf-8gh5-575j"}]}],"getgrav\/grav":[{"advisoryId":"PKSA-p98m-jfx1-qxw4","packageName":"getgrav\/grav","remoteId":"GHSA-pmf8-g7c8-7v54","title":"Grav: Stored CSS injection via Markdown image ?style=\u2026 reaches MediaObjectTrait::style() \u2014 incomplete patch of GHSA-r7fx-8g49-7hhr","link":"https:\/\/github.com\/advisories\/GHSA-pmf8-g7c8-7v54","cve":"CVE-2026-55890","affectedVersions":"\u003C=2.0.0-rc.8","source":"GitHub","reportedAt":"2026-06-18 14:49:19","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pmf8-g7c8-7v54"}]},{"advisoryId":"PKSA-wg3b-cs1z-bny5","packageName":"getgrav\/grav","remoteId":"GHSA-2f86-9cp8-6hcf","title":"Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets","link":"https:\/\/github.com\/advisories\/GHSA-2f86-9cp8-6hcf","cve":"CVE-2026-55885","affectedVersions":"\u003C1.7.53","source":"GitHub","reportedAt":"2026-06-18 14:31:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2f86-9cp8-6hcf"}]},{"advisoryId":"PKSA-jw9z-qj9h-1drk","packageName":"getgrav\/grav","remoteId":"GHSA-j274-39qw-32c9","title":"Grav: Twig sandbox allows editor-role users to exfiltrate all plugin secrets via Config::toArray()","link":"https:\/\/github.com\/advisories\/GHSA-j274-39qw-32c9","cve":"CVE-2026-44738","affectedVersions":"\u003C=2.0.0-rc.1","source":"GitHub","reportedAt":"2026-05-13 15:29:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j274-39qw-32c9"}]},{"advisoryId":"PKSA-pfs8-6ghq-nzcr","packageName":"getgrav\/grav","remoteId":"GHSA-fmg2-f5r9-24qc","title":"Grav: Stored XSS via page title (data[header][title]) in admin panel","link":"https:\/\/github.com\/advisories\/GHSA-fmg2-f5r9-24qc","cve":"CVE-2026-44737","affectedVersions":"\u003C1.7.49.5","source":"GitHub","reportedAt":"2026-05-08 19:38:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fmg2-f5r9-24qc"}]},{"advisoryId":"PKSA-jtpz-17pm-t9v9","packageName":"getgrav\/grav","remoteId":"GHSA-6xx2-m8wv-756h","title":"Low-privileged Grav API users can create super-admin accounts via blueprint-upload","link":"https:\/\/github.com\/advisories\/GHSA-6xx2-m8wv-756h","cve":"CVE-2026-42844","affectedVersions":"\u003C2.0.0-beta.4","source":"GitHub","reportedAt":"2026-05-06 21:19:21","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6xx2-m8wv-756h"}]},{"advisoryId":"PKSA-ncnf-tf1t-zhtj","packageName":"getgrav\/grav","remoteId":"GHSA-hmcx-ch82-3fv2","title":"Grav has Unauthenticated Path Traversal \u0026 Arbitrary File Write in its FormFlash component","link":"https:\/\/github.com\/advisories\/GHSA-hmcx-ch82-3fv2","cve":"CVE-2026-42608","affectedVersions":"\u003C2.0.0-beta.2","source":"GitHub","reportedAt":"2026-05-05 21:34:58","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hmcx-ch82-3fv2"}]},{"advisoryId":"PKSA-59xg-9744-g5wz","packageName":"getgrav\/grav","remoteId":"GHSA-3446-6mgw-f79p","title":"Grav is Vulnerable to XXE via SVG Upload ","link":"https:\/\/github.com\/advisories\/GHSA-3446-6mgw-f79p","cve":null,"affectedVersions":"\u003C2.0.0-beta.2","source":"GitHub","reportedAt":"2026-05-05 21:35:53","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3446-6mgw-f79p"}]},{"advisoryId":"PKSA-sd9s-hpbv-6d8f","packageName":"getgrav\/grav","remoteId":"GHSA-w8cg-7jcj-4vv2","title":"Grav is Vulnerable to Stored XSS via Tag Injection","link":"https:\/\/github.com\/advisories\/GHSA-w8cg-7jcj-4vv2","cve":"CVE-2026-42611","affectedVersions":"\u003C2.0.0-beta.2","source":"GitHub","reportedAt":"2026-05-05 21:36:27","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w8cg-7jcj-4vv2"}]},{"advisoryId":"PKSA-st6r-p3js-kbk7","packageName":"getgrav\/grav","remoteId":"GHSA-w48r-jppp-rcfw","title":"Grav Vulnerable to Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Feature","link":"https:\/\/github.com\/advisories\/GHSA-w48r-jppp-rcfw","cve":"CVE-2026-42607","affectedVersions":"\u003C2.0.0-beta.2","source":"GitHub","reportedAt":"2026-05-05 21:21:10","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-w48r-jppp-rcfw"}]},{"advisoryId":"PKSA-yx72-zyj1-gtxy","packageName":"getgrav\/grav","remoteId":"GHSA-r7fx-8g49-7hhr","title":"Grav CMS vulnerable to stored XSS via Markdown media attribute() action","link":"https:\/\/github.com\/advisories\/GHSA-r7fx-8g49-7hhr","cve":"CVE-2026-42841","affectedVersions":"\u003C2.0.0-beta.2","source":"GitHub","reportedAt":"2026-05-05 21:24:08","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r7fx-8g49-7hhr"}]},{"advisoryId":"PKSA-ddbz-4vx4-q29g","packageName":"getgrav\/grav","remoteId":"GHSA-c2q3-p4jr-c55f","title":"Grav Vulnerable to XSS via Taxonomy Field Values in Admin Panel","link":"https:\/\/github.com\/advisories\/GHSA-c2q3-p4jr-c55f","cve":"CVE-2026-42842","affectedVersions":"\u003C2.0.0-beta.2","source":"GitHub","reportedAt":"2026-05-05 21:24:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c2q3-p4jr-c55f"}]},{"advisoryId":"PKSA-pzhx-ftqg-8fxh","packageName":"getgrav\/grav","remoteId":"GHSA-pxm6-mhxr-q4mj","title":"Grav Vulnerable to Privilege Escalation via Missing Server-Side Validation of groups\/access","link":"https:\/\/github.com\/advisories\/GHSA-pxm6-mhxr-q4mj","cve":"CVE-2026-42613","affectedVersions":"\u003C2.0.0-beta.2","source":"GitHub","reportedAt":"2026-05-05 21:26:06","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-pxm6-mhxr-q4mj"}]},{"advisoryId":"PKSA-69wb-mt3g-24xp","packageName":"getgrav\/grav","remoteId":"GHSA-3f29-pqwf-v4j4","title":"Grav Vulnerable to Sensitive Information Disclosure via Accounts Service Bypass","link":"https:\/\/github.com\/advisories\/GHSA-3f29-pqwf-v4j4","cve":"CVE-2026-42610","affectedVersions":"\u003C2.0.0-beta.2","source":"GitHub","reportedAt":"2026-05-05 21:26:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3f29-pqwf-v4j4"}]},{"advisoryId":"PKSA-dxs6-j3rv-n16d","packageName":"getgrav\/grav","remoteId":"GHSA-9695-8fr9-hw5q","title":"Grav Vulnerable to Publisher-Level Stored XSS via Unquoted Event Attributes","link":"https:\/\/github.com\/advisories\/GHSA-9695-8fr9-hw5q","cve":"CVE-2026-42612","affectedVersions":"\u003C2.0.0-beta.2","source":"GitHub","reportedAt":"2026-05-05 21:27:15","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9695-8fr9-hw5q"}]},{"advisoryId":"PKSA-vnvp-8nvk-g8ck","packageName":"getgrav\/grav","remoteId":"GHSA-vj3m-2g9h-vm4p","title":"Grav has multiple RCE vectors: unsafe unserialize (x3), command injection in git clone, SSTI blocklist bypass","link":"https:\/\/github.com\/advisories\/GHSA-vj3m-2g9h-vm4p","cve":null,"affectedVersions":"\u003C2.0.0-beta.2","source":"GitHub","reportedAt":"2026-05-05 21:29:02","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-vj3m-2g9h-vm4p"}]},{"advisoryId":"PKSA-t2z1-v63n-9cpk","packageName":"getgrav\/grav","remoteId":"GHSA-gwfr-jfjf-92vv","title":"Grav has Insecure Deserialization in File Cache","link":"https:\/\/github.com\/advisories\/GHSA-gwfr-jfjf-92vv","cve":"CVE-2026-7317","affectedVersions":"\u003C2.0.0-beta.2","source":"GitHub","reportedAt":"2026-05-05 21:29:29","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-gwfr-jfjf-92vv"}]},{"advisoryId":"PKSA-fchw-jdvj-kg96","packageName":"getgrav\/grav","remoteId":"GHSA-rr73-568v-28f8","title":"Grav Vulnerable to Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic","link":"https:\/\/github.com\/advisories\/GHSA-rr73-568v-28f8","cve":"CVE-2026-42609","affectedVersions":"\u003C2.0.0-beta.2","source":"GitHub","reportedAt":"2026-05-05 21:29:53","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-rr73-568v-28f8"}]},{"advisoryId":"PKSA-ytd5-dvb1-2bq7","packageName":"getgrav\/grav","remoteId":"GHSA-729w-j79f-2c34","title":"Grav may be vulnerable to SSRF attack via Twig Templates","link":"https:\/\/github.com\/advisories\/GHSA-729w-j79f-2c34","cve":"CVE-2025-66844","affectedVersions":"\u003C=1.7.49.5","source":"GitHub","reportedAt":"2025-12-15 18:30:39","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-729w-j79f-2c34"}]},{"advisoryId":"PKSA-89qw-n7p7-yysf","packageName":"getgrav\/grav","remoteId":"GHSA-mh85-44c2-3m97","title":"Grav is vulnerable to Stored XSS through authenticated user-edited content","link":"https:\/\/github.com\/advisories\/GHSA-mh85-44c2-3m97","cve":"CVE-2025-66843","affectedVersions":"\u003C=1.7.49.5","source":"GitHub","reportedAt":"2025-12-15 18:30:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mh85-44c2-3m97"}]},{"advisoryId":"PKSA-1qqp-d2tf-94bx","packageName":"getgrav\/grav","remoteId":"GHSA-cchq-397m-q2qm","title":"Grav CMS is vulnerable to Cross Site Scripting (XSS) in the page editor","link":"https:\/\/github.com\/advisories\/GHSA-cchq-397m-q2qm","cve":"CVE-2025-65186","affectedVersions":"\u003C=1.7.49","source":"GitHub","reportedAt":"2025-12-02 18:30:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cchq-397m-q2qm"}]},{"advisoryId":"PKSA-87p7-31n6-n4f3","packageName":"getgrav\/grav","remoteId":"GHSA-h756-wh59-hhjv","title":"Grav vulnerable to Path traversal \/ arbitrary YAML write via user creation leading to Account Takeover \/ System Corruption","link":"https:\/\/github.com\/advisories\/GHSA-h756-wh59-hhjv","cve":"CVE-2025-66295","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 01:23:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h756-wh59-hhjv"}]},{"advisoryId":"PKSA-j9sn-rww3-fk26","packageName":"getgrav\/grav","remoteId":"GHSA-gqxx-248x-g29f","title":"Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `\/admin\/config\/site` parameter `data[taxonomies]`","link":"https:\/\/github.com\/advisories\/GHSA-gqxx-248x-g29f","cve":"CVE-2025-66308","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 01:23:19","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gqxx-248x-g29f"}]},{"advisoryId":"PKSA-69s1-6gdk-gbrs","packageName":"getgrav\/grav","remoteId":"GHSA-858q-77wx-hhx6","title":"Grav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig Injection","link":"https:\/\/github.com\/advisories\/GHSA-858q-77wx-hhx6","cve":"CVE-2025-66297","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 01:24:19","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-858q-77wx-hhx6"}]},{"advisoryId":"PKSA-fhbw-8kkc-q4g7","packageName":"getgrav\/grav","remoteId":"GHSA-65mj-f7p4-wggq","title":"Grav is vulnerable to Cross-Site Scripting (XSS) Reflected endpoint \/admin\/pages\/[page], parameter data[header][content][items], located in the \u0022Blog Config\u0022 tab","link":"https:\/\/github.com\/advisories\/GHSA-65mj-f7p4-wggq","cve":"CVE-2025-66309","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 01:24:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-65mj-f7p4-wggq"}]},{"advisoryId":"PKSA-6ybw-qvkx-41s3","packageName":"getgrav\/grav","remoteId":"GHSA-7g78-5g5g-mvfj","title":"Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `\/admin\/pages\/[page]` parameter `data[header][template]` in Advanced Tab","link":"https:\/\/github.com\/advisories\/GHSA-7g78-5g5g-mvfj","cve":"CVE-2025-66310","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 01:24:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7g78-5g5g-mvfj"}]},{"advisoryId":"PKSA-cyrn-zc8g-f5mw","packageName":"getgrav\/grav","remoteId":"GHSA-662m-56v4-3r8f","title":"Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass","link":"https:\/\/github.com\/advisories\/GHSA-662m-56v4-3r8f","cve":"CVE-2025-66294","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 01:25:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-662m-56v4-3r8f"}]},{"advisoryId":"PKSA-b17c-1fcn-dgtx","packageName":"getgrav\/grav","remoteId":"GHSA-8535-hvm8-2hmv","title":"Grav is vulnerable to Server-Side Template Injection (SSTI) via Forms","link":"https:\/\/github.com\/advisories\/GHSA-8535-hvm8-2hmv","cve":"CVE-2025-66298","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 01:25:33","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8535-hvm8-2hmv"}]},{"advisoryId":"PKSA-nbf5-vjfz-hnnq","packageName":"getgrav\/grav","remoteId":"GHSA-m8vh-v6r6-w7p6","title":"Grav vulnerable to Denial of Service via Improper Input Handling in \u0027Supported\u0027 Parameter","link":"https:\/\/github.com\/advisories\/GHSA-m8vh-v6r6-w7p6","cve":"CVE-2025-66305","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 00:46:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-m8vh-v6r6-w7p6"}]},{"advisoryId":"PKSA-h4jv-pmqx-9phz","packageName":"getgrav\/grav","remoteId":"GHSA-cjcp-qxvg-4rjm","title":"Grav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account Takeover","link":"https:\/\/github.com\/advisories\/GHSA-cjcp-qxvg-4rjm","cve":"CVE-2025-66296","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 00:35:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-cjcp-qxvg-4rjm"}]},{"advisoryId":"PKSA-83gv-619f-b6h7","packageName":"getgrav\/grav","remoteId":"GHSA-gjc5-8cfh-653x","title":"Grav is Vulnerable to Security Sandbox Bypass with SSTI (Server Side Template Injection)","link":"https:\/\/github.com\/advisories\/GHSA-gjc5-8cfh-653x","cve":"CVE-2025-66299","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 00:36:36","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gjc5-8cfh-653x"}]},{"advisoryId":"PKSA-82ft-1nmh-cs67","packageName":"getgrav\/grav","remoteId":"GHSA-p4ww-mcp9-j6f2","title":"Grav is vulnerable to Arbitrary File Read","link":"https:\/\/github.com\/advisories\/GHSA-p4ww-mcp9-j6f2","cve":"CVE-2025-66300","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 00:36:43","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-p4ww-mcp9-j6f2"}]},{"advisoryId":"PKSA-8gyx-1dyf-y75r","packageName":"getgrav\/grav","remoteId":"GHSA-v8x2-fjv7-8hjh","title":"Grav has Broken Access Control which allows an Editor to modify the page\u0027s YAML Frontmatter to alter form processing actions","link":"https:\/\/github.com\/advisories\/GHSA-v8x2-fjv7-8hjh","cve":"CVE-2025-66301","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 00:36:51","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v8x2-fjv7-8hjh"}]},{"advisoryId":"PKSA-v47z-3557-jjwp","packageName":"getgrav\/grav","remoteId":"GHSA-x62q-p736-3997","title":"Grav is vulnerable to a DOS on the admin panel","link":"https:\/\/github.com\/advisories\/GHSA-x62q-p736-3997","cve":"CVE-2025-66303","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 00:36:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x62q-p736-3997"}]},{"advisoryId":"PKSA-gsfs-x94c-47x5","packageName":"getgrav\/grav","remoteId":"GHSA-gq3g-666w-7h85","title":"Grav Exposes Password Hashes Leading to privilege escalation","link":"https:\/\/github.com\/advisories\/GHSA-gq3g-666w-7h85","cve":"CVE-2025-66304","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 00:37:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gq3g-666w-7h85"}]},{"advisoryId":"PKSA-mhn3-t14t-g84c","packageName":"getgrav\/grav","remoteId":"GHSA-mpjj-4688-3fxg","title":"Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `\/admin\/pages\/[page]` in Multiples parameters","link":"https:\/\/github.com\/advisories\/GHSA-mpjj-4688-3fxg","cve":"CVE-2025-66311","affectedVersions":"\u003C1.11.0-beta.1","source":"GitHub","reportedAt":"2025-12-02 00:37:14","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mpjj-4688-3fxg"}]},{"advisoryId":"PKSA-w4p2-x7q2-ymxv","packageName":"getgrav\/grav","remoteId":"GHSA-rmw5-f87r-w988","title":"Grav Admin Plugin is vulnerable to Cross-Site Scripting (XSS) Stored endpoint `\/admin\/accounts\/groups\/[group]` parameter `data[readableName]`","link":"https:\/\/github.com\/advisories\/GHSA-rmw5-f87r-w988","cve":"CVE-2025-66312","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 00:37:38","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rmw5-f87r-w988"}]},{"advisoryId":"PKSA-kdts-d57h-cyfm","packageName":"getgrav\/grav","remoteId":"GHSA-q3qx-cp62-f6m7","title":"Grav Admin Plugin vulnerable to User Enumeration \u0026 Email Disclosure","link":"https:\/\/github.com\/advisories\/GHSA-q3qx-cp62-f6m7","cve":"CVE-2025-66307","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 00:38:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q3qx-cp62-f6m7"}]},{"advisoryId":"PKSA-pps4-ft6r-rq3g","packageName":"getgrav\/grav","remoteId":"GHSA-j422-qmxp-hv94","title":"Grav vulnerable to Path Traversal allowing server files backup","link":"https:\/\/github.com\/advisories\/GHSA-j422-qmxp-hv94","cve":"CVE-2025-66302","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 00:38:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j422-qmxp-hv94"}]},{"advisoryId":"PKSA-rdds-1cns-2prg","packageName":"getgrav\/grav","remoteId":"GHSA-4cwq-j7jv-qmwg","title":"Grav vulnerable to Information Disclosure via IDOR in Grav Admin Panel","link":"https:\/\/github.com\/advisories\/GHSA-4cwq-j7jv-qmwg","cve":"CVE-2025-66306","affectedVersions":"\u003C1.8.0-beta.27","source":"GitHub","reportedAt":"2025-12-02 00:39:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4cwq-j7jv-qmwg"}]},{"advisoryId":"PKSA-s32r-k9tt-xp19","packageName":"getgrav\/grav","remoteId":"GHSA-f6g2-h7qv-3m5v","title":"Remote Code Execution by uploading a phar file using frontmatter","link":"https:\/\/github.com\/advisories\/GHSA-f6g2-h7qv-3m5v","cve":"CVE-2024-27923","affectedVersions":"\u003C1.7.43","source":"GitHub","reportedAt":"2024-03-06 16:58:33","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f6g2-h7qv-3m5v"}]}],"spomky-labs\/otphp":[{"advisoryId":"PKSA-qv5y-crcz-9nxw","packageName":"spomky-labs\/otphp","remoteId":"spomky-labs\/otphp\/GHSA-2jx3-65f3-xr8r.yaml","title":"Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught TypeError","link":"https:\/\/github.com\/Spomky-Labs\/otphp\/security\/advisories\/GHSA-2jx3-65f3-xr8r","cve":null,"affectedVersions":"\u003C11.4.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-31 09:08:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2jx3-65f3-xr8r"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"spomky-labs\/otphp\/GHSA-2jx3-65f3-xr8r.yaml"}]},{"advisoryId":"PKSA-kbc7-dq62-pt7d","packageName":"spomky-labs\/otphp","remoteId":"spomky-labs\/otphp\/GHSA-g7m4-839x-ch6v.yaml","title":"Unbounded digits parameter in a provisioning URI triggers an uncaught DivisionByZeroError in OTP generation","link":"https:\/\/github.com\/Spomky-Labs\/otphp\/security\/advisories\/GHSA-g7m4-839x-ch6v","cve":null,"affectedVersions":"\u003C11.4.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-31 09:06:37","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g7m4-839x-ch6v"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"spomky-labs\/otphp\/GHSA-g7m4-839x-ch6v.yaml"}]}],"web-token\/jwt-framework":[{"advisoryId":"PKSA-815n-fyy9-rqkd","packageName":"web-token\/jwt-framework","remoteId":"web-token\/jwt-framework\/GHSA-3prj-6hqw-cm82.yaml","title":"PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service","link":"https:\/\/github.com\/web-token\/jwt-framework\/security\/advisories\/GHSA-3prj-6hqw-cm82","cve":null,"affectedVersions":"\u003C3.4.10|\u003E=4.0.0,\u003C4.0.7|\u003E=4.1.0,\u003C4.1.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-06 16:26:43","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"web-token\/jwt-framework\/GHSA-3prj-6hqw-cm82.yaml"}]},{"advisoryId":"PKSA-m2bn-5kyy-vzsk","packageName":"web-token\/jwt-framework","remoteId":"web-token\/jwt-framework\/GHSA-5739-39v2-5754.yaml","title":"RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher\/Marvin padding oracle","link":"https:\/\/github.com\/web-token\/jwt-framework\/security\/advisories\/GHSA-5739-39v2-5754","cve":null,"affectedVersions":"\u003C3.4.10|\u003E=4.0.0,\u003C4.0.7|\u003E=4.1.0,\u003C4.1.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-06 16:27:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3prj-6hqw-cm82"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"web-token\/jwt-framework\/GHSA-5739-39v2-5754.yaml"}]},{"advisoryId":"PKSA-p7vh-1fk6-znth","packageName":"web-token\/jwt-framework","remoteId":"web-token\/jwt-framework\/GHSA-6vvh-pxr4-25r7.yaml","title":"Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption","link":"https:\/\/github.com\/web-token\/jwt-framework\/security\/advisories\/GHSA-6vvh-pxr4-25r7","cve":null,"affectedVersions":"\u003C3.4.10|\u003E=4.0.0,\u003C4.0.7|\u003E=4.1.0,\u003C4.1.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-06 16:27:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jc38-x7x8-2xc8"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"web-token\/jwt-framework\/GHSA-6vvh-pxr4-25r7.yaml"}]},{"advisoryId":"PKSA-ztxk-m2k2-bkgv","packageName":"web-token\/jwt-framework","remoteId":"web-token\/jwt-framework\/GHSA-jc38-x7x8-2xc8.yaml","title":"JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks","link":"https:\/\/github.com\/web-token\/jwt-framework\/security\/advisories\/GHSA-jc38-x7x8-2xc8","cve":null,"affectedVersions":"\u003C3.4.10|\u003E=4.0.0,\u003C4.0.7|\u003E=4.1.0,\u003C4.1.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-06 16:30:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5739-39v2-5754"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"web-token\/jwt-framework\/GHSA-jc38-x7x8-2xc8.yaml"}]}],"web-token\/jwt-library":[{"advisoryId":"PKSA-qw7k-npv6-3pbk","packageName":"web-token\/jwt-library","remoteId":"web-token\/jwt-library\/GHSA-3prj-6hqw-cm82.yaml","title":"PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service","link":"https:\/\/github.com\/web-token\/jwt-framework\/security\/advisories\/GHSA-3prj-6hqw-cm82","cve":null,"affectedVersions":"\u003C3.4.10|\u003E=4.0.0,\u003C4.0.7|\u003E=4.1.0,\u003C4.1.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-06 16:26:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6vvh-pxr4-25r7"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"web-token\/jwt-library\/GHSA-3prj-6hqw-cm82.yaml"}]},{"advisoryId":"PKSA-237v-kv6c-dpkr","packageName":"web-token\/jwt-library","remoteId":"web-token\/jwt-library\/GHSA-5739-39v2-5754.yaml","title":"RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher\/Marvin padding oracle","link":"https:\/\/github.com\/web-token\/jwt-framework\/security\/advisories\/GHSA-5739-39v2-5754","cve":null,"affectedVersions":"\u003C3.4.10|\u003E=4.0.0,\u003C4.0.7|\u003E=4.1.0,\u003C4.1.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-06 16:27:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3prj-6hqw-cm82"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"web-token\/jwt-library\/GHSA-5739-39v2-5754.yaml"}]},{"advisoryId":"PKSA-66dc-42nb-26yy","packageName":"web-token\/jwt-library","remoteId":"web-token\/jwt-library\/GHSA-6vvh-pxr4-25r7.yaml","title":"Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption","link":"https:\/\/github.com\/web-token\/jwt-framework\/security\/advisories\/GHSA-6vvh-pxr4-25r7","cve":null,"affectedVersions":"\u003C3.4.10|\u003E=4.0.0,\u003C4.0.7|\u003E=4.1.0,\u003C4.1.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-06 16:27:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jc38-x7x8-2xc8"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"web-token\/jwt-library\/GHSA-6vvh-pxr4-25r7.yaml"}]},{"advisoryId":"PKSA-58h1-qnck-61bt","packageName":"web-token\/jwt-library","remoteId":"web-token\/jwt-library\/GHSA-jc38-x7x8-2xc8.yaml","title":"JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks","link":"https:\/\/github.com\/web-token\/jwt-framework\/security\/advisories\/GHSA-jc38-x7x8-2xc8","cve":null,"affectedVersions":"\u003C3.4.10|\u003E=4.0.0,\u003C4.0.7|\u003E=4.1.0,\u003C4.1.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-06 16:30:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5739-39v2-5754"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"web-token\/jwt-library\/GHSA-jc38-x7x8-2xc8.yaml"}]}],"mtdowling\/jmespath.php":[{"advisoryId":"PKSA-mnyp-475s-ywph","packageName":"mtdowling\/jmespath.php","remoteId":"mtdowling\/jmespath.php\/CVE-2026-54133.yaml","title":"CompilerRuntime code injection via unescaped function names","link":"https:\/\/github.com\/jmespath\/jmespath.php\/security\/advisories\/GHSA-pcw8-m77r-2528","cve":"CVE-2026-54133","affectedVersions":"\u003C2.9.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-11 10:41:50","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"mtdowling\/jmespath.php\/CVE-2026-54133.yaml"}]}],"cakephp\/authentication":[{"advisoryId":"PKSA-bz6x-t8z8-r26p","packageName":"cakephp\/authentication","remoteId":"GHSA-hhpq-7wg4-36jm","title":"CakePHP Authentication: Open redirect weakness via backslash bypass","link":"https:\/\/github.com\/advisories\/GHSA-hhpq-7wg4-36jm","cve":"CVE-2026-55590","affectedVersions":"\u003E=4.0.0,\u003C4.1.1|\u003C3.3.6","source":"GitHub","reportedAt":"2026-06-17 18:52:09","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hhpq-7wg4-36jm"}]}],"filament\/forms":[{"advisoryId":"PKSA-n7tx-gkfb-14yj","packageName":"filament\/forms","remoteId":"GHSA-m9cv-24rx-8mv7","title":"Filament: Disabled RichEditor field state can be used for XSS","link":"https:\/\/github.com\/advisories\/GHSA-m9cv-24rx-8mv7","cve":"CVE-2026-55409","affectedVersions":"\u003E=3.0.0,\u003C=3.3.52","source":"GitHub","reportedAt":"2026-06-17 18:41:12","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-m9cv-24rx-8mv7"}]}],"laravel\/framework":[{"advisoryId":"PKSA-3r5d-mb8f-1qw9","packageName":"laravel\/framework","remoteId":"GHSA-5vg9-5847-vvmq","title":"Laravel Framework: CRLF injection in default email rule ","link":"https:\/\/github.com\/advisories\/GHSA-5vg9-5847-vvmq","cve":null,"affectedVersions":"\u003C12.60.0|\u003E=13.0.0,\u003C=13.9.0","source":"GitHub","reportedAt":"2026-06-17 13:53:44","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5vg9-5847-vvmq"}]},{"advisoryId":"PKSA-m5cs-t1y6-qpcs","packageName":"laravel\/framework","remoteId":"GHSA-crmm-hgp2-wgrp","title":"Laravel Framework: Temporary Signed URL Path Confusion","link":"https:\/\/github.com\/advisories\/GHSA-crmm-hgp2-wgrp","cve":null,"affectedVersions":"\u003C12.61.1|\u003E=13.0.0,\u003C13.12.0","source":"GitHub","reportedAt":"2026-06-17 13:54:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-crmm-hgp2-wgrp"}]},{"advisoryId":"PKSA-mdq4-51ck-6kdq","packageName":"laravel\/framework","remoteId":"laravel\/framework\/CVE-2026-48019.yaml","title":"Laravel CRLF injection in default email rule","link":"https:\/\/github.com\/laravel\/framework\/security\/advisories\/GHSA-5vg9-5847-vvmq","cve":"CVE-2026-48019","affectedVersions":"\u003E=9.0.0,\u003C10.0.0|\u003E=10.0.0,\u003C11.0.0|\u003E=11.0.0,\u003C12.0.0|\u003E=12.0.0,\u003C12.60.0|\u003E=13.0.0,\u003C13.10.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-19 18:13:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"laravel\/framework\/CVE-2026-48019.yaml"}]}],"phpseclib\/phpseclib":[{"advisoryId":"PKSA-432p-hv1d-chf7","packageName":"phpseclib\/phpseclib","remoteId":"GHSA-m557-wrgg-6rp4","title":"phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information Access","link":"https:\/\/github.com\/advisories\/GHSA-m557-wrgg-6rp4","cve":"CVE-2026-55599","affectedVersions":"\u003E=3.0.0,\u003C=3.0.53|\u003E=2.0.0,\u003C=2.0.54|\u003E=0.1.1,\u003C=1.0.29","source":"GitHub","reportedAt":"2026-06-16 15:03:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m557-wrgg-6rp4"}]},{"advisoryId":"PKSA-smrh-yx37-92ws","packageName":"phpseclib\/phpseclib","remoteId":"GHSA-3qpq-r242-jqj7","title":"phpseclib has a CVE-2024-27355 mitigation bypass \u2014 OID amplification DoS in ASN1::decodeOID()","link":"https:\/\/github.com\/advisories\/GHSA-3qpq-r242-jqj7","cve":"CVE-2026-44167","affectedVersions":"\u003E=0.1.1,\u003C=1.0.28|\u003E=3.0.0,\u003C=3.0.51|\u003E=2.0.0,\u003C=2.0.53","source":"GitHub","reportedAt":"2026-05-05 21:17:57","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3qpq-r242-jqj7"}]},{"advisoryId":"PKSA-zh4j-by9m-7mz8","packageName":"phpseclib\/phpseclib","remoteId":"GHSA-r854-jrxh-36qx","title":"phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals()","link":"https:\/\/github.com\/advisories\/GHSA-r854-jrxh-36qx","cve":"CVE-2026-40194","affectedVersions":"\u003E=0.1.1,\u003C1.0.28|\u003E=3.0.0,\u003C3.0.51|\u003E=2.0.0,\u003C2.0.53","source":"GitHub","reportedAt":"2026-04-10 20:58:10","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-r854-jrxh-36qx"}]},{"advisoryId":"PKSA-km2b-zc3b-mjm3","packageName":"phpseclib\/phpseclib","remoteId":"GHSA-94g3-g5v7-q4jg","title":"phpseclib\u0027s AES-CBC unpadding susceptible to padding oracle timing attack","link":"https:\/\/github.com\/advisories\/GHSA-94g3-g5v7-q4jg","cve":"CVE-2026-32935","affectedVersions":"\u003E=0.1.1,\u003C=1.0.26|\u003E=2.0.0,\u003C=2.0.51|\u003E=3.0.0,\u003C=3.0.49","source":"GitHub","reportedAt":"2026-03-19 16:42:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-94g3-g5v7-q4jg"}]}],"typo3\/cms-recycler":[{"advisoryId":"PKSA-9psw-d46q-t3cr","packageName":"typo3\/cms-recycler","remoteId":"GHSA-f34x-rx2w-7pm3","title":"TYPO3 CMS has Broken Access Control in the Recycler Module","link":"https:\/\/github.com\/advisories\/GHSA-f34x-rx2w-7pm3","cve":"CVE-2026-47349","affectedVersions":"\u003E=14.0.0,\u003C14.3.3|\u003E=13.0.0,\u003C13.4.31|\u003E=12.0.0,\u003C12.4.46|\u003E=11.0.0,\u003C11.5.51|\u003C10.4.57","source":"GitHub","reportedAt":"2026-06-12 20:08:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f34x-rx2w-7pm3"}]},{"advisoryId":"PKSA-kq4c-tzdn-3hmx","packageName":"typo3\/cms-recycler","remoteId":"GHSA-p52w-7rhw-9m67","title":"TYPO3 CMS Allows Broken Access Control in Recycler Module","link":"https:\/\/github.com\/advisories\/GHSA-p52w-7rhw-9m67","cve":"CVE-2025-59022","affectedVersions":"\u003E=10.0.0,\u003C=10.4.54|\u003E=11.0.0,\u003C=11.5.48|\u003E=12.0.0,\u003C=12.4.40|\u003E=13.0.0,\u003C=13.4.22|\u003E=14.0.0,\u003C=14.0.1","source":"GitHub","reportedAt":"2026-01-13 20:37:44","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-p52w-7rhw-9m67"}]}],"typo3\/cms-form":[{"advisoryId":"PKSA-8hzt-dvj5-mc5s","packageName":"typo3\/cms-form","remoteId":"GHSA-pjpj-v387-x4vq","title":"TYPO3 CMS has Broken Access Control in its Form Framework","link":"https:\/\/github.com\/advisories\/GHSA-pjpj-v387-x4vq","cve":"CVE-2026-11607","affectedVersions":"\u003E=14.0.0,\u003C14.3.3|\u003E=13.0.0,\u003C13.4.31|\u003E=12.0.0,\u003C12.4.46|\u003E=11.0.0,\u003C11.5.51|\u003C10.4.57","source":"GitHub","reportedAt":"2026-06-12 20:08:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pjpj-v387-x4vq"}]},{"advisoryId":"PKSA-m239-hcqk-kg59","packageName":"typo3\/cms-form","remoteId":"GHSA-hwvq-2w67-rvxp","title":"TYPO3 CMS has Broken Access Control in its Form Framework","link":"https:\/\/github.com\/advisories\/GHSA-hwvq-2w67-rvxp","cve":"CVE-2026-47346","affectedVersions":"\u003E=14.0.0,\u003C14.3.3|\u003E=13.0.0,\u003C13.4.31|\u003E=12.0.0,\u003C12.4.46|\u003E=11.0.0,\u003C11.5.51|\u003C10.4.57","source":"GitHub","reportedAt":"2026-06-12 19:32:09","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hwvq-2w67-rvxp"}]},{"advisoryId":"PKSA-w8hs-qvzm-sf5x","packageName":"typo3\/cms-form","remoteId":"GHSA-jh32-v29g-68pq","title":"TYPO3 CMS has Privilege Escalation \u0026 SQL Injection in its Form Framework","link":"https:\/\/github.com\/advisories\/GHSA-jh32-v29g-68pq","cve":"CVE-2026-49741","affectedVersions":"\u003E=14.0.0,\u003C14.3.3","source":"GitHub","reportedAt":"2026-06-12 19:32:22","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jh32-v29g-68pq"}]}],"typo3\/cms-indexed-search":[{"advisoryId":"PKSA-38f7-f61m-dktr","packageName":"typo3\/cms-indexed-search","remoteId":"GHSA-cg75-qfg2-w9hj","title":"TYPO3 CMS has Cross-Site Scripting in Indexed Search","link":"https:\/\/github.com\/advisories\/GHSA-cg75-qfg2-w9hj","cve":"CVE-2026-47348","affectedVersions":"\u003E=14.0.0,\u003C14.3.3|\u003E=13.0.0,\u003C13.4.31","source":"GitHub","reportedAt":"2026-06-12 19:06:52","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cg75-qfg2-w9hj"}]}],"typo3\/cms-backend":[{"advisoryId":"PKSA-4mhm-w6hx-yhcy","packageName":"typo3\/cms-backend","remoteId":"GHSA-q93m-25xv-94hh","title":"TYPO3 CMS: Broken Access Control in Media Module","link":"https:\/\/github.com\/advisories\/GHSA-q93m-25xv-94hh","cve":"CVE-2026-47351","affectedVersions":"\u003E=14.0.0,\u003C14.3.3|\u003E=13.0.0,\u003C13.4.31|\u003E=12.0.0,\u003C12.4.46|\u003E=11.0.0,\u003C11.5.51|\u003C10.4.57","source":"GitHub","reportedAt":"2026-06-12 19:06:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q93m-25xv-94hh"}]},{"advisoryId":"PKSA-gksc-phy8-f181","packageName":"typo3\/cms-backend","remoteId":"GHSA-2j54-93q2-3hjq","title":"TYPO3 CMS has Broken Access Control in Backend API","link":"https:\/\/github.com\/advisories\/GHSA-2j54-93q2-3hjq","cve":"CVE-2026-47352","affectedVersions":"\u003E=14.0.0,\u003C14.3.3|\u003E=13.0.0,\u003C13.4.31|\u003E=12.0.0,\u003C12.4.46|\u003E=11.0.0,\u003C11.5.51|\u003C10.4.57","source":"GitHub","reportedAt":"2026-06-12 19:08:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2j54-93q2-3hjq"}]},{"advisoryId":"PKSA-j4dd-3nrn-j8w4","packageName":"typo3\/cms-backend","remoteId":"GHSA-xvv6-p4wf-mvx7","title":"TYPO3 CMS Stores Cleartext Password in User Settings Module","link":"https:\/\/github.com\/advisories\/GHSA-xvv6-p4wf-mvx7","cve":"CVE-2026-6553","affectedVersions":"=14.2.0","source":"GitHub","reportedAt":"2026-04-24 16:39:15","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xvv6-p4wf-mvx7"}]},{"advisoryId":"PKSA-54yn-xn5g-k3j9","packageName":"typo3\/cms-backend","remoteId":"GHSA-5j7q-wmh7-cqhg","title":"TYPO3 CMS Allows Broken Access Control in Edit Document Controller","link":"https:\/\/github.com\/advisories\/GHSA-5j7q-wmh7-cqhg","cve":"CVE-2025-59020","affectedVersions":"\u003E=10.0.0,\u003C=10.4.54|\u003E=11.0.0,\u003C=11.5.48|\u003E=12.0.0,\u003C=12.4.40|\u003E=13.0.0,\u003C=13.4.22|\u003E=14.0.0,\u003C=14.0.1","source":"GitHub","reportedAt":"2026-01-13 20:37:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5j7q-wmh7-cqhg"}]}],"typo3\/cms-filelist":[{"advisoryId":"PKSA-br9n-75sp-8dqy","packageName":"typo3\/cms-filelist","remoteId":"GHSA-chm7-4vch-h8vr","title":"TYPO3 CMS has Broken Access Control in its Media Module","link":"https:\/\/github.com\/advisories\/GHSA-chm7-4vch-h8vr","cve":"CVE-2026-49742","affectedVersions":"\u003E=14.0.0,\u003C14.3.3|\u003E=13.0.0,\u003C13.4.31|\u003E=12.0.0,\u003C12.4.46|\u003E=11.0.0,\u003C11.5.51","source":"GitHub","reportedAt":"2026-06-12 19:09:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-chm7-4vch-h8vr"}]}],"grumpydictator\/firefly-iii":[{"advisoryId":"PKSA-197r-m2ry-57db","packageName":"grumpydictator\/firefly-iii","remoteId":"GHSA-6jq6-x4cx-qvcm","title":"Firefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig)","link":"https:\/\/github.com\/advisories\/GHSA-6jq6-x4cx-qvcm","cve":null,"affectedVersions":"\u003C=6.6.2","source":"GitHub","reportedAt":"2026-06-12 15:04:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6jq6-x4cx-qvcm"}]},{"advisoryId":"PKSA-gsvb-yc3b-2hf2","packageName":"grumpydictator\/firefly-iii","remoteId":"GHSA-5q8v-j673-m5v4","title":"Firefly III user API endpoints expose all users\u0027 information to any authenticated user (IDOR)","link":"https:\/\/github.com\/advisories\/GHSA-5q8v-j673-m5v4","cve":null,"affectedVersions":"\u003E=6.4.23,\u003C=6.5.0","source":"GitHub","reportedAt":"2026-03-07 02:10:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5q8v-j673-m5v4"}]}],"symfony\/runtime":[{"advisoryId":"PKSA-xf5h-y6vg-qj98","packageName":"symfony\/runtime","remoteId":"GHSA-fqc7-9xjw-jrh3","title":"SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV\/APP_DEBUG via parse_str\/SAPI Argv Mismatch","link":"https:\/\/github.com\/advisories\/GHSA-fqc7-9xjw-jrh3","cve":"CVE-2026-47767","affectedVersions":"\u003E=8.0.0,\u003C8.0.12|\u003E=7.1.7,\u003C7.4.12|\u003E=6.4.14,\u003C6.4.40|\u003E=5.4.46,\u003C5.4.52","source":"GitHub","reportedAt":"2026-06-09 21:58:11","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fqc7-9xjw-jrh3"}]},{"advisoryId":"PKSA-py8y-z9q7-q197","packageName":"symfony\/runtime","remoteId":"symfony\/runtime\/CVE-2026-46626.yaml","title":"CVE-2026-46626: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV\/APP_DEBUG via parse_str\/SAPI Argv Mismatch","link":"https:\/\/symfony.com\/cve-2026-46626","cve":"CVE-2026-46626","affectedVersions":"\u003E=5.4.46,\u003C5.4.52|\u003E=6.4.14,\u003C6.4.40|\u003E=7.1.7,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/runtime\/CVE-2026-46626.yaml"}]}],"symfony\/symfony":[{"advisoryId":"PKSA-9crr-v2h4-wg18","packageName":"symfony\/symfony","remoteId":"GHSA-fqc7-9xjw-jrh3","title":"SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV\/APP_DEBUG via parse_str\/SAPI Argv Mismatch","link":"https:\/\/github.com\/advisories\/GHSA-fqc7-9xjw-jrh3","cve":"CVE-2026-47767","affectedVersions":"\u003E=8.0.0,\u003C8.0.12|\u003E=7.1.7,\u003C7.4.12|\u003E=6.4.14,\u003C6.4.40|\u003E=5.4.46,\u003C5.4.52","source":"GitHub","reportedAt":"2026-06-09 21:58:11","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fqc7-9xjw-jrh3"}]},{"advisoryId":"PKSA-bd71-n14y-wh1d","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-48736.yaml","title":"CVE-2026-48736: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient","link":"https:\/\/symfony.com\/cve-2026-48736","cve":"CVE-2026-48736","affectedVersions":"\u003E=5.4.0,\u003C5.4.53|\u003E=6.4.0,\u003C6.4.41|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.13|\u003E=8.0.0,\u003C8.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-26 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-38cx-cq6f-5755"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-48736.yaml"}]},{"advisoryId":"PKSA-qpkt-z1gq-qf6m","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-48761.yaml","title":"CVE-2026-48761: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on \u003Cobject\u003E, \u003Capplet\u003E, \u003Ciframe\u003E, \u003Cimg\u003E and the URL Inside \u003Cmeta http-equiv=\u0022refresh\u0022\u003E content","link":"https:\/\/symfony.com\/cve-2026-48761","cve":"CVE-2026-48761","affectedVersions":"\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.41|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.13|\u003E=8.0.0,\u003C8.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-26 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x5qj-865h-mgvm"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-48761.yaml"}]},{"advisoryId":"PKSA-nshj-ydrr-y3c1","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-48784.yaml","title":"CVE-2026-48784: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `..\/` or `.\/` \u2192 Generated URL Collapses Off-Route Under RFC 3986 Normalization","link":"https:\/\/symfony.com\/cve-2026-48784","cve":"CVE-2026-48784","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.53|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.41|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.13|\u003E=8.0.0,\u003C8.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-26 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h5x3-xfc9-m39h"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-48784.yaml"}]},{"advisoryId":"PKSA-v1cq-8qyb-2p5n","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-48747.yaml","title":"CVE-2026-48747: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade","link":"https:\/\/symfony.com\/cve-2026-48747","cve":"CVE-2026-48747","affectedVersions":"\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.13|\u003E=8.0.0,\u003C8.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-26 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rrj9-5q2j-4gvr"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-48747.yaml"}]},{"advisoryId":"PKSA-gc1j-s49p-r1kv","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-48760.yaml","title":"CVE-2026-48760: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense","link":"https:\/\/symfony.com\/cve-2026-48760","cve":"CVE-2026-48760","affectedVersions":"\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.41|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.13|\u003E=8.0.0,\u003C8.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-26 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-v3wm-qf9p-c549"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-48760.yaml"}]},{"advisoryId":"PKSA-pjp2-q1z1-mmvn","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-48489.yaml","title":"CVE-2026-48489: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes","link":"https:\/\/symfony.com\/cve-2026-48489","cve":"CVE-2026-48489","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.53|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.41|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.13|\u003E=8.0.0,\u003C8.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-26 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6h46-9jf5-q59x"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-48489.yaml"}]},{"advisoryId":"PKSA-2zh8-n335-x575","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45304.yaml","title":"CVE-2026-45304: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion (\u0022Billion Laughs\u0022)","link":"https:\/\/symfony.com\/cve-2026-45304","cve":"CVE-2026-45304","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-4qpc-3hr4-r2p4"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45304.yaml"}]},{"advisoryId":"PKSA-9sj3-tcvg-s7g4","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45068.yaml","title":"CVE-2026-45068: Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address","link":"https:\/\/symfony.com\/cve-2026-45068","cve":"CVE-2026-45068","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xx3c-qf5g-hc39"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45068.yaml"}]},{"advisoryId":"PKSA-qgpb-b2wz-rty6","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45070.yaml","title":"CVE-2026-45070: Email Header Injection via Non-Token Characters in Mime Parameter Names","link":"https:\/\/symfony.com\/cve-2026-45070","cve":"CVE-2026-45070","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vqc8-7275-q272"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45070.yaml"}]},{"advisoryId":"PKSA-j6yc-z95h-xyjq","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45305.yaml","title":"CVE-2026-45305: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex","link":"https:\/\/symfony.com\/cve-2026-45305","cve":"CVE-2026-45305","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-9frc-8383-795m"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45305.yaml"}]},{"advisoryId":"PKSA-kp1y-8sfh-4r87","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45753.yaml","title":"CVE-2026-45753: HtmlSanitizer UrlAttributeSanitizer Omits action\/formaction\/poster\/cite: javascript: URI Survives Sanitization (XSS)","link":"https:\/\/symfony.com\/cve-2026-45753","cve":"CVE-2026-45753","affectedVersions":"\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-hhg7-c65m-h7ff"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45753.yaml"}]},{"advisoryId":"PKSA-9ss4-yr44-h3bt","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45071.yaml","title":"CVE-2026-45071: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true","link":"https:\/\/symfony.com\/cve-2026-45071","cve":"CVE-2026-45071","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-x6g4-fwcc-jj8w"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45071.yaml"}]},{"advisoryId":"PKSA-3ds8-wrg2-pjdq","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45754.yaml","title":"CVE-2026-45754: Mailjet Mailer and LOX24 Notifier Webhook Parsers Never Verify the Configured Secret: Unauthenticated Webhook Event Injection","link":"https:\/\/symfony.com\/cve-2026-45754","cve":"CVE-2026-45754","affectedVersions":"\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-64hg-93w9-fc35"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45754.yaml"}]},{"advisoryId":"PKSA-rgzg-p3v4-grbh","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-47212.yaml","title":"CVE-2026-47212: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event Injection","link":"https:\/\/symfony.com\/cve-2026-47212","cve":"CVE-2026-47212","affectedVersions":"\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-55rj-x2vc-4whq"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-47212.yaml"}]},{"advisoryId":"PKSA-94ry-294g-7bbc","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45756.yaml","title":"CVE-2026-45756: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()\/search() Without Limits: ReDoS","link":"https:\/\/symfony.com\/cve-2026-45756","cve":"CVE-2026-45756","affectedVersions":"\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-8v8v-g73j-492j"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45756.yaml"}]},{"advisoryId":"PKSA-13hy-qbkf-1ty7","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45077.yaml","title":"CVE-2026-45077: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener","link":"https:\/\/symfony.com\/cve-2026-45077","cve":"CVE-2026-45077","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-m7v2-7gxm-vc2v"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45077.yaml"}]},{"advisoryId":"PKSA-7tp5-63ss-rycr","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45069.yaml","title":"CVE-2026-45069: OidcTokenHandler Accepts JWTs Missing aud\/iss\/exp Claims","link":"https:\/\/symfony.com\/cve-2026-45069","cve":"CVE-2026-45069","affectedVersions":"\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-29fc-p6c4-24cg"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45069.yaml"}]},{"advisoryId":"PKSA-29h7-kzb3-pdfy","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45073.yaml","title":"CVE-2026-45073: SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix","link":"https:\/\/symfony.com\/cve-2026-45073","cve":"CVE-2026-45073","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6qh9-h6wf-jgqc"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45073.yaml"}]},{"advisoryId":"PKSA-vty3-cvqg-rtn4","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45066.yaml","title":"CVE-2026-45066: HtmlSanitizer allowLinkHosts() \/ allowMediaHosts() Bypass via URL-Parser Differentials and \u003Carea\u003E Misclassification","link":"https:\/\/symfony.com\/cve-2026-45066","cve":"CVE-2026-45066","affectedVersions":"\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qc95-4862-92fh"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45066.yaml"}]},{"advisoryId":"PKSA-t5z9-jvfg-zqhb","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45064.yaml","title":"CVE-2026-45064: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters \u2192 Visual href Spoofing","link":"https:\/\/symfony.com\/cve-2026-45064","cve":"CVE-2026-45064","affectedVersions":"\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h5vq-qfcg-4m6p"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45064.yaml"}]},{"advisoryId":"PKSA-1jhn-nv8n-vjk2","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45755.yaml","title":"CVE-2026-45755: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC: Unauthenticated Webhook Event Injection","link":"https:\/\/symfony.com\/cve-2026-45755","cve":"CVE-2026-45755","affectedVersions":"\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-59f3-vp2f-mp9w"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45755.yaml"}]},{"advisoryId":"PKSA-wyg9-y12c-3kdv","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45063.yaml","title":"CVE-2026-45063: Identity Spoofing via Unanchored DN Regex in X509Authenticator","link":"https:\/\/symfony.com\/cve-2026-45063","cve":"CVE-2026-45063","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-ph86-p8f6-f9r2"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45063.yaml"}]},{"advisoryId":"PKSA-3f27-q682-kfn9","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45065.yaml","title":"CVE-2026-45065: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation \u2192 Off-Site \/\/host URL Injection","link":"https:\/\/symfony.com\/cve-2026-45065","cve":"CVE-2026-45065","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-72xp-p242-47p9"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45065.yaml"}]},{"advisoryId":"PKSA-92n4-ftnd-xj82","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-46626.yaml","title":"CVE-2026-46626: SymfonyRuntime CVE-2024-50340 Patch Bypass: Web Requests Can Still Set APP_ENV\/APP_DEBUG via parse_str\/SAPI Argv Mismatch","link":"https:\/\/symfony.com\/cve-2026-46626","cve":"CVE-2026-46626","affectedVersions":"\u003E=5.4.46,\u003C5.4.52|\u003E=6.4.14,\u003C6.4.40|\u003E=7.1.7,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-46626.yaml"}]},{"advisoryId":"PKSA-z2fd-3m4y-rrss","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45067.yaml","title":"CVE-2026-45067: Email Header \/ SMTP Command Injection via CRLF in Symfony\\Component\\Mime\\Address","link":"https:\/\/symfony.com\/cve-2026-45067","cve":"CVE-2026-45067","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qpmx-3rfj-7rhv"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45067.yaml"}]},{"advisoryId":"PKSA-mbth-mcd4-2tr8","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45074.yaml","title":"CVE-2026-45074: Cas2Handler Derives CAS service URL from Client Host Header \u2192 Cross-Service Ticket Replay","link":"https:\/\/symfony.com\/cve-2026-45074","cve":"CVE-2026-45074","affectedVersions":"\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j8gj-9rm5-4xhx"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45074.yaml"}]},{"advisoryId":"PKSA-wps4-zyhx-xws4","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45133.yaml","title":"CVE-2026-45133: YAML Parser Stack Exhaustion via Unbounded Recursion in Nested Blocks, Sequences, and Mappings","link":"https:\/\/symfony.com\/cve-2026-45133","cve":"CVE-2026-45133","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-c2p3-7m5p-cv8x"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45133.yaml"}]},{"advisoryId":"PKSA-smg5-pq2q-kjkh","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45072.yaml","title":"CVE-2026-45072: Stored XSS in WebProfiler CodeExtension::fileExcerpt(): Unescaped Non-PHP File Rendering","link":"https:\/\/symfony.com\/cve-2026-45072","cve":"CVE-2026-45072","affectedVersions":"\u003E=6.4.24,\u003C6.4.40|\u003E=7.2.9,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-hmr5-2xcr-v8pp"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45072.yaml"}]},{"advisoryId":"PKSA-xxm6-3p32-rqz7","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45075.yaml","title":"CVE-2026-45075: HEAD Request Bypasses methods: [\u0027GET\u0027] Filter in #[IsGranted] \/ #[IsSignatureValid] \/ #[IsCsrfTokenValid]","link":"https:\/\/symfony.com\/cve-2026-45075","cve":"CVE-2026-45075","affectedVersions":"\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6439-2f28-8p8q"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45075.yaml"}]},{"advisoryId":"PKSA-2xjm-ff52-fzd5","packageName":"symfony\/symfony","remoteId":"GHSA-r39x-jcww-82v6","title":"Symfony\u0027s incorrect argument escaping under MSYS2\/Git Bash can lead to destructive file operations on Windows","link":"https:\/\/github.com\/advisories\/GHSA-r39x-jcww-82v6","cve":"CVE-2026-24739","affectedVersions":"\u003E=8.0,\u003C8.0.5|\u003E=7.4,\u003C7.4.5|\u003E=7.3,\u003C7.3.11|\u003E=6.4,\u003C6.4.33|\u003C5.4.51","source":"GitHub","reportedAt":"2026-01-28 21:28:10","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r39x-jcww-82v6"}]},{"advisoryId":"PKSA-nqwp-2kdm-491t","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2025-64500.yaml","title":"CVE-2025-64500: Incorrect parsing of PATH_INFO can lead to limited authorization bypass","link":"https:\/\/symfony.com\/blog\/cve-2025-64500-incorrect-parsing-of-path-info-can-lead-to-limited-authorization-bypass","cve":"CVE-2025-64500","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.50|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.29|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.3.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2025-11-12 11:09:14","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3rg7-wf37-54rm"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2025-64500.yaml"}]}],"pheditor\/pheditor":[{"advisoryId":"PKSA-5cjp-hkk1-6kzk","packageName":"pheditor\/pheditor","remoteId":"GHSA-jvc5-6g7q-c843","title":"Pheditor: OS Command Injection in terminal handler via unsanitized \u0027dir\u0027 parameter","link":"https:\/\/github.com\/advisories\/GHSA-jvc5-6g7q-c843","cve":"CVE-2026-48030","affectedVersions":"\u003E=2.0.1,\u003C=2.0.3","source":"GitHub","reportedAt":"2026-06-09 22:00:35","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-jvc5-6g7q-c843"}]}],"guzzlehttp\/guzzle-services":[{"advisoryId":"PKSA-39d7-zgf3-b3y1","packageName":"guzzlehttp\/guzzle-services","remoteId":"guzzlehttp\/guzzle-services\/CVE-2026-53723.yaml","title":"XML injection via CDATA terminator in XML request serialization","link":"https:\/\/github.com\/guzzle\/guzzle-services\/security\/advisories\/GHSA-q8r6-5hfw-5jff","cve":"CVE-2026-53723","affectedVersions":"\u003C1.5.4","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-02 11:38:10","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q8r6-5hfw-5jff"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/guzzle-services\/CVE-2026-53723.yaml"}]}],"codeigniter4\/framework":[{"advisoryId":"PKSA-217t-qqjr-nkt3","packageName":"codeigniter4\/framework","remoteId":"GHSA-2gr4-ppc7-7mhx","title":"CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule","link":"https:\/\/github.com\/advisories\/GHSA-2gr4-ppc7-7mhx","cve":"CVE-2026-48062","affectedVersions":"\u003C4.7.2","source":"GitHub","reportedAt":"2026-06-11 17:16:09","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-2gr4-ppc7-7mhx"}]}],"filament\/actions":[{"advisoryId":"PKSA-ndkp-2znf-9m7c","packageName":"filament\/actions","remoteId":"GHSA-7q3w-xqjw-g3cr","title":"Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields","link":"https:\/\/github.com\/advisories\/GHSA-7q3w-xqjw-g3cr","cve":"CVE-2026-48067","affectedVersions":"\u003E=5.0.0,\u003C=5.6.3|\u003E=4.0.0,\u003C=4.11.3","source":"GitHub","reportedAt":"2026-06-11 20:26:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7q3w-xqjw-g3cr"}]}],"typo3\/cms-core":[{"advisoryId":"PKSA-32mm-z25f-2ysj","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-47351.yaml","title":"TYPO3-CORE-SA-2026-014: Broken Access Control in Clipboard","link":"https:\/\/typo3.org\/security\/advisory\/typo3-core-sa-2026-014","cve":"CVE-2026-47351","affectedVersions":"\u003C10.4.57|\u003E=11.0.0,\u003C11.5.51|\u003E=12.0.0,\u003C12.4.46|\u003E=13.0.0,\u003C13.4.31|\u003E=14.0.0,\u003C14.3.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-09 09:00:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q93m-25xv-94hh"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-47351.yaml"}]},{"advisoryId":"PKSA-q3vc-jr63-rrrj","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-49740.yaml","title":"TYPO3-CORE-SA-2026-018: Insecure Deserialization in Core API","link":"https:\/\/typo3.org\/security\/advisory\/typo3-core-sa-2026-018","cve":"CVE-2026-49740","affectedVersions":"\u003C10.4.57|\u003E=11.0.0,\u003C11.5.51|\u003E=12.0.0,\u003C12.4.46|\u003E=13.0.0,\u003C13.4.31|\u003E=14.0.0,\u003C14.3.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-09 09:03:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c78m-c52x-jgwp"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-49740.yaml"}]},{"advisoryId":"PKSA-pg93-52nb-x8ym","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-47348.yaml","title":"TYPO3-CORE-SA-2026-010: Cross-Site Scripting in Indexed Search","link":"https:\/\/typo3.org\/security\/advisory\/typo3-core-sa-2026-010","cve":"CVE-2026-47348","affectedVersions":"\u003E=13.0.0,\u003C13.4.31|\u003E=14.0.0,\u003C14.3.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-09 08:57:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cg75-qfg2-w9hj"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-47348.yaml"}]},{"advisoryId":"PKSA-gj1k-954p-nhmk","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-49738.yaml","title":"TYPO3-CORE-SA-2026-016: Broken Access Control in File Abstraction Layer","link":"https:\/\/typo3.org\/security\/advisory\/typo3-core-sa-2026-016","cve":"CVE-2026-49738","affectedVersions":"\u003C10.4.57|\u003E=11.0.0,\u003C11.5.51|\u003E=12.0.0,\u003C12.4.46|\u003E=13.0.0,\u003C13.4.31|\u003E=14.0.0,\u003C14.3.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-09 09:01:48","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-jf56-v8jc-jcc5"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-49738.yaml"}]},{"advisoryId":"PKSA-gr4f-6g49-cg8v","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-47352.yaml","title":"TYPO3-CORE-SA-2026-015: Broken Access Control in Backend API","link":"https:\/\/typo3.org\/security\/advisory\/typo3-core-sa-2026-015","cve":"CVE-2026-47352","affectedVersions":"\u003C10.4.57|\u003E=11.0.0,\u003C11.5.51|\u003E=12.0.0,\u003C12.4.46|\u003E=13.0.0,\u003C13.4.31|\u003E=14.0.0,\u003C14.3.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-09 09:01:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2j54-93q2-3hjq"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-47352.yaml"}]},{"advisoryId":"PKSA-6jfs-jhtj-72x7","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-47346.yaml","title":"TYPO3-CORE-SA-2026-008: Broken Access Control in Form Framework","link":"https:\/\/typo3.org\/security\/advisory\/typo3-core-sa-2026-008","cve":"CVE-2026-47346","affectedVersions":"\u003C10.4.57|\u003E=11.0.0,\u003C11.5.51|\u003E=12.0.0,\u003C12.4.46|\u003E=13.0.0,\u003C13.4.31|\u003E=14.0.0,\u003C14.3.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-09 08:56:21","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hwvq-2w67-rvxp"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-47346.yaml"}]},{"advisoryId":"PKSA-2yr3-by9d-r1gh","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-11607.yaml","title":"TYPO3-CORE-SA-2026-019: Broken Access Control in Form Framework","link":"https:\/\/typo3.org\/security\/advisory\/typo3-core-sa-2026-019","cve":"CVE-2026-11607","affectedVersions":"\u003C10.4.57|\u003E=11.0.0,\u003C11.5.51|\u003E=12.0.0,\u003C12.4.46|\u003E=13.0.0,\u003C13.4.31|\u003E=14.0.0,\u003C14.3.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-09 09:06:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pjpj-v387-x4vq"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-11607.yaml"}]},{"advisoryId":"PKSA-bzt2-2962-49bj","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-47349.yaml","title":"TYPO3-CORE-SA-2026-011: Broken Access Control in Recycler","link":"https:\/\/typo3.org\/security\/advisory\/typo3-core-sa-2026-011","cve":"CVE-2026-47349","affectedVersions":"\u003C10.4.57|\u003E=11.0.0,\u003C11.5.51|\u003E=12.0.0,\u003C12.4.46|\u003E=13.0.0,\u003C13.4.31|\u003E=14.0.0,\u003C14.3.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-09 08:58:19","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f34x-rx2w-7pm3"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-47349.yaml"}]},{"advisoryId":"PKSA-vbrn-fwpj-xmx5","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-49742.yaml","title":"TYPO3-CORE-SA-2026-013: Broken Access Control in Media Module","link":"https:\/\/typo3.org\/security\/advisory\/typo3-core-sa-2026-013","cve":"CVE-2026-49742","affectedVersions":"\u003E=11.0.0,\u003C11.5.51|\u003E=12.0.0,\u003C12.4.46|\u003E=13.0.0,\u003C13.4.31|\u003E=14.0.0,\u003C14.3.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-09 08:59:35","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-chm7-4vch-h8vr"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-49742.yaml"}]},{"advisoryId":"PKSA-s3vj-chpj-8wrn","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-47347.yaml","title":"TYPO3-CORE-SA-2026-009: Open Redirect in TYPO3 CMS","link":"https:\/\/typo3.org\/security\/advisory\/typo3-core-sa-2026-009","cve":"CVE-2026-47347","affectedVersions":"\u003C10.4.57|\u003E=11.0.0,\u003C11.5.51|\u003E=12.0.0,\u003C12.4.46|\u003E=13.0.0,\u003C13.4.31|\u003E=14.0.0,\u003C14.3.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-09 08:57:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3p42-w5ch-gg42"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-47347.yaml"}]},{"advisoryId":"PKSA-ghx2-mc2z-fx6x","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-47343.yaml","title":"TYPO3-CORE-SA-2026-007: Broken Access Control in File Abstraction Layer","link":"https:\/\/typo3.org\/security\/advisory\/typo3-core-sa-2026-007","cve":"CVE-2026-47343","affectedVersions":"\u003C10.4.57|\u003E=11.0.0,\u003C11.5.51|\u003E=12.0.0,\u003C12.4.46|\u003E=13.0.0,\u003C13.4.31|\u003E=14.0.0,\u003C14.3.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-09 08:55:42","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3v8v-4wg6-r7qh"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-47343.yaml"}]},{"advisoryId":"PKSA-vv7s-w171-wb2j","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-47350.yaml","title":"TYPO3-CORE-SA-2026-012: Broken Access Control in DataHandler","link":"https:\/\/typo3.org\/security\/advisory\/typo3-core-sa-2026-012","cve":"CVE-2026-47350","affectedVersions":"\u003E=13.0.0,\u003C13.4.31|\u003E=14.0.0,\u003C14.3.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-09 08:58:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qcmw-6rm2-5x78"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-47350.yaml"}]},{"advisoryId":"PKSA-hqhs-7j5f-td2d","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-49741.yaml","title":"TYPO3-CORE-SA-2026-017: Privilege Escalation \u0026amp; SQL Injection in Form Framework","link":"https:\/\/typo3.org\/security\/advisory\/typo3-core-sa-2026-017","cve":"CVE-2026-49741","affectedVersions":"\u003E=14.0.0,\u003C14.3.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-09 09:02:19","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jh32-v29g-68pq"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-49741.yaml"}]},{"advisoryId":"PKSA-rtck-8z1q-gn5s","packageName":"typo3\/cms-core","remoteId":"GHSA-7vp9-x248-9vr9","title":"TYPO3 CMS Allows Insecure Deserialization via Mailer File Spool","link":"https:\/\/github.com\/advisories\/GHSA-7vp9-x248-9vr9","cve":"CVE-2026-0859","affectedVersions":"\u003E=10.0.0,\u003C=10.4.54|\u003E=11.0.0,\u003C=11.5.48|\u003E=12.0.0,\u003C=12.4.40|\u003E=13.0.0,\u003C=13.4.22|\u003E=14.0.0,\u003C=14.0.1","source":"GitHub","reportedAt":"2026-01-13 21:54:06","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7vp9-x248-9vr9"}]}],"typo3\/html-sanitizer":[{"advisoryId":"PKSA-7jn3-yc49-35c6","packageName":"typo3\/html-sanitizer","remoteId":"typo3\/html-sanitizer\/CVE-2026-47345.yaml","title":"TYPO3-CORE-SA-2026-006: TYPO3 HTML Sanitizer allows Cross-Site Scripting","link":"https:\/\/typo3.org\/security\/advisory\/typo3-core-sa-2026-006","cve":"CVE-2026-47345","affectedVersions":"\u003C2.3.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-08 20:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-p5j5-4j3q-8mq8"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/html-sanitizer\/CVE-2026-47345.yaml"}]},{"advisoryId":"PKSA-5mxx-9w1m-fqfb","packageName":"typo3\/html-sanitizer","remoteId":"typo3\/html-sanitizer\/CVE-2026-47344.yaml","title":"TYPO3-CORE-SA-2026-006: TYPO3 HTML Sanitizer allows Cross-Site Scripting","link":"https:\/\/typo3.org\/security\/advisory\/typo3-core-sa-2026-006","cve":"CVE-2026-47344","affectedVersions":"\u003C2.3.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-08 20:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-jvf5-rxvv-3mcg"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/html-sanitizer\/CVE-2026-47344.yaml"}]}],"shopware\/shopware":[{"advisoryId":"PKSA-62rz-jzfj-ym5j","packageName":"shopware\/shopware","remoteId":"GHSA-3pcr-4982-548m","title":"Exposure of .env if project root is configured as web root in shopware\/production","link":"https:\/\/github.com\/advisories\/GHSA-3pcr-4982-548m","cve":null,"affectedVersions":"\u003C=6.3.5.2","source":"GitHub","reportedAt":"2021-04-13 15:13:37","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3pcr-4982-548m"}]},{"advisoryId":"PKSA-bc17-t4m6-cf6m","packageName":"shopware\/shopware","remoteId":"GHSA-7cw6-7h3h-v8pf","title":"Shopware Has Improper Control of Generation of Code in Twig rendered views","link":"https:\/\/github.com\/advisories\/GHSA-7cw6-7h3h-v8pf","cve":"CVE-2026-23498","affectedVersions":"\u003E=6.7.0.0,\u003C6.7.6.1","source":"GitHub","reportedAt":"2026-01-14 16:54:27","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7cw6-7h3h-v8pf"}]},{"advisoryId":"PKSA-fpkr-chs9-vmj6","packageName":"shopware\/shopware","remoteId":"GHSA-6w82-v552-wjw2","title":"Shopware Storefront Reflected XSS in Storefront Login Page","link":"https:\/\/github.com\/advisories\/GHSA-6w82-v552-wjw2","cve":"CVE-2025-67648","affectedVersions":"\u003E=6.7.0.0,\u003C6.7.5.1|\u003E=6.4.6.0,\u003C6.6.10.10","source":"GitHub","reportedAt":"2025-12-09 17:24:21","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6w82-v552-wjw2"}]}],"phpoffice\/phpspreadsheet":[{"advisoryId":"PKSA-x678-4z45-v3d5","packageName":"phpoffice\/phpspreadsheet","remoteId":"GHSA-87m4-826x-3crx","title":"PHPSpreadsheet has a patch bypass for CVE-2026-34084 ","link":"https:\/\/github.com\/advisories\/GHSA-87m4-826x-3crx","cve":"CVE-2026-45034","affectedVersions":"\u003C=1.30.4","source":"GitHub","reportedAt":"2026-06-08 23:00:14","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-87m4-826x-3crx"}]},{"advisoryId":"PKSA-8cfg-tzhf-fr83","packageName":"phpoffice\/phpspreadsheet","remoteId":"GHSA-q4q6-r8wh-5cgh","title":"PhpSpreadsheet has SSRF\/RCE in IOFactory::load when $filename is user controlled","link":"https:\/\/github.com\/advisories\/GHSA-q4q6-r8wh-5cgh","cve":"CVE-2026-34084","affectedVersions":"\u003C=1.30.2|\u003E=2.0.0,\u003C=2.1.14|\u003E=2.2.0,\u003C=2.4.3|\u003E=3.3.0,\u003C=3.10.3|\u003E=4.0.0,\u003C=5.5.0","source":"GitHub","reportedAt":"2026-04-29 20:22:30","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-q4q6-r8wh-5cgh"}]},{"advisoryId":"PKSA-x13r-n4wc-4gcr","packageName":"phpoffice\/phpspreadsheet","remoteId":"GHSA-84wq-86v6-x5j6","title":"PhpSpreadsheet has CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader","link":"https:\/\/github.com\/advisories\/GHSA-84wq-86v6-x5j6","cve":"CVE-2026-40863","affectedVersions":"\u003C=1.30.3|\u003E=2.0.0,\u003C=2.1.15|\u003E=2.2.0,\u003C=2.4.4|\u003E=3.3.0,\u003C=3.10.4|\u003E=4.0.0,\u003C=5.6.0","source":"GitHub","reportedAt":"2026-04-29 20:23:27","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-84wq-86v6-x5j6"}]},{"advisoryId":"PKSA-gz3f-3cz3-3wsw","packageName":"phpoffice\/phpspreadsheet","remoteId":"GHSA-7c6m-4442-2x6m","title":"PhpSpreadsheet has CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions","link":"https:\/\/github.com\/advisories\/GHSA-7c6m-4442-2x6m","cve":"CVE-2026-40902","affectedVersions":"\u003C=1.30.3|\u003E=2.0.0,\u003C=2.1.15|\u003E=2.2.0,\u003C=2.4.4|\u003E=3.3.0,\u003C=3.10.4|\u003E=4.0.0,\u003C=5.6.0","source":"GitHub","reportedAt":"2026-04-29 20:24:13","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7c6m-4442-2x6m"}]},{"advisoryId":"PKSA-jtdk-dcr5-f11n","packageName":"phpoffice\/phpspreadsheet","remoteId":"GHSA-6wpp-88cp-7q68","title":"PhpSpreadsheet has XSS via NumberFormat @ Text Substitution in HTML Writer","link":"https:\/\/github.com\/advisories\/GHSA-6wpp-88cp-7q68","cve":"CVE-2026-35453","affectedVersions":"\u003C=1.30.3|\u003E=2.0.0,\u003C=2.1.15|\u003E=2.2.0,\u003C=2.4.4|\u003E=3.3.0,\u003C=3.10.4|\u003E=4.0.0,\u003C=5.6.0","source":"GitHub","reportedAt":"2026-04-28 22:50:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6wpp-88cp-7q68"}]},{"advisoryId":"PKSA-hznc-gbby-6w16","packageName":"phpoffice\/phpspreadsheet","remoteId":"GHSA-hrmw-qprp-wgmc","title":"PhpSpreadsheet has XSS via number format code with @ text placeholder bypasses htmlspecialchars in HTML writer","link":"https:\/\/github.com\/advisories\/GHSA-hrmw-qprp-wgmc","cve":"CVE-2026-40296","affectedVersions":"\u003C=1.30.3|\u003E=2.0.0,\u003C=2.1.15|\u003E=2.2.0,\u003C=2.4.4|\u003E=3.3.0,\u003C=3.10.4|\u003E=4.0.0,\u003C=5.6.0","source":"GitHub","reportedAt":"2026-04-28 22:57:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hrmw-qprp-wgmc"}]},{"advisoryId":"PKSA-v15t-c7gz-7kpt","packageName":"phpoffice\/phpspreadsheet","remoteId":"phpoffice\/phpspreadsheet\/CVE-2018-19277.yaml","title":"XXE Vulnerability","link":"https:\/\/github.com\/PHPOffice\/PhpSpreadsheet\/issues\/771","cve":"CVE-2018-19277","affectedVersions":"\u003C1.5.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2018-11-20 19:50:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xcrg-29h7-h4cj"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"phpoffice\/phpspreadsheet\/CVE-2018-19277.yaml"}]}],"poweradmin\/poweradmin":[{"advisoryId":"PKSA-8yh4-2h9f-995z","packageName":"poweradmin\/poweradmin","remoteId":"GHSA-3h6h-67x3-cv5x","title":"Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications","link":"https:\/\/github.com\/advisories\/GHSA-3h6h-67x3-cv5x","cve":"CVE-2026-47693","affectedVersions":"\u003E=4.3.0,\u003C4.3.3|\u003C4.2.4","source":"GitHub","reportedAt":"2026-06-08 23:04:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3h6h-67x3-cv5x"}]}],"shopper\/framework":[{"advisoryId":"PKSA-jg8p-p13z-fkym","packageName":"shopper\/framework","remoteId":"GHSA-h4mp-g9c6-xwph","title":"Shopper: Missing authorization on Product admin Livewire sub-form components","link":"https:\/\/github.com\/advisories\/GHSA-h4mp-g9c6-xwph","cve":"CVE-2026-47742","affectedVersions":"\u003C2.8.0","source":"GitHub","reportedAt":"2026-06-05 20:33:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h4mp-g9c6-xwph"}]},{"advisoryId":"PKSA-7v8h-262h-wzkz","packageName":"shopper\/framework","remoteId":"GHSA-fxqw-97cc-7g5c","title":"Shopper: Missing per-action authorization on PaymentMethods, Currencies and Carriers admin tables","link":"https:\/\/github.com\/advisories\/GHSA-fxqw-97cc-7g5c","cve":"CVE-2026-47745","affectedVersions":"\u003C2.8.0","source":"GitHub","reportedAt":"2026-06-05 20:34:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fxqw-97cc-7g5c"}]},{"advisoryId":"PKSA-88dm-mp91-mkr8","packageName":"shopper\/framework","remoteId":"GHSA-hr9v-r8r2-hg7j","title":"Shopper: Multiple data integrity and disclosure issues in admin Livewire components","link":"https:\/\/github.com\/advisories\/GHSA-hr9v-r8r2-hg7j","cve":"CVE-2026-47743","affectedVersions":"\u003C2.8.0","source":"GitHub","reportedAt":"2026-06-05 20:35:14","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hr9v-r8r2-hg7j"}]},{"advisoryId":"PKSA-5g52-7x8y-w2y1","packageName":"shopper\/framework","remoteId":"GHSA-c3qp-2ggw-xjg7","title":"Shopper: Authorization bypass and RBAC privilege escalation in team settings","link":"https:\/\/github.com\/advisories\/GHSA-c3qp-2ggw-xjg7","cve":"CVE-2026-47744","affectedVersions":"\u003C2.8.0","source":"GitHub","reportedAt":"2026-06-05 20:35:51","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-c3qp-2ggw-xjg7"}]},{"advisoryId":"PKSA-vtqh-k648-prz7","packageName":"shopper\/framework","remoteId":"GHSA-f946-9qp6-vgch","title":"shopper\/framework: Authorization bypass in multiple Livewire admin components","link":"https:\/\/github.com\/advisories\/GHSA-f946-9qp6-vgch","cve":"CVE-2026-47740","affectedVersions":"\u003C2.8.0","source":"GitHub","reportedAt":"2026-05-18 16:34:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f946-9qp6-vgch"}]}],"tinymce\/tinymce":[{"advisoryId":"PKSA-rf1b-835f-6yyv","packageName":"tinymce\/tinymce","remoteId":"GHSA-q742-qvgc-gc2f","title":"TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes","link":"https:\/\/github.com\/advisories\/GHSA-q742-qvgc-gc2f","cve":"CVE-2026-47759","affectedVersions":"\u003C=5.10.9|\u003E=8.0.0,\u003C8.5.1|\u003E=6.0.0,\u003C7.9.3","source":"GitHub","reportedAt":"2026-06-05 20:27:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-q742-qvgc-gc2f"}]},{"advisoryId":"PKSA-2v47-9p8y-4qt3","packageName":"tinymce\/tinymce","remoteId":"GHSA-v98h-vmpc-fpqv","title":"TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments","link":"https:\/\/github.com\/advisories\/GHSA-v98h-vmpc-fpqv","cve":"CVE-2026-47762","affectedVersions":"\u003E=8.0.0,\u003C8.5.1|\u003E=6.0.0,\u003C7.9.3|\u003C5.11.1","source":"GitHub","reportedAt":"2026-06-05 20:29:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v98h-vmpc-fpqv"}]},{"advisoryId":"PKSA-k4d6-bt7k-7ddp","packageName":"tinymce\/tinymce","remoteId":"GHSA-vg35-5wq7-3x7w","title":"TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection","link":"https:\/\/github.com\/advisories\/GHSA-vg35-5wq7-3x7w","cve":"CVE-2026-47761","affectedVersions":"\u003E0,\u003C=5.10.9|\u003E=8.0.0,\u003C8.5.1|\u003E=6.0.0,\u003C7.9.3","source":"GitHub","reportedAt":"2026-06-05 20:29:43","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vg35-5wq7-3x7w"}]},{"advisoryId":"PKSA-fp8q-vmhs-msy9","packageName":"tinymce\/tinymce","remoteId":"GHSA-mh5m-5hw4-5c69","title":"TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs","link":"https:\/\/github.com\/advisories\/GHSA-mh5m-5hw4-5c69","cve":"CVE-2026-47760","affectedVersions":"\u003E=6.8.0,\u003C7.1.0","source":"GitHub","reportedAt":"2026-06-05 20:09:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mh5m-5hw4-5c69"}]}],"billabear\/billabear":[{"advisoryId":"PKSA-tks4-h5gc-8mrj","packageName":"billabear\/billabear","remoteId":"GHSA-xp6r-8pcc-xv5p","title":"BillaBear is Vulnerable to SQL Injection in the EventRepository","link":"https:\/\/github.com\/advisories\/GHSA-xp6r-8pcc-xv5p","cve":"CVE-2026-31069","affectedVersions":"\u003C=2025.01.03","source":"GitHub","reportedAt":"2026-05-19 18:32:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xp6r-8pcc-xv5p"}]}],"shopware\/core":[{"advisoryId":"PKSA-yt77-qm1k-2vvb","packageName":"shopware\/core","remoteId":"GHSA-7w52-7jvm-m9vw","title":"Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames","link":"https:\/\/github.com\/advisories\/GHSA-7w52-7jvm-m9vw","cve":"CVE-2026-48011","affectedVersions":"\u003C6.6.10.18|\u003E=6.7.0.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:31:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7w52-7jvm-m9vw"}]},{"advisoryId":"PKSA-xknd-fd7t-crfc","packageName":"shopware\/core","remoteId":"GHSA-4x3x-869w-xx3m","title":"Shopware SSO referer trust leading to an arbitrary redirect target","link":"https:\/\/github.com\/advisories\/GHSA-4x3x-869w-xx3m","cve":"CVE-2026-48012","affectedVersions":"\u003E=6.7.3.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:32:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4x3x-869w-xx3m"}]},{"advisoryId":"PKSA-rnpb-7fbj-phyz","packageName":"shopware\/core","remoteId":"GHSA-f8q6-3g5w-jjr6","title":"Shopware: Admin API ACL Bypass in Order State Transition Endpoints","link":"https:\/\/github.com\/advisories\/GHSA-f8q6-3g5w-jjr6","cve":"CVE-2026-48014","affectedVersions":"\u003C6.6.10.18|\u003E=6.7.0.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:33:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f8q6-3g5w-jjr6"}]},{"advisoryId":"PKSA-y5sy-w7mt-r97k","packageName":"shopware\/core","remoteId":"GHSA-9v5m-39wh-5chq","title":"Shopware: Unauthorized Payment Trigger for Foreign Orders via \/store-api\/handle-payment","link":"https:\/\/github.com\/advisories\/GHSA-9v5m-39wh-5chq","cve":"CVE-2026-48016","affectedVersions":"\u003C6.6.10.18|\u003E=6.7.0.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:33:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9v5m-39wh-5chq"}]},{"advisoryId":"PKSA-qf56-zbmm-29m8","packageName":"shopware\/core","remoteId":"GHSA-xvhc-gm7j-mhmc","title":"Shopware: Stored XSS via SVG file upload \u2014 no SVG sanitization","link":"https:\/\/github.com\/advisories\/GHSA-xvhc-gm7j-mhmc","cve":"CVE-2026-48015","affectedVersions":"\u003C6.6.10.18|\u003E=6.7.0.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:35:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xvhc-gm7j-mhmc"}]},{"advisoryId":"PKSA-9x83-17hb-ky3t","packageName":"shopware\/core","remoteId":"GHSA-gq96-5pfx-f4vc","title":"Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation","link":"https:\/\/github.com\/advisories\/GHSA-gq96-5pfx-f4vc","cve":"CVE-2026-48013","affectedVersions":"\u003E=6.7.0.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:36:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gq96-5pfx-f4vc"}]},{"advisoryId":"PKSA-zymb-qg2c-csgb","packageName":"shopware\/core","remoteId":"GHSA-gv8p-48fr-4fxg","title":"Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass","link":"https:\/\/github.com\/advisories\/GHSA-gv8p-48fr-4fxg","cve":"CVE-2026-48008","affectedVersions":"\u003C6.6.10.18|\u003E=6.7.0.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:23:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gv8p-48fr-4fxg"}]},{"advisoryId":"PKSA-946b-qy3w-67d7","packageName":"shopware\/core","remoteId":"GHSA-8v9p-g828-v98f","title":"Shopware: Admin Account Takeover via User Recovery Hash Exposure","link":"https:\/\/github.com\/advisories\/GHSA-8v9p-g828-v98f","cve":"CVE-2026-48009","affectedVersions":"\u003C6.6.10.18|\u003E=6.7.0.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:27:15","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8v9p-g828-v98f"}]},{"advisoryId":"PKSA-fstf-sh35-tmx7","packageName":"shopware\/core","remoteId":"GHSA-v39m-97p8-gqg7","title":"Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts","link":"https:\/\/github.com\/advisories\/GHSA-v39m-97p8-gqg7","cve":"CVE-2026-48010","affectedVersions":"\u003C6.6.10.18|\u003E=6.7.0.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:28:29","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-v39m-97p8-gqg7"}]},{"advisoryId":"PKSA-1d39-xhww-sgwf","packageName":"shopware\/core","remoteId":"GHSA-7vvp-j573-5584","title":"Shopware: Unauthenticated data extraction possible through store-api.order endpoint","link":"https:\/\/github.com\/advisories\/GHSA-7vvp-j573-5584","cve":"CVE-2026-31887","affectedVersions":"\u003C6.6.10.15|\u003E=6.7.0.0,\u003C6.7.8.1","source":"GitHub","reportedAt":"2026-03-11 19:23:43","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7vvp-j573-5584"}]},{"advisoryId":"PKSA-cck7-yytv-pqc6","packageName":"shopware\/core","remoteId":"GHSA-gqc5-xv7m-gcjq","title":"Shopware has user enumeration via distinct error codes on Store API login endpoint","link":"https:\/\/github.com\/advisories\/GHSA-gqc5-xv7m-gcjq","cve":"CVE-2026-31888","affectedVersions":"\u003C6.6.10.15|\u003E=6.7.0.0,\u003C6.7.8.1","source":"GitHub","reportedAt":"2026-03-11 19:23:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gqc5-xv7m-gcjq"}]},{"advisoryId":"PKSA-fyfg-936j-xtjc","packageName":"shopware\/core","remoteId":"GHSA-c4p7-rwrg-pf6p","title":"Shopware vulnerable to a potential take over of app credentials","link":"https:\/\/github.com\/advisories\/GHSA-c4p7-rwrg-pf6p","cve":"CVE-2026-31889","affectedVersions":"\u003C6.6.10.15|\u003E=6.7.0.0,\u003C6.7.8.1","source":"GitHub","reportedAt":"2026-03-11 19:24:06","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c4p7-rwrg-pf6p"}]},{"advisoryId":"PKSA-sj7p-kg8p-gg2k","packageName":"shopware\/core","remoteId":"GHSA-7cw6-7h3h-v8pf","title":"Shopware Has Improper Control of Generation of Code in Twig rendered views","link":"https:\/\/github.com\/advisories\/GHSA-7cw6-7h3h-v8pf","cve":"CVE-2026-23498","affectedVersions":"\u003E=6.7.0.0,\u003C6.7.6.1","source":"GitHub","reportedAt":"2026-01-14 16:54:27","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7cw6-7h3h-v8pf"}]},{"advisoryId":"PKSA-w3qy-s9h7-2hqr","packageName":"shopware\/core","remoteId":"GHSA-2w46-vq8h-98vh","title":"Shopware 6\u0027s password recovery link does not expire after email change","link":"https:\/\/github.com\/advisories\/GHSA-2w46-vq8h-98vh","cve":null,"affectedVersions":"\u003E=6.7.0.0,\u003C6.7.4.1|\u003C6.6.10.9","source":"GitHub","reportedAt":"2025-11-14 20:42:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2w46-vq8h-98vh"}]},{"advisoryId":"PKSA-b824-t6kf-bqqz","packageName":"shopware\/core","remoteId":"GHSA-m895-2hj3-8cg9","title":"Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individually","link":"https:\/\/github.com\/advisories\/GHSA-m895-2hj3-8cg9","cve":null,"affectedVersions":"\u003C6.6.10.7|\u003E=6.7.0.0,\u003C6.7.3.1","source":"GitHub","reportedAt":"2025-10-21 18:02:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m895-2hj3-8cg9"}]},{"advisoryId":"PKSA-6wp3-462p-vyty","packageName":"shopware\/core","remoteId":"GHSA-6wh5-mw9h-5c3w","title":"Shopware vulnerable to path traversal via Plugin upload","link":"https:\/\/github.com\/advisories\/GHSA-6wh5-mw9h-5c3w","cve":null,"affectedVersions":"\u003C6.6.10.7|\u003E=6.7.0.0,\u003C6.7.3.1","source":"GitHub","reportedAt":"2025-10-21 18:02:14","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-6wh5-mw9h-5c3w"}]},{"advisoryId":"PKSA-h5dj-jyqc-4fjr","packageName":"shopware\/core","remoteId":"GHSA-3cpp-fv95-mpr5","title":"Shopware vulnerable to Server-Side Request Forgery (SSRF) \u2013 order invoice","link":"https:\/\/github.com\/advisories\/GHSA-3cpp-fv95-mpr5","cve":null,"affectedVersions":"\u003C6.6.10.7|\u003E=6.7.0.0,\u003C6.7.3.1","source":"GitHub","reportedAt":"2025-10-21 18:02:52","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-3cpp-fv95-mpr5"}]},{"advisoryId":"PKSA-kypv-cx5n-qkc8","packageName":"shopware\/core","remoteId":"GHSA-27c9-vp3w-6ww8","title":"Shopware exposes sensitive user information via CSV export mapping","link":"https:\/\/github.com\/advisories\/GHSA-27c9-vp3w-6ww8","cve":null,"affectedVersions":"\u003C6.6.10.7|\u003E=6.7.0.0,\u003C6.7.3.1","source":"GitHub","reportedAt":"2025-10-21 18:03:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-27c9-vp3w-6ww8"}]},{"advisoryId":"PKSA-v415-g75g-bqsy","packageName":"shopware\/core","remoteId":"GHSA-r2vg-hvjm-fg38","title":"Shopware Customer Orders can be canceled, even if refunds are disabled","link":"https:\/\/github.com\/advisories\/GHSA-r2vg-hvjm-fg38","cve":null,"affectedVersions":"\u003C6.6.10.7|\u003E=6.7.0.0,\u003C6.7.3.1","source":"GitHub","reportedAt":"2025-10-21 18:03:27","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r2vg-hvjm-fg38"}]},{"advisoryId":"PKSA-kd1k-vbw9-69fx","packageName":"shopware\/core","remoteId":"GHSA-7v2v-9rm4-7m8f","title":"Shopware Has Improper Control of Generation of Code in Twig rendered views","link":"https:\/\/github.com\/advisories\/GHSA-7v2v-9rm4-7m8f","cve":"CVE-2023-2017","affectedVersions":"\u003C=6.4.20.0","source":"GitHub","reportedAt":"2023-04-18 13:14:20","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7v2v-9rm4-7m8f"}]}],"shopware\/platform":[{"advisoryId":"PKSA-xwkj-rryn-xz6v","packageName":"shopware\/platform","remoteId":"GHSA-7w52-7jvm-m9vw","title":"Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames","link":"https:\/\/github.com\/advisories\/GHSA-7w52-7jvm-m9vw","cve":"CVE-2026-48011","affectedVersions":"\u003C6.6.10.18|\u003E=6.7.0.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:31:17","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7w52-7jvm-m9vw"}]},{"advisoryId":"PKSA-54rn-sm9v-17vx","packageName":"shopware\/platform","remoteId":"GHSA-4x3x-869w-xx3m","title":"Shopware SSO referer trust leading to an arbitrary redirect target","link":"https:\/\/github.com\/advisories\/GHSA-4x3x-869w-xx3m","cve":"CVE-2026-48012","affectedVersions":"\u003E=6.7.3.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:32:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4x3x-869w-xx3m"}]},{"advisoryId":"PKSA-1xdm-446c-t7rz","packageName":"shopware\/platform","remoteId":"GHSA-f8q6-3g5w-jjr6","title":"Shopware: Admin API ACL Bypass in Order State Transition Endpoints","link":"https:\/\/github.com\/advisories\/GHSA-f8q6-3g5w-jjr6","cve":"CVE-2026-48014","affectedVersions":"\u003C6.6.10.18|\u003E=6.7.0.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:33:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f8q6-3g5w-jjr6"}]},{"advisoryId":"PKSA-6c8x-wdsy-zx17","packageName":"shopware\/platform","remoteId":"GHSA-9v5m-39wh-5chq","title":"Shopware: Unauthorized Payment Trigger for Foreign Orders via \/store-api\/handle-payment","link":"https:\/\/github.com\/advisories\/GHSA-9v5m-39wh-5chq","cve":"CVE-2026-48016","affectedVersions":"\u003C6.6.10.18|\u003E=6.7.0.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:33:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9v5m-39wh-5chq"}]},{"advisoryId":"PKSA-xngt-2zh8-qhq6","packageName":"shopware\/platform","remoteId":"GHSA-xvhc-gm7j-mhmc","title":"Shopware: Stored XSS via SVG file upload \u2014 no SVG sanitization","link":"https:\/\/github.com\/advisories\/GHSA-xvhc-gm7j-mhmc","cve":"CVE-2026-48015","affectedVersions":"\u003C6.6.10.18|\u003E=6.7.0.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:35:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xvhc-gm7j-mhmc"}]},{"advisoryId":"PKSA-yg4m-g48j-bdvp","packageName":"shopware\/platform","remoteId":"GHSA-gq96-5pfx-f4vc","title":"Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation","link":"https:\/\/github.com\/advisories\/GHSA-gq96-5pfx-f4vc","cve":"CVE-2026-48013","affectedVersions":"\u003E=6.7.0.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:36:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gq96-5pfx-f4vc"}]},{"advisoryId":"PKSA-b8bq-4ngt-d89p","packageName":"shopware\/platform","remoteId":"GHSA-gv8p-48fr-4fxg","title":"Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass","link":"https:\/\/github.com\/advisories\/GHSA-gv8p-48fr-4fxg","cve":"CVE-2026-48008","affectedVersions":"\u003C6.6.10.18|\u003E=6.7.0.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:23:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gv8p-48fr-4fxg"}]},{"advisoryId":"PKSA-tk1x-h875-8y1s","packageName":"shopware\/platform","remoteId":"GHSA-8v9p-g828-v98f","title":"Shopware: Admin Account Takeover via User Recovery Hash Exposure","link":"https:\/\/github.com\/advisories\/GHSA-8v9p-g828-v98f","cve":"CVE-2026-48009","affectedVersions":"\u003C6.6.10.18|\u003E=6.7.0.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:27:15","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8v9p-g828-v98f"}]},{"advisoryId":"PKSA-xbrd-fvys-3t24","packageName":"shopware\/platform","remoteId":"GHSA-v39m-97p8-gqg7","title":"Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts","link":"https:\/\/github.com\/advisories\/GHSA-v39m-97p8-gqg7","cve":"CVE-2026-48010","affectedVersions":"\u003C6.6.10.18|\u003E=6.7.0.0,\u003C6.7.10.1","source":"GitHub","reportedAt":"2026-06-04 19:28:29","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-v39m-97p8-gqg7"}]},{"advisoryId":"PKSA-bwqq-zb6b-g5dh","packageName":"shopware\/platform","remoteId":"GHSA-7vvp-j573-5584","title":"Shopware: Unauthenticated data extraction possible through store-api.order endpoint","link":"https:\/\/github.com\/advisories\/GHSA-7vvp-j573-5584","cve":"CVE-2026-31887","affectedVersions":"\u003C6.6.10.15|\u003E=6.7.0.0,\u003C6.7.8.1","source":"GitHub","reportedAt":"2026-03-11 19:23:43","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7vvp-j573-5584"}]},{"advisoryId":"PKSA-8zg6-v85t-wcz3","packageName":"shopware\/platform","remoteId":"GHSA-gqc5-xv7m-gcjq","title":"Shopware has user enumeration via distinct error codes on Store API login endpoint","link":"https:\/\/github.com\/advisories\/GHSA-gqc5-xv7m-gcjq","cve":"CVE-2026-31888","affectedVersions":"\u003C6.6.10.14|\u003E=6.7.0.0,\u003C6.7.8.1","source":"GitHub","reportedAt":"2026-03-11 19:23:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gqc5-xv7m-gcjq"}]},{"advisoryId":"PKSA-qj2q-c8sp-3qyg","packageName":"shopware\/platform","remoteId":"GHSA-c4p7-rwrg-pf6p","title":"Shopware vulnerable to a potential take over of app credentials","link":"https:\/\/github.com\/advisories\/GHSA-c4p7-rwrg-pf6p","cve":"CVE-2026-31889","affectedVersions":"\u003C6.6.10.15|\u003E=6.7.0.0,\u003C6.7.8.1","source":"GitHub","reportedAt":"2026-03-11 19:24:06","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c4p7-rwrg-pf6p"}]},{"advisoryId":"PKSA-h7xc-cnc9-hq4s","packageName":"shopware\/platform","remoteId":"GHSA-m895-2hj3-8cg9","title":"Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individually","link":"https:\/\/github.com\/advisories\/GHSA-m895-2hj3-8cg9","cve":null,"affectedVersions":"\u003C6.6.10.7|\u003E=6.7.0.0,\u003C6.7.3.1","source":"GitHub","reportedAt":"2025-10-21 18:02:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m895-2hj3-8cg9"}]},{"advisoryId":"PKSA-wg2b-w14d-z55p","packageName":"shopware\/platform","remoteId":"GHSA-6wh5-mw9h-5c3w","title":"Shopware vulnerable to path traversal via Plugin upload","link":"https:\/\/github.com\/advisories\/GHSA-6wh5-mw9h-5c3w","cve":null,"affectedVersions":"\u003C6.6.10.7|\u003E=6.7.0.0,\u003C6.7.3.1","source":"GitHub","reportedAt":"2025-10-21 18:02:14","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-6wh5-mw9h-5c3w"}]},{"advisoryId":"PKSA-ph5g-5w5h-nqtz","packageName":"shopware\/platform","remoteId":"GHSA-3cpp-fv95-mpr5","title":"Shopware vulnerable to Server-Side Request Forgery (SSRF) \u2013 order invoice","link":"https:\/\/github.com\/advisories\/GHSA-3cpp-fv95-mpr5","cve":null,"affectedVersions":"\u003C6.6.10.7|\u003E=6.7.0.0,\u003C6.7.3.1","source":"GitHub","reportedAt":"2025-10-21 18:02:52","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-3cpp-fv95-mpr5"}]},{"advisoryId":"PKSA-cb17-wqsx-y85w","packageName":"shopware\/platform","remoteId":"GHSA-27c9-vp3w-6ww8","title":"Shopware exposes sensitive user information via CSV export mapping","link":"https:\/\/github.com\/advisories\/GHSA-27c9-vp3w-6ww8","cve":null,"affectedVersions":"\u003C6.6.10.7|\u003E=6.7.0.0,\u003C6.7.3.1","source":"GitHub","reportedAt":"2025-10-21 18:03:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-27c9-vp3w-6ww8"}]},{"advisoryId":"PKSA-g23j-x3sb-wcbc","packageName":"shopware\/platform","remoteId":"GHSA-r2vg-hvjm-fg38","title":"Shopware Customer Orders can be canceled, even if refunds are disabled","link":"https:\/\/github.com\/advisories\/GHSA-r2vg-hvjm-fg38","cve":null,"affectedVersions":"\u003C6.6.10.7|\u003E=6.7.0.0,\u003C6.7.3.1","source":"GitHub","reportedAt":"2025-10-21 18:03:27","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r2vg-hvjm-fg38"}]},{"advisoryId":"PKSA-hh61-vznp-4z86","packageName":"shopware\/platform","remoteId":"GHSA-c2f9-4jmm-v45m","title":"Shopware\u0027s session is persistent in Cache for 404 pages","link":"https:\/\/github.com\/advisories\/GHSA-c2f9-4jmm-v45m","cve":"CVE-2024-27917","affectedVersions":"\u003E=6.5.8.0,\u003C6.5.8.7","source":"GitHub","reportedAt":"2024-03-06 15:06:54","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c2f9-4jmm-v45m"}]},{"advisoryId":"PKSA-y73d-9xyp-2rvj","packageName":"shopware\/platform","remoteId":"GHSA-7v2v-9rm4-7m8f","title":"Shopware Has Improper Control of Generation of Code in Twig rendered views","link":"https:\/\/github.com\/advisories\/GHSA-7v2v-9rm4-7m8f","cve":"CVE-2023-2017","affectedVersions":"\u003C=6.4.20.0","source":"GitHub","reportedAt":"2023-04-18 13:14:20","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7v2v-9rm4-7m8f"}]},{"advisoryId":"PKSA-67qk-k65g-j8tn","packageName":"shopware\/platform","remoteId":"GHSA-h9q8-5gv2-v6mg","title":"Potential Session Hijacking","link":"https:\/\/github.com\/advisories\/GHSA-h9q8-5gv2-v6mg","cve":"CVE-2021-32710","affectedVersions":"\u003C=6.3.5.1","source":"GitHub","reportedAt":"2021-03-12 23:09:08","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-h9q8-5gv2-v6mg"}]}],"easycorp\/easyadmin-bundle":[{"advisoryId":"PKSA-8yhb-cz5n-f41h","packageName":"easycorp\/easyadmin-bundle","remoteId":"easycorp\/easyadmin-bundle\/GHSA-8559-gwj3-q37r.yaml","title":"Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField","link":"https:\/\/github.com\/EasyCorp\/EasyAdminBundle\/security\/advisories\/GHSA-8559-gwj3-q37r","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-04 06:43:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"easycorp\/easyadmin-bundle\/GHSA-8559-gwj3-q37r.yaml"}]},{"advisoryId":"PKSA-z6tn-c4hk-yb9y","packageName":"easycorp\/easyadmin-bundle","remoteId":"easycorp\/easyadmin-bundle\/GHSA-2wwr-9x6f-88gp.yaml","title":"Path traversal and reflected XSS in Flag and Icon Twig components","link":"https:\/\/github.com\/EasyCorp\/EasyAdminBundle\/security\/advisories\/GHSA-2wwr-9x6f-88gp","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C4.29.10|\u003E=5.0.0,\u003C5.0.10","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-28 18:30:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"easycorp\/easyadmin-bundle\/GHSA-2wwr-9x6f-88gp.yaml"},{"name":"GitHub","remoteId":"GHSA-2wwr-9x6f-88gp"}]}],"backpack\/crud":[{"advisoryId":"PKSA-8yrj-8khf-srxh","packageName":"backpack\/crud","remoteId":"GHSA-m8xx-3x29-84h8","title":"backpack\/crud is vulnerable to Cross-Site Scripting (XSS)","link":"https:\/\/github.com\/advisories\/GHSA-m8xx-3x29-84h8","cve":"CVE-2022-31114","affectedVersions":"\u003C4.0.63|\u003E=4.1.0,\u003C4.1.69|\u003E=5.0.0,\u003C5.0.13","source":"GitHub","reportedAt":"2026-06-03 20:25:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m8xx-3x29-84h8"}]}],"illuminate\/mail":[{"advisoryId":"PKSA-zwc5-qtrz-zm1n","packageName":"illuminate\/mail","remoteId":"illuminate\/mail\/CVE-2026-48019.yaml","title":"Laravel CRLF injection in default email rule","link":"https:\/\/github.com\/laravel\/framework\/security\/advisories\/GHSA-5vg9-5847-vvmq","cve":"CVE-2026-48019","affectedVersions":"\u003E=9.0.0,\u003C10.0.0|\u003E=10.0.0,\u003C11.0.0|\u003E=11.0.0,\u003C12.0.0|\u003E=12.0.0,\u003C12.60.0|\u003E=13.0.0,\u003C13.10.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-19 18:13:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"illuminate\/mail\/CVE-2026-48019.yaml"}]}],"phanan\/koel":[{"advisoryId":"PKSA-bprq-tfgm-1hd2","packageName":"phanan\/koel","remoteId":"GHSA-7j2f-6h2r-6cqc","title":"Koel Vulnerable to SSRF via Podcast Episode Enclosure URLs","link":"https:\/\/github.com\/advisories\/GHSA-7j2f-6h2r-6cqc","cve":"CVE-2026-47260","affectedVersions":"\u003C=9.3.4","source":"GitHub","reportedAt":"2026-05-29 19:56:06","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7j2f-6h2r-6cqc"}]}],"ezsystems\/ezpublish-legacy":[{"advisoryId":"PKSA-vrcj-tzjw-khtt","packageName":"ezsystems\/ezpublish-legacy","remoteId":"GHSA-xg9x-h37w-h3r3","title":"ezsystems\/ezpublish-legacy has a SQL injection in dfscleanup","link":"https:\/\/github.com\/advisories\/GHSA-xg9x-h37w-h3r3","cve":"CVE-2026-38739","affectedVersions":"=2019.03","source":"GitHub","reportedAt":"2026-05-29 19:07:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xg9x-h37w-h3r3"}]}],"symfony\/ux-live-component":[{"advisoryId":"PKSA-kwkg-rq7h-gh18","packageName":"symfony\/ux-live-component","remoteId":"symfony\/ux-live-component\/CVE-2026-49208.yaml","title":"symfony\/ux-live-component Format-less date LiveProps parsed with the permissive DateTime constructor","link":"https:\/\/github.com\/symfony\/ux\/security\/advisories\/GHSA-89g7-22c8-3j23","cve":"CVE-2026-49208","affectedVersions":"\u003E=2.8.0,\u003C2.36.0|\u003E=3.0.0,\u003C3.1.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-29 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-89g7-22c8-3j23"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/ux-live-component\/CVE-2026-49208.yaml"}]},{"advisoryId":"PKSA-tv34-cfvx-rr9r","packageName":"symfony\/ux-live-component","remoteId":"symfony\/ux-live-component\/CVE-2026-49209.yaml","title":"symfony\/ux-live-component Denial of service via unbounded batch action requests","link":"https:\/\/github.com\/symfony\/ux\/security\/advisories\/GHSA-mm82-c99c-h2cf","cve":"CVE-2026-49209","affectedVersions":"\u003E=2.5.0,\u003C2.36.0|\u003E=3.0.0,\u003C3.1.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-29 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-mm82-c99c-h2cf"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/ux-live-component\/CVE-2026-49209.yaml"}]},{"advisoryId":"PKSA-ks3q-z9y3-61pz","packageName":"symfony\/ux-live-component","remoteId":"symfony\/ux-live-component\/CVE-2026-49215.yaml","title":"symfony\/ux-live-component CSRF Protection Bypass: Accept Header is CORS-Safelisted","link":"https:\/\/github.com\/symfony\/ux\/security\/advisories\/GHSA-4m4j-hmqq-3gxm","cve":"CVE-2026-49215","affectedVersions":"\u003E=2.22.0,\u003C2.36.0|\u003E=3.0.0,\u003C3.1.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-29 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-4m4j-hmqq-3gxm"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/ux-live-component\/CVE-2026-49215.yaml"}]},{"advisoryId":"PKSA-87hx-5gp4-x12b","packageName":"symfony\/ux-live-component","remoteId":"symfony\/ux-live-component\/CVE-2026-49210.yaml","title":"symfony\/ux-live-component XSS via attacker-controlled child component tag","link":"https:\/\/github.com\/symfony\/ux\/security\/advisories\/GHSA-38x5-rcv4-xf7x","cve":"CVE-2026-49210","affectedVersions":"\u003E=2.8.0,\u003C2.36.0|\u003E=3.0.0,\u003C3.1.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-29 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-38x5-rcv4-xf7x"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/ux-live-component\/CVE-2026-49210.yaml"}]},{"advisoryId":"PKSA-wxdb-kw41-yhdy","packageName":"symfony\/ux-live-component","remoteId":"symfony\/ux-live-component\/CVE-2026-49212.yaml","title":"symfony\/ux-live-component LiveComponentHydrator HMAC checksum lacks component and slot binding","link":"https:\/\/github.com\/symfony\/ux\/security\/advisories\/GHSA-34w5-c283-j9fg","cve":"CVE-2026-49212","affectedVersions":"\u003E=2.8.0,\u003C2.36.0|\u003E=3.0.0,\u003C3.1.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-29 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-34w5-c283-j9fg"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/ux-live-component\/CVE-2026-49212.yaml"}]}],"symfony\/ux-autocomplete":[{"advisoryId":"PKSA-q7f1-2s55-5c1z","packageName":"symfony\/ux-autocomplete","remoteId":"symfony\/ux-autocomplete\/CVE-2026-49216.yaml","title":"symfony\/ux-autocomplete XSS via unescaped AJAX response data","link":"https:\/\/github.com\/symfony\/ux\/security\/advisories\/GHSA-mwqm-4fw3-cjvr","cve":"CVE-2026-49216","affectedVersions":"\u003E=2.2.0,\u003C2.36.0|\u003E=3.0.0,\u003C3.1.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-29 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mwqm-4fw3-cjvr"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/ux-autocomplete\/CVE-2026-49216.yaml"}]},{"advisoryId":"PKSA-msh7-gxqk-k56q","packageName":"symfony\/ux-autocomplete","remoteId":"symfony\/ux-autocomplete\/CVE-2026-49211.yaml","title":"symfony\/ux-autocomplete Information exposure via unescaped LIKE wildcards in EntitySearchUtil","link":"https:\/\/github.com\/symfony\/ux\/security\/advisories\/GHSA-946h-jp5c-8fvh","cve":"CVE-2026-49211","affectedVersions":"\u003E=2.2.0,\u003C2.36.0|\u003E=3.0.0,\u003C3.1.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-29 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-946h-jp5c-8fvh"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/ux-autocomplete\/CVE-2026-49211.yaml"}]}],"automad\/automad":[{"advisoryId":"PKSA-v8bn-6yk2-7qjk","packageName":"automad\/automad","remoteId":"GHSA-xm76-r88j-vm3g","title":"Automad has Broken Access Control: Unauthenticated exposure of administrator bcrypt password hashes and TOTP secrets via public API endpoint","link":"https:\/\/github.com\/advisories\/GHSA-xm76-r88j-vm3g","cve":"CVE-2026-45332","affectedVersions":"\u003E=2.0.0-alpha.1,\u003C=2.0.0-beta.27","source":"GitHub","reportedAt":"2026-05-27 21:32:31","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xm76-r88j-vm3g"}]}],"symfony\/mailomat-mailer":[{"advisoryId":"PKSA-9y9v-rcsm-h82j","packageName":"symfony\/mailomat-mailer","remoteId":"symfony\/mailomat-mailer\/CVE-2026-48747.yaml","title":"CVE-2026-48747: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm Downgrade","link":"https:\/\/symfony.com\/cve-2026-48747","cve":"CVE-2026-48747","affectedVersions":"\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.13|\u003E=8.0.0,\u003C8.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-26 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rrj9-5q2j-4gvr"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/mailomat-mailer\/CVE-2026-48747.yaml"}]}],"symfony\/http-foundation":[{"advisoryId":"PKSA-y6py-qpv1-h52p","packageName":"symfony\/http-foundation","remoteId":"symfony\/http-foundation\/CVE-2026-48736.yaml","title":"CVE-2026-48736: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient","link":"https:\/\/symfony.com\/cve-2026-48736","cve":"CVE-2026-48736","affectedVersions":"\u003E=6.4.0,\u003C6.4.41|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.13|\u003E=8.0.0,\u003C8.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-26 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-38cx-cq6f-5755"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/http-foundation\/CVE-2026-48736.yaml"}]},{"advisoryId":"PKSA-365x-2zjk-pt47","packageName":"symfony\/http-foundation","remoteId":"symfony\/http-foundation\/CVE-2025-64500.yaml","title":"CVE-2025-64500: Incorrect parsing of PATH_INFO can lead to limited authorization bypass","link":"https:\/\/symfony.com\/blog\/cve-2025-64500-incorrect-parsing-of-path-info-can-lead-to-limited-authorization-bypass","cve":"CVE-2025-64500","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.50|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.29|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.3.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2025-11-12 11:09:14","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3rg7-wf37-54rm"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/http-foundation\/CVE-2025-64500.yaml"}]}],"symfony\/security-http":[{"advisoryId":"PKSA-c28x-6bj5-8spx","packageName":"symfony\/security-http","remoteId":"symfony\/security-http\/CVE-2026-48489.yaml","title":"CVE-2026-48489: Security Firewall Bypass via failure_forward Subrequest: Unauthenticated Access to access_control-Protected GET Routes","link":"https:\/\/symfony.com\/cve-2026-48489","cve":"CVE-2026-48489","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.53|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.41|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.13|\u003E=8.0.0,\u003C8.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-26 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6h46-9jf5-q59x"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/security-http\/CVE-2026-48489.yaml"}]},{"advisoryId":"PKSA-jzjr-4n2h-knvd","packageName":"symfony\/security-http","remoteId":"symfony\/security-http\/CVE-2026-45069.yaml","title":"CVE-2026-45069: OidcTokenHandler Accepts JWTs Missing aud\/iss\/exp Claims","link":"https:\/\/symfony.com\/cve-2026-45069","cve":"CVE-2026-45069","affectedVersions":"\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-29fc-p6c4-24cg"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/security-http\/CVE-2026-45069.yaml"}]},{"advisoryId":"PKSA-tbsf-h7vc-j7hn","packageName":"symfony\/security-http","remoteId":"symfony\/security-http\/CVE-2026-45063.yaml","title":"CVE-2026-45063: Identity Spoofing via Unanchored DN Regex in X509Authenticator","link":"https:\/\/symfony.com\/cve-2026-45063","cve":"CVE-2026-45063","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-ph86-p8f6-f9r2"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/security-http\/CVE-2026-45063.yaml"}]},{"advisoryId":"PKSA-5df2-zpfk-xgsv","packageName":"symfony\/security-http","remoteId":"symfony\/security-http\/CVE-2026-45074.yaml","title":"CVE-2026-45074: Cas2Handler Derives CAS service URL from Client Host Header \u2192 Cross-Service Ticket Replay","link":"https:\/\/symfony.com\/cve-2026-45074","cve":"CVE-2026-45074","affectedVersions":"\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j8gj-9rm5-4xhx"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/security-http\/CVE-2026-45074.yaml"}]},{"advisoryId":"PKSA-4tmc-tz3m-9xpb","packageName":"symfony\/security-http","remoteId":"symfony\/security-http\/CVE-2026-45075.yaml","title":"CVE-2026-45075: HEAD Request Bypasses methods: [\u0027GET\u0027] Filter in #[IsGranted] \/ #[IsSignatureValid] \/ #[IsCsrfTokenValid]","link":"https:\/\/symfony.com\/cve-2026-45075","cve":"CVE-2026-45075","affectedVersions":"\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6439-2f28-8p8q"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/security-http\/CVE-2026-45075.yaml"}]}],"symfony\/http-client":[{"advisoryId":"PKSA-35by-yxtt-jc85","packageName":"symfony\/http-client","remoteId":"symfony\/http-client\/CVE-2026-48736.yaml","title":"CVE-2026-48736: IpUtils::PRIVATE_SUBNETS Omits IPv6 Transition Forms (6to4, NAT64, Teredo, IPv4-compatible): SSRF Bypass in NoPrivateNetworkHttpClient","link":"https:\/\/symfony.com\/cve-2026-48736","cve":"CVE-2026-48736","affectedVersions":"\u003E=5.4.0,\u003C5.4.53","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-26 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-38cx-cq6f-5755"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/http-client\/CVE-2026-48736.yaml"}]}],"symfony\/routing":[{"advisoryId":"PKSA-bf7t-jnpz-492k","packageName":"symfony\/routing","remoteId":"symfony\/routing\/CVE-2026-48784.yaml","title":"CVE-2026-48784: UrlGenerator Dot-Segment Encoding Skips Every Other Chained `..\/` or `.\/` \u2192 Generated URL Collapses Off-Route Under RFC 3986 Normalization","link":"https:\/\/symfony.com\/cve-2026-48784","cve":"CVE-2026-48784","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.53|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.41|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.13|\u003E=8.0.0,\u003C8.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-26 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h5x3-xfc9-m39h"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/routing\/CVE-2026-48784.yaml"}]},{"advisoryId":"PKSA-yc7t-91v9-99xs","packageName":"symfony\/routing","remoteId":"symfony\/routing\/CVE-2026-45065.yaml","title":"CVE-2026-45065: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation \u2192 Off-Site \/\/host URL Injection","link":"https:\/\/symfony.com\/cve-2026-45065","cve":"CVE-2026-45065","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-72xp-p242-47p9"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/routing\/CVE-2026-45065.yaml"}]}],"symfony\/html-sanitizer":[{"advisoryId":"PKSA-3d8r-4bff-vcj1","packageName":"symfony\/html-sanitizer","remoteId":"symfony\/html-sanitizer\/CVE-2026-48761.yaml","title":"CVE-2026-48761: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes on \u003Cobject\u003E, \u003Capplet\u003E, \u003Ciframe\u003E, \u003Cimg\u003E and the URL Inside \u003Cmeta http-equiv=\u0022refresh\u0022\u003E content","link":"https:\/\/symfony.com\/cve-2026-48761","cve":"CVE-2026-48761","affectedVersions":"\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.41|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.13|\u003E=8.0.0,\u003C8.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-26 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x5qj-865h-mgvm"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/html-sanitizer\/CVE-2026-48761.yaml"}]},{"advisoryId":"PKSA-bvdf-tk8n-sbsf","packageName":"symfony\/html-sanitizer","remoteId":"symfony\/html-sanitizer\/CVE-2026-48760.yaml","title":"CVE-2026-48760: HtmlSanitizer URL Parser Deny Gates Underinclusive: Percent-Encoded BiDi Marks and Unicode Whitespace Bypass Visual-Spoofing Defense","link":"https:\/\/symfony.com\/cve-2026-48760","cve":"CVE-2026-48760","affectedVersions":"\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.41|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.13|\u003E=8.0.0,\u003C8.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-26 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-v3wm-qf9p-c549"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/html-sanitizer\/CVE-2026-48760.yaml"}]},{"advisoryId":"PKSA-q2wy-m7mz-kg58","packageName":"symfony\/html-sanitizer","remoteId":"symfony\/html-sanitizer\/CVE-2026-45753.yaml","title":"CVE-2026-45753: HtmlSanitizer UrlAttributeSanitizer Omits action\/formaction\/poster\/cite: javascript: URI Survives Sanitization (XSS)","link":"https:\/\/symfony.com\/cve-2026-45753","cve":"CVE-2026-45753","affectedVersions":"\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-hhg7-c65m-h7ff"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/html-sanitizer\/CVE-2026-45753.yaml"}]},{"advisoryId":"PKSA-jwvg-gphd-brbz","packageName":"symfony\/html-sanitizer","remoteId":"symfony\/html-sanitizer\/CVE-2026-45066.yaml","title":"CVE-2026-45066: HtmlSanitizer allowLinkHosts() \/ allowMediaHosts() Bypass via URL-Parser Differentials and \u003Carea\u003E Misclassification","link":"https:\/\/symfony.com\/cve-2026-45066","cve":"CVE-2026-45066","affectedVersions":"\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qc95-4862-92fh"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/html-sanitizer\/CVE-2026-45066.yaml"}]},{"advisoryId":"PKSA-4fc7-y875-17k3","packageName":"symfony\/html-sanitizer","remoteId":"symfony\/html-sanitizer\/CVE-2026-45064.yaml","title":"CVE-2026-45064: HtmlSanitizer URL Attributes Pass Through BiDi Override Characters \u2192 Visual href Spoofing","link":"https:\/\/symfony.com\/cve-2026-45064","cve":"CVE-2026-45064","affectedVersions":"\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h5vq-qfcg-4m6p"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/html-sanitizer\/CVE-2026-45064.yaml"}]}],"spatie\/schema-org":[{"advisoryId":"PKSA-6mmh-w4kg-c2xp","packageName":"spatie\/schema-org","remoteId":"spatie\/schema-org\/2026-04-20.yaml","title":"Cross-site scripting (XSS) via script break-out in toScript() output","link":"https:\/\/github.com\/spatie\/schema-org\/releases\/tag\/4.0.2","cve":null,"affectedVersions":"\u003E=3.23.1,\u003C3.23.2|\u003E=4.0.0,\u003C4.0.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-04-20 00:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-hwmc-r6mf-jh83"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"spatie\/schema-org\/2026-04-20.yaml"}]}],"pimcore\/admin-ui-classic-bundle":[{"advisoryId":"PKSA-v29g-sqpm-mznn","packageName":"pimcore\/admin-ui-classic-bundle","remoteId":"GHSA-h4ph-crvj-9h92","title":"Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter","link":"https:\/\/github.com\/advisories\/GHSA-h4ph-crvj-9h92","cve":"CVE-2026-44741","affectedVersions":"\u003C1.7.18|\u003E=2.0.0-RC1,\u003C=2.3.5","source":"GitHub","reportedAt":"2026-05-27 00:35:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h4ph-crvj-9h92"}]},{"advisoryId":"PKSA-nx96-fm8s-mdqg","packageName":"pimcore\/admin-ui-classic-bundle","remoteId":"GHSA-hqrp-m84v-2m2f","title":"Pimcore\u0027s Admin Classic Bundle is Missing Function Level Authorization on \u0022Predefined Properties\u0022 Listing","link":"https:\/\/github.com\/advisories\/GHSA-hqrp-m84v-2m2f","cve":"CVE-2026-23495","affectedVersions":"\u003C=1.7.15|\u003E=2.0.0-RC1,\u003C=2.2.2","source":"GitHub","reportedAt":"2026-01-15 18:13:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hqrp-m84v-2m2f"}]},{"advisoryId":"PKSA-qhpb-4nkm-4qn3","packageName":"pimcore\/admin-ui-classic-bundle","remoteId":"GHSA-6f58-j323-6472","title":"pimcore\/admin-ui-classic-bundle Unverified Password Change","link":"https:\/\/github.com\/advisories\/GHSA-6f58-j323-6472","cve":"CVE-2023-5844","affectedVersions":"\u003C1.2.0-RC1","source":"GitHub","reportedAt":"2023-10-31 22:23:18","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6f58-j323-6472"}]}],"symfony\/polyfill":[{"advisoryId":"PKSA-df53-cqz9-c3zn","packageName":"symfony\/polyfill","remoteId":"symfony\/polyfill\/CVE-2026-46644.yaml","title":"CVE-2026-46644: symfony\/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalence","link":"https:\/\/symfony.com\/cve-2026-46644","cve":"CVE-2026-46644","affectedVersions":"\u003E=1.17.1,\u003C1.38.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-26 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-2xf4-cg6j-vhgq"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/polyfill\/CVE-2026-46644.yaml"}]}],"symfony\/polyfill-intl-idn":[{"advisoryId":"PKSA-dwsq-ppd2-mb1x","packageName":"symfony\/polyfill-intl-idn","remoteId":"symfony\/polyfill-intl-idn\/CVE-2026-46644.yaml","title":"CVE-2026-46644: symfony\/polyfill-intl-idn accepts xn-- labels whose Punycode payload decodes to ASCII-only: insecure equivalence","link":"https:\/\/symfony.com\/cve-2026-46644","cve":"CVE-2026-46644","affectedVersions":"\u003E=1.17.1,\u003C1.38.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-26 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-2xf4-cg6j-vhgq"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/polyfill-intl-idn\/CVE-2026-46644.yaml"}]}],"evoweb\/sf-register":[{"advisoryId":"PKSA-1gw5-qx8s-xyvr","packageName":"evoweb\/sf-register","remoteId":"evoweb\/sf-register\/CVE-2026-46721.yaml","title":"TYPO3-EXT-SA-2026-009: Broken Access Control in extension \u0022Frontend User Registration\u0022 (sf_register)","link":"https:\/\/typo3.org\/security\/advisory\/typo3-ext-sa-2026-009","cve":"CVE-2026-46721","affectedVersions":"\u003E=14.0.0,\u003C14.0.2|\u003C13.2.4","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-18 16:40:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"evoweb\/sf-register\/CVE-2026-46721.yaml"},{"name":"GitHub","remoteId":"GHSA-v348-vr4q-fv9p"}]}],"tpwd\/ke_search":[{"advisoryId":"PKSA-cy57-p12b-t759","packageName":"tpwd\/ke_search","remoteId":"tpwd\/ke_search\/CVE-2026-46722.yaml","title":"TYPO3-EXT-SA-2026-011: XML External Entity Injection in extension \u0022Faceted Search\u0022 (ke_search)","link":"https:\/\/typo3.org\/security\/advisory\/typo3-ext-sa-2026-011","cve":"CVE-2026-46722","affectedVersions":"\u003E=7.0.0,\u003C7.0.1|\u003E=6.0.0,\u003C6.6.1|\u003E=5.0.0,\u003C5.6.2|\u003C4.6.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-18 14:30:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fq39-62gx-8hqx"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"tpwd\/ke_search\/CVE-2026-46722.yaml"}]},{"advisoryId":"PKSA-ybqg-nm5d-my8d","packageName":"tpwd\/ke_search","remoteId":"tpwd\/ke_search\/CVE-2026-46724.yaml","title":"TYPO3-EXT-SA-2026-011: Path Traversal in extension \u0022Faceted Search\u0022 (ke_search)","link":"https:\/\/typo3.org\/security\/advisory\/typo3-ext-sa-2026-011","cve":"CVE-2026-46724","affectedVersions":"\u003E=7.0.0,\u003C7.0.1|\u003E=6.0.0,\u003C6.6.1|\u003E=5.0.0,\u003C5.6.2|\u003C4.6.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-18 14:30:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c72x-mc2p-wv7x"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"tpwd\/ke_search\/CVE-2026-46724.yaml"}]},{"advisoryId":"PKSA-pb46-78nq-81hw","packageName":"tpwd\/ke_search","remoteId":"tpwd\/ke_search\/CVE-2026-46723.yaml","title":"TYPO3-EXT-SA-2026-011: Path Traversal in extension \u0022Faceted Search\u0022 (ke_search)","link":"https:\/\/typo3.org\/security\/advisory\/typo3-ext-sa-2026-011","cve":"CVE-2026-46723","affectedVersions":"\u003E=7.0.0,\u003C7.0.1|\u003E=6.0.0,\u003C6.6.1|\u003C5.6.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-18 14:30:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-67j3-jmm3-32xc"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"tpwd\/ke_search\/CVE-2026-46723.yaml"}]}],"mmc\/ceselector":[{"advisoryId":"PKSA-kfm7-j6tb-2qn9","packageName":"mmc\/ceselector","remoteId":"mmc\/ceselector\/CVE-2026-46725.yaml","title":"TYPO3-EXT-SA-2026-013: Remote Code Execution in extension \u0022Content Element Selector\u0022 (ceselector)","link":"https:\/\/typo3.org\/security\/advisory\/typo3-ext-sa-2026-013","cve":"CVE-2026-46725","affectedVersions":"\u003E=6.0.0,\u003C6.0.1|\u003E=5.0.0,\u003C5.0.1|\u003E=4.0.0,\u003C4.0.2|\u003C3.0.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-04-07 10:50:50","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-8x3j-439w-537c"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"mmc\/ceselector\/CVE-2026-46725.yaml"}]}],"friendsoftypo3\/tt-address":[{"advisoryId":"PKSA-s9h4-6qfr-k554","packageName":"friendsoftypo3\/tt-address","remoteId":"friendsoftypo3\/tt-address\/CVE-2026-8827.yaml","title":"TYPO3-EXT-SA-2026-012: SQL Injection in extension \u0022Address List\u0022 (tt_address)","link":"https:\/\/typo3.org\/security\/advisory\/typo3-ext-sa-2026-012","cve":"CVE-2026-8827","affectedVersions":"\u003E=10.0.0,\u003C10.0.1|\u003E=9.0.0,\u003C9.1.1|\u003C8.1.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-18 15:13:22","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"friendsoftypo3\/tt-address\/CVE-2026-8827.yaml"},{"name":"GitHub","remoteId":"GHSA-3h52-6v6j-6wwv"}]}],"tomasnorre\/crawler":[{"advisoryId":"PKSA-bt63-cwpy-49h9","packageName":"tomasnorre\/crawler","remoteId":"tomasnorre\/crawler\/CVE-2026-8727.yaml","title":"TYPO3-EXT-SA-2026-008: Remote Code Execution in extension \u0022Site Crawler\u0022 (crawler)","link":"https:\/\/typo3.org\/security\/advisory\/typo3-ext-sa-2026-008","cve":"CVE-2026-8727","affectedVersions":"\u003E=12.0.0,\u003C12.0.11|\u003C11.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-11 19:18:44","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jr8m-x4p7-p3v5"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"tomasnorre\/crawler\/CVE-2026-8727.yaml"}]}],"knplabs\/knp-snappy":[{"advisoryId":"PKSA-p1pz-jv1j-6msg","packageName":"knplabs\/knp-snappy","remoteId":"GHSA-c5fp-p67m-gq56","title":"Snappy : SSRF and local file read via the xsl-style-sheet option","link":"https:\/\/github.com\/advisories\/GHSA-c5fp-p67m-gq56","cve":"CVE-2026-46683","affectedVersions":"\u003C=1.6.0","source":"GitHub","reportedAt":"2026-05-21 20:20:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c5fp-p67m-gq56"}]},{"advisoryId":"PKSA-13wp-m816-mvdd","packageName":"knplabs\/knp-snappy","remoteId":"GHSA-vpr4-p6fq-85jc","title":"Snappy: Binary path is never shell-escaped due to an inverted is_executable check","link":"https:\/\/github.com\/advisories\/GHSA-vpr4-p6fq-85jc","cve":"CVE-2026-46643","affectedVersions":"\u003C=1.7.0","source":"GitHub","reportedAt":"2026-05-21 20:22:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vpr4-p6fq-85jc"}]},{"advisoryId":"PKSA-cd3f-fj3y-g547","packageName":"knplabs\/knp-snappy","remoteId":"knplabs\/knp-snappy\/CVE-2023-41330.yaml","title":"Snappy PHAR deserialization vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-92rv-4j2h-8mjj","cve":"CVE-2023-41330","affectedVersions":"\u003C1.4.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2023-09-06 15:24:48","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-92rv-4j2h-8mjj"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"knplabs\/knp-snappy\/CVE-2023-41330.yaml"}]}],"cockpit-hq\/cockpit":[{"advisoryId":"PKSA-by8z-q792-wbvd","packageName":"cockpit-hq\/cockpit","remoteId":"GHSA-ch4j-vcf5-58x5","title":"Cockpit CMS: Stored cross-site scripting vulnerability in the Set field type\u0027s Display template option","link":"https:\/\/github.com\/advisories\/GHSA-ch4j-vcf5-58x5","cve":"CVE-2026-23695","affectedVersions":"\u003C=2.14.0","source":"GitHub","reportedAt":"2026-05-15 18:30:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-ch4j-vcf5-58x5"}]},{"advisoryId":"PKSA-dpw9-65w1-pksf","packageName":"cockpit-hq\/cockpit","remoteId":"GHSA-j2rx-4jg9-79mw","title":"Cockpit Vulnerable to Unrestricted Upload of File with Dangerous Type","link":"https:\/\/github.com\/advisories\/GHSA-j2rx-4jg9-79mw","cve":"CVE-2026-38991","affectedVersions":"\u003C2.14.0","source":"GitHub","reportedAt":"2026-04-29 18:31:34","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j2rx-4jg9-79mw"}]},{"advisoryId":"PKSA-gx1h-274c-423s","packageName":"cockpit-hq\/cockpit","remoteId":"GHSA-p46p-7pmj-m34f","title":"Cockpit is vulnerable to directory traversal","link":"https:\/\/github.com\/advisories\/GHSA-p46p-7pmj-m34f","cve":"CVE-2026-38993","affectedVersions":"\u003C2.14.0","source":"GitHub","reportedAt":"2026-04-29 18:31:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-p46p-7pmj-m34f"}]},{"advisoryId":"PKSA-496r-cnzn-ck12","packageName":"cockpit-hq\/cockpit","remoteId":"GHSA-fm6c-rhcf-7439","title":"Cockpit is vulnerable to arbitrary code execution","link":"https:\/\/github.com\/advisories\/GHSA-fm6c-rhcf-7439","cve":"CVE-2026-38992","affectedVersions":"\u003C2.14.0","source":"GitHub","reportedAt":"2026-04-29 15:30:39","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-fm6c-rhcf-7439"}]},{"advisoryId":"PKSA-qffw-6vr2-p3h9","packageName":"cockpit-hq\/cockpit","remoteId":"GHSA-5pv2-86qj-5jf9","title":"Cockpit has NoSQL Injection Through Content Aggregation Pipelines","link":"https:\/\/github.com\/advisories\/GHSA-5pv2-86qj-5jf9","cve":"CVE-2026-6626","affectedVersions":"\u003C2.14.0","source":"GitHub","reportedAt":"2026-04-20 12:32:01","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-5pv2-86qj-5jf9"}]},{"advisoryId":"PKSA-rm9w-whnt-2jgw","packageName":"cockpit-hq\/cockpit","remoteId":"GHSA-7x5c-vfhj-9628","title":"Cockpit CMS has SQL Injection in MongoLite Aggregation Optimizer via toJsonExtractRaw() ","link":"https:\/\/github.com\/advisories\/GHSA-7x5c-vfhj-9628","cve":"CVE-2026-31891","affectedVersions":"\u003C2.13.5","source":"GitHub","reportedAt":"2026-03-17 17:07:41","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7x5c-vfhj-9628"}]}],"georgringer\/news":[{"advisoryId":"PKSA-grgc-xpj3-tvw1","packageName":"georgringer\/news","remoteId":"georgringer\/news\/CVE-2026-8726.yaml","title":"SQL Injection in extension \u0022News system\u0022 (news)","link":"https:\/\/typo3.org\/security\/advisory\/typo3-ext-sa-2026-010","cve":"CVE-2026-8726","affectedVersions":"\u003C10.0.4|\u003E=11.0.0,\u003C11.4.4|\u003E=12.0.0,\u003C12.3.2|\u003E=13.0.0,\u003C13.0.2|\u003E=14.0.0,\u003C14.0.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-19 12:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"georgringer\/news\/CVE-2026-8726.yaml"},{"name":"GitHub","remoteId":"GHSA-g868-j3qm-4j28"}]}],"laktak\/hjson":[{"advisoryId":"PKSA-fmxt-7v2r-bbsn","packageName":"laktak\/hjson","remoteId":"GHSA-5wfc-hjrc-gq87","title":"hjson stack exhaustion vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-5wfc-hjrc-gq87","cve":"CVE-2023-34620","affectedVersions":"\u003C2.3.0","source":"GitHub","reportedAt":"2023-06-14 15:30:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5wfc-hjrc-gq87"}]}],"symfony\/mailtrap-mailer":[{"advisoryId":"PKSA-n517-312t-6vqg","packageName":"symfony\/mailtrap-mailer","remoteId":"symfony\/mailtrap-mailer\/CVE-2026-45755.yaml","title":"CVE-2026-45755: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC: Unauthenticated Webhook Event Injection","link":"https:\/\/symfony.com\/cve-2026-45755","cve":"CVE-2026-45755","affectedVersions":"\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-59f3-vp2f-mp9w"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/mailtrap-mailer\/CVE-2026-45755.yaml"}]}],"symfony\/lox24-notifier":[{"advisoryId":"PKSA-675k-fhbn-1yh5","packageName":"symfony\/lox24-notifier","remoteId":"symfony\/lox24-notifier\/CVE-2026-45754.yaml","title":"CVE-2026-45754: Mailjet Mailer and LOX24 Notifier Webhook Parsers Never Verify the Configured Secret: Unauthenticated Webhook Event Injection","link":"https:\/\/symfony.com\/cve-2026-45754","cve":"CVE-2026-45754","affectedVersions":"\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-64hg-93w9-fc35"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/lox24-notifier\/CVE-2026-45754.yaml"}]}],"symfony\/mailjet-mailer":[{"advisoryId":"PKSA-swxr-w76k-fd2b","packageName":"symfony\/mailjet-mailer","remoteId":"symfony\/mailjet-mailer\/CVE-2026-45754.yaml","title":"CVE-2026-45754: Mailjet Mailer and LOX24 Notifier Webhook Parsers Never Verify the Configured Secret: Unauthenticated Webhook Event Injection","link":"https:\/\/symfony.com\/cve-2026-45754","cve":"CVE-2026-45754","affectedVersions":"\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-64hg-93w9-fc35"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/mailjet-mailer\/CVE-2026-45754.yaml"}]}],"symfony\/yaml":[{"advisoryId":"PKSA-v5yj-8nmz-sk2q","packageName":"symfony\/yaml","remoteId":"symfony\/yaml\/CVE-2026-45304.yaml","title":"CVE-2026-45304: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion (\u0022Billion Laughs\u0022)","link":"https:\/\/symfony.com\/cve-2026-45304","cve":"CVE-2026-45304","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-4qpc-3hr4-r2p4"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/yaml\/CVE-2026-45304.yaml"}]},{"advisoryId":"PKSA-ft77-7h5f-p3r6","packageName":"symfony\/yaml","remoteId":"symfony\/yaml\/CVE-2026-45305.yaml","title":"CVE-2026-45305: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex","link":"https:\/\/symfony.com\/cve-2026-45305","cve":"CVE-2026-45305","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-9frc-8383-795m"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/yaml\/CVE-2026-45305.yaml"}]},{"advisoryId":"PKSA-b14r-zh1d-vdrc","packageName":"symfony\/yaml","remoteId":"symfony\/yaml\/CVE-2026-45133.yaml","title":"CVE-2026-45133: YAML Parser Stack Exhaustion via Unbounded Recursion in Nested Blocks, Sequences, and Mappings","link":"https:\/\/symfony.com\/cve-2026-45133","cve":"CVE-2026-45133","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-c2p3-7m5p-cv8x"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/yaml\/CVE-2026-45133.yaml"}]}],"symfony\/mime":[{"advisoryId":"PKSA-wtxr-p26d-nn42","packageName":"symfony\/mime","remoteId":"symfony\/mime\/CVE-2026-45070.yaml","title":"CVE-2026-45070: Email Header Injection via Non-Token Characters in Mime Parameter Names","link":"https:\/\/symfony.com\/cve-2026-45070","cve":"CVE-2026-45070","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vqc8-7275-q272"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/mime\/CVE-2026-45070.yaml"}]},{"advisoryId":"PKSA-2n2k-66v2-bwg3","packageName":"symfony\/mime","remoteId":"symfony\/mime\/CVE-2026-45067.yaml","title":"CVE-2026-45067: Email Header \/ SMTP Command Injection via CRLF in Symfony\\Component\\Mime\\Address","link":"https:\/\/symfony.com\/cve-2026-45067","cve":"CVE-2026-45067","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qpmx-3rfj-7rhv"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/mime\/CVE-2026-45067.yaml"}]}],"symfony\/http-kernel":[{"advisoryId":"PKSA-dw7n-x7f5-zf63","packageName":"symfony\/http-kernel","remoteId":"symfony\/http-kernel\/CVE-2026-45075.yaml","title":"CVE-2026-45075: HEAD Request Bypasses methods: [\u0027GET\u0027] Filter in #[IsGranted] \/ #[IsSignatureValid] \/ #[IsCsrfTokenValid]","link":"https:\/\/symfony.com\/cve-2026-45075","cve":"CVE-2026-45075","affectedVersions":"\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6439-2f28-8p8q"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/http-kernel\/CVE-2026-45075.yaml"}]}],"symfony\/monolog-bridge":[{"advisoryId":"PKSA-4wjj-gy1p-ft3r","packageName":"symfony\/monolog-bridge","remoteId":"symfony\/monolog-bridge\/CVE-2026-45077.yaml","title":"CVE-2026-45077: Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener","link":"https:\/\/symfony.com\/cve-2026-45077","cve":"CVE-2026-45077","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-m7v2-7gxm-vc2v"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/monolog-bridge\/CVE-2026-45077.yaml"}]}],"symfony\/twilio-notifier":[{"advisoryId":"PKSA-fgw6-3k5j-cfkn","packageName":"symfony\/twilio-notifier","remoteId":"symfony\/twilio-notifier\/CVE-2026-47212.yaml","title":"CVE-2026-47212: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event Injection","link":"https:\/\/symfony.com\/cve-2026-47212","cve":"CVE-2026-47212","affectedVersions":"\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-55rj-x2vc-4whq"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/twilio-notifier\/CVE-2026-47212.yaml"}]}],"symfony\/dom-crawler":[{"advisoryId":"PKSA-5r1g-c7b7-y1zg","packageName":"symfony\/dom-crawler","remoteId":"symfony\/dom-crawler\/CVE-2026-45071.yaml","title":"CVE-2026-45071: XXE (Local File Disclosure) in DomCrawler::addXmlContent() via validateOnParse = true","link":"https:\/\/symfony.com\/cve-2026-45071","cve":"CVE-2026-45071","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-x6g4-fwcc-jj8w"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/dom-crawler\/CVE-2026-45071.yaml"}]}],"symfony\/twig-bridge":[{"advisoryId":"PKSA-11dz-rdmf-vfgt","packageName":"symfony\/twig-bridge","remoteId":"symfony\/twig-bridge\/CVE-2026-45072.yaml","title":"CVE-2026-45072: Stored XSS in WebProfiler CodeExtension::fileExcerpt(): Unescaped Non-PHP File Rendering","link":"https:\/\/symfony.com\/cve-2026-45072","cve":"CVE-2026-45072","affectedVersions":"\u003E=6.4.24,\u003C6.4.40","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-hmr5-2xcr-v8pp"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/twig-bridge\/CVE-2026-45072.yaml"}]}],"symfony\/cache":[{"advisoryId":"PKSA-z7t6-zt6p-wtng","packageName":"symfony\/cache","remoteId":"symfony\/cache\/CVE-2026-45073.yaml","title":"CVE-2026-45073: SQL Injection in PdoAdapter::doClear() via Unsanitized $prefix","link":"https:\/\/symfony.com\/cve-2026-45073","cve":"CVE-2026-45073","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6qh9-h6wf-jgqc"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/cache\/CVE-2026-45073.yaml"}]}],"symfony\/json-path":[{"advisoryId":"PKSA-rj1d-mpts-8wrt","packageName":"symfony\/json-path","remoteId":"symfony\/json-path\/CVE-2026-45756.yaml","title":"CVE-2026-45756: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()\/search() Without Limits: ReDoS","link":"https:\/\/symfony.com\/cve-2026-45756","cve":"CVE-2026-45756","affectedVersions":"\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-8v8v-g73j-492j"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/json-path\/CVE-2026-45756.yaml"}]}],"symfony\/mailer":[{"advisoryId":"PKSA-28rh-rzzn-djk4","packageName":"symfony\/mailer","remoteId":"symfony\/mailer\/CVE-2026-45068.yaml","title":"CVE-2026-45068: Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address","link":"https:\/\/symfony.com\/cve-2026-45068","cve":"CVE-2026-45068","affectedVersions":"\u003E=2.0.0,\u003C3.0.0|\u003E=3.0.0,\u003C4.0.0|\u003E=4.0.0,\u003C5.0.0|\u003E=5.0.0,\u003C5.1.0|\u003E=5.1.0,\u003C5.2.0|\u003E=5.2.0,\u003C5.3.0|\u003E=5.3.0,\u003C5.4.0|\u003E=5.4.0,\u003C5.4.52|\u003E=6.0.0,\u003C6.1.0|\u003E=6.1.0,\u003C6.2.0|\u003E=6.2.0,\u003C6.3.0|\u003E=6.3.0,\u003C6.4.0|\u003E=6.4.0,\u003C6.4.40|\u003E=7.0.0,\u003C7.1.0|\u003E=7.1.0,\u003C7.2.0|\u003E=7.2.0,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xx3c-qf5g-hc39"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/mailer\/CVE-2026-45068.yaml"}]}],"symfony\/web-profiler-bundle":[{"advisoryId":"PKSA-rg9h-crk2-m8zt","packageName":"symfony\/web-profiler-bundle","remoteId":"symfony\/web-profiler-bundle\/CVE-2026-45072.yaml","title":"CVE-2026-45072: Stored XSS in WebProfiler CodeExtension::fileExcerpt(): Unescaped Non-PHP File Rendering","link":"https:\/\/symfony.com\/cve-2026-45072","cve":"CVE-2026-45072","affectedVersions":"\u003E=7.2.9,\u003C7.3.0|\u003E=7.3.0,\u003C7.4.0|\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-hmr5-2xcr-v8pp"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/web-profiler-bundle\/CVE-2026-45072.yaml"}]}],"twig\/markdown-extra":[{"advisoryId":"PKSA-7b1y-jwqf-x6v6","packageName":"twig\/markdown-extra","remoteId":"twig\/markdown-extra\/CVE-2026-46637.yaml","title":"HTML-output filters in twig\/* extras incorrectly declared `is_safe =\u003E [\u0027all\u0027]`","link":"https:\/\/symfony.com\/cve-2026-46637","cve":"CVE-2026-46637","affectedVersions":"\u003E=2.12.0,\u003C3.0.0|\u003E=3.0.0,\u003C3.26.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-jv8m-2544-3pg3"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/markdown-extra\/CVE-2026-46637.yaml"}]}],"twig\/intl-extra":[{"advisoryId":"PKSA-2rbx-bjdx-4d4d","packageName":"twig\/intl-extra","remoteId":"twig\/intl-extra\/CVE-2026-46629.yaml","title":"Unbounded formatter memoisation in twig\/intl-extra keyed on template-controlled arguments","link":"https:\/\/symfony.com\/cve-2026-46629","cve":"CVE-2026-46629","affectedVersions":"\u003E=2.12.0,\u003C3.0.0|\u003E=3.0.0,\u003C3.26.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-35wc-cvqg-78fp"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/intl-extra\/CVE-2026-46629.yaml"}]}],"twig\/cssinliner-extra":[{"advisoryId":"PKSA-fs5b-x5k4-1h39","packageName":"twig\/cssinliner-extra","remoteId":"twig\/cssinliner-extra\/CVE-2026-46637.yaml","title":"HTML-output filters in twig\/* extras incorrectly declared `is_safe =\u003E [\u0027all\u0027]`","link":"https:\/\/symfony.com\/cve-2026-46637","cve":"CVE-2026-46637","affectedVersions":"\u003E=2.12.0,\u003C3.0.0|\u003E=3.0.0,\u003C3.26.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-jv8m-2544-3pg3"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"twig\/cssinliner-extra\/CVE-2026-46637.yaml"}]}],"setasign\/fpdi":[{"advisoryId":"PKSA-37cw-b473-k9np","packageName":"setasign\/fpdi","remoteId":"GHSA-2mgw-7q6p-8grg","title":"FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service","link":"https:\/\/github.com\/advisories\/GHSA-2mgw-7q6p-8grg","cve":"CVE-2026-45802","affectedVersions":"\u003C2.6.7","source":"GitHub","reportedAt":"2026-05-19 19:56:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2mgw-7q6p-8grg"}]}],"sulu\/sulu":[{"advisoryId":"PKSA-2mt7-sd38-1xng","packageName":"sulu\/sulu","remoteId":"GHSA-9m6v-8fxc-4r44","title":"Sulu: Used API Keys may be available via Admin API","link":"https:\/\/github.com\/advisories\/GHSA-9m6v-8fxc-4r44","cve":null,"affectedVersions":"\u003C=2.6.22|\u003E=3.0.0-alpha1,\u003C=3.0.5","source":"GitHub","reportedAt":"2026-05-18 17:34:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-9m6v-8fxc-4r44"}]},{"advisoryId":"PKSA-psv3-gm5n-8wm5","packageName":"sulu\/sulu","remoteId":"GHSA-7fv8-6pp7-6h85","title":"Sulu: Weak Cryptographical usage for API Key generation and Reset Tokens","link":"https:\/\/github.com\/advisories\/GHSA-7fv8-6pp7-6h85","cve":"CVE-2026-45701","affectedVersions":"\u003C=2.6.22|\u003E=3.0.0-alpha1,\u003C=3.0.5","source":"GitHub","reportedAt":"2026-05-18 17:27:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7fv8-6pp7-6h85"}]},{"advisoryId":"PKSA-s8fv-tzzv-5y3k","packageName":"sulu\/sulu","remoteId":"GHSA-6h7h-m7p5-hjqp","title":"Sulu checks fix permissions for subentities endpoints","link":"https:\/\/github.com\/advisories\/GHSA-6h7h-m7p5-hjqp","cve":"CVE-2026-34372","affectedVersions":"\u003E=3.0.0,\u003C3.0.5|\u003E=1.0.0,\u003C2.6.22","source":"GitHub","reportedAt":"2026-03-30 18:04:10","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6h7h-m7p5-hjqp"}]}],"librenms\/librenms":[{"advisoryId":"PKSA-g8mh-y1x4-3d27","packageName":"librenms\/librenms","remoteId":"GHSA-5gm9-622f-qcg5","title":"LibreNMS: Cross-Site Scripting in ShowConfigController","link":"https:\/\/github.com\/advisories\/GHSA-5gm9-622f-qcg5","cve":"CVE-2026-2728","affectedVersions":"\u003E=25.12.0,\u003C26.3.0","source":"GitHub","reportedAt":"2026-05-18 17:00:49","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-5gm9-622f-qcg5"}]},{"advisoryId":"PKSA-crbw-6n6w-1qmb","packageName":"librenms\/librenms","remoteId":"GHSA-pr3g-phhr-h8fh","title":"LibreNMS is Vulnerable to Remote Code Execution by Arbitrary File Write","link":"https:\/\/github.com\/advisories\/GHSA-pr3g-phhr-h8fh","cve":"CVE-2026-6204","affectedVersions":"\u003E=1.48,\u003C26.3.0","source":"GitHub","reportedAt":"2026-03-26 18:04:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pr3g-phhr-h8fh"}]},{"advisoryId":"PKSA-rjmn-cvhz-y4dy","packageName":"librenms\/librenms","remoteId":"GHSA-h3rv-q4rq-pqcv","title":"LibreNMS: SQL Injection in ajax_table.php spreads through a covert data stream.","link":"https:\/\/github.com\/advisories\/GHSA-h3rv-q4rq-pqcv","cve":"CVE-2026-26988","affectedVersions":"\u003C26.2.0","source":"GitHub","reportedAt":"2026-02-18 22:30:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h3rv-q4rq-pqcv"}]},{"advisoryId":"PKSA-p35m-1xws-mn72","packageName":"librenms\/librenms","remoteId":"GHSA-6xmx-xr9p-58p7","title":"LibreNMS has a Stored XSS in Alert Rule","link":"https:\/\/github.com\/advisories\/GHSA-6xmx-xr9p-58p7","cve":"CVE-2026-26989","affectedVersions":"\u003C=25.12.0","source":"GitHub","reportedAt":"2026-02-18 22:30:32","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6xmx-xr9p-58p7"}]},{"advisoryId":"PKSA-fgg9-gkd1-czx2","packageName":"librenms\/librenms","remoteId":"GHSA-79q9-wc6p-cf92","title":"LibreNMS has a Time-Based Blind SQL Injection in address-search.inc.php","link":"https:\/\/github.com\/advisories\/GHSA-79q9-wc6p-cf92","cve":"CVE-2026-26990","affectedVersions":"\u003C26.2.0","source":"GitHub","reportedAt":"2026-02-18 22:31:37","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-79q9-wc6p-cf92"}]},{"advisoryId":"PKSA-8m8q-njcw-35gd","packageName":"librenms\/librenms","remoteId":"GHSA-gqx7-99jw-6fpr","title":"LibreNMS affected by reflected xss via email field ","link":"https:\/\/github.com\/advisories\/GHSA-gqx7-99jw-6fpr","cve":"CVE-2026-26987","affectedVersions":"\u003C26.2.0","source":"GitHub","reportedAt":"2026-02-18 22:07:06","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gqx7-99jw-6fpr"}]},{"advisoryId":"PKSA-5ndn-cv3t-wdqt","packageName":"librenms\/librenms","remoteId":"GHSA-5pqf-54qp-32wx","title":"LibreNMS \/device-groups name Stored Cross-Site Scripting","link":"https:\/\/github.com\/advisories\/GHSA-5pqf-54qp-32wx","cve":"CVE-2026-26991","affectedVersions":"\u003C26.2.0","source":"GitHub","reportedAt":"2026-02-18 22:07:19","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5pqf-54qp-32wx"}]},{"advisoryId":"PKSA-zkdz-sv4x-6wvp","packageName":"librenms\/librenms","remoteId":"GHSA-93fx-g747-695x","title":"LibreNMS \/port-groups name Stored Cross-Site Scripting","link":"https:\/\/github.com\/advisories\/GHSA-93fx-g747-695x","cve":"CVE-2026-26992","affectedVersions":"\u003C26.2.0","source":"GitHub","reportedAt":"2026-02-18 22:07:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-93fx-g747-695x"}]},{"advisoryId":"PKSA-vfym-rfx7-wjpv","packageName":"librenms\/librenms","remoteId":"GHSA-fqx6-693c-f55g","title":"LibreNMS has a Stored XSS in Custom OID - unit parameter missing strip_tags()","link":"https:\/\/github.com\/advisories\/GHSA-fqx6-693c-f55g","cve":"CVE-2026-27016","affectedVersions":"\u003E=24.10.0,\u003C26.2.0","source":"GitHub","reportedAt":"2026-02-18 22:08:15","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fqx6-693c-f55g"}]},{"advisoryId":"PKSA-hvh6-kn1x-g814","packageName":"librenms\/librenms","remoteId":"GHSA-qp2j-v5jg-hg68","title":"LibreNMS contains an authenticated SQL Injection vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-qp2j-v5jg-hg68","cve":"CVE-2020-36947","affectedVersions":"\u003C=1.46","source":"GitHub","reportedAt":"2026-01-27 18:32:14","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qp2j-v5jg-hg68"}]},{"advisoryId":"PKSA-qmxf-dcgt-4ft3","packageName":"librenms\/librenms","remoteId":"GHSA-c89f-8g7g-59wj","title":"LibreNMS Alert Rule API Cross-Site Scripting Vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-c89f-8g7g-59wj","cve":"CVE-2025-68614","affectedVersions":"\u003C25.12.0","source":"GitHub","reportedAt":"2025-12-23 18:19:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c89f-8g7g-59wj"}]},{"advisoryId":"PKSA-7dfn-9svk-zsqn","packageName":"librenms\/librenms","remoteId":"GHSA-6pmj-xjxp-p8g9","title":"LibreNMS is vulnerable to SQL Injection (Boolean-Based Blind) in hostname parameter in ajax_output.php endpoint","link":"https:\/\/github.com\/advisories\/GHSA-6pmj-xjxp-p8g9","cve":"CVE-2025-65093","affectedVersions":"\u003C=25.10.0","source":"GitHub","reportedAt":"2025-11-18 18:48:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6pmj-xjxp-p8g9"}]},{"advisoryId":"PKSA-2rhd-6w4r-2261","packageName":"librenms\/librenms","remoteId":"GHSA-j8cq-7f6p-256x","title":"LibreNMS vulnerable to Reflected Cross-Site Scripting (XSS) in endpoint `\/maps\/nodeimage` parameter `Image Name`  ","link":"https:\/\/github.com\/advisories\/GHSA-j8cq-7f6p-256x","cve":"CVE-2025-65013","affectedVersions":"\u003C25.11.0","source":"GitHub","reportedAt":"2025-11-18 18:21:28","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j8cq-7f6p-256x"}]},{"advisoryId":"PKSA-5jjt-bqv9-rkt7","packageName":"librenms\/librenms","remoteId":"GHSA-5mrf-j8v6-f45g","title":"LibreNMS has Weak Password Policy","link":"https:\/\/github.com\/advisories\/GHSA-5mrf-j8v6-f45g","cve":"CVE-2025-65014","affectedVersions":"\u003C25.11.0","source":"GitHub","reportedAt":"2025-11-18 18:24:26","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-5mrf-j8v6-f45g"}]},{"advisoryId":"PKSA-dd4d-7vsb-nysk","packageName":"librenms\/librenms","remoteId":"GHSA-6g2v-66ch-6xmh","title":"LibreNMS alert-rules has a Cross-Site Scripting Vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-6g2v-66ch-6xmh","cve":"CVE-2025-62412","affectedVersions":"\u003C=25.8.0","source":"GitHub","reportedAt":"2025-10-16 20:18:32","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-6g2v-66ch-6xmh"}]},{"advisoryId":"PKSA-d4tx-zpjw-46cf","packageName":"librenms\/librenms","remoteId":"GHSA-frc6-pwgr-c28w","title":"LibreNMS has a Stored XSS vulnerability in its Alert Transport name field","link":"https:\/\/github.com\/advisories\/GHSA-frc6-pwgr-c28w","cve":"CVE-2025-62411","affectedVersions":"\u003C25.10.0","source":"GitHub","reportedAt":"2025-10-16 16:52:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-frc6-pwgr-c28w"}]},{"advisoryId":"PKSA-hmpp-vqmr-y8ct","packageName":"librenms\/librenms","remoteId":"GHSA-86rg-8hc8-v82p","title":"LibreNMS is vulnerable to Reflected-XSS in `report_this` function","link":"https:\/\/github.com\/advisories\/GHSA-86rg-8hc8-v82p","cve":"CVE-2025-62365","affectedVersions":"\u003C=25.6.0","source":"GitHub","reportedAt":"2025-10-13 22:11:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-86rg-8hc8-v82p"}]},{"advisoryId":"PKSA-6jtq-3877-1tyc","packageName":"librenms\/librenms","remoteId":"GHSA-4ccx-wjqp-5fww","title":"LibreNMS Arbitrary File Read","link":"https:\/\/github.com\/advisories\/GHSA-4ccx-wjqp-5fww","cve":"CVE-2017-16759","affectedVersions":"\u003C1.31","source":"GitHub","reportedAt":"2022-05-13 01:44:10","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4ccx-wjqp-5fww"}]},{"advisoryId":"PKSA-v1yf-jwjx-pk3d","packageName":"librenms\/librenms","remoteId":"GHSA-254q-rqmw-vx45","title":"Missing Authorization in librenms\/librenms","link":"https:\/\/github.com\/advisories\/GHSA-254q-rqmw-vx45","cve":"CVE-2022-0588","affectedVersions":"\u003C22.2.0","source":"GitHub","reportedAt":"2022-02-16 00:01:52","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-254q-rqmw-vx45"}]}],"shopper\/cart":[{"advisoryId":"PKSA-92pp-1wvt-fk91","packageName":"shopper\/cart","remoteId":"GHSA-9rh9-hf3w-9fgg","title":"shopper\/framework: Race condition on Discount.usage_limit allows silent over-redemption","link":"https:\/\/github.com\/advisories\/GHSA-9rh9-hf3w-9fgg","cve":"CVE-2026-47741","affectedVersions":"\u003C2.8.0","source":"GitHub","reportedAt":"2026-05-18 16:37:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9rh9-hf3w-9fgg"}]}],"ci4-cms-erp\/ci4ms":[{"advisoryId":"PKSA-x2rt-sj8n-h21z","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-245j-xjvr-xvm5","title":"CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations","link":"https:\/\/github.com\/advisories\/GHSA-245j-xjvr-xvm5","cve":"CVE-2026-45139","affectedVersions":"\u003C=0.31.8.0","source":"GitHub","reportedAt":"2026-05-18 16:21:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-245j-xjvr-xvm5"}]},{"advisoryId":"PKSA-cfx9-7tcq-n157","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-gqr2-7hcg-rchf","title":"CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule","link":"https:\/\/github.com\/advisories\/GHSA-gqr2-7hcg-rchf","cve":"CVE-2026-45270","affectedVersions":"\u003C=0.31.8.0","source":"GitHub","reportedAt":"2026-05-18 16:23:34","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gqr2-7hcg-rchf"}]},{"advisoryId":"PKSA-7xbg-9dns-gxm5","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-2m69-jmvh-6chr","title":"CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule","link":"https:\/\/github.com\/advisories\/GHSA-2m69-jmvh-6chr","cve":"CVE-2026-45138","affectedVersions":"\u003C=0.31.8.0","source":"GitHub","reportedAt":"2026-05-18 15:39:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2m69-jmvh-6chr"}]},{"advisoryId":"PKSA-kq1j-n47j-c2p7","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-vgrf-pr28-vf98","title":"CI4MS Vulnerable to Arbitrary Database Table Drop via Theme deleteProcess","link":"https:\/\/github.com\/advisories\/GHSA-vgrf-pr28-vf98","cve":"CVE-2026-41890","affectedVersions":"\u003E=0.31.1.0,\u003C=0.31.7.0","source":"GitHub","reportedAt":"2026-05-04 20:50:10","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vgrf-pr28-vf98"}]},{"advisoryId":"PKSA-cf98-gsv6-bv96","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-5hfv-c864-qcq9","title":"CI4MS has a Deactivated User Session Bypass (active=0)","link":"https:\/\/github.com\/advisories\/GHSA-5hfv-c864-qcq9","cve":"CVE-2026-41891","affectedVersions":"\u003E=0.26.0,\u003C=0.31.7.0","source":"GitHub","reportedAt":"2026-05-04 20:50:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5hfv-c864-qcq9"}]},{"advisoryId":"PKSA-gg2g-kjmj-cghy","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-fw49-9xq4-gmx6","title":"CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution","link":"https:\/\/github.com\/advisories\/GHSA-fw49-9xq4-gmx6","cve":"CVE-2026-41587","affectedVersions":"\u003E=0.26.0.0,\u003C=0.31.6.0","source":"GitHub","reportedAt":"2026-04-29 20:42:44","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fw49-9xq4-gmx6"}]},{"advisoryId":"PKSA-219p-5b8k-2v2r","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-qxpq-82f3-xj47","title":"CI4MS: Backup Management Full Account Takeover for All Roles \u0026 Privilege Escalation via Stored DOM Blind XSS","link":"https:\/\/github.com\/advisories\/GHSA-qxpq-82f3-xj47","cve":"CVE-2026-41201","affectedVersions":"\u003C0.31.5.0","source":"GitHub","reportedAt":"2026-04-22 17:27:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qxpq-82f3-xj47"}]},{"advisoryId":"PKSA-2xsc-43zp-v4cr","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-xp9f-pvvc-57p4","title":"CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE","link":"https:\/\/github.com\/advisories\/GHSA-xp9f-pvvc-57p4","cve":"CVE-2026-41202","affectedVersions":"\u003C0.31.5.0","source":"GitHub","reportedAt":"2026-04-22 17:28:39","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-xp9f-pvvc-57p4"}]},{"advisoryId":"PKSA-tyjg-jzs3-mzjt","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-xv3r-vr59-95rg","title":"CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE","link":"https:\/\/github.com\/advisories\/GHSA-xv3r-vr59-95rg","cve":"CVE-2026-41203","affectedVersions":"\u003C0.31.5.0","source":"GitHub","reportedAt":"2026-04-22 17:29:58","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-xv3r-vr59-95rg"}]},{"advisoryId":"PKSA-qjrw-zc8d-74p2","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-9rxp-f27p-wv3h","title":"CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files","link":"https:\/\/github.com\/advisories\/GHSA-9rxp-f27p-wv3h","cve":"CVE-2026-39389","affectedVersions":"\u003C=0.31.3.0","source":"GitHub","reportedAt":"2026-04-08 19:15:08","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9rxp-f27p-wv3h"}]},{"advisoryId":"PKSA-znp8-d94g-vhxv","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-x3hr-cp7x-44r2","title":"CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting","link":"https:\/\/github.com\/advisories\/GHSA-x3hr-cp7x-44r2","cve":"CVE-2026-39390","affectedVersions":"\u003C=0.31.3.0","source":"GitHub","reportedAt":"2026-04-08 19:15:21","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x3hr-cp7x-44r2"}]},{"advisoryId":"PKSA-v96y-q2b3-cqc5","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-7cm9-v848-cfh2","title":"CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List","link":"https:\/\/github.com\/advisories\/GHSA-7cm9-v848-cfh2","cve":"CVE-2026-39391","affectedVersions":"\u003C=0.31.3.0","source":"GitHub","reportedAt":"2026-04-08 19:15:32","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7cm9-v848-cfh2"}]},{"advisoryId":"PKSA-9pcd-vkjt-q5hq","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-fjpj-6qcq-6pw2","title":"CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization","link":"https:\/\/github.com\/advisories\/GHSA-fjpj-6qcq-6pw2","cve":"CVE-2026-39392","affectedVersions":"\u003C=0.31.3.0","source":"GitHub","reportedAt":"2026-04-08 19:15:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fjpj-6qcq-6pw2"}]},{"advisoryId":"PKSA-1wjp-gt44-q5bg","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-8rh5-4mvx-xj7j","title":"CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass","link":"https:\/\/github.com\/advisories\/GHSA-8rh5-4mvx-xj7j","cve":"CVE-2026-39393","affectedVersions":"\u003C=0.31.3.0","source":"GitHub","reportedAt":"2026-04-08 19:15:57","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8rh5-4mvx-xj7j"}]},{"advisoryId":"PKSA-rh74-dqx1-j9wm","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-vfhx-5459-qhqh","title":"CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller","link":"https:\/\/github.com\/advisories\/GHSA-vfhx-5459-qhqh","cve":"CVE-2026-39394","affectedVersions":"\u003C=0.31.3.0","source":"GitHub","reportedAt":"2026-04-08 19:16:12","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vfhx-5459-qhqh"}]},{"advisoryId":"PKSA-2zsh-chw8-v8ty","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-5ghq-42rg-769x","title":"CI4MS: Company Information Public-Facing Page Full Platform Compromise \u0026 Full Account Takeover for All Roles \u0026 Privilege-Escalation via System Settings Company Information Stored DOM XSS","link":"https:\/\/github.com\/advisories\/GHSA-5ghq-42rg-769x","cve":"CVE-2026-35035","affectedVersions":"\u003C=0.31.1.0","source":"GitHub","reportedAt":"2026-04-06 17:53:02","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-5ghq-42rg-769x"}]},{"advisoryId":"PKSA-m42v-jjr9-d9jw","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-vr2g-rhm5-q4jr","title":"CI4MS: Profile \u0026 User Management Full Account Takeover for All-Roles \u0026 Privilege-Escalation via Stored DOM XSS","link":"https:\/\/github.com\/advisories\/GHSA-vr2g-rhm5-q4jr","cve":"CVE-2026-34989","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-03 04:00:57","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-vr2g-rhm5-q4jr"}]},{"advisoryId":"PKSA-76s3-z1f6-2f6c","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-gcfj-cf7j-vwgj","title":"CI4MS: System Settings (Social Media Management) Full Platform Compromise \u0026 Full Account Takeover for All-Roles \u0026 Privilege-Escalation via Stored DOM XSS","link":"https:\/\/github.com\/advisories\/GHSA-gcfj-cf7j-vwgj","cve":"CVE-2026-34561","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-01 22:02:34","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-gcfj-cf7j-vwgj"}]},{"advisoryId":"PKSA-5wvv-b5q1-7q3y","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-v897-c6vq-6cr3","title":"CI4MS: System Settings (Company Information) Full Platform Compromise \u0026 Full Account Takeover for All-Roles \u0026 Privilege-Escalation via Stored DOM XSS","link":"https:\/\/github.com\/advisories\/GHSA-v897-c6vq-6cr3","cve":"CVE-2026-34562","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-01 22:03:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-v897-c6vq-6cr3"}]},{"advisoryId":"PKSA-htcp-qzb1-t2rb","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-85m8-g393-jcxf","title":"CI4MS: Backup Management Full Account Takeover for All-Roles \u0026 Privilege-Escalation via Stored DOM Blind XSS","link":"https:\/\/github.com\/advisories\/GHSA-85m8-g393-jcxf","cve":"CVE-2026-34563","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-01 22:04:21","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-85m8-g393-jcxf"}]},{"advisoryId":"PKSA-dscn-pm72-89xm","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-g4pp-fhgf-8653","title":"CI4MS: Menu Management (Pages) Full Account Takeover for All-Roles \u0026 Privilege-Escalation via Stored DOM XSS","link":"https:\/\/github.com\/advisories\/GHSA-g4pp-fhgf-8653","cve":"CVE-2026-34564","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-01 22:04:54","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-g4pp-fhgf-8653"}]},{"advisoryId":"PKSA-xz64-59cc-54j6","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-xgh5-w62m-8mpr","title":"CI4MS: Menu Management (Posts) Full Account Takeover for All-Roles \u0026 Privilege-Escalation via Stored DOM XSS","link":"https:\/\/github.com\/advisories\/GHSA-xgh5-w62m-8mpr","cve":"CVE-2026-34565","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-01 22:05:45","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-xgh5-w62m-8mpr"}]},{"advisoryId":"PKSA-xqh9-kym3-gzkm","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-458r-h248-29c5","title":"CI4MS: Pages Management Full Account Takeover for All-Roles \u0026 Privilege-Escalation via Stored DOM XSS","link":"https:\/\/github.com\/advisories\/GHSA-458r-h248-29c5","cve":"CVE-2026-34566","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-01 22:06:28","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-458r-h248-29c5"}]},{"advisoryId":"PKSA-485k-t9tj-8z9f","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-r33w-c82v-x5v7","title":"CI4MS: Blogs Posts (Categories) Full Account Takeover for All-Roles \u0026 Privilege-Escalation via Stored DOM XSS","link":"https:\/\/github.com\/advisories\/GHSA-r33w-c82v-x5v7","cve":"CVE-2026-34567","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-01 22:06:50","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-r33w-c82v-x5v7"}]},{"advisoryId":"PKSA-vbz6-f418-8p15","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-x7wh-g25g-53vg","title":"CI4MS: Blogs Posts Full Account Takeover for All-Roles \u0026 Privilege-Escalation via Stored DOM XSS","link":"https:\/\/github.com\/advisories\/GHSA-x7wh-g25g-53vg","cve":"CVE-2026-34568","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-01 22:07:13","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-x7wh-g25g-53vg"}]},{"advisoryId":"PKSA-418j-5ftc-hsbw","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-fhrf-q333-82fm","title":"CI4MS: Blogs Categories Full Account Takeover for All-Roles \u0026 Privilege-Escalation via Stored DOM XSS","link":"https:\/\/github.com\/advisories\/GHSA-fhrf-q333-82fm","cve":"CVE-2026-34569","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-01 22:07:37","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-fhrf-q333-82fm"}]},{"advisoryId":"PKSA-xc2p-nr46-tjxw","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-4vxv-4xq4-p84h","title":"CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All\u2011Roles via Improper Session Invalidation (Logic Flaw)","link":"https:\/\/github.com\/advisories\/GHSA-4vxv-4xq4-p84h","cve":"CVE-2026-34570","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-01 22:08:29","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4vxv-4xq4-p84h"}]},{"advisoryId":"PKSA-vgkt-cmh2-qyjg","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-fc4p-p49v-r948","title":"CI4MS: Stored Cross\u2011Site Scripting (Stored XSS) in Backend User Management Allows Session Hijacking and Full Administrative Account Compromise","link":"https:\/\/github.com\/advisories\/GHSA-fc4p-p49v-r948","cve":"CVE-2026-34571","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-01 22:09:03","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-fc4p-p49v-r948"}]},{"advisoryId":"PKSA-srvq-v3bs-mj79","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-8fq3-c5w3-pj3q","title":"CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All\u2011Roles via Improper Session Invalidation (Logic Flaw)","link":"https:\/\/github.com\/advisories\/GHSA-8fq3-c5w3-pj3q","cve":"CVE-2026-34572","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-01 22:09:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8fq3-c5w3-pj3q"}]},{"advisoryId":"PKSA-vjzx-2b18-dktw","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-4333-387x-w245","title":"CI4MS: Blogs Tags Full Account Takeover for All-Roles \u0026 Privilege-Escalation via Stored DOM XSS","link":"https:\/\/github.com\/advisories\/GHSA-4333-387x-w245","cve":"CVE-2026-34559","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-01 21:53:01","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-4333-387x-w245"}]},{"advisoryId":"PKSA-9k1p-9kvd-d2db","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-r4v5-rwr2-q7r4","title":"CI4MS: Logs Full Account Takeover for All-Roles \u0026 Privilege-Escalation via Stored DOM XSS","link":"https:\/\/github.com\/advisories\/GHSA-r4v5-rwr2-q7r4","cve":"CVE-2026-34560","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-01 21:54:27","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-r4v5-rwr2-q7r4"}]},{"advisoryId":"PKSA-rqgq-p6xv-4qz8","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-rpjr-985c-qhvm","title":"CI4MS: Permissions Management Full Account Takeover for All-Roles \u0026 Privilege-Escalation via Stored DOM XSS","link":"https:\/\/github.com\/advisories\/GHSA-rpjr-985c-qhvm","cve":"CVE-2026-34557","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-01 00:10:00","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-rpjr-985c-qhvm"}]},{"advisoryId":"PKSA-r2q1-2d2k-3p65","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-v77r-xg3p-75g7","title":"CI4MS: Methods Management Full Account Takeover for All-Roles \u0026 Privilege-Escalation via Stored DOM XSS","link":"https:\/\/github.com\/advisories\/GHSA-v77r-xg3p-75g7","cve":"CVE-2026-34558","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-04-01 00:09:24","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-v77r-xg3p-75g7"}]},{"advisoryId":"PKSA-3cpq-nyc1-zgst","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-66m2-v9v9-95c3","title":"ci4-cms-erp\/ci4ms: System Settings (Mail Settings) Full Platform Compromise \u0026 Full Account Takeover for All-Roles \u0026 Privilege-Escalation via Stored DOM XSS","link":"https:\/\/github.com\/advisories\/GHSA-66m2-v9v9-95c3","cve":"CVE-2026-27599","affectedVersions":"\u003C=0.28.6.0","source":"GitHub","reportedAt":"2026-03-30 16:19:05","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-66m2-v9v9-95c3"}]},{"advisoryId":"PKSA-72bz-jm9q-1sgn","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-654x-9q7r-g966","title":"CI4MS Vulnerable to User Email Enumeration via Password Reset Flow","link":"https:\/\/github.com\/advisories\/GHSA-654x-9q7r-g966","cve":"CVE-2026-25509","affectedVersions":"\u003C0.28.5.0","source":"GitHub","reportedAt":"2026-02-02 21:52:06","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-654x-9q7r-g966"}]},{"advisoryId":"PKSA-ztv6-h3sy-m4xc","packageName":"ci4-cms-erp\/ci4ms","remoteId":"GHSA-gp56-f67f-m4px","title":"CI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File Editor","link":"https:\/\/github.com\/advisories\/GHSA-gp56-f67f-m4px","cve":"CVE-2026-25510","affectedVersions":"\u003C0.28.5.0","source":"GitHub","reportedAt":"2026-02-02 21:52:58","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-gp56-f67f-m4px"}]}],"simplesamlphp\/simplesamlphp-module-casserver":[{"advisoryId":"PKSA-4zw8-rhj7-ftzt","packageName":"simplesamlphp\/simplesamlphp-module-casserver","remoteId":"GHSA-jrrg-99xh-5j2q","title":"SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read\/unserialize and conditional deletion","link":"https:\/\/github.com\/advisories\/GHSA-jrrg-99xh-5j2q","cve":"CVE-2026-46491","affectedVersions":"\u003C=7.0.2","source":"GitHub","reportedAt":"2026-05-15 18:07:51","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jrrg-99xh-5j2q"}]},{"advisoryId":"PKSA-5vs1-v1t7-v5tj","packageName":"simplesamlphp\/simplesamlphp-module-casserver","remoteId":"GHSA-cvrm-5hp6-h523","title":"SimpleSAMLphp casserver: Open Redirect in logout","link":"https:\/\/github.com\/advisories\/GHSA-cvrm-5hp6-h523","cve":"CVE-2025-65954","affectedVersions":"\u003C6.3.1|\u003E=7.0.0-rc1,\u003C7.0.0-rc3","source":"GitHub","reportedAt":"2026-05-15 16:21:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cvrm-5hp6-h523"}]}],"nukeviet\/nukeviet":[{"advisoryId":"PKSA-3wj7-33bv-rdwf","packageName":"nukeviet\/nukeviet","remoteId":"GHSA-64rr-pp78-62ww","title":"NukeViet CMS: Stored Cross-Site Scripting (XSS) via insufficient server-side input sanitization in Request class","link":"https:\/\/github.com\/advisories\/GHSA-64rr-pp78-62ww","cve":"CVE-2026-41147","affectedVersions":"\u003C=4.4.01","source":"GitHub","reportedAt":"2026-05-15 16:45:03","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-64rr-pp78-62ww"}]}],"coreshop\/core-shop":[{"advisoryId":"PKSA-9rch-wbbh-7nr6","packageName":"coreshop\/core-shop","remoteId":"GHSA-q58j-g3f4-h26h","title":"CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration","link":"https:\/\/github.com\/advisories\/GHSA-q58j-g3f4-h26h","cve":"CVE-2026-41249","affectedVersions":"=5.0.0","source":"GitHub","reportedAt":"2026-05-14 13:18:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-q58j-g3f4-h26h"}]},{"advisoryId":"PKSA-vfgm-9q5v-977q","packageName":"coreshop\/core-shop","remoteId":"GHSA-fqcv-8859-86x2","title":"CoreShop Vulnerable to SQL Injection via Admin customer-company-modifier","link":"https:\/\/github.com\/advisories\/GHSA-fqcv-8859-86x2","cve":"CVE-2026-23959","affectedVersions":"\u003C4.1.9","source":"GitHub","reportedAt":"2026-01-21 16:13:12","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fqcv-8859-86x2"}]},{"advisoryId":"PKSA-x7h5-362r-pw3g","packageName":"coreshop\/core-shop","remoteId":"GHSA-ch7p-mpv4-4vg4","title":"CoreShop Vulnerable to SQL Injection via Admin Reports","link":"https:\/\/github.com\/advisories\/GHSA-ch7p-mpv4-4vg4","cve":"CVE-2026-22242","affectedVersions":"\u003C=4.1.7","source":"GitHub","reportedAt":"2026-01-07 19:29:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-ch7p-mpv4-4vg4"}]}],"composer\/composer":[{"advisoryId":"PKSA-pwvr-3754-v57r","packageName":"composer\/composer","remoteId":"composer\/composer\/CVE-2026-45793.yaml","title":"Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs","link":"https:\/\/github.com\/composer\/composer\/security\/advisories\/GHSA-f9f8-rm49-7jv2","cve":"CVE-2026-45793","affectedVersions":"\u003E=2.3,\u003C2.9.8|\u003E=2.0.0,\u003C2.2.28|\u003E=1.0,\u003C1.10.28","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-13 07:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"composer\/composer\/CVE-2026-45793.yaml"},{"name":"GitHub","remoteId":"GHSA-f9f8-rm49-7jv2"}]},{"advisoryId":"PKSA-t5r2-p5q9-mtpn","packageName":"composer\/composer","remoteId":"composer\/composer\/CVE-2026-40261.yaml","title":"Command injection via malicious Perforce source reference\/url","link":"https:\/\/github.com\/composer\/composer\/security\/advisories\/GHSA-gqw4-4w2p-838q","cve":"CVE-2026-40261","affectedVersions":"\u003E=2.3,\u003C2.9.6|\u003E=1.0,\u003C2.2.27","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-04-14 09:42:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"composer\/composer\/CVE-2026-40261.yaml"},{"name":"GitHub","remoteId":"GHSA-gqw4-4w2p-838q"}]},{"advisoryId":"PKSA-6bp1-9hfj-2cgv","packageName":"composer\/composer","remoteId":"composer\/composer\/CVE-2026-40176.yaml","title":"Command injection via malicious Perforce repository definition","link":"https:\/\/github.com\/composer\/composer\/security\/advisories\/GHSA-wg36-wvj6-r67p","cve":"CVE-2026-40176","affectedVersions":"\u003E=2.3,\u003C2.9.6|\u003E=1.0,\u003C2.2.27","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-04-14 09:42:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"composer\/composer\/CVE-2026-40176.yaml"},{"name":"GitHub","remoteId":"GHSA-wg36-wvj6-r67p"}]},{"advisoryId":"PKSA-1gck-s111-yq7g","packageName":"composer\/composer","remoteId":"GHSA-59pp-r3rg-353g","title":"Composer is vulnerable to ANSI sequence injection","link":"https:\/\/github.com\/advisories\/GHSA-59pp-r3rg-353g","cve":"CVE-2025-67746","affectedVersions":"\u003E=2.3.0,\u003C2.9.3|\u003E=2.0.0,\u003C2.2.26","source":"GitHub","reportedAt":"2025-12-30 17:44:10","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-59pp-r3rg-353g"}]},{"advisoryId":"PKSA-qx8p-c3v3-6yfg","packageName":"composer\/composer","remoteId":"composer\/composer\/CVE-2015-8371.yaml","title":"Composer Cache Injection vulnerability","link":"http:\/\/flyingmana.de\/blog_en\/2016\/02\/14\/composer_cache_injection_vulnerability_cve_2015_8371.html","cve":"CVE-2015-8371","affectedVersions":"\u003C1.0.0-beta1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2016-02-10 14:51:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"composer\/composer\/CVE-2015-8371.yaml"},{"name":"GitHub","remoteId":"GHSA-725m-w832-q973"}]}],"krayin\/laravel-crm":[{"advisoryId":"PKSA-bfyk-wk4r-cjz9","packageName":"krayin\/laravel-crm","remoteId":"GHSA-j822-46r5-h4qx","title":"Webkul Krayin CRM is Vulnerable to Cross-Site Scripting in the \/admin\/activities\/create endpoint","link":"https:\/\/github.com\/advisories\/GHSA-j822-46r5-h4qx","cve":"CVE-2026-36341","affectedVersions":"=2.1.5","source":"GitHub","reportedAt":"2026-05-07 18:30:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j822-46r5-h4qx"}]},{"advisoryId":"PKSA-vkyr-b96k-z2ks","packageName":"krayin\/laravel-crm","remoteId":"GHSA-32px-ccfx-cxq3","title":"Krayin CRM allows a remote attacker to execute arbitrary code via compose email function","link":"https:\/\/github.com\/advisories\/GHSA-32px-ccfx-cxq3","cve":"CVE-2026-36340","affectedVersions":"=2.1.5","source":"GitHub","reportedAt":"2026-04-30 18:30:32","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-32px-ccfx-cxq3"}]},{"advisoryId":"PKSA-y1wv-79ht-f4db","packageName":"krayin\/laravel-crm","remoteId":"GHSA-rm5f-3c25-p4cw","title":"Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the \/Controllers\/Lead\/LeadController.php","link":"https:\/\/github.com\/advisories\/GHSA-rm5f-3c25-p4cw","cve":"CVE-2026-38530","affectedVersions":"\u003C=2.2.0","source":"GitHub","reportedAt":"2026-04-14 18:30:35","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-rm5f-3c25-p4cw"}]},{"advisoryId":"PKSA-5xsp-55yb-hdyp","packageName":"krayin\/laravel-crm","remoteId":"GHSA-r8rp-5f55-5j9x","title":"Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the \/Settings\/UserController.php","link":"https:\/\/github.com\/advisories\/GHSA-r8rp-5f55-5j9x","cve":"CVE-2026-38529","affectedVersions":"\u003C=2.2.0","source":"GitHub","reportedAt":"2026-04-14 18:30:35","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r8rp-5f55-5j9x"}]},{"advisoryId":"PKSA-2w9z-jxqd-y35k","packageName":"krayin\/laravel-crm","remoteId":"GHSA-2xx8-j85v-j7wh","title":"Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the \/Contact\/Persons\/PersonController.php","link":"https:\/\/github.com\/advisories\/GHSA-2xx8-j85v-j7wh","cve":"CVE-2026-38532","affectedVersions":"\u003C=2.2.0","source":"GitHub","reportedAt":"2026-04-14 18:30:35","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2xx8-j85v-j7wh"}]},{"advisoryId":"PKSA-gcg3-xvcm-8tz7","packageName":"krayin\/laravel-crm","remoteId":"GHSA-fpx9-9hq8-w2xc","title":"Webkul Krayin CRM has Server-Side Request Forgery (SSRF)","link":"https:\/\/github.com\/advisories\/GHSA-fpx9-9hq8-w2xc","cve":"CVE-2026-38527","affectedVersions":"\u003C=2.2.0","source":"GitHub","reportedAt":"2026-04-14 18:30:35","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fpx9-9hq8-w2xc"}]},{"advisoryId":"PKSA-9rzv-szxy-ckw5","packageName":"krayin\/laravel-crm","remoteId":"GHSA-9m2v-hc5g-5jpv","title":"Krayin CRM is vulnerable to Cross-site Scripting (XSS)","link":"https:\/\/github.com\/advisories\/GHSA-9m2v-hc5g-5jpv","cve":"CVE-2026-5370","affectedVersions":"\u003C=2.2.0","source":"GitHub","reportedAt":"2026-04-02 18:31:39","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-9m2v-hc5g-5jpv"}]}],"mantisbt\/mantisbt":[{"advisoryId":"PKSA-x2q4-xdvd-5bhg","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-7mqj-8gj2-cg59","title":"MantisBT has Stored XSS on Move Attachments Admin Page","link":"https:\/\/github.com\/advisories\/GHSA-7mqj-8gj2-cg59","cve":"CVE-2026-44655","affectedVersions":"\u003E=1.3.0,\u003C=2.28.1","source":"GitHub","reportedAt":"2026-05-11 19:40:29","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7mqj-8gj2-cg59"}]},{"advisoryId":"PKSA-2yw5-k1t7-1bg1","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-p6fr-rxq7-xcg8","title":"MantisBT Vulnerable to Stored XSS in File Download","link":"https:\/\/github.com\/advisories\/GHSA-p6fr-rxq7-xcg8","cve":"CVE-2026-44657","affectedVersions":"\u003C=2.28.1","source":"GitHub","reportedAt":"2026-05-11 19:40:43","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-p6fr-rxq7-xcg8"}]},{"advisoryId":"PKSA-9b5m-7bg5-xjqr","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-frf7-jhp9-jxm6","title":"MantisBT Vulnerable to Privilege Escalation from Manager to Administrator","link":"https:\/\/github.com\/advisories\/GHSA-frf7-jhp9-jxm6","cve":"CVE-2026-34390","affectedVersions":"\u003C=2.28.1","source":"GitHub","reportedAt":"2026-05-11 19:32:06","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-frf7-jhp9-jxm6"}]},{"advisoryId":"PKSA-fybf-x73k-s1x5","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-fvjf-68wh-rwp2","title":"MantisBT is Vulnerable to Stored HTML Injection\/XSS in Clone Issue Form","link":"https:\/\/github.com\/advisories\/GHSA-fvjf-68wh-rwp2","cve":"CVE-2026-34463","affectedVersions":"\u003C=2.28.1","source":"GitHub","reportedAt":"2026-05-11 19:32:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fvjf-68wh-rwp2"}]},{"advisoryId":"PKSA-wqq3-5hnc-g52v","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-ggw7-9675-6v4v","title":"MantisBT has an authorization bypass in private issue monitoring","link":"https:\/\/github.com\/advisories\/GHSA-ggw7-9675-6v4v","cve":"CVE-2026-34579","affectedVersions":"\u003E=2.26.1,\u003C=2.28.1","source":"GitHub","reportedAt":"2026-05-11 19:32:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-ggw7-9675-6v4v"}]},{"advisoryId":"PKSA-mqx4-yq62-zbx3","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-rmp5-5jj7-gmvf","title":"MantisBT has an authorization bypass that allows reading attachments after losing access to a private issue","link":"https:\/\/github.com\/advisories\/GHSA-rmp5-5jj7-gmvf","cve":"CVE-2026-34744","affectedVersions":"\u003C=2.28.1","source":"GitHub","reportedAt":"2026-05-11 19:32:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rmp5-5jj7-gmvf"}]},{"advisoryId":"PKSA-vg9w-dq6n-8d9w","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-h4x5-gvx6-3rwc","title":"MantisBT has an Authorization Bypass that Allows Uploading Attachments to Private Issues via REST API","link":"https:\/\/github.com\/advisories\/GHSA-h4x5-gvx6-3rwc","cve":"CVE-2026-34754","affectedVersions":"\u003C=2.28.1","source":"GitHub","reportedAt":"2026-05-11 19:33:06","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h4x5-gvx6-3rwc"}]},{"advisoryId":"PKSA-r5kj-njzm-rsnd","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-crmx-4p49-46m2","title":"MantisBT: Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is Revoked","link":"https:\/\/github.com\/advisories\/GHSA-crmx-4p49-46m2","cve":"CVE-2026-34970","affectedVersions":"\u003C=2.28.1","source":"GitHub","reportedAt":"2026-05-11 19:33:10","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-crmx-4p49-46m2"}]},{"advisoryId":"PKSA-vqsr-dxg3-8yzy","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-qj6w-v29q-4rgx","title":"MantisBT is Vulnerable to Stored XSS in Custom Field Textarea Values","link":"https:\/\/github.com\/advisories\/GHSA-qj6w-v29q-4rgx","cve":"CVE-2026-39960","affectedVersions":"\u003C=2.28.1","source":"GitHub","reportedAt":"2026-05-11 19:34:32","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qj6w-v29q-4rgx"}]},{"advisoryId":"PKSA-gt1y-4mwq-1fky","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-j3v9-553h-x28j","title":"MantisBT is Vulnerable to XSS leading to account takeover via updating a user\u0027s font family preference","link":"https:\/\/github.com\/advisories\/GHSA-j3v9-553h-x28j","cve":"CVE-2026-40596","affectedVersions":"\u003E=2.11.0,\u003C=2.28.1","source":"GitHub","reportedAt":"2026-05-11 19:34:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j3v9-553h-x28j"}]},{"advisoryId":"PKSA-vmj5-ycv9-cm2v","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-9c3j-xm6v-j7j3","title":"MantisBT has a Content Security Policy bypass via attachments","link":"https:\/\/github.com\/advisories\/GHSA-9c3j-xm6v-j7j3","cve":"CVE-2026-40597","affectedVersions":"\u003C=2.28.1","source":"GitHub","reportedAt":"2026-05-11 19:34:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9c3j-xm6v-j7j3"}]},{"advisoryId":"PKSA-gycx-g1kn-1tnd","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-6jh4-47v2-4g37","title":"MantisBT has Potential Referer-Based Reflected HTML Injection \/ XSS in Tag Update Page","link":"https:\/\/github.com\/advisories\/GHSA-6jh4-47v2-4g37","cve":"CVE-2026-40598","affectedVersions":"\u003C=2.28.1","source":"GitHub","reportedAt":"2026-05-11 19:35:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6jh4-47v2-4g37"}]},{"advisoryId":"PKSA-j9zz-q8wb-jgsg","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-f633-865q-2mhh","title":"MantisBT is Vulnerable to Stored XSS in Saved-Filter Owner Column","link":"https:\/\/github.com\/advisories\/GHSA-f633-865q-2mhh","cve":"CVE-2026-40607","affectedVersions":"\u003E=2.1.0,\u003C=2.28.1","source":"GitHub","reportedAt":"2026-05-11 19:35:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f633-865q-2mhh"}]},{"advisoryId":"PKSA-p4dp-frh9-2khv","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-j7v9-f46r-2rp4","title":"MantisBT is Vulnerable to Reflected XSS in Rendering Dynamic Custom Textarea Field","link":"https:\/\/github.com\/advisories\/GHSA-j7v9-f46r-2rp4","cve":"CVE-2026-41897","affectedVersions":"\u003E=1.0.0,\u003C2.28.2","source":"GitHub","reportedAt":"2026-05-11 19:39:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j7v9-f46r-2rp4"}]},{"advisoryId":"PKSA-67ww-bjf6-fqgz","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-pq86-j2c2-47f6","title":"MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API","link":"https:\/\/github.com\/advisories\/GHSA-pq86-j2c2-47f6","cve":"CVE-2026-42070","affectedVersions":"\u003C=2.28.1","source":"GitHub","reportedAt":"2026-05-11 19:39:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pq86-j2c2-47f6"}]},{"advisoryId":"PKSA-d3fh-4w7k-rvy1","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-pw5x-2mf9-3xc8","title":"MantisBT has a Private Bugnote Attachment Content Leak via REST API","link":"https:\/\/github.com\/advisories\/GHSA-pw5x-2mf9-3xc8","cve":"CVE-2026-42071","affectedVersions":"\u003E=2.23.0,\u003C=2.28.1","source":"GitHub","reportedAt":"2026-05-11 19:39:43","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pw5x-2mf9-3xc8"}]},{"advisoryId":"PKSA-7hdg-8xc6-bhnt","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-68w5-w573-q2r8","title":"MantisBT Has Authorization Bypass in Global Profile Creation","link":"https:\/\/github.com\/advisories\/GHSA-68w5-w573-q2r8","cve":"CVE-2026-33052","affectedVersions":"\u003E=2.28.0,\u003C2.28.2","source":"GitHub","reportedAt":"2026-05-11 17:58:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-68w5-w573-q2r8"}]},{"advisoryId":"PKSA-snjj-r5pw-fbgn","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-73vx-49mv-v8w5","title":"MantisBT has Stored HTML Injection\/XSS when displaying Tags in Timeline","link":"https:\/\/github.com\/advisories\/GHSA-73vx-49mv-v8w5","cve":"CVE-2026-33548","affectedVersions":"=2.28.0","source":"GitHub","reportedAt":"2026-03-25 20:09:09","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-73vx-49mv-v8w5"}]},{"advisoryId":"PKSA-dcyg-8m67-cs7k","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-fh48-f69w-7vmp","title":"MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmation","link":"https:\/\/github.com\/advisories\/GHSA-fh48-f69w-7vmp","cve":"CVE-2026-33517","affectedVersions":"=2.28.0","source":"GitHub","reportedAt":"2026-03-25 19:56:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fh48-f69w-7vmp"}]},{"advisoryId":"PKSA-cwyv-kt56-ndf5","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-phrq-pc6r-f6gh","title":"MantisBT is vulnerable to authentication bypass through the SOAP API on MySQL","link":"https:\/\/github.com\/advisories\/GHSA-phrq-pc6r-f6gh","cve":"CVE-2026-30849","affectedVersions":"\u003C2.28.1","source":"GitHub","reportedAt":"2026-03-23 20:28:52","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-phrq-pc6r-f6gh"}]},{"advisoryId":"PKSA-983m-gpx4-ywx3","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-q747-c74m-69pr","title":"MantisBT lacks verification when changing a user\u0027s email address","link":"https:\/\/github.com\/advisories\/GHSA-q747-c74m-69pr","cve":"CVE-2025-55155","affectedVersions":"\u003C2.27.2","source":"GitHub","reportedAt":"2025-11-03 20:12:18","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q747-c74m-69pr"}]},{"advisoryId":"PKSA-h3h3-9cvh-htmg","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-g582-8vwr-68h2","title":"MantisBT unauthorized disclosure of private project column configuration","link":"https:\/\/github.com\/advisories\/GHSA-g582-8vwr-68h2","cve":"CVE-2025-62520","affectedVersions":"\u003C2.27.2","source":"GitHub","reportedAt":"2025-11-03 20:13:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g582-8vwr-68h2"}]},{"advisoryId":"PKSA-gxs3-7yhj-kxf3","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-4v8w-gg5j-ph37","title":"MantisBT vulnerable to authentication bypass for some passwords due to PHP type juggling","link":"https:\/\/github.com\/advisories\/GHSA-4v8w-gg5j-ph37","cve":"CVE-2025-47776","affectedVersions":"\u003C2.27.2","source":"GitHub","reportedAt":"2025-11-03 17:07:36","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4v8w-gg5j-ph37"}]},{"advisoryId":"PKSA-r8rw-8k4b-bvgz","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-r3jf-hm7q-qfw5","title":"MantisBT Vulnerable to Denial-of-Service (DoS) via Excessive Note Length","link":"https:\/\/github.com\/advisories\/GHSA-r3jf-hm7q-qfw5","cve":"CVE-2025-46556","affectedVersions":"\u003C2.27.2","source":"GitHub","reportedAt":"2025-11-03 17:07:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r3jf-hm7q-qfw5"}]}],"yiisoft\/yii2":[{"advisoryId":"PKSA-mxtc-f5ct-dqqd","packageName":"yiisoft\/yii2","remoteId":"GHSA-5vpg-rj7q-qpw2","title":"Yii 2: Local file inclusion via view parameter name collision","link":"https:\/\/github.com\/advisories\/GHSA-5vpg-rj7q-qpw2","cve":"CVE-2026-39850","affectedVersions":"\u003C2.0.55","source":"GitHub","reportedAt":"2026-05-11 19:34:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5vpg-rj7q-qpw2"}]}],"torrentpier\/torrentpier":[{"advisoryId":"PKSA-yfmp-ydrw-v24w","packageName":"torrentpier\/torrentpier","remoteId":"GHSA-h29g-c9cx-c73q","title":"torrentpier has PHP Serialize Injections","link":"https:\/\/github.com\/advisories\/GHSA-h29g-c9cx-c73q","cve":null,"affectedVersions":"\u003C=2.4.3","source":"GitHub","reportedAt":"2026-05-11 17:53:20","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-h29g-c9cx-c73q"}]},{"advisoryId":"PKSA-8wv3-ffky-dfvg","packageName":"torrentpier\/torrentpier","remoteId":"GHSA-4rwr-8c3m-55f6","title":"TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel\u0027s topic_id parameter","link":"https:\/\/github.com\/advisories\/GHSA-4rwr-8c3m-55f6","cve":"CVE-2025-64519","affectedVersions":"\u003C=2.8.8","source":"GitHub","reportedAt":"2025-11-10 21:30:44","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4rwr-8c3m-55f6"}]}],"studio-42\/elfinder":[{"advisoryId":"PKSA-42xd-jnjn-nrty","packageName":"studio-42\/elfinder","remoteId":"GHSA-c3gj-q88f-7hqj","title":"elFinder MySQL has a SQL Injection in its Volume Driver (elFinderVolumeMySQL)","link":"https:\/\/github.com\/advisories\/GHSA-c3gj-q88f-7hqj","cve":"CVE-2026-44521","affectedVersions":"\u003C=2.1.67","source":"GitHub","reportedAt":"2026-05-11 16:11:31","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c3gj-q88f-7hqj"}]},{"advisoryId":"PKSA-2p87-h1j5-yb5n","packageName":"studio-42\/elfinder","remoteId":"GHSA-8q4h-8crm-5cvc","title":"elFinder: Command injection in resize background color parameter when using ImageMagick CLI","link":"https:\/\/github.com\/advisories\/GHSA-8q4h-8crm-5cvc","cve":"CVE-2026-41247","affectedVersions":"\u003C2.1.67","source":"GitHub","reportedAt":"2026-04-17 22:33:51","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8q4h-8crm-5cvc"}]}],"devcode-it\/openstamanager":[{"advisoryId":"PKSA-4d6v-4cnw-287h","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-rm34-fg4m-39mw","title":"OpenSTAManager contains an arbitrary file upload vulnerability in its module update functionality ","link":"https:\/\/github.com\/advisories\/GHSA-rm34-fg4m-39mw","cve":"CVE-2026-38751","affectedVersions":"\u003C=2.10-beta","source":"GitHub","reportedAt":"2026-05-04 21:30:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-rm34-fg4m-39mw"}]},{"advisoryId":"PKSA-398m-bjsp-p21n","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-mmm5-3g4x-qw39","title":"OpenSTAManager has a SQL Injection via righe Parameter in confronta_righe Modals","link":"https:\/\/github.com\/advisories\/GHSA-mmm5-3g4x-qw39","cve":"CVE-2026-35470","affectedVersions":"\u003C=2.10.1","source":"GitHub","reportedAt":"2026-04-03 21:57:08","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mmm5-3g4x-qw39"}]},{"advisoryId":"PKSA-dx7q-hp3f-cn12","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-2fr7-cc4f-wh98","title":"OpenSTAManager: SQL Injection via Aggiornamenti Module","link":"https:\/\/github.com\/advisories\/GHSA-2fr7-cc4f-wh98","cve":"CVE-2026-35168","affectedVersions":"\u003C=2.10.1","source":"GitHub","reportedAt":"2026-04-03 03:47:37","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2fr7-cc4f-wh98"}]},{"advisoryId":"PKSA-84pv-3jy7-8y8y","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-3gw8-3mg3-jmpc","title":"OpenSTAManager has a Time-Based Blind SQL Injection via `options[stato]` Parameter","link":"https:\/\/github.com\/advisories\/GHSA-3gw8-3mg3-jmpc","cve":"CVE-2026-28805","affectedVersions":"\u003C=2.10.1","source":"GitHub","reportedAt":"2026-04-01 19:46:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3gw8-3mg3-jmpc"}]},{"advisoryId":"PKSA-7wd8-5d3q-gt4k","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-whv5-4q2f-q68g","title":"OpenSTAManager Affected by Remote Code Execution via Insecure Deserialization in OAuth2","link":"https:\/\/github.com\/advisories\/GHSA-whv5-4q2f-q68g","cve":"CVE-2026-29782","affectedVersions":"\u003C=2.10.1","source":"GitHub","reportedAt":"2026-04-01 19:46:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-whv5-4q2f-q68g"}]},{"advisoryId":"PKSA-gkxr-gfn8-3tk2","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-247v-7cw6-q57v","title":"OpenSTAManager affected by unauthenticated privilege escalation via modules\/utenti\/actions.php","link":"https:\/\/github.com\/advisories\/GHSA-247v-7cw6-q57v","cve":"CVE-2026-27012","affectedVersions":"\u003C=2.9.8","source":"GitHub","reportedAt":"2026-03-03 17:43:49","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-247v-7cw6-q57v"}]},{"advisoryId":"PKSA-xj58-vqx8-fbpq","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-jfgp-g7x7-j25j","title":"OpenSTAManager Affected by XSS in modifica_iva.php via righe parameter","link":"https:\/\/github.com\/advisories\/GHSA-jfgp-g7x7-j25j","cve":"CVE-2026-24415","affectedVersions":"\u003C2.9.8","source":"GitHub","reportedAt":"2026-03-03 17:39:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jfgp-g7x7-j25j"}]},{"advisoryId":"PKSA-h29d-v9rg-p75n","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-4hc4-8599-xh2h","title":"OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service","link":"https:\/\/github.com\/advisories\/GHSA-4hc4-8599-xh2h","cve":"CVE-2026-24417","affectedVersions":"\u003C2.9.8","source":"GitHub","reportedAt":"2026-02-06 18:23:14","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4hc4-8599-xh2h"}]},{"advisoryId":"PKSA-ff9m-7w2n-x2fw","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-4xwv-49c8-fvhq","title":"OpenSTAManager has a SQL Injection vulnerability in the Scadenzario bulk operations module","link":"https:\/\/github.com\/advisories\/GHSA-4xwv-49c8-fvhq","cve":"CVE-2026-24418","affectedVersions":"\u003C=2.9.8","source":"GitHub","reportedAt":"2026-02-06 18:24:10","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4xwv-49c8-fvhq"}]},{"advisoryId":"PKSA-6h6r-npfh-qb3m","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-4j2x-jh4m-fqv6","title":"OpenSTAManager has a SQL Injection in the Prima Nota  module ","link":"https:\/\/github.com\/advisories\/GHSA-4j2x-jh4m-fqv6","cve":"CVE-2026-24419","affectedVersions":"\u003C=2.9.8","source":"GitHub","reportedAt":"2026-02-06 18:25:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4j2x-jh4m-fqv6"}]},{"advisoryId":"PKSA-9s5k-763f-q4yd","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-p864-fqgv-92q4","title":"OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module","link":"https:\/\/github.com\/advisories\/GHSA-p864-fqgv-92q4","cve":"CVE-2026-24416","affectedVersions":"\u003C=2.9.8","source":"GitHub","reportedAt":"2026-02-06 18:19:51","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-p864-fqgv-92q4"}]},{"advisoryId":"PKSA-wvq9-cxvz-jy62","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-qjv8-63xq-gq8m","title":"OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint)","link":"https:\/\/github.com\/advisories\/GHSA-qjv8-63xq-gq8m","cve":"CVE-2025-69214","affectedVersions":"\u003C=2.9.8","source":"GitHub","reportedAt":"2026-02-06 18:04:32","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qjv8-63xq-gq8m"}]},{"advisoryId":"PKSA-vrdb-wqb7-67h2","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-q6g3-fv43-m2w6","title":"OpenSTAManager has a SQL Injection in Scadenzario Print Template","link":"https:\/\/github.com\/advisories\/GHSA-q6g3-fv43-m2w6","cve":"CVE-2025-69216","affectedVersions":"\u003C=2.9.8","source":"GitHub","reportedAt":"2026-02-06 18:06:13","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-q6g3-fv43-m2w6"}]},{"advisoryId":"PKSA-myj2-kgh7-vymm","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-25fp-8w8p-mx36","title":"OpenSTAManager has an OS Command Injection in P7M File Processing","link":"https:\/\/github.com\/advisories\/GHSA-25fp-8w8p-mx36","cve":"CVE-2025-69212","affectedVersions":"\u003C=2.9.8","source":"GitHub","reportedAt":"2026-02-06 17:59:37","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-25fp-8w8p-mx36"}]},{"advisoryId":"PKSA-z7vr-c7n6-k2xn","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-qx9p-w3vj-q24q","title":"OpenSTAManager has an SQL Injection in the Stampe Module","link":"https:\/\/github.com\/advisories\/GHSA-qx9p-w3vj-q24q","cve":"CVE-2025-69215","affectedVersions":"\u003C=2.9.8","source":"GitHub","reportedAt":"2026-02-03 19:01:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qx9p-w3vj-q24q"}]},{"advisoryId":"PKSA-8235-xswg-bmnf","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-w995-ff8h-rppg","title":"OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint)","link":"https:\/\/github.com\/advisories\/GHSA-w995-ff8h-rppg","cve":"CVE-2025-69213","affectedVersions":"\u003C=2.9.8","source":"GitHub","reportedAt":"2026-02-03 18:44:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w995-ff8h-rppg"}]},{"advisoryId":"PKSA-xh8m-q572-khyv","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-2jm2-2p35-rp3j","title":"OpenSTAManager has Authenticated SQL Injection in API via \u0027display\u0027 parameter","link":"https:\/\/github.com\/advisories\/GHSA-2jm2-2p35-rp3j","cve":"CVE-2025-65103","affectedVersions":"\u003C=2.9.4","source":"GitHub","reportedAt":"2025-11-19 21:00:37","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2jm2-2p35-rp3j"}]}],"prestashop\/prestashop":[{"advisoryId":"PKSA-f9zy-1yrp-415w","packageName":"prestashop\/prestashop","remoteId":"GHSA-w9f3-qc75-qgx9","title":"PrestaShop has a stored XSS executable in customer service view","link":"https:\/\/github.com\/advisories\/GHSA-w9f3-qc75-qgx9","cve":"CVE-2026-44212","affectedVersions":"\u003E=9.0.0,\u003C9.1.1|\u003C8.2.6","source":"GitHub","reportedAt":"2026-05-08 16:54:22","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-w9f3-qc75-qgx9"}]},{"advisoryId":"PKSA-qc2t-77k5-sq5w","packageName":"prestashop\/prestashop","remoteId":"GHSA-283w-xf3q-788v","title":"PrestaShop: Improper Use of Validation Framework","link":"https:\/\/github.com\/advisories\/GHSA-283w-xf3q-788v","cve":"CVE-2026-33674","affectedVersions":"\u003E=9.0.0-alpha.1,\u003C9.1.0|\u003C8.2.5","source":"GitHub","reportedAt":"2026-03-25 19:40:42","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-283w-xf3q-788v"}]},{"advisoryId":"PKSA-327m-nm79-1t19","packageName":"prestashop\/prestashop","remoteId":"GHSA-35pf-37c6-jxjv","title":"PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables","link":"https:\/\/github.com\/advisories\/GHSA-35pf-37c6-jxjv","cve":"CVE-2026-33673","affectedVersions":"\u003C8.2.5|\u003E=9.0.0-alpha.1,\u003C9.1.0","source":"GitHub","reportedAt":"2026-03-25 19:41:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-35pf-37c6-jxjv"}]},{"advisoryId":"PKSA-b6pc-d5t4-9nqt","packageName":"prestashop\/prestashop","remoteId":"GHSA-67v7-3g49-mxh2","title":"PrestaShop affected by time based enumeration in FO login form","link":"https:\/\/github.com\/advisories\/GHSA-67v7-3g49-mxh2","cve":"CVE-2026-25597","affectedVersions":"\u003C8.2.4|\u003E=9.0.0-alpha.1,\u003C9.0.3","source":"GitHub","reportedAt":"2026-02-03 21:13:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-67v7-3g49-mxh2"}]}],"funadmin\/funadmin":[{"advisoryId":"PKSA-1r81-6z2f-xhbh","packageName":"funadmin\/funadmin","remoteId":"GHSA-qhh7-263p-54r3","title":"Funadmin has an Improper Access Control Issue","link":"https:\/\/github.com\/advisories\/GHSA-qhh7-263p-54r3","cve":"CVE-2026-7733","affectedVersions":"\u003C=7.1.0-rc6","source":"GitHub","reportedAt":"2026-05-04 06:32:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qhh7-263p-54r3"}]},{"advisoryId":"PKSA-46y2-3dk3-ygyt","packageName":"funadmin\/funadmin","remoteId":"GHSA-8hhx-xq9j-xwfj","title":"funadmin exposes sensitive information via getMember function","link":"https:\/\/github.com\/advisories\/GHSA-8hhx-xq9j-xwfj","cve":"CVE-2026-2894","affectedVersions":"\u003C=7.1.0-rc4","source":"GitHub","reportedAt":"2026-02-22 00:31:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8hhx-xq9j-xwfj"}]},{"advisoryId":"PKSA-j1rx-v5j5-4zrh","packageName":"funadmin\/funadmin","remoteId":"GHSA-fmr2-m7gc-577w","title":"funadmin has Weak Password Recovery Mechanism for Forgotten Password","link":"https:\/\/github.com\/advisories\/GHSA-fmr2-m7gc-577w","cve":"CVE-2026-2895","affectedVersions":"\u003C=7.1.0-rc4","source":"GitHub","reportedAt":"2026-02-22 00:31:01","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-fmr2-m7gc-577w"}]},{"advisoryId":"PKSA-dwjy-41q2-31rt","packageName":"funadmin\/funadmin","remoteId":"GHSA-5m2g-4cf6-c3rg","title":"funadmin has Incorrect Privilege Assignment in its Configuration Handler","link":"https:\/\/github.com\/advisories\/GHSA-5m2g-4cf6-c3rg","cve":"CVE-2026-2896","affectedVersions":"\u003C=7.1.0-rc4","source":"GitHub","reportedAt":"2026-02-22 00:31:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5m2g-4cf6-c3rg"}]},{"advisoryId":"PKSA-rzcm-2t96-zr56","packageName":"funadmin\/funadmin","remoteId":"GHSA-gcxp-xg77-798j","title":"funadmin: Deserialization Vulnerability in Backend Endpoint via AuthCloudService getMember Function","link":"https:\/\/github.com\/advisories\/GHSA-gcxp-xg77-798j","cve":"CVE-2026-2898","affectedVersions":"\u003C=7.1.0-rc4","source":"GitHub","reportedAt":"2026-02-22 03:30:26","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-gcxp-xg77-798j"}]},{"advisoryId":"PKSA-z36f-6d88-bjdd","packageName":"funadmin\/funadmin","remoteId":"GHSA-rfh7-7v27-6p9r","title":"funadmin: XSS through Value argument in Backend Interface component","link":"https:\/\/github.com\/advisories\/GHSA-rfh7-7v27-6p9r","cve":"CVE-2026-2897","affectedVersions":"\u003C=7.1.0-rc4","source":"GitHub","reportedAt":"2026-02-22 03:30:26","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-rfh7-7v27-6p9r"}]}],"web-auth\/webauthn-framework":[{"advisoryId":"PKSA-3b1p-96n1-3rfh","packageName":"web-auth\/webauthn-framework","remoteId":"GHSA-h4fw-6r7f-w494","title":"Webauthn has a User Verification Downgrade via Default-Open ClientOverridePolicy","link":"https:\/\/github.com\/advisories\/GHSA-h4fw-6r7f-w494","cve":null,"affectedVersions":"\u003E=5.3.0,\u003C5.3.1","source":"GitHub","reportedAt":"2026-05-07 21:05:33","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-h4fw-6r7f-w494"}]},{"advisoryId":"PKSA-1sct-n8q3-hf7r","packageName":"web-auth\/webauthn-framework","remoteId":"GHSA-f7pm-6hr8-7ggm","title":"Webauthn Framework: allowed_origins collapses URL-like origins to host-only values, bypassing exact origin validation","link":"https:\/\/github.com\/advisories\/GHSA-f7pm-6hr8-7ggm","cve":"CVE-2026-30964","affectedVersions":"\u003E=5.2.0,\u003C5.2.4","source":"GitHub","reportedAt":"2026-03-10 01:19:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f7pm-6hr8-7ggm"}]}],"facturascripts\/facturascripts":[{"advisoryId":"PKSA-jz8v-9c91-p1x8","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-vrxf-vrc4-22p7","title":"FacturaScripts Vulnerable to Unauthenticated phpinfo() Disclosure via Installer Endpoint","link":"https:\/\/github.com\/advisories\/GHSA-vrxf-vrc4-22p7","cve":"CVE-2026-42878","affectedVersions":"\u003E=2026,\u003C=2026.1","source":"GitHub","reportedAt":"2026-05-07 19:43:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vrxf-vrc4-22p7"}]},{"advisoryId":"PKSA-rs14-58cq-g5jg","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-vf3q-frmr-vrr9","title":"FacturaScripts Vulnerable to Authenticated Remote Code Execution (RCE) via GIF Image Upload in Product Images","link":"https:\/\/github.com\/advisories\/GHSA-vf3q-frmr-vrr9","cve":"CVE-2026-42879","affectedVersions":"\u003C=2025.81","source":"GitHub","reportedAt":"2026-05-07 19:49:05","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vf3q-frmr-vrr9"}]},{"advisoryId":"PKSA-xfzw-dtp7-gwj8","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-3pgc-xqg9-cfr6","title":"FacturaScripts Vulnerable to Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism","link":"https:\/\/github.com\/advisories\/GHSA-3pgc-xqg9-cfr6","cve":"CVE-2026-27891","affectedVersions":"\u003C=2025.71","source":"GitHub","reportedAt":"2026-05-07 19:32:14","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3pgc-xqg9-cfr6"}]},{"advisoryId":"PKSA-zck8-p11k-g1qj","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-q7f2-rv22-2xgr","title":"FacturaScripts Vulnerable to Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload\/Download","link":"https:\/\/github.com\/advisories\/GHSA-q7f2-rv22-2xgr","cve":"CVE-2026-27892","affectedVersions":"\u003C=2025.81","source":"GitHub","reportedAt":"2026-05-07 19:33:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q7f2-rv22-2xgr"}]},{"advisoryId":"PKSA-qm4y-jdfc-4pmf","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-gq5c-rw37-g46c","title":"FacturaScripts vulnerable to Reflected Cross-Site Scripting (XSS) via Cookie Manipulation","link":"https:\/\/github.com\/advisories\/GHSA-gq5c-rw37-g46c","cve":"CVE-2026-27964","affectedVersions":"\u003C=2025.71","source":"GitHub","reportedAt":"2026-05-07 19:34:28","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-gq5c-rw37-g46c"}]},{"advisoryId":"PKSA-1ktk-zddg-2f2s","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-r736-2678-fcrx","title":"FacturaScripts vulnerable to stored XSS via product reference in sales\/purchases","link":"https:\/\/github.com\/advisories\/GHSA-r736-2678-fcrx","cve":"CVE-2026-42877","affectedVersions":"\u003C=2025.92","source":"GitHub","reportedAt":"2026-05-07 19:37:08","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r736-2678-fcrx"}]},{"advisoryId":"PKSA-8tbv-2p1s-9wnk","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-pp79-hqv6-vmc3","title":"FacturaScripts has Insecure Parameter Handling: Unauthorized Modification of Immutable \u0027nick\u0027 Field","link":"https:\/\/github.com\/advisories\/GHSA-pp79-hqv6-vmc3","cve":"CVE-2026-32699","affectedVersions":"\u003C=2024.92.x-dev","source":"GitHub","reportedAt":"2026-04-28 22:39:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pp79-hqv6-vmc3"}]},{"advisoryId":"PKSA-tnd6-5wk6-f448","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-cjfx-qhwm-hf99","title":"FacturaScripts has SQL Injection in API ORDER BY Clause","link":"https:\/\/github.com\/advisories\/GHSA-cjfx-qhwm-hf99","cve":"CVE-2026-25513","affectedVersions":"\u003C2025.81","source":"GitHub","reportedAt":"2026-02-03 18:14:43","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-cjfx-qhwm-hf99"}]},{"advisoryId":"PKSA-gc7x-dnq3-tkv9","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-pqqg-5f4f-8952","title":"FacturaScripts has SQL Injection in Autocomplete Actions","link":"https:\/\/github.com\/advisories\/GHSA-pqqg-5f4f-8952","cve":"CVE-2026-25514","affectedVersions":"\u003C2025.81","source":"GitHub","reportedAt":"2026-02-03 18:17:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pqqg-5f4f-8952"}]},{"advisoryId":"PKSA-xpcq-5crs-c78v","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-4v7v-7v7r-3r5h","title":"FacturaScripts has Stored Cross-Site Scripting (XSS) in \u0022Observations\u0022 field via History View","link":"https:\/\/github.com\/advisories\/GHSA-4v7v-7v7r-3r5h","cve":"CVE-2026-23997","affectedVersions":"\u003C=2025.71","source":"GitHub","reportedAt":"2026-02-02 18:17:33","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4v7v-7v7r-3r5h"}]},{"advisoryId":"PKSA-qkt1-mscz-6n4p","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-g6w2-q45f-xrp4","title":"FacturaScripts is Vulnerable to Reflected XSS","link":"https:\/\/github.com\/advisories\/GHSA-g6w2-q45f-xrp4","cve":"CVE-2026-23476","affectedVersions":"\u003C2025.81","source":"GitHub","reportedAt":"2026-02-02 18:00:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g6w2-q45f-xrp4"}]},{"advisoryId":"PKSA-5rds-6cgc-6zg4","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-2267-xqcf-gw2m","title":"FacturaScripts is Vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload","link":"https:\/\/github.com\/advisories\/GHSA-2267-xqcf-gw2m","cve":"CVE-2025-69210","affectedVersions":"\u003C=2025.4|=2025.43|=2025.41|=2025.11","source":"GitHub","reportedAt":"2025-12-30 20:52:21","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2267-xqcf-gw2m"}]}],"mix\/mix":[{"advisoryId":"PKSA-vrn6-t5ym-qs6h","packageName":"mix\/mix","remoteId":"GHSA-vf35-8m4j-gm8v","title":"MixPHP Framework has an SQL injection vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-vf35-8m4j-gm8v","cve":"CVE-2026-42475","affectedVersions":"\u003E=2.0.0,\u003C=2.2.17","source":"GitHub","reportedAt":"2026-05-01 18:31:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vf35-8m4j-gm8v"}]},{"advisoryId":"PKSA-rnvq-qnrp-k5ms","packageName":"mix\/mix","remoteId":"GHSA-q57j-rwwx-7rwp","title":"MixPHP Framework has an SQL injection vulnerability via crafted `data` array","link":"https:\/\/github.com\/advisories\/GHSA-q57j-rwwx-7rwp","cve":"CVE-2026-42474","affectedVersions":"\u003E=2.0.0,\u003C=2.2.17","source":"GitHub","reportedAt":"2026-05-01 18:31:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q57j-rwwx-7rwp"}]}],"intercom\/intercom-php":[{"advisoryId":"PKSA-gwt3-5dgf-97fx","packageName":"intercom\/intercom-php","remoteId":"GHSA-gr3r-crp5-qrrm","title":"Compromised tag of intercom-php published via GitHub","link":"https:\/\/github.com\/advisories\/GHSA-gr3r-crp5-qrrm","cve":null,"affectedVersions":"=5.0.2","source":"GitHub","reportedAt":"2026-05-07 16:48:41","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-gr3r-crp5-qrrm"}]}],"getgrav\/grav-plugin-form":[{"advisoryId":"PKSA-t8zh-nz62-2js9","packageName":"getgrav\/grav-plugin-form","remoteId":"GHSA-w4rc-p66m-x6qq","title":"Grav Form Plugin has an Anonymous Page Content Overwrite via Form File Upload filename Override","link":"https:\/\/github.com\/advisories\/GHSA-w4rc-p66m-x6qq","cve":"CVE-2026-42845","affectedVersions":"\u003C9.1.0","source":"GitHub","reportedAt":"2026-05-06 23:03:13","composerRepository":null,"severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w4rc-p66m-x6qq"}]}],"bagisto\/bagisto":[{"advisoryId":"PKSA-fphw-3zcz-ygcb","packageName":"bagisto\/bagisto","remoteId":"GHSA-65fp-7g2v-658r","title":"Bagisto affected by Cross-site Scripting","link":"https:\/\/github.com\/advisories\/GHSA-65fp-7g2v-658r","cve":"CVE-2026-6745","affectedVersions":"\u003C=2.3.15","source":"GitHub","reportedAt":"2026-04-21 21:31:23","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-65fp-7g2v-658r"}]},{"advisoryId":"PKSA-5txd-q8wz-njb7","packageName":"bagisto\/bagisto","remoteId":"GHSA-x3f9-vcp2-hgcw","title":"Bagisto affected by Server-Side Request Forgery","link":"https:\/\/github.com\/advisories\/GHSA-x3f9-vcp2-hgcw","cve":"CVE-2026-6744","affectedVersions":"\u003C=2.3.15","source":"GitHub","reportedAt":"2026-04-21 21:31:23","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-x3f9-vcp2-hgcw"}]},{"advisoryId":"PKSA-jq1s-445j-c4rw","packageName":"bagisto\/bagisto","remoteId":"GHSA-x5rw-qvvp-5cgm","title":"Bagisto has IDOR in Customer Order Reorder Functionality","link":"https:\/\/github.com\/advisories\/GHSA-x5rw-qvvp-5cgm","cve":"CVE-2026-21447","affectedVersions":"\u003C2.3.10","source":"GitHub","reportedAt":"2026-01-02 22:50:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-x5rw-qvvp-5cgm"}]},{"advisoryId":"PKSA-xfmk-zmw2-3qhw","packageName":"bagisto\/bagisto","remoteId":"GHSA-mqhg-v22x-pqj8","title":"Bagisto is vulnerable to SSTI via name parameters provided by non-admin low-privilege users","link":"https:\/\/github.com\/advisories\/GHSA-mqhg-v22x-pqj8","cve":"CVE-2026-21449","affectedVersions":"\u003C2.3.10","source":"GitHub","reportedAt":"2026-01-02 22:51:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mqhg-v22x-pqj8"}]},{"advisoryId":"PKSA-td46-kz3d-nfhj","packageName":"bagisto\/bagisto","remoteId":"GHSA-5j4h-4f72-qpm6","title":"Bagisto has Normal \u0026 Blind SSTI from low-privilege user when ordering product","link":"https:\/\/github.com\/advisories\/GHSA-5j4h-4f72-qpm6","cve":"CVE-2026-21448","affectedVersions":"\u003C2.3.10","source":"GitHub","reportedAt":"2026-01-02 22:13:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5j4h-4f72-qpm6"}]},{"advisoryId":"PKSA-fhhx-v12v-v3yr","packageName":"bagisto\/bagisto","remoteId":"GHSA-9hvg-qw5q-wqwp","title":"Bagisto SSTI vulnerability in type parameter can lead to RCE","link":"https:\/\/github.com\/advisories\/GHSA-9hvg-qw5q-wqwp","cve":"CVE-2026-21450","affectedVersions":"\u003C2.3.10","source":"GitHub","reportedAt":"2026-01-02 21:56:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9hvg-qw5q-wqwp"}]},{"advisoryId":"PKSA-xqj5-c6ws-xpvm","packageName":"bagisto\/bagisto","remoteId":"GHSA-6h7w-v2xr-mqvw","title":"Bagisto Missing Authentication on Installer API Endpoints","link":"https:\/\/github.com\/advisories\/GHSA-6h7w-v2xr-mqvw","cve":"CVE-2026-21446","affectedVersions":"\u003E=2.3.0,\u003C2.3.10","source":"GitHub","reportedAt":"2026-01-02 21:14:06","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6h7w-v2xr-mqvw"}]},{"advisoryId":"PKSA-441j-tpq7-k5ms","packageName":"bagisto\/bagisto","remoteId":"GHSA-2mwc-h2mg-v6p8","title":"Bagisto has HTML Filter Bypass that Enables Stored XSS","link":"https:\/\/github.com\/advisories\/GHSA-2mwc-h2mg-v6p8","cve":"CVE-2026-21451","affectedVersions":"\u003C2.3.10","source":"GitHub","reportedAt":"2026-01-02 21:16:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2mwc-h2mg-v6p8"}]},{"advisoryId":"PKSA-29h4-8qhb-8hq4","packageName":"bagisto\/bagisto","remoteId":"GHSA-fg89-g389-p346","title":"bagisto has a Cross Site Scripting (XSS) vulnerability in TinyMCE Image Upload (SVG)","link":"https:\/\/github.com\/advisories\/GHSA-fg89-g389-p346","cve":"CVE-2025-62418","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2025-10-16 20:41:03","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fg89-g389-p346"}]},{"advisoryId":"PKSA-25zg-f27r-886n","packageName":"bagisto\/bagisto","remoteId":"GHSA-jqrp-58fv-w8cq","title":"bagisto has CSV Formula Injection in Create New Product","link":"https:\/\/github.com\/advisories\/GHSA-jqrp-58fv-w8cq","cve":"CVE-2025-62417","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2025-10-16 20:48:11","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-jqrp-58fv-w8cq"}]},{"advisoryId":"PKSA-9w6g-8v1f-df8w","packageName":"bagisto\/bagisto","remoteId":"GHSA-r9xj-mvqf-jm7w","title":"bagisto has Cross Site Scripting (XSS) in Create New Customer","link":"https:\/\/github.com\/advisories\/GHSA-r9xj-mvqf-jm7w","cve":"CVE-2025-62414","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2025-10-16 20:48:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r9xj-mvqf-jm7w"}]},{"advisoryId":"PKSA-tfym-n9wv-r1z9","packageName":"bagisto\/bagisto","remoteId":"GHSA-527q-4wqv-g9wj","title":"bagisto has Server Side Template Injection (SSTI) in Product Description","link":"https:\/\/github.com\/advisories\/GHSA-527q-4wqv-g9wj","cve":"CVE-2025-62416","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2025-10-16 20:28:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-527q-4wqv-g9wj"}]},{"advisoryId":"PKSA-wxrw-qyv9-p442","packageName":"bagisto\/bagisto","remoteId":"GHSA-67px-r26w-598x","title":"bagisto has Cross Site Scripting (XSS) issue in TinyMCE Image Upload (HTML)","link":"https:\/\/github.com\/advisories\/GHSA-67px-r26w-598x","cve":"CVE-2025-62415","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2025-10-16 18:12:10","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-67px-r26w-598x"}]},{"advisoryId":"PKSA-dg6m-m2pq-jzgx","packageName":"bagisto\/bagisto","remoteId":"GHSA-29mf-w486-v3vc","title":"Bagisto is vulnerable to XSS through Admin Panel\u0027s product creation path","link":"https:\/\/github.com\/advisories\/GHSA-29mf-w486-v3vc","cve":"CVE-2025-60880","affectedVersions":"=2.3.6","source":"GitHub","reportedAt":"2025-10-10 21:31:15","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-29mf-w486-v3vc"}]}],"flightphp\/core":[{"advisoryId":"PKSA-wvkx-qqd9-sqb6","packageName":"flightphp\/core","remoteId":"GHSA-fcx8-ph5r-mxr4","title":"Flight has reflected XSS through an unvalidated JSONP callback in Flight::jsonp() ","link":"https:\/\/github.com\/advisories\/GHSA-fcx8-ph5r-mxr4","cve":"CVE-2026-42548","affectedVersions":"\u003C3.18.1","source":"GitHub","reportedAt":"2026-05-06 21:34:15","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fcx8-ph5r-mxr4"}]},{"advisoryId":"PKSA-1wr3-jdqm-7ppr","packageName":"flightphp\/core","remoteId":"GHSA-3xjv-pmf2-gf2q","title":"Flight has path traversal in `make:controller` CLI that creates arbitrary directories outside project root","link":"https:\/\/github.com\/advisories\/GHSA-3xjv-pmf2-gf2q","cve":"CVE-2026-42549","affectedVersions":"\u003C3.18.1","source":"GitHub","reportedAt":"2026-05-06 21:34:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3xjv-pmf2-gf2q"}]},{"advisoryId":"PKSA-jtc2-k2n3-ck2b","packageName":"flightphp\/core","remoteId":"GHSA-xwqr-rcqg-22mr","title":"Flight vulnerable to SQL Injection via unvalidated identifiers in SimplePdo::insert \/ update \/ delete","link":"https:\/\/github.com\/advisories\/GHSA-xwqr-rcqg-22mr","cve":"CVE-2026-42550","affectedVersions":"\u003C3.18.1","source":"GitHub","reportedAt":"2026-05-06 21:35:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xwqr-rcqg-22mr"}]},{"advisoryId":"PKSA-w12s-8pdm-4hrq","packageName":"flightphp\/core","remoteId":"GHSA-vxrr-w42w-w76g","title":"Flight: HTTP method override enabled by default, facilitating CSRF escalation and middleware bypass","link":"https:\/\/github.com\/advisories\/GHSA-vxrr-w42w-w76g","cve":"CVE-2026-42551","affectedVersions":"\u003C3.18.1","source":"GitHub","reportedAt":"2026-05-06 21:38:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vxrr-w42w-w76g"}]},{"advisoryId":"PKSA-c4m3-5zjm-wjht","packageName":"flightphp\/core","remoteId":"GHSA-qrch-52m5-vv85","title":"Flight vulnerable to sensitive information disclosure via default error handler","link":"https:\/\/github.com\/advisories\/GHSA-qrch-52m5-vv85","cve":"CVE-2026-42552","affectedVersions":"\u003C3.18.1","source":"GitHub","reportedAt":"2026-05-06 21:39:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qrch-52m5-vv85"}]}],"openmage\/magento-lts":[{"advisoryId":"PKSA-j61z-h6ts-jp8k","packageName":"openmage\/magento-lts","remoteId":"GHSA-x8jv-q8j2-487c","title":"Magento LTS: Reflected XSS - Import -\u003E Data Flow (profiles) ","link":"https:\/\/github.com\/advisories\/GHSA-x8jv-q8j2-487c","cve":"CVE-2026-42458","affectedVersions":"\u003C=20.17.0","source":"GitHub","reportedAt":"2026-05-06 20:57:37","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x8jv-q8j2-487c"}]},{"advisoryId":"PKSA-3c4m-s9d4-ycyr","packageName":"openmage\/magento-lts","remoteId":"GHSA-qpgq-5g92-j5q8","title":"Magento LTS Vulnerable to Open Redirect via Unvalidated `uenc` Parameter in `stockAction()`","link":"https:\/\/github.com\/advisories\/GHSA-qpgq-5g92-j5q8","cve":"CVE-2026-42207","affectedVersions":"\u003C=20.17.0","source":"GitHub","reportedAt":"2026-05-05 20:11:21","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qpgq-5g92-j5q8"}]},{"advisoryId":"PKSA-qjnm-jjkr-qktb","packageName":"openmage\/magento-lts","remoteId":"GHSA-2cwr-gcf9-pvxr","title":"Magento LTS has Weak API Session ID \u2014 Predictable MD5 of Time-Derived Inputs","link":"https:\/\/github.com\/advisories\/GHSA-2cwr-gcf9-pvxr","cve":"CVE-2026-42155","affectedVersions":"\u003C=20.17.0","source":"GitHub","reportedAt":"2026-05-05 19:35:56","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-2cwr-gcf9-pvxr"}]},{"advisoryId":"PKSA-ctbx-q2cr-ntvc","packageName":"openmage\/magento-lts","remoteId":"GHSA-3j5q-7q7h-2hhv","title":"OpenMage LTS: Customer File Upload Extension Blocklist Bypass \u2192 Remote Code Execution","link":"https:\/\/github.com\/advisories\/GHSA-3j5q-7q7h-2hhv","cve":"CVE-2026-40488","affectedVersions":"\u003C=20.16.0","source":"GitHub","reportedAt":"2026-04-21 18:53:13","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3j5q-7q7h-2hhv"}]},{"advisoryId":"PKSA-sg96-p97c-1769","packageName":"openmage\/magento-lts","remoteId":"GHSA-665x-ppc4-685w","title":"OpenMage LTS: Cross-user wishlist import leads to private option \u0026 file disclosure","link":"https:\/\/github.com\/advisories\/GHSA-665x-ppc4-685w","cve":"CVE-2026-40098","affectedVersions":"\u003C20.17.0","source":"GitHub","reportedAt":"2026-04-21 15:20:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-665x-ppc4-685w"}]},{"advisoryId":"PKSA-w28m-jx16-bpbn","packageName":"openmage\/magento-lts","remoteId":"GHSA-fg79-cr9c-7369","title":"OpenMage LTS: Phar Deserialization leads to Remote Code Execution","link":"https:\/\/github.com\/advisories\/GHSA-fg79-cr9c-7369","cve":"CVE-2026-25524","affectedVersions":"\u003C20.17.0","source":"GitHub","reportedAt":"2026-04-21 14:32:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fg79-cr9c-7369"}]},{"advisoryId":"PKSA-t8bb-kchx-xyxb","packageName":"openmage\/magento-lts","remoteId":"GHSA-6vqf-6fhm-7rc6","title":"OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module","link":"https:\/\/github.com\/advisories\/GHSA-6vqf-6fhm-7rc6","cve":"CVE-2026-25525","affectedVersions":"\u003C20.17.0","source":"GitHub","reportedAt":"2026-04-21 14:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6vqf-6fhm-7rc6"}]},{"advisoryId":"PKSA-nz6n-ckcm-yb2x","packageName":"openmage\/magento-lts","remoteId":"GHSA-jg68-vhv3-9r8f","title":"Magento\u0027s X-Original-Url header can expose admin url","link":"https:\/\/github.com\/advisories\/GHSA-jg68-vhv3-9r8f","cve":"CVE-2026-25523","affectedVersions":"\u003C20.16.1","source":"GitHub","reportedAt":"2026-02-02 23:12:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jg68-vhv3-9r8f"}]},{"advisoryId":"PKSA-t425-mpgn-4yhs","packageName":"openmage\/magento-lts","remoteId":"GHSA-qv78-c8hc-438r","title":"OpenMage vulnerable to XSS in Admin Notifications","link":"https:\/\/github.com\/advisories\/GHSA-qv78-c8hc-438r","cve":"CVE-2025-64174","affectedVersions":"\u003C20.16.0","source":"GitHub","reportedAt":"2025-11-03 20:24:10","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qv78-c8hc-438r"}]}],"dedoc\/scramble":[{"advisoryId":"PKSA-kb5d-bgb1-8ykp","packageName":"dedoc\/scramble","remoteId":"GHSA-4rm2-28vj-fj39","title":"Scramble vulnerable to remote code execution via evaluation of user-controlled input in validation rules","link":"https:\/\/github.com\/advisories\/GHSA-4rm2-28vj-fj39","cve":"CVE-2026-44262","affectedVersions":"\u003E=0.13.2,\u003C=0.13.21","source":"GitHub","reportedAt":"2026-05-06 19:54:56","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-4rm2-28vj-fj39"}]},{"advisoryId":"PKSA-qgg1-cfs4-rkb8","packageName":"dedoc\/scramble","remoteId":"dedoc\/scramble\/2026-04-28.yaml","title":"Remote code execution via evaluation of user-controlled input in validation rules","link":"https:\/\/github.com\/dedoc\/scramble\/security\/advisories\/GHSA-4rm2-28vj-fj39","cve":null,"affectedVersions":"\u003E=0.13.2,\u003C0.13.22","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-04-28 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"dedoc\/scramble\/2026-04-28.yaml"}]}],"getgrav\/grav-plugin-api":[{"advisoryId":"PKSA-pxqc-bymp-4wtn","packageName":"getgrav\/grav-plugin-api","remoteId":"GHSA-r945-h4vm-h736","title":"Grav API Privilege Escalation to Super Admin","link":"https:\/\/github.com\/advisories\/GHSA-r945-h4vm-h736","cve":"CVE-2026-42843","affectedVersions":"\u003C1.0.0-beta.15","source":"GitHub","reportedAt":"2026-05-05 21:20:03","composerRepository":null,"severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r945-h4vm-h736"}]}],"showdoc\/showdoc":[{"advisoryId":"PKSA-r6d8-qs1d-pj19","packageName":"showdoc\/showdoc","remoteId":"GHSA-fm5r-cj7v-rj2c","title":"ShowDoc has an Injection vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-fm5r-cj7v-rj2c","cve":"CVE-2026-6982","affectedVersions":"\u003C3.8.1","source":"GitHub","reportedAt":"2026-04-25 15:33:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fm5r-cj7v-rj2c"}]}],"webonyx\/graphql-php":[{"advisoryId":"PKSA-xwpn-zs9j-6wy5","packageName":"webonyx\/graphql-php","remoteId":"GHSA-r7cg-qjjm-xhqq","title":"webonyx\/graphql-php has unbounded recursion in parser that causes stack overflow on crafted nested input","link":"https:\/\/github.com\/advisories\/GHSA-r7cg-qjjm-xhqq","cve":null,"affectedVersions":"\u003C=15.32.2","source":"GitHub","reportedAt":"2026-05-05 17:24:57","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r7cg-qjjm-xhqq"}]},{"advisoryId":"PKSA-sf9j-1gs7-xzvx","packageName":"webonyx\/graphql-php","remoteId":"GHSA-fc86-6rv6-2jpm","title":"webonyx\/graphql-php has quadratic validation cost in OverlappingFieldsCanBeMerged via inline fragments","link":"https:\/\/github.com\/advisories\/GHSA-fc86-6rv6-2jpm","cve":null,"affectedVersions":"\u003C15.32.2","source":"GitHub","reportedAt":"2026-05-04 22:22:09","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fc86-6rv6-2jpm"}]},{"advisoryId":"PKSA-7h5p-prw9-w5nr","packageName":"webonyx\/graphql-php","remoteId":"GHSA-68jq-c3rv-pcrr","title":"graphql-php is affected by a Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validation","link":"https:\/\/github.com\/advisories\/GHSA-68jq-c3rv-pcrr","cve":"CVE-2026-40476","affectedVersions":"\u003C=15.31.4","source":"GitHub","reportedAt":"2026-04-14 01:05:05","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-68jq-c3rv-pcrr"}]}],"mckenziearts\/livewire-markdown-editor":[{"advisoryId":"PKSA-nr7m-pf27-n9rt","packageName":"mckenziearts\/livewire-markdown-editor","remoteId":"GHSA-gxxh-8vcj-w2mh","title":"livewire-markdown-editor has arbitrary file upload that allows stored XSS via attachment handler","link":"https:\/\/github.com\/advisories\/GHSA-gxxh-8vcj-w2mh","cve":null,"affectedVersions":"\u003C1.3","source":"GitHub","reportedAt":"2026-05-04 22:11:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gxxh-8vcj-w2mh"}]}],"nabeel\/phpvms":[{"advisoryId":"PKSA-21zk-g67c-5537","packageName":"nabeel\/phpvms","remoteId":"GHSA-fv26-4939-62fh","title":"phpVMS has an \/importer authorization bypass causing full database wipe","link":"https:\/\/github.com\/advisories\/GHSA-fv26-4939-62fh","cve":"CVE-2026-42569","affectedVersions":"\u003C7.0.6","source":"GitHub","reportedAt":"2026-05-04 21:20:40","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-fv26-4939-62fh"}]}],"azuracast\/azuracast":[{"advisoryId":"PKSA-nx6v-99r9-ndh5","packageName":"azuracast\/azuracast","remoteId":"GHSA-vp2f-cqqp-478j","title":"AzuraCast has Path Traversal in `currentDirectory` Parameter that Enables Remote Code Execution via Media Upload","link":"https:\/\/github.com\/advisories\/GHSA-vp2f-cqqp-478j","cve":"CVE-2026-42605","affectedVersions":"\u003C=0.23.5","source":"GitHub","reportedAt":"2026-05-04 21:16:51","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vp2f-cqqp-478j"}]},{"advisoryId":"PKSA-8467-6xvh-v57b","packageName":"azuracast\/azuracast","remoteId":"GHSA-gv7r-3mr9-h5x8","title":"AzuraCast has Password Reset Poisoning via Untrusted X-Forwarded-Host Header that Leads to Account Takeover and 2FA Bypass","link":"https:\/\/github.com\/advisories\/GHSA-gv7r-3mr9-h5x8","cve":"CVE-2026-42606","affectedVersions":"\u003C=0.23.5","source":"GitHub","reportedAt":"2026-05-04 21:17:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gv7r-3mr9-h5x8"}]},{"advisoryId":"PKSA-x7rb-qk7x-brrk","packageName":"azuracast\/azuracast","remoteId":"GHSA-4fm3-ggg2-c6qx","title":"AzuraCast\u0027s Missing RequireInternalConnection on Liquidsoap API Allows Low-Privilege Metadata Injection and Broadcast Disruption","link":"https:\/\/github.com\/advisories\/GHSA-4fm3-ggg2-c6qx","cve":null,"affectedVersions":"\u003C=0.23.5","source":"GitHub","reportedAt":"2026-05-04 21:18:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4fm3-ggg2-c6qx"}]},{"advisoryId":"PKSA-6p4x-2pyn-gcq9","packageName":"azuracast\/azuracast","remoteId":"GHSA-qff7-q5fm-8p76","title":"AzuraCast has Missing Permissions Check on Media File Download, Allowing Cross-Station Data Exfiltration","link":"https:\/\/github.com\/advisories\/GHSA-qff7-q5fm-8p76","cve":null,"affectedVersions":"\u003C=0.23.5","source":"GitHub","reportedAt":"2026-05-04 21:19:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qff7-q5fm-8p76"}]},{"advisoryId":"PKSA-wgbn-7zcq-1tdt","packageName":"azuracast\/azuracast","remoteId":"GHSA-q4ph-8x8g-95f8","title":"AzuraCast Vulnerable to Liquidsoap Code Injection via Incomplete cleanUpString-to-toRawString Migration in Remote Relay Password Field","link":"https:\/\/github.com\/advisories\/GHSA-q4ph-8x8g-95f8","cve":null,"affectedVersions":"\u003C=0.23.5","source":"GitHub","reportedAt":"2026-05-04 21:19:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-q4ph-8x8g-95f8"}]},{"advisoryId":"PKSA-p9gy-8v98-hsfy","packageName":"azuracast\/azuracast","remoteId":"GHSA-93fx-5qgc-wr38","title":"AzuraCast: RCE via Liquidsoap string interpolation injection in station metadata and playlist URLs","link":"https:\/\/github.com\/advisories\/GHSA-93fx-5qgc-wr38","cve":null,"affectedVersions":"\u003C=0.23.3","source":"GitHub","reportedAt":"2026-03-09 19:55:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-93fx-5qgc-wr38"}]},{"advisoryId":"PKSA-9fw1-5251-nmm8","packageName":"azuracast\/azuracast","remoteId":"GHSA-9449-rphm-mjqr","title":"AzuraCast Vulnerable to Pre-Auth File Deletion \u0026 Admin RCE","link":"https:\/\/github.com\/advisories\/GHSA-9449-rphm-mjqr","cve":"CVE-2025-67737","affectedVersions":"\u003C=0.23.1","source":"GitHub","reportedAt":"2025-12-11 17:01:13","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-9449-rphm-mjqr"}]}],"prestashop\/ps_checkout":[{"advisoryId":"PKSA-vdq5-bx4j-ybb1","packageName":"prestashop\/ps_checkout","remoteId":"GHSA-mqq7-wxx5-mp8h","title":"ps_checkout allows unauthorized method invocation through unvalidated parameter","link":"https:\/\/github.com\/advisories\/GHSA-mqq7-wxx5-mp8h","cve":null,"affectedVersions":"\u003C5.3.0","source":"GitHub","reportedAt":"2026-04-30 20:59:28","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-mqq7-wxx5-mp8h"}]},{"advisoryId":"PKSA-2hfz-bts5-gnys","packageName":"prestashop\/ps_checkout","remoteId":"GHSA-wvpg-4wrh-5889","title":"PrestaShop Checkout Target PayPal merchant account hijacking from backoffice","link":"https:\/\/github.com\/advisories\/GHSA-wvpg-4wrh-5889","cve":"CVE-2025-61924","affectedVersions":"\u003E=5.0.0,\u003C5.0.5|\u003C4.4.1","source":"GitHub","reportedAt":"2025-10-16 20:00:47","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-wvpg-4wrh-5889"}]},{"advisoryId":"PKSA-vkh4-53ww-nks1","packageName":"prestashop\/ps_checkout","remoteId":"GHSA-54hq-mf6h-48xh","title":"PrestaShop Checkout allows customer account takeover via email","link":"https:\/\/github.com\/advisories\/GHSA-54hq-mf6h-48xh","cve":"CVE-2025-61922","affectedVersions":"\u003E=1.3.0,\u003C4.4.1|\u003E=5.0.0,\u003C5.0.5","source":"GitHub","reportedAt":"2025-10-16 19:56:32","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-54hq-mf6h-48xh"}]},{"advisoryId":"PKSA-4wgy-szzb-yy2d","packageName":"prestashop\/ps_checkout","remoteId":"GHSA-fpxp-pfqm-x54w","title":"PrestaShop Checkout Backoffice directory traversal allows arbitrary file disclosure","link":"https:\/\/github.com\/advisories\/GHSA-fpxp-pfqm-x54w","cve":"CVE-2025-61923","affectedVersions":"\u003E=5.0.0,\u003C5.0.5|\u003C4.4.1","source":"GitHub","reportedAt":"2025-10-16 19:59:44","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fpxp-pfqm-x54w"}]}],"ipl\/web":[{"advisoryId":"PKSA-k319-99m7-bjxd","packageName":"ipl\/web","remoteId":"GHSA-55wf-5m3q-6jjf","title":"ipl\/web is vulnerable to reflected XSS by malformed search requests","link":"https:\/\/github.com\/advisories\/GHSA-55wf-5m3q-6jjf","cve":"CVE-2026-42224","affectedVersions":"\u003C=0.10.2|\u003E=0.11.0,\u003C=0.13.0","source":"GitHub","reportedAt":"2026-04-29 21:01:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-55wf-5m3q-6jjf"}]}],"roadiz\/openid":[{"advisoryId":"PKSA-h9v7-gkkk-sf31","packageName":"roadiz\/openid","remoteId":"GHSA-3gx8-q682-38mx","title":"OpenID Connect nonce generated but never validated \u2014 ID token replay attack","link":"https:\/\/github.com\/advisories\/GHSA-3gx8-q682-38mx","cve":"CVE-2026-42206","affectedVersions":"\u003C2.3.43|\u003E=2.5.0,\u003C2.5.45|\u003E=2.6.0,\u003C2.6.31|\u003E=2.7.0,\u003C2.7.18","source":"GitHub","reportedAt":"2026-04-29 20:51:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3gx8-q682-38mx"}]}],"almirhodzic\/nova-toggle-5":[{"advisoryId":"PKSA-bty3-jphf-3n5y","packageName":"almirhodzic\/nova-toggle-5","remoteId":"GHSA-f5c8-m5vw-rmgq","title":"nova-toggle-5: Improper authorization on toggle endpoint allowed non-Nova users to modify boolean fields","link":"https:\/\/github.com\/advisories\/GHSA-f5c8-m5vw-rmgq","cve":"CVE-2026-42202","affectedVersions":"\u003C1.3.0","source":"GitHub","reportedAt":"2026-04-24 16:00:09","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f5c8-m5vw-rmgq"}]}],"flarum\/core":[{"advisoryId":"PKSA-4s1v-jz1f-4jpx","packageName":"flarum\/core","remoteId":"GHSA-xjvc-pw2r-6878","title":"Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)","link":"https:\/\/github.com\/advisories\/GHSA-xjvc-pw2r-6878","cve":"CVE-2026-41887","affectedVersions":"\u003E=2.0.0-beta.1,\u003C=2.0.0-beta.8|\u003C=1.8.15","source":"GitHub","reportedAt":"2026-04-22 20:34:52","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xjvc-pw2r-6878"}]}],"phpunit\/phpunit":[{"advisoryId":"PKSA-qccq-2pht-gg3w","packageName":"phpunit\/phpunit","remoteId":"GHSA-mh6w-vxff-9wqp","title":"PHPUnit: Argument injection via newline in PHP INI values forwarded to child processes","link":"https:\/\/github.com\/advisories\/GHSA-mh6w-vxff-9wqp","cve":null,"affectedVersions":"\u003E=13.1.5,\u003C13.1.6|\u003E=12.5.21,\u003C12.5.22","source":"GitHub","reportedAt":"2026-04-22 14:56:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mh6w-vxff-9wqp"}]},{"advisoryId":"PKSA-5jz8-6tcw-pbk4","packageName":"phpunit\/phpunit","remoteId":"phpunit\/phpunit\/CVE-2026-41570.yaml","title":"Argument injection via newline in PHP INI values forwarded to child processes","link":"https:\/\/github.com\/sebastianbergmann\/phpunit\/security\/advisories\/GHSA-qrr6-mg7r-m243","cve":"CVE-2026-41570","affectedVersions":"\u003E=12.5.21,\u003C12.5.22|\u003E=13.1.5,\u003C13.1.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-04-17 12:52:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qrr6-mg7r-m243"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"phpunit\/phpunit\/CVE-2026-41570.yaml"}]},{"advisoryId":"PKSA-z3gr-8qht-p93v","packageName":"phpunit\/phpunit","remoteId":"phpunit\/phpunit\/CVE-2026-24765.yaml","title":"Unsafe Deserialization in PHPT Code Coverage Handling","link":"https:\/\/github.com\/sebastianbergmann\/phpunit\/security\/advisories\/GHSA-vvj3-c3rp-c85p","cve":"CVE-2026-24765","affectedVersions":"\u003E=0,\u003C8.5.52|\u003E=9.0.0,\u003C9.6.33|\u003E=10.0.0,\u003C10.5.62|\u003E=11.0.0,\u003C11.5.50|\u003E=12.0.0,\u003C12.5.8","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-01-27 05:21:14","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vvj3-c3rp-c85p"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"phpunit\/phpunit\/CVE-2026-24765.yaml"}]}],"october\/system":[{"advisoryId":"PKSA-drxd-zbt8-s1kh","packageName":"october\/system","remoteId":"GHSA-jj38-h5w5-mvpf","title":"October CMS: Reflected XSS via DataTable Form Widget","link":"https:\/\/github.com\/advisories\/GHSA-jj38-h5w5-mvpf","cve":"CVE-2026-27937","affectedVersions":"\u003E=4.0.0,\u003C4.1.16|\u003C3.7.16","source":"GitHub","reportedAt":"2026-04-21 17:15:21","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-jj38-h5w5-mvpf"}]},{"advisoryId":"PKSA-h2tj-db1h-m5mf","packageName":"october\/system","remoteId":"GHSA-jvwg-phxx-j3rp","title":"October CMS: Editor Sub-Permission Bypass for Asset and Blueprint File Operations","link":"https:\/\/github.com\/advisories\/GHSA-jvwg-phxx-j3rp","cve":"CVE-2026-29179","affectedVersions":"\u003C3.7.16|\u003E=4.0.0,\u003C4.1.16","source":"GitHub","reportedAt":"2026-04-21 17:15:38","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-jvwg-phxx-j3rp"}]},{"advisoryId":"PKSA-4k1j-qzgm-rvr3","packageName":"october\/system","remoteId":"GHSA-3888-q23f-x7qh","title":"October CMS has Safe Mode Bypass via CSS Preprocessor Compilers","link":"https:\/\/github.com\/advisories\/GHSA-3888-q23f-x7qh","cve":"CVE-2026-26067","affectedVersions":"\u003E=4.0.0,\u003C4.1.10|\u003C3.7.14","source":"GitHub","reportedAt":"2026-04-21 16:43:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3888-q23f-x7qh"}]},{"advisoryId":"PKSA-44b4-zdw9-q1j5","packageName":"october\/system","remoteId":"GHSA-6qmh-j78v-ffp7","title":"October CMS has Stored XSS in Backend Editor Markup Classes","link":"https:\/\/github.com\/advisories\/GHSA-6qmh-j78v-ffp7","cve":"CVE-2026-24906","affectedVersions":"\u003C=3.7.13|\u003E=4.0.0,\u003C=4.1.9","source":"GitHub","reportedAt":"2026-04-14 20:02:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6qmh-j78v-ffp7"}]},{"advisoryId":"PKSA-57nm-kh7g-ddrg","packageName":"october\/system","remoteId":"GHSA-j4j5-9x6g-rgxc","title":"October CMS has Stored XSS in Event Log Mail Preview","link":"https:\/\/github.com\/advisories\/GHSA-j4j5-9x6g-rgxc","cve":"CVE-2026-24907","affectedVersions":"\u003C=3.7.13|\u003E=4.0.0,\u003C=4.1.9","source":"GitHub","reportedAt":"2026-04-14 20:02:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j4j5-9x6g-rgxc"}]},{"advisoryId":"PKSA-bbp3-wdjz-b51v","packageName":"october\/system","remoteId":"GHSA-wvpq-h33f-8rp6","title":"October CMS Vulnerable to Stored XSS via Branding Styles","link":"https:\/\/github.com\/advisories\/GHSA-wvpq-h33f-8rp6","cve":"CVE-2025-61676","affectedVersions":"\u003E=4.0.0,\u003C=4.0.11|\u003C=3.7.12","source":"GitHub","reportedAt":"2026-01-09 20:12:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wvpq-h33f-8rp6"}]},{"advisoryId":"PKSA-4qp4-vb8r-g3zj","packageName":"october\/system","remoteId":"GHSA-gxxc-m74c-f48x","title":"October CMS Vulnerable to Stored XSS via Editor and Branding Styles","link":"https:\/\/github.com\/advisories\/GHSA-gxxc-m74c-f48x","cve":"CVE-2025-61674","affectedVersions":"\u003E=4.0.0,\u003C=4.0.11|\u003C=3.7.12","source":"GitHub","reportedAt":"2026-01-09 18:12:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gxxc-m74c-f48x"}]}],"october\/october":[{"advisoryId":"PKSA-yqc2-m5mr-13xt","packageName":"october\/october","remoteId":"GHSA-h6jm-f4hh-fw27","title":"October CMS has Safe Mode Bypass via Twig Database Write Operations","link":"https:\/\/github.com\/advisories\/GHSA-h6jm-f4hh-fw27","cve":"CVE-2026-26274","affectedVersions":"\u003E=4.0.0,\u003C4.1.10|\u003C3.7.14","source":"GitHub","reportedAt":"2026-04-21 16:44:19","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h6jm-f4hh-fw27"}]}],"markhuot\/craftql":[{"advisoryId":"PKSA-nwgj-1fc9-zj7r","packageName":"markhuot\/craftql","remoteId":"GHSA-8wmw-prw8-2ggm","title":"Craftql vulnerable to Server-Side Request Forgery","link":"https:\/\/github.com\/advisories\/GHSA-8wmw-prw8-2ggm","cve":"CVE-2026-31317","affectedVersions":"\u003C=1.3.7","source":"GitHub","reportedAt":"2026-04-17 15:31:18","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8wmw-prw8-2ggm"}]}],"goodoneuz\/pay-uz":[{"advisoryId":"PKSA-hc2w-9ctz-542g","packageName":"goodoneuz\/pay-uz","remoteId":"GHSA-m5wg-cjgh-223j","title":"goodoneuz\/pay-uz: the \/payment\/api\/editable\/update endpoint overwrites existing PHP payment hook files","link":"https:\/\/github.com\/advisories\/GHSA-m5wg-cjgh-223j","cve":"CVE-2026-31843","affectedVersions":"\u003C=2.2.24","source":"GitHub","reportedAt":"2026-04-16 15:31:32","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-m5wg-cjgh-223j"}]}],"processwire\/processwire":[{"advisoryId":"PKSA-m19p-x1h4-xw57","packageName":"processwire\/processwire","remoteId":"GHSA-gmwr-9j4p-96vm","title":"ProcessWire: server-side request forgery vulnerability in the admin panel\u0027s \u0027Add Module From URL\u0027 feature","link":"https:\/\/github.com\/advisories\/GHSA-gmwr-9j4p-96vm","cve":"CVE-2026-40500","affectedVersions":"\u003C=3.0.255","source":"GitHub","reportedAt":"2026-04-16 00:54:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gmwr-9j4p-96vm"}]},{"advisoryId":"PKSA-rq7g-qqyk-nz8t","packageName":"processwire\/processwire","remoteId":"GHSA-9p44-q66p-xm6p","title":"ProcessWire CMS vulnerable to resource-exhaustion Denial of Service","link":"https:\/\/github.com\/advisories\/GHSA-9p44-q66p-xm6p","cve":"CVE-2025-60790","affectedVersions":"\u003C=3.0.246","source":"GitHub","reportedAt":"2025-10-21 18:30:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9p44-q66p-xm6p"}]}],"joedolson\/my-calendar":[{"advisoryId":"PKSA-zws9-hgnd-t1ht","packageName":"joedolson\/my-calendar","remoteId":"GHSA-2mvx-f5qm-v2ch","title":"Unauthenticated Information Disclosure (IDOR) via Multisite switch_to_blog in My Calendar","link":"https:\/\/github.com\/advisories\/GHSA-2mvx-f5qm-v2ch","cve":"CVE-2026-40308","affectedVersions":"\u003C3.7.7","source":"GitHub","reportedAt":"2026-04-16 21:34:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2mvx-f5qm-v2ch"}]}],"silverstripe\/assets":[{"advisoryId":"PKSA-tfnf-7k34-fpdv","packageName":"silverstripe\/assets","remoteId":"silverstripe\/assets\/CVE-2026-24749.yaml","title":"CVE-2026-24749 - DBFile permission bypass","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-24749","cve":"CVE-2026-24749","affectedVersions":"\u003E=2.0.0,\u003C2.4.5|\u003E=3.0.0,\u003C3.1.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-04-16 02:30:38","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jgcf-rf45-2f8v"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/assets\/CVE-2026-24749.yaml"}]}],"khodakhah\/nodcms":[{"advisoryId":"PKSA-j2zd-bc4z-jzrm","packageName":"khodakhah\/nodcms","remoteId":"GHSA-3qcm-pj6q-w4c5","title":"Nodcms contains a cross-site request forgery vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-3qcm-pj6q-w4c5","cve":"CVE-2016-20054","affectedVersions":"\u003C=3.4.1","source":"GitHub","reportedAt":"2026-04-04 21:30:27","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3qcm-pj6q-w4c5"}]}],"pocketmine\/pocketmine-mp":[{"advisoryId":"PKSA-tnfd-ykdn-862g","packageName":"pocketmine\/pocketmine-mp","remoteId":"GHSA-xp4f-g2cm-rhg7","title":"PocketMine-MP has LogDoS by many junk properties in client data JWT in LoginPacket","link":"https:\/\/github.com\/advisories\/GHSA-xp4f-g2cm-rhg7","cve":null,"affectedVersions":"\u003C5.42.1","source":"GitHub","reportedAt":"2026-04-15 19:43:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xp4f-g2cm-rhg7"}]},{"advisoryId":"PKSA-h4z5-fb6q-736p","packageName":"pocketmine\/pocketmine-mp","remoteId":"GHSA-h6rj-3m53-887h","title":"PocketMine-MP: LogDoS by large complex unknown property logging in clientData in LoginPacket","link":"https:\/\/github.com\/advisories\/GHSA-h6rj-3m53-887h","cve":null,"affectedVersions":"\u003C5.41.1","source":"GitHub","reportedAt":"2026-04-06 22:54:03","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h6rj-3m53-887h"}]},{"advisoryId":"PKSA-cnjv-js4w-1xcs","packageName":"pocketmine\/pocketmine-mp","remoteId":"GHSA-788v-5pfp-93ff","title":"PocketMine-MP: JSON decoding of unlimited size large arrays\/objects in ModalFormResponse Handling","link":"https:\/\/github.com\/advisories\/GHSA-788v-5pfp-93ff","cve":null,"affectedVersions":"\u003C5.39.2","source":"GitHub","reportedAt":"2026-04-06 22:54:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-788v-5pfp-93ff"}]},{"advisoryId":"PKSA-yw3m-b28c-y6hc","packageName":"pocketmine\/pocketmine-mp","remoteId":"GHSA-7hmv-4j2j-pp6f","title":"PocketMine-MP: Network amplification vulnerability with `ActorEventPacket`","link":"https:\/\/github.com\/advisories\/GHSA-7hmv-4j2j-pp6f","cve":null,"affectedVersions":"\u003C5.39.2","source":"GitHub","reportedAt":"2026-04-06 22:54:10","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7hmv-4j2j-pp6f"}]},{"advisoryId":"PKSA-t7y4-spmt-39ct","packageName":"pocketmine\/pocketmine-mp","remoteId":"GHSA-f9jp-856v-8642","title":"PocketMine-MP: Player entities can still die and drop items in flaggedForDespawn state","link":"https:\/\/github.com\/advisories\/GHSA-f9jp-856v-8642","cve":null,"affectedVersions":"\u003C5.39.2","source":"GitHub","reportedAt":"2026-04-06 22:54:14","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-f9jp-856v-8642"}]},{"advisoryId":"PKSA-rjb4-mbc7-gvrq","packageName":"pocketmine\/pocketmine-mp","remoteId":"GHSA-h87r-f4vc-mchv","title":"PocketMine-MP vulnerable to improperly checked dropped item count leading to server crash","link":"https:\/\/github.com\/advisories\/GHSA-h87r-f4vc-mchv","cve":"CVE-2023-7332","affectedVersions":"\u003C4.18.1","source":"GitHub","reportedAt":"2023-06-06 01:51:09","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h87r-f4vc-mchv"}]}],"s9y\/serendipity":[{"advisoryId":"PKSA-vfgc-2rdq-w256","packageName":"s9y\/serendipity","remoteId":"GHSA-4m6c-649p-f6gf","title":"Serendipity has a Host Header Injection allows authentication cookie scoping to attacker-controlled domain in functions_config.inc.php","link":"https:\/\/github.com\/advisories\/GHSA-4m6c-649p-f6gf","cve":"CVE-2026-39963","affectedVersions":"\u003C2.6.0","source":"GitHub","reportedAt":"2026-04-14 22:32:29","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4m6c-649p-f6gf"}]},{"advisoryId":"PKSA-fdbd-416g-v2zm","packageName":"s9y\/serendipity","remoteId":"GHSA-458g-q4fh-mj6r","title":"Serendipity has a Host Header Injection allows SMTP header injection via unvalidated HTTP_HOST in Message-ID email header","link":"https:\/\/github.com\/advisories\/GHSA-458g-q4fh-mj6r","cve":"CVE-2026-39971","affectedVersions":"\u003C2.6.0","source":"GitHub","reportedAt":"2026-04-14 22:32:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-458g-q4fh-mj6r"}]}],"october\/rain":[{"advisoryId":"PKSA-qst9-2ky5-dhpn","packageName":"october\/rain","remoteId":"GHSA-g6v3-wv4j-x9hg","title":"October Rain has Environment Variable Exfiltration via INI Parser Interpolation","link":"https:\/\/github.com\/advisories\/GHSA-g6v3-wv4j-x9hg","cve":"CVE-2026-25125","affectedVersions":"\u003C=3.7.13|\u003E=4.0.0,\u003C=4.1.9","source":"GitHub","reportedAt":"2026-04-14 22:29:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g6v3-wv4j-x9hg"}]},{"advisoryId":"PKSA-22sk-dxft-df3d","packageName":"october\/rain","remoteId":"GHSA-gcqv-f29m-67gr","title":"October Rain has Stored XSS via SVG Filter Bypass","link":"https:\/\/github.com\/advisories\/GHSA-gcqv-f29m-67gr","cve":"CVE-2026-25133","affectedVersions":"\u003C=3.7.13|\u003E=4.0.0,\u003C=4.1.9","source":"GitHub","reportedAt":"2026-04-14 22:29:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gcqv-f29m-67gr"}]},{"advisoryId":"PKSA-7hg1-vmz2-j7w6","packageName":"october\/rain","remoteId":"GHSA-m5qg-jc75-4jp6","title":"October Rain has a Twig Sandbox Bypass via Collection Methods","link":"https:\/\/github.com\/advisories\/GHSA-m5qg-jc75-4jp6","cve":"CVE-2026-22692","affectedVersions":"\u003C=3.7.12|\u003E=4.0.0,\u003C=4.1.4","source":"GitHub","reportedAt":"2026-04-14 20:02:05","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m5qg-jc75-4jp6"}]}],"rhukster\/dom-sanitizer":[{"advisoryId":"PKSA-x5pq-tgg3-vhtm","packageName":"rhukster\/dom-sanitizer","remoteId":"GHSA-93vf-569f-22cq","title":"rhukster\/dom-sanitizer: SVG \u003Cstyle\u003E tag allows CSS injection via unfiltered url() and @import directives","link":"https:\/\/github.com\/advisories\/GHSA-93vf-569f-22cq","cve":"CVE-2026-40301","affectedVersions":"\u003C1.0.10","source":"GitHub","reportedAt":"2026-04-10 21:08:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-93vf-569f-22cq"}]}],"redaxo\/source":[{"advisoryId":"PKSA-4w67-7bxw-yj96","packageName":"redaxo\/source","remoteId":"GHSA-m662-8jrj-cw6v","title":"REDAXO has reflected XSS in backend Metainfo API via type parameter (CSRF token required)","link":"https:\/\/github.com\/advisories\/GHSA-m662-8jrj-cw6v","cve":null,"affectedVersions":"\u003C5.21.0","source":"GitHub","reportedAt":"2026-04-10 19:40:23","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-m662-8jrj-cw6v"}]},{"advisoryId":"PKSA-ps7n-211c-nz3j","packageName":"redaxo\/source","remoteId":"GHSA-xq4j-g85q-wf97","title":"REDAXO has reflected XSS backend packages API via function parameter (CSRF token required)","link":"https:\/\/github.com\/advisories\/GHSA-xq4j-g85q-wf97","cve":null,"affectedVersions":"\u003C5.21.0","source":"GitHub","reportedAt":"2026-04-10 19:40:42","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xq4j-g85q-wf97"}]},{"advisoryId":"PKSA-h8yt-8rph-k3h8","packageName":"redaxo\/source","remoteId":"GHSA-824x-88xg-cwrv","title":"Redaxo has Path Traversal in Backup Addon Leading to Arbitrary File Read","link":"https:\/\/github.com\/advisories\/GHSA-824x-88xg-cwrv","cve":"CVE-2026-21857","affectedVersions":"\u003C=5.20.1","source":"GitHub","reportedAt":"2026-01-05 20:02:58","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-824x-88xg-cwrv"}]},{"advisoryId":"PKSA-wnfn-tqc3-fmcx","packageName":"redaxo\/source","remoteId":"GHSA-xj9j-gjxg-7jvq","title":"REDAXO CMS is vulnerable to RCE attack through its template management component","link":"https:\/\/github.com\/advisories\/GHSA-xj9j-gjxg-7jvq","cve":"CVE-2025-64050","affectedVersions":"\u003C5.20.1","source":"GitHub","reportedAt":"2025-11-25 18:32:22","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xj9j-gjxg-7jvq"}]},{"advisoryId":"PKSA-wmbc-n846-7h2f","packageName":"redaxo\/source","remoteId":"GHSA-vqc7-7fj4-3fm3","title":"REDAXO CMS is vulnerable to XSS through its module management component","link":"https:\/\/github.com\/advisories\/GHSA-vqc7-7fj4-3fm3","cve":"CVE-2025-64049","affectedVersions":"\u003C5.20.1","source":"GitHub","reportedAt":"2025-11-25 18:32:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vqc7-7fj4-3fm3"}]},{"advisoryId":"PKSA-dcqq-vjpq-jyz4","packageName":"redaxo\/source","remoteId":"GHSA-x6vr-q3vf-vqgq","title":"REDAXO CMS is vulnerable to Reflected XSS in Mediapool Info Banner via args[types]","link":"https:\/\/github.com\/advisories\/GHSA-x6vr-q3vf-vqgq","cve":"CVE-2025-66026","affectedVersions":"\u003C5.20.1","source":"GitHub","reportedAt":"2025-11-25 23:53:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x6vr-q3vf-vqgq"}]}],"kantorge\/yaffa":[{"advisoryId":"PKSA-bprf-j9w1-t7bq","packageName":"kantorge\/yaffa","remoteId":"GHSA-pq95-94c9-j987","title":"yaffa vulnerable to Cross Site Scripting","link":"https:\/\/github.com\/advisories\/GHSA-pq95-94c9-j987","cve":"CVE-2025-70844","affectedVersions":"\u003C=2.0.0","source":"GitHub","reportedAt":"2026-04-07 18:31:37","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pq95-94c9-j987"}]}],"laravel\/passport":[{"advisoryId":"PKSA-wc55-9qj2-7v4h","packageName":"laravel\/passport","remoteId":"GHSA-349c-2h2f-mxf6","title":"Laravel Passport: TokenGuard Authenticates Unrelated User for Client Credentials Tokens","link":"https:\/\/github.com\/advisories\/GHSA-349c-2h2f-mxf6","cve":"CVE-2026-39976","affectedVersions":"\u003E=13.0.0,\u003C13.7.1","source":"GitHub","reportedAt":"2026-04-08 19:57:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-349c-2h2f-mxf6"}]}],"feehi\/cms":[{"advisoryId":"PKSA-csfn-tqkm-331b","packageName":"feehi\/cms","remoteId":"GHSA-cvjh-88c8-2jjx","title":"Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the creation\/editing module","link":"https:\/\/github.com\/advisories\/GHSA-cvjh-88c8-2jjx","cve":"CVE-2026-31351","affectedVersions":"=2.1.1","source":"GitHub","reportedAt":"2026-04-06 18:33:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cvjh-88c8-2jjx"}]},{"advisoryId":"PKSA-mqjt-q7xt-ffry","packageName":"feehi\/cms","remoteId":"GHSA-hqjc-wfvx-x2fv","title":"Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Role Management module","link":"https:\/\/github.com\/advisories\/GHSA-hqjc-wfvx-x2fv","cve":"CVE-2026-31352","affectedVersions":"=2.1.1","source":"GitHub","reportedAt":"2026-04-06 18:33:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hqjc-wfvx-x2fv"}]},{"advisoryId":"PKSA-ws91-wc7w-vwjs","packageName":"feehi\/cms","remoteId":"GHSA-664p-j3q6-p843","title":"Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Category module","link":"https:\/\/github.com\/advisories\/GHSA-664p-j3q6-p843","cve":"CVE-2026-31353","affectedVersions":"=2.1.1","source":"GitHub","reportedAt":"2026-04-06 18:33:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-664p-j3q6-p843"}]},{"advisoryId":"PKSA-rwph-3mr4-xjw2","packageName":"feehi\/cms","remoteId":"GHSA-xqm9-6qmm-xrqh","title":"Feehi CMS has authenticated stored cross-site scripting (XSS) vulnerabilities via the Permissions module","link":"https:\/\/github.com\/advisories\/GHSA-xqm9-6qmm-xrqh","cve":"CVE-2026-31354","affectedVersions":"=2.1.1","source":"GitHub","reportedAt":"2026-04-06 18:33:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xqm9-6qmm-xrqh"}]},{"advisoryId":"PKSA-tgmx-kn2c-zmk2","packageName":"feehi\/cms","remoteId":"GHSA-cgxr-v74v-g9mm","title":"Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Page Sign parameter","link":"https:\/\/github.com\/advisories\/GHSA-cgxr-v74v-g9mm","cve":"CVE-2026-31350","affectedVersions":"=2.1.1","source":"GitHub","reportedAt":"2026-04-06 18:33:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cgxr-v74v-g9mm"}]},{"advisoryId":"PKSA-ssrk-53xg-dbbn","packageName":"feehi\/cms","remoteId":"GHSA-hj9c-p59c-vqph","title":"Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the creation\/editing module","link":"https:\/\/github.com\/advisories\/GHSA-hj9c-p59c-vqph","cve":"CVE-2026-31313","affectedVersions":"=2.1.1","source":"GitHub","reportedAt":"2026-04-06 18:33:08","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hj9c-p59c-vqph"}]},{"advisoryId":"PKSA-8ccr-c5yg-83p5","packageName":"feehi\/cms","remoteId":"GHSA-mcxq-54f4-mmx5","title":"FeehiCMS Has a Remote Code Execution via Unrestricted File Upload in Ad Management","link":"https:\/\/github.com\/advisories\/GHSA-mcxq-54f4-mmx5","cve":"CVE-2025-65657","affectedVersions":"\u003C=2.1.1","source":"GitHub","reportedAt":"2025-12-02 21:31:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mcxq-54f4-mmx5"}]}],"roundcube\/roundcubemail":[{"advisoryId":"PKSA-wjqw-j5qy-sdfr","packageName":"roundcube\/roundcubemail","remoteId":"GHSA-rxj3-rrwm-pj4r","title":"Roundcube Webmail: Unsafe deserialization in the redis\/memcache session handler","link":"https:\/\/github.com\/advisories\/GHSA-rxj3-rrwm-pj4r","cve":"CVE-2026-35537","affectedVersions":"\u003E=1.7-beta,\u003C1.7-rc5","source":"GitHub","reportedAt":"2026-04-03 06:31:32","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-rxj3-rrwm-pj4r"}]},{"advisoryId":"PKSA-764m-m66v-9t4g","packageName":"roundcube\/roundcubemail","remoteId":"GHSA-8jr8-v43g-5c57","title":"Roundcube Webmail: Unsanitized IMAP SEARCH command arguments","link":"https:\/\/github.com\/advisories\/GHSA-8jr8-v43g-5c57","cve":"CVE-2026-35538","affectedVersions":"\u003E=1.7-beta,\u003C1.7-rc5","source":"GitHub","reportedAt":"2026-04-03 06:31:32","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-8jr8-v43g-5c57"}]},{"advisoryId":"PKSA-3z5p-dc2d-4drb","packageName":"roundcube\/roundcubemail","remoteId":"GHSA-x4q5-8j5g-hpjc","title":"Roundcube Webmail: Insufficient HTML attachment sanitization in preview mode","link":"https:\/\/github.com\/advisories\/GHSA-x4q5-8j5g-hpjc","cve":"CVE-2026-35539","affectedVersions":"\u003E=1.7-beta,\u003C1.7-rc5","source":"GitHub","reportedAt":"2026-04-03 06:31:32","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x4q5-8j5g-hpjc"}]},{"advisoryId":"PKSA-vsf6-6r3q-jc1x","packageName":"roundcube\/roundcubemail","remoteId":"GHSA-vxg2-hhgr-37fx","title":"Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages","link":"https:\/\/github.com\/advisories\/GHSA-vxg2-hhgr-37fx","cve":"CVE-2026-35540","affectedVersions":"\u003E=1.7-beta,\u003C1.7-rc5","source":"GitHub","reportedAt":"2026-04-03 06:31:32","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vxg2-hhgr-37fx"}]},{"advisoryId":"PKSA-5v34-b81b-ng2h","packageName":"roundcube\/roundcubemail","remoteId":"GHSA-46pv-mj2g-93gh","title":"Roundcube Webmail: Incorrect password comparison in the password plugin","link":"https:\/\/github.com\/advisories\/GHSA-46pv-mj2g-93gh","cve":"CVE-2026-35541","affectedVersions":"\u003E=1.7-beta,\u003C1.7-rc5","source":"GitHub","reportedAt":"2026-04-03 06:31:32","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-46pv-mj2g-93gh"}]},{"advisoryId":"PKSA-kj9x-s73h-chn8","packageName":"roundcube\/roundcubemail","remoteId":"GHSA-5hf6-crg4-fg59","title":"Roundcube: Bypass of remote image blocking via crafted BODY background attribute","link":"https:\/\/github.com\/advisories\/GHSA-5hf6-crg4-fg59","cve":"CVE-2026-35542","affectedVersions":"\u003E=1.7-beta,\u003C1.7-rc5","source":"GitHub","reportedAt":"2026-04-03 06:31:32","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5hf6-crg4-fg59"}]},{"advisoryId":"PKSA-qdpg-77hy-3x5t","packageName":"roundcube\/roundcubemail","remoteId":"GHSA-j2g6-8rvg-7mf6","title":"Roundcube Webmail: Bypass of remote image blocking via SVG content (with animate attributes) in an e-mail message","link":"https:\/\/github.com\/advisories\/GHSA-j2g6-8rvg-7mf6","cve":"CVE-2026-35543","affectedVersions":"\u003E=1.7-beta,\u003C1.7-rc5","source":"GitHub","reportedAt":"2026-04-03 06:31:32","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j2g6-8rvg-7mf6"}]},{"advisoryId":"PKSA-wvxn-8qzx-v8n9","packageName":"roundcube\/roundcubemail","remoteId":"GHSA-xpqh-grpw-4xmg","title":"Roundcube Webmail: Insufficient CSS sanitization in HTML e-mail messages","link":"https:\/\/github.com\/advisories\/GHSA-xpqh-grpw-4xmg","cve":"CVE-2026-35544","affectedVersions":"\u003E=1.7-beta,\u003C1.7-rc5","source":"GitHub","reportedAt":"2026-04-03 06:31:32","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xpqh-grpw-4xmg"}]},{"advisoryId":"PKSA-hnx5-g7mc-vpff","packageName":"roundcube\/roundcubemail","remoteId":"GHSA-w846-74jr-76cv","title":"Roundcube Webmail: Remote image blocking feature can be bypassed via SVG content in an e-mail message","link":"https:\/\/github.com\/advisories\/GHSA-w846-74jr-76cv","cve":"CVE-2026-35545","affectedVersions":"\u003E=1.7-beta,\u003C1.7-rc5","source":"GitHub","reportedAt":"2026-04-03 06:31:32","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w846-74jr-76cv"}]}],"auth0\/login":[{"advisoryId":"PKSA-9fpd-p7cq-9hfg","packageName":"auth0\/login","remoteId":"GHSA-fmg6-246m-9g2v","title":"Auth0 laravel-auth0 SDK has Insufficient Entropy in Cookie Encryption","link":"https:\/\/github.com\/advisories\/GHSA-fmg6-246m-9g2v","cve":null,"affectedVersions":"\u003E=7.0.0,\u003C=7.20.0","source":"GitHub","reportedAt":"2026-04-03 03:41:04","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fmg6-246m-9g2v"}]},{"advisoryId":"PKSA-y6vp-t32r-dgs1","packageName":"auth0\/login","remoteId":"GHSA-7hh9-gp72-wh7h","title":"Auth0 Laravel SDK has Improper Audience Validation via Auth0-PHP SDK dependency","link":"https:\/\/github.com\/advisories\/GHSA-7hh9-gp72-wh7h","cve":null,"affectedVersions":"\u003E=7.0.0,\u003C7.20.0","source":"GitHub","reportedAt":"2025-12-17 20:55:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7hh9-gp72-wh7h"}]},{"advisoryId":"PKSA-gczm-ztvk-kyyg","packageName":"auth0\/login","remoteId":"GHSA-hjfh-5jmm-xr24","title":"laravel-auth0 SDK Does Not Properly Handle File Types in Bulk User Import","link":"https:\/\/github.com\/advisories\/GHSA-hjfh-5jmm-xr24","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C=7.18.0","source":"GitHub","reportedAt":"2025-10-01 21:21:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-hjfh-5jmm-xr24"}]}],"auth0\/wordpress":[{"advisoryId":"PKSA-rbsn-2z23-mspc","packageName":"auth0\/wordpress","remoteId":"GHSA-vfpx-q664-h93m","title":"Auth0 WordPress Plugin has Insufficient Entropy in Cookie Encryption","link":"https:\/\/github.com\/advisories\/GHSA-vfpx-q664-h93m","cve":null,"affectedVersions":"\u003E=5.0.0-BETA0,\u003C=5.5.0","source":"GitHub","reportedAt":"2026-04-03 03:43:13","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vfpx-q664-h93m"}]},{"advisoryId":"PKSA-q26s-yhsm-92t7","packageName":"auth0\/wordpress","remoteId":"GHSA-vvg7-8rmq-92g7","title":"Auth0 WordPress has Improper Audience Validation via Auth0-PHP SDK Dependency","link":"https:\/\/github.com\/advisories\/GHSA-vvg7-8rmq-92g7","cve":null,"affectedVersions":"\u003E=5.0.0-BETA0,\u003C=5.4.0","source":"GitHub","reportedAt":"2025-12-17 20:57:09","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vvg7-8rmq-92g7"}]},{"advisoryId":"PKSA-82rv-h1ph-c98y","packageName":"auth0\/wordpress","remoteId":"GHSA-w22c-pw5m-482x","title":"Auth0 Wordpress plugin Does Not Properly Handle File Types in Bulk User Import","link":"https:\/\/github.com\/advisories\/GHSA-w22c-pw5m-482x","cve":null,"affectedVersions":"\u003E5.0.0-BETA0,\u003C=5.3.0","source":"GitHub","reportedAt":"2025-10-01 21:21:20","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-w22c-pw5m-482x"}]}],"auth0\/symfony":[{"advisoryId":"PKSA-kmxg-njz7-dx5f","packageName":"auth0\/symfony","remoteId":"GHSA-ghc5-95c2-vwcv","title":"Auth0 Symfony SDK has Insufficient Entropy in Cookie Encryption","link":"https:\/\/github.com\/advisories\/GHSA-ghc5-95c2-vwcv","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C=5.7.0","source":"GitHub","reportedAt":"2026-04-03 03:44:13","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-ghc5-95c2-vwcv"}]},{"advisoryId":"PKSA-3pss-my3n-f2df","packageName":"auth0\/symfony","remoteId":"GHSA-f3r2-88mq-9v4g","title":"Auth0 Symfony SDK has Improper Audience Validation via Auth0-PHP SDK","link":"https:\/\/github.com\/advisories\/GHSA-f3r2-88mq-9v4g","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C=5.5.0","source":"GitHub","reportedAt":"2025-12-17 20:56:37","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f3r2-88mq-9v4g"}]},{"advisoryId":"PKSA-f26r-1nfs-j3hv","packageName":"auth0\/symfony","remoteId":"GHSA-7jp2-5h22-m432","title":"Auth0 Symfony SDK Does Not Properly Handle File Types in Bulk User Import","link":"https:\/\/github.com\/advisories\/GHSA-7jp2-5h22-m432","cve":null,"affectedVersions":"\u003E=2.0.2,\u003C=5.4.1","source":"GitHub","reportedAt":"2025-10-01 21:21:34","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7jp2-5h22-m432"}]}],"auth0\/auth0-php":[{"advisoryId":"PKSA-3nzc-cgjr-2gwf","packageName":"auth0\/auth0-php","remoteId":"GHSA-w3wc-44p4-m4j7","title":"Auth0 PHP SDK has Insufficient Entropy in Cookie Encryption","link":"https:\/\/github.com\/advisories\/GHSA-w3wc-44p4-m4j7","cve":"CVE-2026-34236","affectedVersions":"\u003E=8.0.0,\u003C=8.18.0","source":"GitHub","reportedAt":"2026-04-01 20:29:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w3wc-44p4-m4j7"}]},{"advisoryId":"PKSA-xk7h-d6qg-hj3r","packageName":"auth0\/auth0-php","remoteId":"GHSA-j2vm-wrq3-f7gf","title":"Auth0-PHP SDK has Improper Audience Validation","link":"https:\/\/github.com\/advisories\/GHSA-j2vm-wrq3-f7gf","cve":"CVE-2025-68129","affectedVersions":"\u003E=8.0.0,\u003C8.18.0","source":"GitHub","reportedAt":"2025-12-17 20:52:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j2vm-wrq3-f7gf"}]},{"advisoryId":"PKSA-r19n-r8k1-m54h","packageName":"auth0\/auth0-php","remoteId":"GHSA-9mh6-g99m-ppcw","title":"auth0-PHP SDK Does Not Properly Handle File Types in Bulk User Import","link":"https:\/\/github.com\/advisories\/GHSA-9mh6-g99m-ppcw","cve":"CVE-2025-58769","affectedVersions":"\u003E=3.3.0,\u003C=8.16.0","source":"GitHub","reportedAt":"2025-10-01 21:20:45","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-9mh6-g99m-ppcw"}]}],"j0k3r\/graby":[{"advisoryId":"PKSA-j5hk-b83d-1p4h","packageName":"j0k3r\/graby","remoteId":"GHSA-3h6j-9x8m-rg3g","title":"Graby has stored XSS via iframe srcdoc Attribute in htmLawed Sanitization Config","link":"https:\/\/github.com\/advisories\/GHSA-3h6j-9x8m-rg3g","cve":null,"affectedVersions":"\u003C=2.5.0","source":"GitHub","reportedAt":"2026-03-31 23:12:36","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-3h6j-9x8m-rg3g"}]}],"baserproject\/basercms":[{"advisoryId":"PKSA-hd1x-n8tw-4v66","packageName":"baserproject\/basercms","remoteId":"GHSA-677c-xv24-crgx","title":"baserCMS is Vulnerable to Cross-site Scripting","link":"https:\/\/github.com\/advisories\/GHSA-677c-xv24-crgx","cve":"CVE-2026-32734","affectedVersions":"\u003C=5.2.2","source":"GitHub","reportedAt":"2026-03-31 22:52:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-677c-xv24-crgx"}]},{"advisoryId":"PKSA-kcyg-5jhp-1x3h","packageName":"baserproject\/basercms","remoteId":"GHSA-jmq3-x8q7-j9qm","title":"baserCMS has a cross-site scripting vulnerability in blog posts","link":"https:\/\/github.com\/advisories\/GHSA-jmq3-x8q7-j9qm","cve":"CVE-2026-30879","affectedVersions":"\u003C=5.2.2","source":"GitHub","reportedAt":"2026-03-31 22:43:10","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jmq3-x8q7-j9qm"}]},{"advisoryId":"PKSA-9wbk-k4bx-zvqq","packageName":"baserproject\/basercms","remoteId":"GHSA-6hpg-8rx3-cwgv","title":"baserCMS has OS command injection vulnerability in installer","link":"https:\/\/github.com\/advisories\/GHSA-6hpg-8rx3-cwgv","cve":"CVE-2026-30880","affectedVersions":"\u003C=5.2.2","source":"GitHub","reportedAt":"2026-03-31 22:43:31","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-6hpg-8rx3-cwgv"}]},{"advisoryId":"PKSA-6jcy-61hj-18tr","packageName":"baserproject\/basercms","remoteId":"GHSA-c5c6-37vq-pjcq","title":"baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API","link":"https:\/\/github.com\/advisories\/GHSA-c5c6-37vq-pjcq","cve":"CVE-2026-30940","affectedVersions":"\u003C=5.2.2","source":"GitHub","reportedAt":"2026-03-31 22:47:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c5c6-37vq-pjcq"}]},{"advisoryId":"PKSA-1768-n8q1-3816","packageName":"baserproject\/basercms","remoteId":"GHSA-vh89-rjph-2g7p","title":"baserCMS has an SQL injection vulnerability in its blog post functionality","link":"https:\/\/github.com\/advisories\/GHSA-vh89-rjph-2g7p","cve":"CVE-2026-27697","affectedVersions":"\u003C=5.2.2","source":"GitHub","reportedAt":"2026-03-31 22:35:08","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vh89-rjph-2g7p"}]},{"advisoryId":"PKSA-mr15-f3n3-4vy5","packageName":"baserproject\/basercms","remoteId":"GHSA-m9g7-rgfc-jcm7","title":"baserCMS Update Functionality Vulnerable to OS Command Injection","link":"https:\/\/github.com\/advisories\/GHSA-m9g7-rgfc-jcm7","cve":"CVE-2026-30877","affectedVersions":"\u003C=5.2.2","source":"GitHub","reportedAt":"2026-03-31 22:35:47","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-m9g7-rgfc-jcm7"}]},{"advisoryId":"PKSA-ztxq-vhtb-jhvy","packageName":"baserproject\/basercms","remoteId":"GHSA-8cr7-r8qw-gp3c","title":"baserCMS has Mail Form Acceptance Bypass via Public API","link":"https:\/\/github.com\/advisories\/GHSA-8cr7-r8qw-gp3c","cve":"CVE-2026-30878","affectedVersions":"\u003C=5.2.2","source":"GitHub","reportedAt":"2026-03-31 22:36:18","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8cr7-r8qw-gp3c"}]},{"advisoryId":"PKSA-mrz2-4hdf-297k","packageName":"baserproject\/basercms","remoteId":"GHSA-hv78-cwp4-8r7r","title":"baserCMS has Unsafe File Upload Leading to Remote Code Execution (RCE)","link":"https:\/\/github.com\/advisories\/GHSA-hv78-cwp4-8r7r","cve":"CVE-2025-32957","affectedVersions":"\u003C=5.2.2","source":"GitHub","reportedAt":"2026-03-31 22:22:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hv78-cwp4-8r7r"}]},{"advisoryId":"PKSA-xyh3-vpd8-cdnh","packageName":"baserproject\/basercms","remoteId":"GHSA-qxmc-6f24-g86g","title":"baserCMS has OS Command Injection Leading to Remote Code Execution (RCE)","link":"https:\/\/github.com\/advisories\/GHSA-qxmc-6f24-g86g","cve":"CVE-2026-21861","affectedVersions":"\u003C=5.2.2","source":"GitHub","reportedAt":"2026-03-31 22:27:05","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-qxmc-6f24-g86g"}]}],"aws\/aws-sdk-php":[{"advisoryId":"PKSA-4t1p-xpk2-nsss","packageName":"aws\/aws-sdk-php","remoteId":"GHSA-27qh-8cxx-2cr5","title":"AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters","link":"https:\/\/github.com\/advisories\/GHSA-27qh-8cxx-2cr5","cve":null,"affectedVersions":"\u003E=3.11.7,\u003C=3.371.3","source":"GitHub","reportedAt":"2026-03-27 19:54:58","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-27qh-8cxx-2cr5"}]},{"advisoryId":"PKSA-dxyf-6n16-t87m","packageName":"aws\/aws-sdk-php","remoteId":"aws\/aws-sdk-php\/CVE-2025-14761.yaml","title":"Key Commitment Issues in S3 Encryption Clients","link":"https:\/\/aws.amazon.com\/security\/security-bulletins\/AWS-2025-032\/","cve":"CVE-2025-14761","affectedVersions":"\u003E=3.0.0,\u003C3.368.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2025-12-17 20:15:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"aws\/aws-sdk-php\/CVE-2025-14761.yaml"},{"name":"GitHub","remoteId":"GHSA-x8cp-jf6f-r4xh"}]}],"saloonphp\/saloon":[{"advisoryId":"PKSA-xnj5-w74d-6wmz","packageName":"saloonphp\/saloon","remoteId":"GHSA-rf88-776r-rcq9","title":"Saloon has insecure deserialization in AccessTokenAuthenticator","link":"https:\/\/github.com\/advisories\/GHSA-rf88-776r-rcq9","cve":"CVE-2026-33942","affectedVersions":"\u003C4.0.0","source":"GitHub","reportedAt":"2026-03-27 18:33:43","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-rf88-776r-rcq9"}]},{"advisoryId":"PKSA-5szq-gvrg-ttfq","packageName":"saloonphp\/saloon","remoteId":"GHSA-c83f-3xp6-hfcp","title":"Saloon is vulnerable to SSRF and credential leakage via absolute URL in endpoint overriding base URL","link":"https:\/\/github.com\/advisories\/GHSA-c83f-3xp6-hfcp","cve":"CVE-2026-33182","affectedVersions":"\u003C4.0.0","source":"GitHub","reportedAt":"2026-03-25 22:00:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c83f-3xp6-hfcp"}]},{"advisoryId":"PKSA-rnpm-45mg-w6ht","packageName":"saloonphp\/saloon","remoteId":"GHSA-f7xc-5852-fj99","title":"Saloon has a Fixture Name Path Traversal Vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-f7xc-5852-fj99","cve":"CVE-2026-33183","affectedVersions":"\u003C4.0.0","source":"GitHub","reportedAt":"2026-03-25 22:00:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f7xc-5852-fj99"}]}],"hybridauth\/hybridauth":[{"advisoryId":"PKSA-27jb-7jhc-ynjm","packageName":"hybridauth\/hybridauth","remoteId":"GHSA-r3hf-q3mf-7h6w","title":"HybridAuth Has Improper SSL Certificate Validation in Curl HTTP Client","link":"https:\/\/github.com\/advisories\/GHSA-r3hf-q3mf-7h6w","cve":"CVE-2026-4587","affectedVersions":"\u003C=3.12.2","source":"GitHub","reportedAt":"2026-03-23 15:30:44","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r3hf-q3mf-7h6w"}]}],"miraheze\/ts-portal":[{"advisoryId":"PKSA-7xkw-5f95-g3th","packageName":"miraheze\/ts-portal","remoteId":"GHSA-f346-8rp3-4h9h","title":"TSPortal\u0027s Uncontrolled User Creation via Validation Side Effects Leads to Potential Denial of Service","link":"https:\/\/github.com\/advisories\/GHSA-f346-8rp3-4h9h","cve":"CVE-2026-33541","affectedVersions":"\u003C=33","source":"GitHub","reportedAt":"2026-03-27 15:42:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f346-8rp3-4h9h"}]},{"advisoryId":"PKSA-95py-dkb3-3t1y","packageName":"miraheze\/ts-portal","remoteId":"GHSA-gfhq-7499-f3f2","title":"TSPortal: Any user can forge self-deletion requests for any account","link":"https:\/\/github.com\/advisories\/GHSA-gfhq-7499-f3f2","cve":"CVE-2026-29788","affectedVersions":"\u003C=29","source":"GitHub","reportedAt":"2026-03-27 15:37:10","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gfhq-7499-f3f2"}]}],"google\/protobuf":[{"advisoryId":"PKSA-tcfz-w4fm-hhk9","packageName":"google\/protobuf","remoteId":"GHSA-p2gh-cfq4-4wjc","title":"Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion","link":"https:\/\/github.com\/advisories\/GHSA-p2gh-cfq4-4wjc","cve":"CVE-2026-6409","affectedVersions":"\u003C4.33.6","source":"GitHub","reportedAt":"2026-03-25 21:02:08","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-p2gh-cfq4-4wjc"}]}],"yansongda\/pay":[{"advisoryId":"PKSA-8dgs-n4fh-5pd5","packageName":"yansongda\/pay","remoteId":"GHSA-q938-ghwv-8gvc","title":"WeChat Pay callback signature verification bypassed when Host header is localhost","link":"https:\/\/github.com\/advisories\/GHSA-q938-ghwv-8gvc","cve":"CVE-2026-33661","affectedVersions":"\u003C=3.7.19","source":"GitHub","reportedAt":"2026-03-25 19:30:09","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-q938-ghwv-8gvc"}]}],"invoiceninja\/invoiceninja":[{"advisoryId":"PKSA-txpv-wmxc-xy2c","packageName":"invoiceninja\/invoiceninja","remoteId":"GHSA-98wm-cxpw-847p","title":"Invoice Ninja Denylist Bypass may Lead to Stored XSS via Invoice Line Items","link":"https:\/\/github.com\/advisories\/GHSA-98wm-cxpw-847p","cve":"CVE-2026-33628","affectedVersions":"\u003C5.13.4","source":"GitHub","reportedAt":"2026-03-24 20:40:16","composerRepository":null,"severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-98wm-cxpw-847p"}]}],"roadiz\/documents":[{"advisoryId":"PKSA-8x28-rsr9-rfb8","packageName":"roadiz\/documents","remoteId":"GHSA-rc55-58f4-687g","title":"Roadiz has Server-Side Request Forgery (SSRF) in roadiz\/documents","link":"https:\/\/github.com\/advisories\/GHSA-rc55-58f4-687g","cve":"CVE-2026-33486","affectedVersions":"\u003C2.3.42|\u003E=2.4.0,\u003C2.5.44|\u003E=2.6.0,\u003C2.6.28|\u003E=2.7.0,\u003C2.7.9","source":"GitHub","reportedAt":"2026-03-23 21:43:14","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rc55-58f4-687g"}]}],"opensource-workshop\/connect-cms":[{"advisoryId":"PKSA-41bx-mcct-sk3j","packageName":"opensource-workshop\/connect-cms","remoteId":"GHSA-hxqw-6qv7-cqfv","title":"Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin","link":"https:\/\/github.com\/advisories\/GHSA-hxqw-6qv7-cqfv","cve":"CVE-2026-32276","affectedVersions":"\u003E=2.0.0,\u003C2.41.1|\u003C1.41.1","source":"GitHub","reportedAt":"2026-03-23 20:33:34","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hxqw-6qv7-cqfv"}]},{"advisoryId":"PKSA-16v9-y28z-87sk","packageName":"opensource-workshop\/connect-cms","remoteId":"GHSA-cmfh-mpmf-fmq4","title":"Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View","link":"https:\/\/github.com\/advisories\/GHSA-cmfh-mpmf-fmq4","cve":"CVE-2026-32277","affectedVersions":"\u003E=2.35.0,\u003C2.41.1|\u003E=1.35.0,\u003C1.41.1","source":"GitHub","reportedAt":"2026-03-23 20:35:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-cmfh-mpmf-fmq4"}]},{"advisoryId":"PKSA-2kyx-vx1v-bbq2","packageName":"opensource-workshop\/connect-cms","remoteId":"GHSA-mv3p-7p89-wq9p","title":"Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin","link":"https:\/\/github.com\/advisories\/GHSA-mv3p-7p89-wq9p","cve":"CVE-2026-32278","affectedVersions":"\u003E=2.0.0,\u003C=2.41.0|\u003C=1.41.0","source":"GitHub","reportedAt":"2026-03-23 20:36:15","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mv3p-7p89-wq9p"}]},{"advisoryId":"PKSA-h93g-m9xg-91qb","packageName":"opensource-workshop\/connect-cms","remoteId":"GHSA-jh46-85jr-6ph9","title":"Connect CMS has SSRF in the External Page Migration Feature of its Page Management Plugin","link":"https:\/\/github.com\/advisories\/GHSA-jh46-85jr-6ph9","cve":"CVE-2026-32279","affectedVersions":"\u003E=2.0.0,\u003C=2.41.0|\u003C=1.41.0","source":"GitHub","reportedAt":"2026-03-23 20:36:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jh46-85jr-6ph9"}]},{"advisoryId":"PKSA-cxpk-mhkk-3kqb","packageName":"opensource-workshop\/connect-cms","remoteId":"GHSA-62ch-j6x7-722j","title":"Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature","link":"https:\/\/github.com\/advisories\/GHSA-62ch-j6x7-722j","cve":"CVE-2026-32299","affectedVersions":"\u003E=2.0.0,\u003C=2.40.0|\u003C=1.40.0","source":"GitHub","reportedAt":"2026-03-23 20:38:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-62ch-j6x7-722j"}]},{"advisoryId":"PKSA-mqv7-zr7q-hc9j","packageName":"opensource-workshop\/connect-cms","remoteId":"GHSA-qr6x-wvxr-8hm9","title":"Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information","link":"https:\/\/github.com\/advisories\/GHSA-qr6x-wvxr-8hm9","cve":"CVE-2026-32300","affectedVersions":"\u003E=2.0.0,\u003C=2.41.0|\u003C=1.41.0","source":"GitHub","reportedAt":"2026-03-23 20:39:10","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qr6x-wvxr-8hm9"}]}],"putyourlightson\/craft-sprig":[{"advisoryId":"PKSA-73p9-59k3-bf4z","packageName":"putyourlightson\/craft-sprig","remoteId":"GHSA-m59h-42jf-cphr","title":"Sprig Plugin for Craft CMS potentially discloses sensitive information via Sprig Playground","link":"https:\/\/github.com\/advisories\/GHSA-m59h-42jf-cphr","cve":"CVE-2026-27131","affectedVersions":"\u003E=3.0.0,\u003C3.7.2|\u003E=2.0.0,\u003C2.15.2","source":"GitHub","reportedAt":"2026-03-23 20:25:37","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m59h-42jf-cphr"}]}],"dreamfactory\/df-core":[{"advisoryId":"PKSA-6vcs-hgyx-yq4f","packageName":"dreamfactory\/df-core","remoteId":"GHSA-gv7f-w92j-383q","title":"DreamFactory has a directory traversal","link":"https:\/\/github.com\/advisories\/GHSA-gv7f-w92j-383q","cve":"CVE-2025-55988","affectedVersions":"\u003C1.0.4","source":"GitHub","reportedAt":"2026-03-20 21:31:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gv7f-w92j-383q"}]}],"johnbillion\/query-monitor":[{"advisoryId":"PKSA-675z-6zmn-1gbt","packageName":"johnbillion\/query-monitor","remoteId":"GHSA-2xr4-chcf-vmvf","title":"The Query Monitor plugin for WordPress has Reflected Cross-Site Scripting via Request URI","link":"https:\/\/github.com\/advisories\/GHSA-2xr4-chcf-vmvf","cve":"CVE-2026-4267","affectedVersions":"\u003C3.20.4","source":"GitHub","reportedAt":"2026-03-19 19:37:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2xr4-chcf-vmvf"}]}],"yoast\/duplicate-post":[{"advisoryId":"PKSA-gmm7-sf5q-mmt1","packageName":"yoast\/duplicate-post","remoteId":"GHSA-g9w4-m5fx-x3wv","title":"Yoast Duplicate Post has an Authenticated (Contributor+) Missing Authorization to Arbitrary Post Duplication and Overwrite","link":"https:\/\/github.com\/advisories\/GHSA-g9w4-m5fx-x3wv","cve":"CVE-2026-1217","affectedVersions":"\u003C=4.5","source":"GitHub","reportedAt":"2026-03-18 12:31:51","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g9w4-m5fx-x3wv"}]}],"league\/commonmark":[{"advisoryId":"PKSA-21fb-n1x5-5nf7","packageName":"league\/commonmark","remoteId":"GHSA-hh8v-hgvp-g3f5","title":"league\/commonmark has an embed extension allowed_domains bypass","link":"https:\/\/github.com\/advisories\/GHSA-hh8v-hgvp-g3f5","cve":"CVE-2026-33347","affectedVersions":"\u003E=2.3.0,\u003C=2.8.1","source":"GitHub","reportedAt":"2026-03-19 19:04:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hh8v-hgvp-g3f5"}]},{"advisoryId":"PKSA-2cx9-ynrq-qdk3","packageName":"league\/commonmark","remoteId":"GHSA-4v6x-c7xx-hw9f","title":"CommonMark has DisallowedRawHtml extension bypass via whitespace in HTML tag names","link":"https:\/\/github.com\/advisories\/GHSA-4v6x-c7xx-hw9f","cve":"CVE-2026-30838","affectedVersions":"\u003E=2.0.0,\u003C=2.8.0","source":"GitHub","reportedAt":"2026-03-06 23:27:03","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4v6x-c7xx-hw9f"}]},{"advisoryId":"PKSA-rqc2-tcc6-nc79","packageName":"league\/commonmark","remoteId":"GHSA-3527-qv2q-pfvx","title":"league\/commonmark contains a XSS vulnerability in Attributes extension","link":"https:\/\/github.com\/advisories\/GHSA-3527-qv2q-pfvx","cve":"CVE-2025-46734","affectedVersions":"\u003E=1.5.0,\u003C2.7.0","source":"GitHub","reportedAt":"2025-05-05 20:40:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3527-qv2q-pfvx"}]}],"kelvinmo\/simplejwt":[{"advisoryId":"PKSA-njxg-bvx9-65t2","packageName":"kelvinmo\/simplejwt","remoteId":"GHSA-xw36-67f8-339x","title":"SimpleJWT has an Unauthenticated Denial of Service via JWE header tampering","link":"https:\/\/github.com\/advisories\/GHSA-xw36-67f8-339x","cve":"CVE-2026-33204","affectedVersions":"\u003C=1.1.0","source":"GitHub","reportedAt":"2026-03-18 20:16:59","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xw36-67f8-339x"}]}],"cpsit\/typo3-mailqueue":[{"advisoryId":"PKSA-nq65-b886-3hc5","packageName":"cpsit\/typo3-mailqueue","remoteId":"GHSA-2pm6-9fhx-vvg3","title":"The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class","link":"https:\/\/github.com\/advisories\/GHSA-2pm6-9fhx-vvg3","cve":"CVE-2026-1323","affectedVersions":"\u003E=0.5.0,\u003C0.5.2|\u003C0.4.5","source":"GitHub","reportedAt":"2026-03-18 16:17:08","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2pm6-9fhx-vvg3"}]},{"advisoryId":"PKSA-ykqx-xqdj-9z2x","packageName":"cpsit\/typo3-mailqueue","remoteId":"GHSA-ggff-9mj3-7246","title":"mailqueue TYPO3 extension affected by Insecure Deserialization in QueueableFileTransport","link":"https:\/\/github.com\/advisories\/GHSA-ggff-9mj3-7246","cve":"CVE-2026-0895","affectedVersions":"\u003E=0.5.0,\u003C0.5.1|\u003C0.4.3","source":"GitHub","reportedAt":"2026-01-21 15:47:44","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-ggff-9mj3-7246"}]}],"ayacoo\/redirect-tab":[{"advisoryId":"PKSA-qm8d-zth2-jq36","packageName":"ayacoo\/redirect-tab","remoteId":"GHSA-755r-r738-mjgp","title":"Broken Access Control in extension \u0022Redirect Tab\u0022 (redirect_tab)","link":"https:\/\/github.com\/advisories\/GHSA-755r-r738-mjgp","cve":"CVE-2026-4202","affectedVersions":"\u003E=4.0.0,\u003C4.0.5|\u003E=3.0.0,\u003C3.1.7|\u003C2.1.2","source":"GitHub","reportedAt":"2026-03-17 09:31:28","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-755r-r738-mjgp"}]}],"ralffreit\/mfa-email":[{"advisoryId":"PKSA-qp7n-s4g1-wsjq","packageName":"ralffreit\/mfa-email","remoteId":"GHSA-29r8-gvx4-r9w3","title":"Authentication Bypass in extension \u0022E-Mail MFA Provider\u0022 (mfa_email)","link":"https:\/\/github.com\/advisories\/GHSA-29r8-gvx4-r9w3","cve":"CVE-2026-4208","affectedVersions":"=2.0.0|\u003C1.0.7","source":"GitHub","reportedAt":"2026-03-17 09:31:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-29r8-gvx4-r9w3"}]}],"aureuserp\/aureuserp":[{"advisoryId":"PKSA-nj38-h5v2-sqrz","packageName":"aureuserp\/aureuserp","remoteId":"GHSA-76c2-3q6g-xvpm","title":"Aureus ERP vulnerable to cross-site scripting in the Chatter Message Handler","link":"https:\/\/github.com\/advisories\/GHSA-76c2-3q6g-xvpm","cve":"CVE-2026-4175","affectedVersions":"\u003C1.3.0-BETA1","source":"GitHub","reportedAt":"2026-03-16 15:30:44","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-76c2-3q6g-xvpm"}]}],"craftcms\/azure-blob":[{"advisoryId":"PKSA-yqn3-q88t-c7wb","packageName":"craftcms\/azure-blob","remoteId":"GHSA-q6fm-p73f-x862","title":"Azure Blob Storage for Craft CMS Potential Sensitive Information Disclosure vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-q6fm-p73f-x862","cve":"CVE-2026-32268","affectedVersions":"\u003E=2.0.0-beta.1,\u003C=2.1.0","source":"GitHub","reportedAt":"2026-03-16 18:44:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-q6fm-p73f-x862"}]}],"craftcms\/webhooks":[{"advisoryId":"PKSA-fnz6-639n-kpcq","packageName":"craftcms\/webhooks","remoteId":"GHSA-8wg7-wm29-2rvg","title":"RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugin","link":"https:\/\/github.com\/advisories\/GHSA-8wg7-wm29-2rvg","cve":"CVE-2026-32261","affectedVersions":"\u003E=3.0.0,\u003C3.2.0","source":"GitHub","reportedAt":"2026-03-16 18:11:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8wg7-wm29-2rvg"}]}],"craftcms\/aws-s3":[{"advisoryId":"PKSA-7kdj-x25g-wc45","packageName":"craftcms\/aws-s3","remoteId":"GHSA-hwj7-4vgc-j3v9","title":"Amazon S3 for Craft CMS has an Information Disclosure vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-hwj7-4vgc-j3v9","cve":"CVE-2026-32265","affectedVersions":"\u003E=2.0.2,\u003C=2.2.4","source":"GitHub","reportedAt":"2026-03-16 18:13:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hwj7-4vgc-j3v9"}]}],"craftcms\/google-cloud":[{"advisoryId":"PKSA-36bt-9p2f-mcy8","packageName":"craftcms\/google-cloud","remoteId":"GHSA-67cr-jmh8-4jpq","title":"Google Cloud Storage for Craft CMS has an Information Disclosure Vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-67cr-jmh8-4jpq","cve":"CVE-2026-32266","affectedVersions":"\u003E=2.0.0-beta.1,\u003C=2.2.0","source":"GitHub","reportedAt":"2026-03-16 18:14:23","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-67cr-jmh8-4jpq"}]}],"simplesamlphp\/xml-security":[{"advisoryId":"PKSA-sxbn-dpg6-6ng9","packageName":"simplesamlphp\/xml-security","remoteId":"GHSA-r353-4845-pr5p","title":"simplesamlphp\/xml-security: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption","link":"https:\/\/github.com\/advisories\/GHSA-r353-4845-pr5p","cve":"CVE-2026-32600","affectedVersions":"\u003C1.13.9|\u003E=2.0.0,\u003C2.3.1","source":"GitHub","reportedAt":"2026-03-13 20:44:21","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r353-4845-pr5p"}]}],"robrichards\/xmlseclibs":[{"advisoryId":"PKSA-pr5h-1dpm-9x4k","packageName":"robrichards\/xmlseclibs","remoteId":"GHSA-4v26-v6cg-g6f9","title":"xmlseclibs: Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption","link":"https:\/\/github.com\/advisories\/GHSA-4v26-v6cg-g6f9","cve":"CVE-2026-32313","affectedVersions":"\u003C3.1.5","source":"GitHub","reportedAt":"2026-03-13 20:04:21","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4v26-v6cg-g6f9"}]},{"advisoryId":"PKSA-pcdf-qvqm-w4tv","packageName":"robrichards\/xmlseclibs","remoteId":"GHSA-c4cc-x928-vjw9","title":"robrichards\/xmlseclibs has an Libxml2 Canonicalization error which can bypass Digest\/Signature validation","link":"https:\/\/github.com\/advisories\/GHSA-c4cc-x928-vjw9","cve":"CVE-2025-66578","affectedVersions":"\u003C=3.1.3","source":"GitHub","reportedAt":"2025-12-08 17:57:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c4cc-x928-vjw9"}]}],"winter\/wn-backend-module":[{"advisoryId":"PKSA-4n8n-yrbw-13gr","packageName":"winter\/wn-backend-module","remoteId":"GHSA-pgpf-m8m4-6cg6","title":"Winter vulnerable to privilege escalation by authenticated backend users","link":"https:\/\/github.com\/advisories\/GHSA-pgpf-m8m4-6cg6","cve":"CVE-2026-27591","affectedVersions":"\u003C1.0.477|\u003E=1.1.0,\u003C1.1.12|\u003E=1.2.0,\u003C1.2.12","source":"GitHub","reportedAt":"2026-03-12 14:07:39","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-pgpf-m8m4-6cg6"}]}],"limesurvey\/limesurvey":[{"advisoryId":"PKSA-g7yy-kkwv-8pkt","packageName":"limesurvey\/limesurvey","remoteId":"GHSA-rccq-2fxq-7x3h","title":"LimeSurvey is vulnerable to SQL injection","link":"https:\/\/github.com\/advisories\/GHSA-rccq-2fxq-7x3h","cve":"CVE-2025-56421","affectedVersions":"\u003C6.15.4","source":"GitHub","reportedAt":"2026-03-10 18:31:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-rccq-2fxq-7x3h"}]}],"wpmetabox\/meta-box":[{"advisoryId":"PKSA-s98v-q9gv-s2bz","packageName":"wpmetabox\/meta-box","remoteId":"GHSA-m4q3-832v-44j6","title":"Meta Box Plugin for WordPress: Authenticated (Contributor+) Arbitrary File Deletion via ajax_delete_file","link":"https:\/\/github.com\/advisories\/GHSA-m4q3-832v-44j6","cve":"CVE-2025-14675","affectedVersions":"\u003C5.11.2","source":"GitHub","reportedAt":"2026-03-07 09:30:14","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-m4q3-832v-44j6"}]}],"flarum\/nicknames":[{"advisoryId":"PKSA-661s-dgrr-6b19","packageName":"flarum\/nicknames","remoteId":"GHSA-3c4m-j3g4-hh25","title":"flarum\/nicknames extension has display name injection in notification emails (autolink \u0026 markdown)","link":"https:\/\/github.com\/advisories\/GHSA-3c4m-j3g4-hh25","cve":"CVE-2026-30913","affectedVersions":"\u003C1.8.3","source":"GitHub","reportedAt":"2026-03-10 00:56:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3c4m-j3g4-hh25"}]}],"ec-cube\/ec-cube":[{"advisoryId":"PKSA-8syj-s477-kgpz","packageName":"ec-cube\/ec-cube","remoteId":"GHSA-7rhv-h82h-vpjh","title":"EC-CUBE has a Vulnerability that Allows MFA Bypass in the Administrative Interface","link":"https:\/\/github.com\/advisories\/GHSA-7rhv-h82h-vpjh","cve":null,"affectedVersions":"\u003E=4.1.0,\u003C=4.3.1","source":"GitHub","reportedAt":"2026-03-05 21:14:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7rhv-h82h-vpjh"}]}],"leantime\/leantime":[{"advisoryId":"PKSA-xts7-ftgj-xm47","packageName":"leantime\/leantime","remoteId":"GHSA-qrfh-cc86-vc8c","title":"Leantime has HTML injection through firstname and lastname fields","link":"https:\/\/github.com\/advisories\/GHSA-qrfh-cc86-vc8c","cve":null,"affectedVersions":"\u003C3.3.0","source":"GitHub","reportedAt":"2026-03-05 18:05:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qrfh-cc86-vc8c"}]}],"idno\/known":[{"advisoryId":"PKSA-tjwq-xm4h-4hs1","packageName":"idno\/known","remoteId":"GHSA-fcrh-fqxh-6fx6","title":"Idno Vulnerable to Unauthenticated SSRF via URL Unfurl Endpoint","link":"https:\/\/github.com\/advisories\/GHSA-fcrh-fqxh-6fx6","cve":"CVE-2026-28508","affectedVersions":"\u003C=1.6.3","source":"GitHub","reportedAt":"2026-03-02 21:24:37","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-fcrh-fqxh-6fx6"}]},{"advisoryId":"PKSA-vr9w-vsjd-wjfy","packageName":"idno\/known","remoteId":"GHSA-37j7-56xc-c468","title":"Idno Vulnerable to Remote Code Execution via Chained Import File Write and Template Path Traversal","link":"https:\/\/github.com\/advisories\/GHSA-37j7-56xc-c468","cve":"CVE-2026-28507","affectedVersions":"\u003C1.6.4","source":"GitHub","reportedAt":"2026-03-02 21:26:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-37j7-56xc-c468"}]},{"advisoryId":"PKSA-mcts-z5dp-tgk3","packageName":"idno\/known","remoteId":"GHSA-78wq-6gcv-w28r","title":"Known affected by Account Takeover via Password Reset Token Leakage","link":"https:\/\/github.com\/advisories\/GHSA-78wq-6gcv-w28r","cve":"CVE-2026-26273","affectedVersions":"\u003C=1.6.2","source":"GitHub","reportedAt":"2026-02-13 22:49:27","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-78wq-6gcv-w28r"}]}],"typicms\/core":[{"advisoryId":"PKSA-4g4t-fqh1-f8mt","packageName":"typicms\/core","remoteId":"GHSA-xfvg-8v67-j7wp","title":"TypiCMS Core has Stored Cross-Site Scripting (XSS) via SVG File Upload","link":"https:\/\/github.com\/advisories\/GHSA-xfvg-8v67-j7wp","cve":"CVE-2026-27621","affectedVersions":"\u003C12.0.5|\u003E=13.0.0,\u003C13.0.9|\u003E=14.0.0,\u003C14.0.27|\u003E=15.0.0,\u003C15.0.29|\u003E=16.0.0,\u003C16.1.7","source":"GitHub","reportedAt":"2026-02-25 16:06:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xfvg-8v67-j7wp"}]}],"moodle\/moodle":[{"advisoryId":"PKSA-d5fc-2jw8-sm45","packageName":"moodle\/moodle","remoteId":"GHSA-cg8j-5cr2-568q","title":"Moodle TeX formula editor is vulnerable to DoS through lack of execution time limits","link":"https:\/\/github.com\/advisories\/GHSA-cg8j-5cr2-568q","cve":"CVE-2026-26047","affectedVersions":"\u003C4.5.9|\u003E=5.0.0-beta,\u003C5.0.5|\u003E=5.1.0-beta,\u003C5.1.2","source":"GitHub","reportedAt":"2026-02-21 06:30:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cg8j-5cr2-568q"}]},{"advisoryId":"PKSA-fh6z-73jv-qwnd","packageName":"moodle\/moodle","remoteId":"GHSA-ggxq-2mg9-8966","title":"Moodle has a Remote Code Execution risk via file restore","link":"https:\/\/github.com\/advisories\/GHSA-ggxq-2mg9-8966","cve":"CVE-2026-26045","affectedVersions":"\u003C4.5.9|\u003E=5.0.0-beta,\u003C5.0.5|\u003E=5.1.0-beta,\u003C5.1.2","source":"GitHub","reportedAt":"2026-02-21 06:30:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-ggxq-2mg9-8966"}]},{"advisoryId":"PKSA-2j87-1r5d-n19k","packageName":"moodle\/moodle","remoteId":"GHSA-vwhw-vp9v-q9c9","title":"Moodle vulnerable to Cross-site Scripting","link":"https:\/\/github.com\/advisories\/GHSA-vwhw-vp9v-q9c9","cve":"CVE-2025-67855","affectedVersions":"\u003E=5.1.0-beta,\u003C5.1.1|\u003E=5.0.0-beta,\u003C5.0.4|\u003E=4.5.0-beta,\u003C4.5.8|\u003E=4.4.0-beta,\u003C4.4.12|\u003C4.1.22","source":"GitHub","reportedAt":"2026-02-03 12:30:29","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vwhw-vp9v-q9c9"}]},{"advisoryId":"PKSA-dz6d-pdgm-m472","packageName":"moodle\/moodle","remoteId":"GHSA-5cx4-w4fh-fr57","title":"Moodle Affected by Improper Restriction of Excessive Authentication Attempts","link":"https:\/\/github.com\/advisories\/GHSA-5cx4-w4fh-fr57","cve":"CVE-2025-67853","affectedVersions":"\u003E=5.1.0-beta,\u003C5.1.1|\u003E=5.0.0-beta,\u003C5.0.4|\u003E=4.5.0-beta,\u003C4.5.8|\u003E=4.4.0-beta,\u003C4.4.12|\u003C4.1.22","source":"GitHub","reportedAt":"2026-02-03 12:30:29","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5cx4-w4fh-fr57"}]},{"advisoryId":"PKSA-d2w7-632f-6wy9","packageName":"moodle\/moodle","remoteId":"GHSA-j5jv-w5cw-j9ff","title":"Moodle authentication bypass vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-j5jv-w5cw-j9ff","cve":"CVE-2025-67848","affectedVersions":"\u003E=5.1.0-beta,\u003C5.1.1|\u003E=5.0.0-beta,\u003C5.0.4|\u003E=4.5.0-beta,\u003C4.5.8|\u003E=4.4.0-beta,\u003C4.4.12|\u003C4.1.22","source":"GitHub","reportedAt":"2026-02-03 12:30:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j5jv-w5cw-j9ff"}]},{"advisoryId":"PKSA-xyd9-vffd-bswp","packageName":"moodle\/moodle","remoteId":"GHSA-hcm6-q6pc-xfhm","title":"Moodle has an authorization logic flaw","link":"https:\/\/github.com\/advisories\/GHSA-hcm6-q6pc-xfhm","cve":"CVE-2025-67856","affectedVersions":"\u003E=5.1.0-beta,\u003C5.1.1|\u003E=5.0.0-beta,\u003C5.0.4|\u003E=4.5.0-beta,\u003C4.5.8|\u003E=4.4.0-beta,\u003C4.4.12|\u003C4.1.22","source":"GitHub","reportedAt":"2026-02-03 12:30:29","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hcm6-q6pc-xfhm"}]},{"advisoryId":"PKSA-2wxn-vc4s-1dkz","packageName":"moodle\/moodle","remoteId":"GHSA-8jrv-wx83-w3xj","title":"Moodle Inserts Sensitive Information Into Sent Data","link":"https:\/\/github.com\/advisories\/GHSA-8jrv-wx83-w3xj","cve":"CVE-2025-67857","affectedVersions":"\u003E=5.1.0-beta,\u003C5.1.1|\u003E=5.0.0-beta,\u003C5.0.4|\u003E=4.5.0-beta,\u003C4.5.8|\u003E=4.4.0-beta,\u003C4.4.12|\u003C4.1.22","source":"GitHub","reportedAt":"2026-02-03 12:30:29","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8jrv-wx83-w3xj"}]},{"advisoryId":"PKSA-qhxz-6rtn-nzx7","packageName":"moodle\/moodle","remoteId":"GHSA-mhf6-pp52-8wqj","title":"Moodle Cross-site Scripting (XSS) vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-mhf6-pp52-8wqj","cve":"CVE-2025-67849","affectedVersions":"\u003E=5.1.0-beta,\u003C5.1.1|\u003E=5.0.0-beta,\u003C5.0.4|\u003E=4.5.0-beta,\u003C4.5.8|\u003E=4.4.0-beta,\u003C4.4.12|\u003C4.1.22","source":"GitHub","reportedAt":"2026-02-03 12:30:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mhf6-pp52-8wqj"}]},{"advisoryId":"PKSA-3g2p-wb92-w82j","packageName":"moodle\/moodle","remoteId":"GHSA-6mmv-f6c6-v6q8","title":"Moodle vulnerable to Cross-site Scripting","link":"https:\/\/github.com\/advisories\/GHSA-6mmv-f6c6-v6q8","cve":"CVE-2025-67850","affectedVersions":"\u003E=5.1.0-beta,\u003C5.1.1|\u003E=5.0.0-beta,\u003C5.0.4|\u003E=4.5.0-beta,\u003C4.5.8|\u003E=4.4.0-beta,\u003C4.4.12|\u003C4.1.22","source":"GitHub","reportedAt":"2026-02-03 12:30:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6mmv-f6c6-v6q8"}]},{"advisoryId":"PKSA-213q-p3b4-49zj","packageName":"moodle\/moodle","remoteId":"GHSA-qfh6-h7j6-fvjv","title":"Moodle formula injection vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-qfh6-h7j6-fvjv","cve":"CVE-2025-67851","affectedVersions":"\u003E=5.1.0-beta,\u003C5.1.1|\u003E=5.0.0-beta,\u003C5.0.4|\u003E=4.5.0-beta,\u003C4.5.8|\u003E=4.4.0-beta,\u003C4.4.12|\u003C4.1.22","source":"GitHub","reportedAt":"2026-02-03 12:30:28","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qfh6-h7j6-fvjv"}]},{"advisoryId":"PKSA-prf5-y5p2-ykmg","packageName":"moodle\/moodle","remoteId":"GHSA-qv78-6gpp-hm68","title":"Moodle Open Redirect vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-qv78-6gpp-hm68","cve":"CVE-2025-67852","affectedVersions":"\u003E=5.1.0-beta,\u003C5.1.1|\u003E=5.0.0-beta,\u003C5.0.4|\u003E=4.5.0-beta,\u003C4.5.8|\u003E=4.4.0-beta,\u003C4.4.12|\u003C4.1.22","source":"GitHub","reportedAt":"2026-02-03 12:30:29","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-qv78-6gpp-hm68"}]},{"advisoryId":"PKSA-41tm-5zq3-pfdc","packageName":"moodle\/moodle","remoteId":"GHSA-xvmh-25jw-gmmm","title":"Moodle affected by a code injection vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-xvmh-25jw-gmmm","cve":"CVE-2025-67847","affectedVersions":"\u003C4.1.22|\u003E=4.2.0-beta,\u003C4.4.12|\u003E=4.5.0-beta,\u003C4.5.8|\u003E=5.0.0-beta,\u003C5.0.4|\u003E=5.1.0-beta,\u003C5.1.1","source":"GitHub","reportedAt":"2026-01-23 06:31:25","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xvmh-25jw-gmmm"}]},{"advisoryId":"PKSA-c2fh-btt6-h7g6","packageName":"moodle\/moodle","remoteId":"GHSA-m58f-9pvv-8mp2","title":"Moodle vulnerable to brute-force password guesses","link":"https:\/\/github.com\/advisories\/GHSA-m58f-9pvv-8mp2","cve":"CVE-2025-62399","affectedVersions":"\u003C4.1.21|\u003E=4.2.0-beta,\u003C4.4.11|\u003E=4.5.0-beta,\u003C4.5.7|\u003E=5.0.0-beta,\u003C5.0.3","source":"GitHub","reportedAt":"2025-10-23 12:31:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-m58f-9pvv-8mp2"}]},{"advisoryId":"PKSA-s9t3-1mh7-mgx2","packageName":"moodle\/moodle","remoteId":"GHSA-c5cj-xp43-qcc3","title":"Moodle\u0027s error handling leads to sensitive information disclosure","link":"https:\/\/github.com\/advisories\/GHSA-c5cj-xp43-qcc3","cve":"CVE-2025-62396","affectedVersions":"\u003E=4.5.0-beta,\u003C4.5.7|\u003E=5.0.0-beta,\u003C5.0.3","source":"GitHub","reportedAt":"2025-10-23 12:31:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c5cj-xp43-qcc3"}]},{"advisoryId":"PKSA-2154-mt94-234t","packageName":"moodle\/moodle","remoteId":"GHSA-w29j-8phw-ffjf","title":"Moodle has a time restriction bypass","link":"https:\/\/github.com\/advisories\/GHSA-w29j-8phw-ffjf","cve":"CVE-2025-62401","affectedVersions":"\u003C4.1.21|\u003E=4.2.0-beta,\u003C4.4.11|\u003E=4.5.0-beta,\u003C4.5.7|\u003E=5.0.0-beta,\u003C5.0.3","source":"GitHub","reportedAt":"2025-10-23 12:31:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w29j-8phw-ffjf"}]},{"advisoryId":"PKSA-7bbm-2bcq-7hnc","packageName":"moodle\/moodle","remoteId":"GHSA-422v-w6c5-vq42","title":"Moodle exposed the names of hidden groups to users","link":"https:\/\/github.com\/advisories\/GHSA-422v-w6c5-vq42","cve":"CVE-2025-62400","affectedVersions":"\u003C4.1.21|\u003E=4.2.0-beta,\u003C4.4.11|\u003E=4.5.0-beta,\u003C4.5.7|\u003E=5.0.0-beta,\u003C5.0.3","source":"GitHub","reportedAt":"2025-10-23 12:31:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-422v-w6c5-vq42"}]},{"advisoryId":"PKSA-618v-fp6m-xcm3","packageName":"moodle\/moodle","remoteId":"GHSA-8fcv-4qp9-pg32","title":"Moodle sends quiz-related messages to inactive\/suspended users","link":"https:\/\/github.com\/advisories\/GHSA-8fcv-4qp9-pg32","cve":"CVE-2025-62394","affectedVersions":"\u003E=4.5.0-beta,\u003C4.5.7|\u003E=5.0.0-beta,\u003C5.0.3","source":"GitHub","reportedAt":"2025-10-23 12:31:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8fcv-4qp9-pg32"}]},{"advisoryId":"PKSA-t4p3-ktd7-6hxq","packageName":"moodle\/moodle","remoteId":"GHSA-rjcm-7v2p-9265","title":"Moodle course access permissions are not properly checked in course_output_fragment_course_overview","link":"https:\/\/github.com\/advisories\/GHSA-rjcm-7v2p-9265","cve":"CVE-2025-62393","affectedVersions":"\u003E=5.0.0-beta,\u003C5.0.3","source":"GitHub","reportedAt":"2025-10-23 12:31:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rjcm-7v2p-9265"}]},{"advisoryId":"PKSA-7pfx-c6p7-vmng","packageName":"moodle\/moodle","remoteId":"GHSA-25wf-7x6c-wmpf","title":"Moodle does not properly enforce MFA","link":"https:\/\/github.com\/advisories\/GHSA-25wf-7x6c-wmpf","cve":"CVE-2025-62398","affectedVersions":"\u003E=4.4.0-beta,\u003C4.4.11|\u003E=4.5.0-beta,\u003C4.5.7|\u003E=5.0.0-beta,\u003C5.0.3","source":"GitHub","reportedAt":"2025-10-23 12:31:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-25wf-7x6c-wmpf"}]}],"zumba\/json-serializer":[{"advisoryId":"PKSA-zhg7-9xn9-qv5j","packageName":"zumba\/json-serializer","remoteId":"GHSA-v7m3-fpcr-h7m2","title":"Zumba Json Serializer has a potential PHP Object Injection via Unrestricted @type in unserialize()","link":"https:\/\/github.com\/advisories\/GHSA-v7m3-fpcr-h7m2","cve":"CVE-2026-27206","affectedVersions":"\u003C3.2.3","source":"GitHub","reportedAt":"2026-02-19 22:05:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v7m3-fpcr-h7m2"}]}],"getformwork\/formwork":[{"advisoryId":"PKSA-s7gr-pq9f-f16r","packageName":"getformwork\/formwork","remoteId":"GHSA-34p4-7w83-35g2","title":"Formwork Improperly Managed Privileges in User creation","link":"https:\/\/github.com\/advisories\/GHSA-34p4-7w83-35g2","cve":"CVE-2026-27198","affectedVersions":"\u003E=2.0.0,\u003C=2.3.3","source":"GitHub","reportedAt":"2026-02-19 20:31:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-34p4-7w83-35g2"}]},{"advisoryId":"PKSA-rmpr-1pwg-drvq","packageName":"getformwork\/formwork","remoteId":"GHSA-7j46-f57w-76pj","title":"Formwork CMS has Stored Cross-Site Scripting Vulnerebility in Blog Tags","link":"https:\/\/github.com\/advisories\/GHSA-7j46-f57w-76pj","cve":"CVE-2025-65956","affectedVersions":"\u003C2.2.0","source":"GitHub","reportedAt":"2025-11-24 22:13:32","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7j46-f57w-76pj"}]}],"firebase\/php-jwt":[{"advisoryId":"PKSA-y2cr-5h3j-g3ys","packageName":"firebase\/php-jwt","remoteId":"GHSA-2x45-7fc3-mxwq","title":"php-jwt contains weak encryption","link":"https:\/\/github.com\/advisories\/GHSA-2x45-7fc3-mxwq","cve":"CVE-2025-45769","affectedVersions":"\u003C7.0.0","source":"GitHub","reportedAt":"2025-07-31 21:31:53","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-2x45-7fc3-mxwq"}]}],"directorytree\/imapengine":[{"advisoryId":"PKSA-r9pf-9w4d-dyr5","packageName":"directorytree\/imapengine","remoteId":"GHSA-rfq9-4wcm-64gh","title":"ImapEngine affected by command injection via the ID command parameters","link":"https:\/\/github.com\/advisories\/GHSA-rfq9-4wcm-64gh","cve":"CVE-2026-2469","affectedVersions":"\u003C1.22.3","source":"GitHub","reportedAt":"2026-02-14 06:30:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rfq9-4wcm-64gh"}]}],"cesargb\/laravel-magiclink":[{"advisoryId":"PKSA-n3xg-c9dz-5k25","packageName":"cesargb\/laravel-magiclink","remoteId":"GHSA-r33w-fg8j-9c94","title":"MagicLink: Insecure Deserialization of MagicLink Actions Leads to Remote Code Execution","link":"https:\/\/github.com\/advisories\/GHSA-r33w-fg8j-9c94","cve":null,"affectedVersions":"\u003E=2.0.0,\u003C2.25.1","source":"GitHub","reportedAt":"2026-02-12 22:11:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r33w-fg8j-9c94"}]}],"phraseanet\/phraseanet":[{"advisoryId":"PKSA-r347-9jgf-7h41","packageName":"phraseanet\/phraseanet","remoteId":"GHSA-gcpq-mrgg-v5f3","title":"Phraseanet vulnerable to stored cross-site scripting through crafted file names","link":"https:\/\/github.com\/advisories\/GHSA-gcpq-mrgg-v5f3","cve":"CVE-2018-25157","affectedVersions":"=4.0.3","source":"GitHub","reportedAt":"2026-02-11 15:30:27","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gcpq-mrgg-v5f3"}]}],"frosh\/adminer-platform":[{"advisoryId":"PKSA-9n8q-v8pv-hdyq","packageName":"frosh\/adminer-platform","remoteId":"GHSA-f339-246p-wwjp","title":"FroshAdminer Adminer UI is accessible without admin session","link":"https:\/\/github.com\/advisories\/GHSA-f339-246p-wwjp","cve":"CVE-2026-25878","affectedVersions":"\u003C2.2.1","source":"GitHub","reportedAt":"2026-02-10 00:22:05","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f339-246p-wwjp"}]}],"vrana\/adminer":[{"advisoryId":"PKSA-5hbx-ykrq-c4p8","packageName":"vrana\/adminer","remoteId":"GHSA-q4f2-39gr-45jh","title":"Adminer has an Unauthenticated Persistent DoS via Array Injection in ?script=version Endpoint","link":"https:\/\/github.com\/advisories\/GHSA-q4f2-39gr-45jh","cve":"CVE-2026-25892","affectedVersions":"\u003E=4.6.2,\u003C5.4.2","source":"GitHub","reportedAt":"2026-02-10 00:25:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-q4f2-39gr-45jh"}]}],"amphp\/http-server":[{"advisoryId":"PKSA-n4yt-trn1-vc6d","packageName":"amphp\/http-server","remoteId":"GHSA-8grv-jq2g-cfhw","title":"amphp\/http-server affected by HTTP\/2 DDoS vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-8grv-jq2g-cfhw","cve":null,"affectedVersions":"\u003E=2.0.0-rc1,\u003C2.1.10|\u003E=3.0.0-beta.1,\u003C3.4.4","source":"GitHub","reportedAt":"2026-02-10 00:25:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8grv-jq2g-cfhw"}]},{"advisoryId":"PKSA-32dn-k7sj-x6b5","packageName":"amphp\/http-server","remoteId":"amphp\/http-server\/CVE-2025-8671.yaml","title":"Denial of Service via \u0022MadeYouReset\u0022 vulnerability","link":"https:\/\/github.com\/amphp\/http-server\/security\/advisories\/GHSA-8grv-jq2g-cfhw","cve":"CVE-2025-8671","affectedVersions":"\u003E=3.0.0-beta1,\u003C3.4.4|\u003E=2.0.0-rc1,\u003C2.1.10","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-02-08 22:45:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"amphp\/http-server\/CVE-2025-8671.yaml"}]}],"craftcms\/craft":[{"advisoryId":"PKSA-jd1d-xg2h-yr6f","packageName":"craftcms\/craft","remoteId":"GHSA-96pq-hxpw-rgh8","title":"Craft CMS: save_images_Asset graphql mutation can be abused to exfiltrate AWS credentials of underlying host","link":"https:\/\/github.com\/advisories\/GHSA-96pq-hxpw-rgh8","cve":"CVE-2026-25492","affectedVersions":"\u003E=3.5.0,\u003C=4.16.17|\u003E=5.0.0-RC1,\u003C=5.8.21","source":"GitHub","reportedAt":"2026-02-09 20:35:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-96pq-hxpw-rgh8"}]}],"mineadmin\/mineadmin":[{"advisoryId":"PKSA-z2mv-nfpy-g9jk","packageName":"mineadmin\/mineadmin","remoteId":"GHSA-23hh-2f47-3p4h","title":"MineAdmin has Incorrect Privilege Assignment","link":"https:\/\/github.com\/advisories\/GHSA-23hh-2f47-3p4h","cve":"CVE-2026-1193","affectedVersions":"\u003E=1.0.0,\u003C=2.0.3","source":"GitHub","reportedAt":"2026-01-20 00:30:27","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-23hh-2f47-3p4h"}]},{"advisoryId":"PKSA-rjjn-j2gd-cv48","packageName":"mineadmin\/mineadmin","remoteId":"GHSA-7f7m-83r3-p644","title":"MineAdmin May Expose Sensitive Information to an Unauthorized Actor","link":"https:\/\/github.com\/advisories\/GHSA-7f7m-83r3-p644","cve":"CVE-2026-1194","affectedVersions":"\u003E=1.0.0,\u003C=2.0.3","source":"GitHub","reportedAt":"2026-01-20 00:30:27","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7f7m-83r3-p644"}]},{"advisoryId":"PKSA-k6s2-6c8x-nwct","packageName":"mineadmin\/mineadmin","remoteId":"GHSA-wq8p-q8cq-94w5","title":"MineAdmin May Expose Sensitive Information to an Unauthorized Actor","link":"https:\/\/github.com\/advisories\/GHSA-wq8p-q8cq-94w5","cve":"CVE-2026-1196","affectedVersions":"\u003E=1.0.0,\u003C=2.0.3","source":"GitHub","reportedAt":"2026-01-20 03:30:28","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-wq8p-q8cq-94w5"}]},{"advisoryId":"PKSA-9946-kzvf-j5bc","packageName":"mineadmin\/mineadmin","remoteId":"GHSA-43rr-x62x-q96w","title":"MineAdmin improperly refreshes tokens","link":"https:\/\/github.com\/advisories\/GHSA-43rr-x62x-q96w","cve":"CVE-2026-1195","affectedVersions":"\u003E=1.0.0,\u003C=2.0.3","source":"GitHub","reportedAt":"2026-01-20 03:30:28","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-43rr-x62x-q96w"}]},{"advisoryId":"PKSA-g1g3-pmx2-vy1t","packageName":"mineadmin\/mineadmin","remoteId":"GHSA-x6mh-4w8x-p34v","title":"MineAdmin has an insecure default password","link":"https:\/\/github.com\/advisories\/GHSA-x6mh-4w8x-p34v","cve":"CVE-2025-65854","affectedVersions":"\u003C=3.0.9","source":"GitHub","reportedAt":"2025-12-12 18:30:35","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-x6mh-4w8x-p34v"}]}],"microweber\/microweber":[{"advisoryId":"PKSA-6k48-bbzp-nbmm","packageName":"microweber\/microweber","remoteId":"GHSA-5jg5-xqfw-rv92","title":"Microweber has a Cross-site Scripting vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-5jg5-xqfw-rv92","cve":"CVE-2025-70791","affectedVersions":"\u003C2.0.20","source":"GitHub","reportedAt":"2026-02-05 18:30:32","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-5jg5-xqfw-rv92"}]},{"advisoryId":"PKSA-s4vd-hp6c-hhgj","packageName":"microweber\/microweber","remoteId":"GHSA-6w5w-jx4x-vjvw","title":"Microweber Cross-site Scripting vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-6w5w-jx4x-vjvw","cve":"CVE-2025-70792","affectedVersions":"\u003C2.0.20","source":"GitHub","reportedAt":"2026-02-05 18:30:32","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-6w5w-jx4x-vjvw"}]}],"winter\/wn-cms-module":[{"advisoryId":"PKSA-dsmp-sffr-jt46","packageName":"winter\/wn-cms-module","remoteId":"GHSA-m7gw-rffq-rxjm","title":"Winter CMS has Stored Cross-site Scripting (XSS) in Asset Manager","link":"https:\/\/github.com\/advisories\/GHSA-m7gw-rffq-rxjm","cve":"CVE-2026-22254","affectedVersions":"\u003C=1.2.9","source":"GitHub","reportedAt":"2026-02-04 21:32:39","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-m7gw-rffq-rxjm"}]}],"intelliants\/subrion":[{"advisoryId":"PKSA-gfy2-s1qm-q2qs","packageName":"intelliants\/subrion","remoteId":"GHSA-9jjm-mc56-3qxv","title":"Subrion CMS vulnerable to cross-site scripting","link":"https:\/\/github.com\/advisories\/GHSA-9jjm-mc56-3qxv","cve":"CVE-2025-70958","affectedVersions":"\u003C=4.2.1","source":"GitHub","reportedAt":"2026-02-03 00:30:18","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9jjm-mc56-3qxv"}]}],"craftcms\/composer":[{"advisoryId":"PKSA-25k7-4kst-zf99","packageName":"craftcms\/composer","remoteId":"GHSA-w8gw-qm8p-j9j3","title":"Craft Commerce has Stored XSS in Shipping Categories (Name \u0026 Description) Fields Leading to Potential Privilege Escalation","link":"https:\/\/github.com\/advisories\/GHSA-w8gw-qm8p-j9j3","cve":"CVE-2026-25485","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.10.0|\u003E=5.0.0-RC1,\u003C=5.5.1","source":"GitHub","reportedAt":"2026-02-02 22:45:03","composerRepository":null,"severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w8gw-qm8p-j9j3"}]}],"billz\/raspap-webgui":[{"advisoryId":"PKSA-vf1y-yyyt-3znd","packageName":"billz\/raspap-webgui","remoteId":"GHSA-4wwf-f7w3-94f5","title":"RaspAP raspap-webgui contains an OS Command Injection vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-4wwf-f7w3-94f5","cve":"CVE-2026-24788","affectedVersions":"\u003C3.3.6","source":"GitHub","reportedAt":"2026-02-02 06:30:52","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4wwf-f7w3-94f5"}]}],"phppgadmin\/phppgadmin":[{"advisoryId":"PKSA-gttq-2dn3-2tnq","packageName":"phppgadmin\/phppgadmin","remoteId":"GHSA-86gh-c8r8-xwhq","title":"phpPgAdmin contains a remote command execution vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-86gh-c8r8-xwhq","cve":"CVE-2021-47853","affectedVersions":"\u003C=7.13.0","source":"GitHub","reportedAt":"2026-01-21 18:30:31","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-86gh-c8r8-xwhq"}]},{"advisoryId":"PKSA-gwrf-4x3w-rx4j","packageName":"phppgadmin\/phppgadmin","remoteId":"GHSA-927w-vq5c-8gc3","title":"phppgadmin contains a SQL injection vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-927w-vq5c-8gc3","cve":"CVE-2025-60797","affectedVersions":"\u003C=7.13.0","source":"GitHub","reportedAt":"2025-11-20 15:30:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-927w-vq5c-8gc3"}]},{"advisoryId":"PKSA-ysfn-hbt6-c5p5","packageName":"phppgadmin\/phppgadmin","remoteId":"GHSA-g6xh-wrpf-v6j6","title":"phppgadmin contains a SQL injection vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-g6xh-wrpf-v6j6","cve":"CVE-2025-60798","affectedVersions":"\u003C=7.13.0","source":"GitHub","reportedAt":"2025-11-20 15:30:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g6xh-wrpf-v6j6"}]},{"advisoryId":"PKSA-zydw-29v8-w73t","packageName":"phppgadmin\/phppgadmin","remoteId":"GHSA-r63p-v37q-g74c","title":"phppgadmin contains an incorrect access control vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-r63p-v37q-g74c","cve":"CVE-2025-60799","affectedVersions":"\u003C=7.13.0","source":"GitHub","reportedAt":"2025-11-20 15:30:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r63p-v37q-g74c"}]},{"advisoryId":"PKSA-8zgg-qmxc-jbhq","packageName":"phppgadmin\/phppgadmin","remoteId":"GHSA-h369-cpjj-qfff","title":"phppgadmin vulnerable to Cross-site Scripting","link":"https:\/\/github.com\/advisories\/GHSA-h369-cpjj-qfff","cve":"CVE-2025-60796","affectedVersions":"\u003C=7.13.0","source":"GitHub","reportedAt":"2025-11-20 15:30:23","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-h369-cpjj-qfff"}]}],"psy\/psysh":[{"advisoryId":"PKSA-4s4z-t146-6123","packageName":"psy\/psysh","remoteId":"GHSA-4486-gxhx-5mg7","title":"PsySH has Local Privilege Escalation via CWD .psysh.php auto-load","link":"https:\/\/github.com\/advisories\/GHSA-4486-gxhx-5mg7","cve":"CVE-2026-25129","affectedVersions":"\u003C=0.11.22|\u003E=0.12.0,\u003C=0.12.18","source":"GitHub","reportedAt":"2026-01-30 21:28:44","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4486-gxhx-5mg7"}]}],"symfony\/process":[{"advisoryId":"PKSA-rkkf-636k-qjb3","packageName":"symfony\/process","remoteId":"GHSA-r39x-jcww-82v6","title":"Symfony\u0027s incorrect argument escaping under MSYS2\/Git Bash can lead to destructive file operations on Windows","link":"https:\/\/github.com\/advisories\/GHSA-r39x-jcww-82v6","cve":"CVE-2026-24739","affectedVersions":"\u003E=8.0,\u003C8.0.5|\u003E=7.4,\u003C7.4.5|\u003E=7.3,\u003C7.3.11|\u003E=6.4,\u003C6.4.33|\u003C5.4.51","source":"GitHub","reportedAt":"2026-01-28 21:28:10","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r39x-jcww-82v6"}]}],"lavalite\/cms":[{"advisoryId":"PKSA-2q69-6cxz-6fkx","packageName":"lavalite\/cms","remoteId":"GHSA-w7rq-fgx4-4xcm","title":"LavaLite CMS affected by a stored cross-site scripting vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-w7rq-fgx4-4xcm","cve":"CVE-2025-71177","affectedVersions":"\u003C=10.1.0","source":"GitHub","reportedAt":"2026-01-23 18:31:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w7rq-fgx4-4xcm"}]}],"solspace\/craft-freeform":[{"advisoryId":"PKSA-xc3n-vk9q-z5t5","packageName":"solspace\/craft-freeform","remoteId":"GHSA-jp3q-wwp3-pwv9","title":"Freeform Craft Plugin CP UI (builder\/integrations) has Stored Cross-Site Scripting (XSS) issue","link":"https:\/\/github.com\/advisories\/GHSA-jp3q-wwp3-pwv9","cve":"CVE-2026-26188","affectedVersions":"\u003E=5.0.0,\u003C=5.14.6","source":"GitHub","reportedAt":"2026-01-22 21:41:14","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-jp3q-wwp3-pwv9"}]},{"advisoryId":"PKSA-p441-f62y-b6vk","packageName":"solspace\/craft-freeform","remoteId":"GHSA-44jg-mv3h-wj6g","title":"solspace\/craft-freeform Vulnerable to XSS in `PhpSpreadsheet` HTML Writer Due to Unsanitized Styling Data","link":"https:\/\/github.com\/advisories\/GHSA-44jg-mv3h-wj6g","cve":null,"affectedVersions":"\u003C4.1.23","source":"GitHub","reportedAt":"2026-01-15 22:40:42","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-44jg-mv3h-wj6g"}]},{"advisoryId":"PKSA-59fn-718f-htt1","packageName":"solspace\/craft-freeform","remoteId":"GHSA-rwr8-xrpw-9qf5","title":"solspace\/craft-freeform Exposed to Known Axios Vulnerabilities via Precompiled Assets","link":"https:\/\/github.com\/advisories\/GHSA-rwr8-xrpw-9qf5","cve":null,"affectedVersions":"\u003E=5.0.0-beta.1,\u003C5.5.9|\u003C4.1.22","source":"GitHub","reportedAt":"2026-01-15 22:41:39","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-rwr8-xrpw-9qf5"}]},{"advisoryId":"PKSA-yj2s-d62t-kqt4","packageName":"solspace\/craft-freeform","remoteId":"GHSA-58q2-9x27-h2jm","title":"solspace\/craft-freeform Has a DoS Vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-58q2-9x27-h2jm","cve":null,"affectedVersions":"\u003C4.1.29","source":"GitHub","reportedAt":"2026-01-15 20:12:25","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-58q2-9x27-h2jm"}]}],"ph7software\/ph7builder":[{"advisoryId":"PKSA-96dq-msvg-t516","packageName":"ph7software\/ph7builder","remoteId":"GHSA-657c-wxg6-jmqv","title":"pH7-Social-Dating-CMS affected by a stored cross-site scripting (XSS) vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-657c-wxg6-jmqv","cve":"CVE-2025-63644","affectedVersions":"\u003C=17.9.1","source":"GitHub","reportedAt":"2026-01-14 18:31:37","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-657c-wxg6-jmqv"}]}],"laravel\/reverb":[{"advisoryId":"PKSA-rh3z-srf7-67z3","packageName":"laravel\/reverb","remoteId":"GHSA-m27r-m6rx-mhm4","title":"Laravel Redis Horizontal Scaling Insecure Deserialization","link":"https:\/\/github.com\/advisories\/GHSA-m27r-m6rx-mhm4","cve":"CVE-2026-23524","affectedVersions":"\u003C1.7.0","source":"GitHub","reportedAt":"2026-01-21 15:40:24","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-m27r-m6rx-mhm4"}]}],"livewire-filemanager\/filemanager":[{"advisoryId":"PKSA-kq11-2g4g-3ddq","packageName":"livewire-filemanager\/filemanager","remoteId":"GHSA-9g95-48c6-r778","title":"Livewire Filemanager does not restrict uploaded file types","link":"https:\/\/github.com\/advisories\/GHSA-9g95-48c6-r778","cve":"CVE-2025-14894","affectedVersions":"\u003C=1.0.4","source":"GitHub","reportedAt":"2026-01-16 15:31:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9g95-48c6-r778"}]}],"aimeos\/aimeos-laravel":[{"advisoryId":"PKSA-wnpp-jn4c-bhds","packageName":"aimeos\/aimeos-laravel","remoteId":"GHSA-hm9j-cgmm-2w36","title":"Aimeos contains a SQL injection vulnerability in the json api \u0027sort\u0027 parameter","link":"https:\/\/github.com\/advisories\/GHSA-hm9j-cgmm-2w36","cve":"CVE-2021-47763","affectedVersions":"=2021.10","source":"GitHub","reportedAt":"2026-01-15 18:31:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hm9j-cgmm-2w36"}]}],"alextselegidis\/easyappointments":[{"advisoryId":"PKSA-wm96-drjh-4138","packageName":"alextselegidis\/easyappointments","remoteId":"GHSA-54v4-4685-vwrj","title":"alextselegidis\/easyappointments is Vulnerable to CSRF Protection Bypass","link":"https:\/\/github.com\/advisories\/GHSA-54v4-4685-vwrj","cve":"CVE-2026-23622","affectedVersions":"\u003C=1.5.2","source":"GitHub","reportedAt":"2026-01-15 20:11:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-54v4-4685-vwrj"}]}],"pimcore\/web2print-tools-bundle":[{"advisoryId":"PKSA-qxkh-dcng-ghsj","packageName":"pimcore\/web2print-tools-bundle","remoteId":"GHSA-4wg4-p27p-5q2r","title":"Pimcore Web2Print Tools Bundle \u0022Favourite Output Channel Configuration\u0022 Missing Function Level Authorization","link":"https:\/\/github.com\/advisories\/GHSA-4wg4-p27p-5q2r","cve":"CVE-2026-23496","affectedVersions":"\u003C=5.2.1|\u003E=6.0.0-RC1,\u003C=6.1","source":"GitHub","reportedAt":"2026-01-15 18:14:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4wg4-p27p-5q2r"}]}],"algolia\/algoliasearch-magento-2":[{"advisoryId":"PKSA-j8tz-vf37-fv2w","packageName":"algolia\/algoliasearch-magento-2","remoteId":"GHSA-595p-g7xc-c333","title":"Algolia Search \u0026 Discovery for Magento 2 Has Untrusted Data Handling","link":"https:\/\/github.com\/advisories\/GHSA-595p-g7xc-c333","cve":null,"affectedVersions":"\u003C=3.16.1|\u003E=3.17.0-beta.1,\u003C=3.17.1","source":"GitHub","reportedAt":"2026-01-14 21:46:11","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-595p-g7xc-c333"}]}],"typo3\/cms-redirects":[{"advisoryId":"PKSA-1ccf-rwwt-88n5","packageName":"typo3\/cms-redirects","remoteId":"GHSA-6c46-p6j5-3f49","title":"TYPO3 CMS Allows Broken Access Control in Redirects Module","link":"https:\/\/github.com\/advisories\/GHSA-6c46-p6j5-3f49","cve":"CVE-2025-59021","affectedVersions":"\u003E=10.0.0,\u003C=10.4.54|\u003E=11.0.0,\u003C=11.5.48|\u003E=12.0.0,\u003C=12.4.40|\u003E=13.0.0,\u003C=13.4.22|\u003E=14.0.0,\u003C=14.0.1","source":"GitHub","reportedAt":"2026-01-13 20:37:37","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6c46-p6j5-3f49"}]}],"paragonie\/sodium_compat":[{"advisoryId":"PKSA-bjyb-w14t-61js","packageName":"paragonie\/sodium_compat","remoteId":"GHSA-mrfv-m5wm-5w6w","title":"libsodium has Incomplete List of Disallowed Inputs","link":"https:\/\/github.com\/advisories\/GHSA-mrfv-m5wm-5w6w","cve":"CVE-2025-69277","affectedVersions":"\u003C1.24.0|\u003E=2,\u003C2.5.0","source":"GitHub","reportedAt":"2025-12-31 06:30:18","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mrfv-m5wm-5w6w"}]},{"advisoryId":"PKSA-8x19-j2j3-bn67","packageName":"paragonie\/sodium_compat","remoteId":"paragonie\/sodium_compat\/2025-12-30.yaml","title":"Missing check that a point is on the prime subgroup for Edwards25519","link":"https:\/\/00f.net\/2025\/12\/30\/libsodium-vulnerability","cve":null,"affectedVersions":"\u003E=2,\u003C2.5.0|\u003C1.24.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2025-12-30 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"paragonie\/sodium_compat\/2025-12-30.yaml"}]}],"yourls\/yourls":[{"advisoryId":"PKSA-qpkp-f36z-t666","packageName":"yourls\/yourls","remoteId":"GHSA-6mp4-q625-mxjp","title":"YOURLS is vulnerable to XSS through JSONP and Callback request parameters","link":"https:\/\/github.com\/advisories\/GHSA-6mp4-q625-mxjp","cve":null,"affectedVersions":"\u003C=1.10.2","source":"GitHub","reportedAt":"2025-12-30 19:34:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6mp4-q625-mxjp"}]}],"croogo\/croogo":[{"advisoryId":"PKSA-p8g5-rjcf-tnz9","packageName":"croogo\/croogo","remoteId":"GHSA-g5p6-3j82-xfm4","title":"Croogo CMS has a path traversal vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-g5p6-3j82-xfm4","cve":"CVE-2024-42718","affectedVersions":"\u003C=4.0.7","source":"GitHub","reportedAt":"2025-12-26 18:30:27","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g5p6-3j82-xfm4"}]}],"cadmium-org\/cadmium-cms":[{"advisoryId":"PKSA-j99j-jfp1-f8zr","packageName":"cadmium-org\/cadmium-cms","remoteId":"GHSA-qx44-p258-3c2v","title":"Cadmium CMS has a background arbitrary file upload vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-qx44-p258-3c2v","cve":"CVE-2025-51511","affectedVersions":"\u003C=0.4.9","source":"GitHub","reportedAt":"2025-12-23 18:30:27","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qx44-p258-3c2v"}]}],"pagekit\/pagekit":[{"advisoryId":"PKSA-jj4g-dt34-dwmv","packageName":"pagekit\/pagekit","remoteId":"GHSA-m4f2-xpfq-h97v","title":"Pagekit CMS is vulnerable to OS Command Injection via Storage component","link":"https:\/\/github.com\/advisories\/GHSA-m4f2-xpfq-h97v","cve":"CVE-2025-67164","affectedVersions":"\u003C=1.0.18","source":"GitHub","reportedAt":"2025-12-17 18:31:33","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-m4f2-xpfq-h97v"}]},{"advisoryId":"PKSA-76gv-drgs-7ygt","packageName":"pagekit\/pagekit","remoteId":"GHSA-w3j8-9p3j-3wjx","title":"Pagekit CMS has an Insecure Direct Object Reference (IDOR) in its User Role component","link":"https:\/\/github.com\/advisories\/GHSA-w3j8-9p3j-3wjx","cve":"CVE-2025-67165","affectedVersions":"\u003C=1.0.18","source":"GitHub","reportedAt":"2025-12-17 18:31:34","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-w3j8-9p3j-3wjx"}]}],"altcha-org\/altcha":[{"advisoryId":"PKSA-5rb8-j658-qvzz","packageName":"altcha-org\/altcha","remoteId":"GHSA-6gvq-jcmp-8959","title":"ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay","link":"https:\/\/github.com\/advisories\/GHSA-6gvq-jcmp-8959","cve":"CVE-2025-68113","affectedVersions":"\u003C1.3.1","source":"GitHub","reportedAt":"2025-12-16 00:43:52","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6gvq-jcmp-8959"}]}],"yungifez\/skuul":[{"advisoryId":"PKSA-zg74-gdbs-sykt","packageName":"yungifez\/skuul","remoteId":"GHSA-xmh7-35v2-fp6h","title":"Skuul School Management System has a Sensitive Data Exposure Vulnerability in Uploaded Images","link":"https:\/\/github.com\/advisories\/GHSA-xmh7-35v2-fp6h","cve":"CVE-2025-13785","affectedVersions":"\u003C=2.6.4","source":"GitHub","reportedAt":"2025-11-30 09:30:18","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xmh7-35v2-fp6h"}]},{"advisoryId":"PKSA-8ssr-j1wg-53js","packageName":"yungifez\/skuul","remoteId":"GHSA-fqq7-h225-8w6h","title":"Skuul School Management System has an Insecure Direct Object Reference (IDOR) Vulnerability in View Fee Invoice","link":"https:\/\/github.com\/advisories\/GHSA-fqq7-h225-8w6h","cve":"CVE-2025-12918","affectedVersions":"\u003C=2.6.4","source":"GitHub","reportedAt":"2025-11-09 09:30:15","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-fqq7-h225-8w6h"}]},{"advisoryId":"PKSA-222h-4358-m2cj","packageName":"yungifez\/skuul","remoteId":"GHSA-92x3-mfjp-j3h3","title":"yungifez Skuul School Management System vulnerable to XSS via SVG","link":"https:\/\/github.com\/advisories\/GHSA-92x3-mfjp-j3h3","cve":"CVE-2025-13784","affectedVersions":"\u003C=2.6.5","source":"GitHub","reportedAt":"2025-11-30 09:30:18","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-92x3-mfjp-j3h3"}]}],"fof\/pretty-mail":[{"advisoryId":"PKSA-zqkh-gtty-c5yv","packageName":"fof\/pretty-mail","remoteId":"GHSA-947q-2xw3-gx9c","title":"FoF Pretty Mail has a server-side template injection vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-947q-2xw3-gx9c","cve":"CVE-2024-58303","affectedVersions":"\u003C=1.1.2","source":"GitHub","reportedAt":"2025-12-12 00:30:21","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-947q-2xw3-gx9c"}]}],"ibexa\/user":[{"advisoryId":"PKSA-tp68-m26r-qqm9","packageName":"ibexa\/user","remoteId":"GHSA-x93p-w2ch-fg67","title":"Ibexa User Bundle is missing password change validation","link":"https:\/\/github.com\/advisories\/GHSA-x93p-w2ch-fg67","cve":"CVE-2025-67719","affectedVersions":"\u003E=5.0.0-beta1,\u003C5.0.4","source":"GitHub","reportedAt":"2025-12-10 18:20:55","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-x93p-w2ch-fg67"}]},{"advisoryId":"PKSA-193d-p3tz-4pbs","packageName":"ibexa\/user","remoteId":"GHSA-q3x8-6898-23g3","title":"ibexa\/user login enumerates user accounts","link":"https:\/\/github.com\/advisories\/GHSA-q3x8-6898-23g3","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.0.3","source":"GitHub","reportedAt":"2025-10-17 17:58:08","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q3x8-6898-23g3"}]}],"onelogin\/php-saml":[{"advisoryId":"PKSA-67d7-mg8j-87zx","packageName":"onelogin\/php-saml","remoteId":"GHSA-5j8p-438x-rgg5","title":" SAML PHP Toolkit Vulnerability on xmlseclibs CVE-2025-66475 ","link":"https:\/\/github.com\/advisories\/GHSA-5j8p-438x-rgg5","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C4.3.1|\u003E=3.0.0,\u003C3.8.1|\u003C2.21.1","source":"GitHub","reportedAt":"2025-12-09 17:24:09","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-5j8p-438x-rgg5"}]}],"shopware\/storefront":[{"advisoryId":"PKSA-hv1g-94j4-tpht","packageName":"shopware\/storefront","remoteId":"GHSA-6w82-v552-wjw2","title":"Shopware Storefront Reflected XSS in Storefront Login Page","link":"https:\/\/github.com\/advisories\/GHSA-6w82-v552-wjw2","cve":"CVE-2025-67648","affectedVersions":"\u003E=6.7.0.0,\u003C6.7.5.1|\u003E=6.4.6.0,\u003C6.6.10.10","source":"GitHub","reportedAt":"2025-12-09 17:24:21","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6w82-v552-wjw2"}]},{"advisoryId":"PKSA-5pbs-7q37-td9b","packageName":"shopware\/storefront","remoteId":"GHSA-c2f9-4jmm-v45m","title":"Shopware\u0027s session is persistent in Cache for 404 pages","link":"https:\/\/github.com\/advisories\/GHSA-c2f9-4jmm-v45m","cve":"CVE-2024-27917","affectedVersions":"\u003E=6.5.8.0,\u003C6.5.8.7","source":"GitHub","reportedAt":"2024-03-06 15:06:54","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c2f9-4jmm-v45m"}]}],"neuron-core\/neuron-ai":[{"advisoryId":"PKSA-3v4g-ypy5-yqkt","packageName":"neuron-core\/neuron-ai","remoteId":"GHSA-j8g6-5gqc-mq36","title":"Neuron MySQLSelectTool \u201cread-only\u201d bypass via `SELECT ... INTO OUTFILE` (file write \u2192 potential RCE)","link":"https:\/\/github.com\/advisories\/GHSA-j8g6-5gqc-mq36","cve":"CVE-2025-67509","affectedVersions":"\u003C=2.8.11","source":"GitHub","reportedAt":"2025-12-09 17:19:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j8g6-5gqc-mq36"}]},{"advisoryId":"PKSA-v9n6-t7d1-c4nb","packageName":"neuron-core\/neuron-ai","remoteId":"GHSA-898v-775g-777c","title":"Neuron MySQLWriteTool allows arbitrary\/destructive SQL when exposed to untrusted prompts (agent \u201cfootgun\u201d)","link":"https:\/\/github.com\/advisories\/GHSA-898v-775g-777c","cve":"CVE-2025-67510","affectedVersions":"\u003C=2.8.11","source":"GitHub","reportedAt":"2025-12-09 17:19:42","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-898v-775g-777c"}]}],"alexusmai\/laravel-file-manager":[{"advisoryId":"PKSA-1wr2-d1dm-qbvs","packageName":"alexusmai\/laravel-file-manager","remoteId":"GHSA-q5hg-wppq-r2cc","title":"alexusmai laravel-file-manager is vulnerable to Directory Traversal via the unzip\/extraction functionality","link":"https:\/\/github.com\/advisories\/GHSA-q5hg-wppq-r2cc","cve":"CVE-2025-65346","affectedVersions":"\u003C=3.3.1","source":"GitHub","reportedAt":"2025-12-04 15:30:33","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-q5hg-wppq-r2cc"}]},{"advisoryId":"PKSA-hxrf-fpvh-g3vm","packageName":"alexusmai\/laravel-file-manager","remoteId":"GHSA-rr44-8j7r-jg2q","title":"alexusmai laravel-file-manager is vulnerable to Directory Traversal","link":"https:\/\/github.com\/advisories\/GHSA-rr44-8j7r-jg2q","cve":"CVE-2025-65345","affectedVersions":"\u003C=3.3.1","source":"GitHub","reportedAt":"2025-12-03 21:31:05","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-rr44-8j7r-jg2q"}]}],"aimeos\/ai-cms-grapesjs":[{"advisoryId":"PKSA-zwdc-m87t-6qvk","packageName":"aimeos\/ai-cms-grapesjs","remoteId":"GHSA-424m-fj2q-g7vg","title":"Aimeos GrapesJS CMS extension has possible stored XSS that\u0027s exploitable by authenticated editors","link":"https:\/\/github.com\/advisories\/GHSA-424m-fj2q-g7vg","cve":"CVE-2025-66468","affectedVersions":"\u003E=2025.04.1,\u003C2025.10.2|\u003E=2024.04.1,\u003C2024.10.8|\u003E=2023.04.1,\u003C2023.10.15|\u003E=2022.04.1,\u003C2022.10.9|\u003E=2021.04.1,\u003C2021.10.8","source":"GitHub","reportedAt":"2025-12-03 14:05:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-424m-fj2q-g7vg"}]}],"mautic\/grapes-js-builder-bundle":[{"advisoryId":"PKSA-71fk-dvg7-c5gr","packageName":"mautic\/grapes-js-builder-bundle","remoteId":"GHSA-5xw2-57jx-pgjp","title":"GrapesJsBuilder File Upload allows all file uploads","link":"https:\/\/github.com\/advisories\/GHSA-5xw2-57jx-pgjp","cve":"CVE-2025-13827","affectedVersions":"\u003E=6.0.0,\u003C6.0.7|\u003E=5.0.0,\u003C5.2.9|\u003E=4.0.0,\u003C4.4.18","source":"GitHub","reportedAt":"2025-12-02 21:11:33","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5xw2-57jx-pgjp"}]}],"feehi\/feehicms":[{"advisoryId":"PKSA-cs8g-pn8z-dp8k","packageName":"feehi\/feehicms","remoteId":"GHSA-c2vx-rx6x-m9wj","title":"FeehiCMS is vulnerable to cross-site scripting via the id parameter of the User Update function","link":"https:\/\/github.com\/advisories\/GHSA-c2vx-rx6x-m9wj","cve":"CVE-2025-63520","affectedVersions":"=2.1.1","source":"GitHub","reportedAt":"2025-12-01 15:30:18","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c2vx-rx6x-m9wj"}]},{"advisoryId":"PKSA-s4mw-3rsw-xxvp","packageName":"feehi\/feehicms","remoteId":"GHSA-qgc9-p7cj-jvh6","title":"FeehiCMS fails to enforce server-side immutability","link":"https:\/\/github.com\/advisories\/GHSA-qgc9-p7cj-jvh6","cve":"CVE-2025-63523","affectedVersions":"=2.1.1","source":"GitHub","reportedAt":"2025-12-01 15:30:18","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qgc9-p7cj-jvh6"}]},{"advisoryId":"PKSA-2tvw-ry46-vvzy","packageName":"feehi\/feehicms","remoteId":"GHSA-w756-rf26-7rmr","title":"FeehiCMS is vulnerable to reverse tabnabbing","link":"https:\/\/github.com\/advisories\/GHSA-w756-rf26-7rmr","cve":"CVE-2025-63522","affectedVersions":"\u003C=2.1.1","source":"GitHub","reportedAt":"2025-12-01 15:30:18","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w756-rf26-7rmr"}]}],"contao\/core-bundle":[{"advisoryId":"PKSA-wjhx-cdbz-9x61","packageName":"contao\/core-bundle","remoteId":"GHSA-98vj-mm79-v77r","title":"Contao is vulnerable to remote code execution in template closures","link":"https:\/\/github.com\/advisories\/GHSA-98vj-mm79-v77r","cve":"CVE-2025-65960","affectedVersions":"\u003E=5.4.0-RC1,\u003C5.6.5|\u003E=5.0.0-RC1,\u003C5.3.42|\u003E=4.0.0,\u003C4.13.57","source":"GitHub","reportedAt":"2025-11-25 20:43:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-98vj-mm79-v77r"}]},{"advisoryId":"PKSA-3p5h-vgz7-458z","packageName":"contao\/core-bundle","remoteId":"GHSA-68q5-78xp-cwwc","title":"Contao is vulnerable to cross-site scripting in templates","link":"https:\/\/github.com\/advisories\/GHSA-68q5-78xp-cwwc","cve":"CVE-2025-65961","affectedVersions":"\u003E=5.4.0-RC1,\u003C5.6.5|\u003E=5.0.0-RC1,\u003C5.3.42|\u003E=4.0.0,\u003C4.13.57","source":"GitHub","reportedAt":"2025-11-25 20:48:13","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-68q5-78xp-cwwc"}]}],"drupal\/email_tfa":[{"advisoryId":"PKSA-k5jz-q6jc-75hh","packageName":"drupal\/email_tfa","remoteId":"GHSA-9jrw-jrrj-p6fr","title":"Drupal Email TFA allows Functionality Bypass","link":"https:\/\/github.com\/advisories\/GHSA-9jrw-jrrj-p6fr","cve":"CVE-2025-12760","affectedVersions":"\u003C2.0.6","source":"GitHub","reportedAt":"2025-11-18 18:32:52","composerRepository":null,"severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9jrw-jrrj-p6fr"}]}],"mongodb\/mongodb-extension":[{"advisoryId":"PKSA-r3zn-9sn1-sy2d","packageName":"mongodb\/mongodb-extension","remoteId":"GHSA-mwcc-7vpp-xmv9","title":"MongoDB driver extension affected by mongoc_bulk_operation_t\u0027s read of invalid memory","link":"https:\/\/github.com\/advisories\/GHSA-mwcc-7vpp-xmv9","cve":"CVE-2025-12119","affectedVersions":"\u003C1.21.2","source":"GitHub","reportedAt":"2025-11-19 00:31:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mwcc-7vpp-xmv9"}]}],"munkireport\/comment":[{"advisoryId":"PKSA-j5xt-x546-jyj1","packageName":"munkireport\/comment","remoteId":"GHSA-vc4f-2g7f-pmqr","title":"MunkiReport Cross-Site Scripting (XSS) Filter Bypass On Comment","link":"https:\/\/github.com\/advisories\/GHSA-vc4f-2g7f-pmqr","cve":"CVE-2020-15885","affectedVersions":"\u003C4.0","source":"GitHub","reportedAt":"2022-05-24 17:24:15","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vc4f-2g7f-pmqr"}]}],"backdrop\/backdrop":[{"advisoryId":"PKSA-2f77-cwcx-9j4j","packageName":"backdrop\/backdrop","remoteId":"GHSA-ffpg-gm3h-4p5p","title":"Backdrop CMS Host Header Injection vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-ffpg-gm3h-4p5p","cve":"CVE-2025-63828","affectedVersions":"\u003C=1.32.0","source":"GitHub","reportedAt":"2025-11-18 18:32:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-ffpg-gm3h-4p5p"}]}],"drupal\/simple_multistep":[{"advisoryId":"PKSA-3hkf-2q8c-m9gq","packageName":"drupal\/simple_multistep","remoteId":"GHSA-gg35-374m-9ph8","title":"Drupal Simple multi step form allows Cross-Site Scripting","link":"https:\/\/github.com\/advisories\/GHSA-gg35-374m-9ph8","cve":"CVE-2025-12761","affectedVersions":"\u003C2.0.0","source":"GitHub","reportedAt":"2025-11-18 18:32:52","composerRepository":null,"severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-gg35-374m-9ph8"}]}],"codingms\/modules":[{"advisoryId":"PKSA-pz3k-gq7g-jcxs","packageName":"codingms\/modules","remoteId":"GHSA-49qv-h8pm-73pf","title":"TYPO3 Modules Extension has Improper Authentication vulnerability ","link":"https:\/\/github.com\/advisories\/GHSA-49qv-h8pm-73pf","cve":"CVE-2025-12998","affectedVersions":"\u003E=6.0.0,\u003C6.4.2|\u003E=7.0.0,\u003C7.5.5|\u003E=5.0.0,\u003C5.7.4|\u003C4.3.11","source":"GitHub","reportedAt":"2025-11-12 12:30:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-49qv-h8pm-73pf"}]}],"privatebin\/privatebin":[{"advisoryId":"PKSA-fq4v-3kvp-3kj2","packageName":"privatebin\/privatebin","remoteId":"GHSA-g2j9-g8r5-rg82","title":"PrivateBin\u0027s template-switching feature allows arbitrary local file inclusion through path traversal","link":"https:\/\/github.com\/advisories\/GHSA-g2j9-g8r5-rg82","cve":"CVE-2025-64714","affectedVersions":"\u003E=1.7.7,\u003C2.0.3","source":"GitHub","reportedAt":"2025-11-14 20:33:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g2j9-g8r5-rg82"}]},{"advisoryId":"PKSA-xp1b-f5r4-zfxh","packageName":"privatebin\/privatebin","remoteId":"GHSA-r9x7-7ggj-fx9f","title":"PrivateBin vulnerable to malicious filename use for self-XSS \/ HTML injection locally for users","link":"https:\/\/github.com\/advisories\/GHSA-r9x7-7ggj-fx9f","cve":"CVE-2025-64711","affectedVersions":"\u003E=1.7.7,\u003C2.0.3","source":"GitHub","reportedAt":"2025-11-14 20:33:52","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-r9x7-7ggj-fx9f"}]},{"advisoryId":"PKSA-rcyz-b3kf-16mn","packageName":"privatebin\/privatebin","remoteId":"GHSA-867c-p784-5q6g","title":"PrivateBin is missing HTML sanitization of attached filename in file size hint","link":"https:\/\/github.com\/advisories\/GHSA-867c-p784-5q6g","cve":"CVE-2025-62796","affectedVersions":"\u003E=1.7.7,\u003C2.0.2","source":"GitHub","reportedAt":"2025-10-28 20:14:09","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-867c-p784-5q6g"}]}],"magento\/project-community-edition":[{"advisoryId":"PKSA-17rr-8v96-bv63","packageName":"magento\/project-community-edition","remoteId":"GHSA-gvfx-9m9v-h839","title":"Magento is affected by an improper input validation vulnerability while saving a customer\u0027s details","link":"https:\/\/github.com\/advisories\/GHSA-gvfx-9m9v-h839","cve":"CVE-2021-36025","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:47","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-gvfx-9m9v-h839"}]},{"advisoryId":"PKSA-8dfr-9b5m-7xr8","packageName":"magento\/project-community-edition","remoteId":"GHSA-qmq6-jpvg-j547","title":"Magento is affected by an os command injection via the Data collection endpoint","link":"https:\/\/github.com\/advisories\/GHSA-qmq6-jpvg-j547","cve":"CVE-2021-36024","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qmq6-jpvg-j547"}]},{"advisoryId":"PKSA-bk68-b64r-znp8","packageName":"magento\/project-community-edition","remoteId":"GHSA-3g7m-g8qm-x6j5","title":"Magento discloses sensitive information","link":"https:\/\/github.com\/advisories\/GHSA-3g7m-g8qm-x6j5","cve":"CVE-2021-36039","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3g7m-g8qm-x6j5"}]},{"advisoryId":"PKSA-zngg-vgy9-4g5p","packageName":"magento\/project-community-edition","remoteId":"GHSA-vrq2-w7r7-3fp2","title":"Magento is affected by an improper authorization vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-vrq2-w7r7-3fp2","cve":"CVE-2021-36037","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vrq2-w7r7-3fp2"}]},{"advisoryId":"PKSA-6wq2-rzmf-jydh","packageName":"magento\/project-community-edition","remoteId":"GHSA-j46h-qjjv-cxfj","title":"Magento affected by remote code execution via a file upload","link":"https:\/\/github.com\/advisories\/GHSA-j46h-qjjv-cxfj","cve":"CVE-2021-36034","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j46h-qjjv-cxfj"}]},{"advisoryId":"PKSA-yjhy-wps1-gwny","packageName":"magento\/project-community-edition","remoteId":"GHSA-wgpr-9675-8r67","title":"Magento discloses sensitive information via the Multishipping Module","link":"https:\/\/github.com\/advisories\/GHSA-wgpr-9675-8r67","cve":"CVE-2021-36038","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wgpr-9675-8r67"}]},{"advisoryId":"PKSA-ztts-2y99-bcdy","packageName":"magento\/project-community-edition","remoteId":"GHSA-2pq5-gpqf-g4r3","title":"Magento has a  file extension restrictions bypass","link":"https:\/\/github.com\/advisories\/GHSA-2pq5-gpqf-g4r3","cve":"CVE-2021-36040","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:46","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-2pq5-gpqf-g4r3"}]},{"advisoryId":"PKSA-v7n8-rj87-rp8f","packageName":"magento\/project-community-edition","remoteId":"GHSA-mx5m-j5xr-jg8c","title":"Magento vulnerable to file upload attack","link":"https:\/\/github.com\/advisories\/GHSA-mx5m-j5xr-jg8c","cve":"CVE-2021-36041","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mx5m-j5xr-jg8c"}]},{"advisoryId":"PKSA-xgws-skjf-gckt","packageName":"magento\/project-community-edition","remoteId":"GHSA-36xq-7w8w-xp68","title":"Magento affected by a blind SSRF vulnerability in the bundled dotmailer extension","link":"https:\/\/github.com\/advisories\/GHSA-36xq-7w8w-xp68","cve":"CVE-2021-36043","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-36xq-7w8w-xp68"}]},{"advisoryId":"PKSA-2kzy-spch-8dtk","packageName":"magento\/project-community-edition","remoteId":"GHSA-6cwv-wj7v-73xp","title":"Magento executes code via the API File Option Upload Extension","link":"https:\/\/github.com\/advisories\/GHSA-6cwv-wj7v-73xp","cve":"CVE-2021-36042","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:46","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-6cwv-wj7v-73xp"}]},{"advisoryId":"PKSA-4s2g-m2hm-n8kp","packageName":"magento\/project-community-edition","remoteId":"GHSA-wr57-3h2f-3q95","title":"Magento affected by a server-side denial-of-service using a GraphQL field","link":"https:\/\/github.com\/advisories\/GHSA-wr57-3h2f-3q95","cve":"CVE-2021-36044","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wr57-3h2f-3q95"}]},{"advisoryId":"PKSA-py55-xtc9-n1vr","packageName":"magento\/project-community-edition","remoteId":"GHSA-5pjj-7fq8-9gpf","title":"Magento has an XML Injection vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-5pjj-7fq8-9gpf","cve":"CVE-2021-36028","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:47","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-5pjj-7fq8-9gpf"}]},{"advisoryId":"PKSA-b5t8-3cfw-p3zr","packageName":"magento\/project-community-edition","remoteId":"GHSA-5vw8-r55w-f4q4","title":"Magento is affected by an improper input validation vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-5vw8-r55w-f4q4","cve":"CVE-2021-36032","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5vw8-r55w-f4q4"}]},{"advisoryId":"PKSA-85p5-zgy5-5xnz","packageName":"magento\/project-community-edition","remoteId":"GHSA-m8wx-whpp-q283","title":"Magento improper authorization vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-m8wx-whpp-q283","cve":"CVE-2021-36029","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-m8wx-whpp-q283"}]},{"advisoryId":"PKSA-21fx-wcrz-h4sg","packageName":"magento\/project-community-edition","remoteId":"GHSA-p746-qw73-qmmx","title":"Magento XML Injection vulnerability in the Widgets Module","link":"https:\/\/github.com\/advisories\/GHSA-p746-qw73-qmmx","cve":"CVE-2021-36033","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:47","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-p746-qw73-qmmx"}]},{"advisoryId":"PKSA-7dd8-p7yr-6sty","packageName":"magento\/project-community-edition","remoteId":"GHSA-7w95-qwhh-q9p3","title":"Magento Path Traversal vulnerability via the `theme[preview_image]` parameter","link":"https:\/\/github.com\/advisories\/GHSA-7w95-qwhh-q9p3","cve":"CVE-2021-36031","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7w95-qwhh-q9p3"}]},{"advisoryId":"PKSA-8rbp-3yr4-kzsk","packageName":"magento\/project-community-edition","remoteId":"GHSA-rhff-65hp-55rw","title":"Magento allows attackers to alter the price of items","link":"https:\/\/github.com\/advisories\/GHSA-rhff-65hp-55rw","cve":"CVE-2021-36030","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-rhff-65hp-55rw"}]},{"advisoryId":"PKSA-gz8m-d97x-xcsb","packageName":"magento\/project-community-edition","remoteId":"GHSA-xvpx-6hh8-7h72","title":"Magento XML Injection vulnerability in the \u0027City\u0027 field","link":"https:\/\/github.com\/advisories\/GHSA-xvpx-6hh8-7h72","cve":"CVE-2021-36020","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xvpx-6hh8-7h72"}]},{"advisoryId":"PKSA-rcpd-m1gd-98mf","packageName":"magento\/project-community-edition","remoteId":"GHSA-3x9x-vhqj-cv27","title":"Magento XML Injection vulnerability in the Widgets Update Layout","link":"https:\/\/github.com\/advisories\/GHSA-3x9x-vhqj-cv27","cve":"CVE-2021-36022","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3x9x-vhqj-cv27"}]},{"advisoryId":"PKSA-24m8-9psy-djq7","packageName":"magento\/project-community-edition","remoteId":"GHSA-x2v2-2jhp-c5hv","title":"Magento stored cross-site scripting vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-x2v2-2jhp-c5hv","cve":"CVE-2021-36027","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 22:29:05","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x2v2-2jhp-c5hv"}]},{"advisoryId":"PKSA-k1yz-gr5t-hhxm","packageName":"magento\/project-community-edition","remoteId":"GHSA-8gfq-m4cf-w975","title":"Magento stored cross-site scripting vulnerability in the customer address upload feature","link":"https:\/\/github.com\/advisories\/GHSA-8gfq-m4cf-w975","cve":"CVE-2021-36026","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 22:28:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8gfq-m4cf-w975"}]},{"advisoryId":"PKSA-t2xp-vd66-ybyt","packageName":"magento\/project-community-edition","remoteId":"GHSA-3f97-7pgv-gmgr","title":"Magento affected by a business logic error in the placeOrder graphql mutation","link":"https:\/\/github.com\/advisories\/GHSA-3f97-7pgv-gmgr","cve":"CVE-2021-36012","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2022-05-24 19:12:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3f97-7pgv-gmgr"}]},{"advisoryId":"PKSA-3w2j-148y-fbkd","packageName":"magento\/project-community-edition","remoteId":"GHSA-7r99-8wqp-h7pc","title":"Magento Path Traversal vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-7r99-8wqp-h7pc","cve":"CVE-2024-39399","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7r99-8wqp-h7pc"}]},{"advisoryId":"PKSA-sxwm-bffz-sx8t","packageName":"magento\/project-community-edition","remoteId":"GHSA-52fg-wjxm-pp44","title":"Magento DOM-based Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-52fg-wjxm-pp44","cve":"CVE-2024-39400","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-52fg-wjxm-pp44"}]},{"advisoryId":"PKSA-2rtt-dsym-g9ss","packageName":"magento\/project-community-edition","remoteId":"GHSA-4g27-q2w9-m8m8","title":"Magento affected by remote code execution vulnerability in the CMS page scheduled update feature","link":"https:\/\/github.com\/advisories\/GHSA-4g27-q2w9-m8m8","cve":"CVE-2021-36021","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2023-09-06 15:30:27","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-4g27-q2w9-m8m8"}]},{"advisoryId":"PKSA-ct3s-553f-dgt1","packageName":"magento\/project-community-edition","remoteId":"GHSA-wqr6-wv6c-p8fx","title":"Magento improper access control vulnerability within Magento\u0027s Media Gallery Upload workflow","link":"https:\/\/github.com\/advisories\/GHSA-wqr6-wv6c-p8fx","cve":"CVE-2021-36036","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2023-09-06 15:30:27","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-wqr6-wv6c-p8fx"}]},{"advisoryId":"PKSA-hpxx-kn39-41wv","packageName":"magento\/project-community-edition","remoteId":"GHSA-8cjg-f53m-8m9q","title":"Magento XML Injection vulnerability in the Widgets Update Layout","link":"https:\/\/github.com\/advisories\/GHSA-8cjg-f53m-8m9q","cve":"CVE-2021-36023","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2023-09-06 15:30:27","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-8cjg-f53m-8m9q"}]},{"advisoryId":"PKSA-q7s3-frdr-1dn6","packageName":"magento\/project-community-edition","remoteId":"GHSA-q628-54wg-4r5q","title":"Magento does not properly restrict excessive authentication attempts","link":"https:\/\/github.com\/advisories\/GHSA-q628-54wg-4r5q","cve":"CVE-2024-39398","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-q628-54wg-4r5q"}]},{"advisoryId":"PKSA-vk95-4ddg-k6zr","packageName":"magento\/project-community-edition","remoteId":"GHSA-mmp7-8cg4-9wrg","title":"Magento Stored Cross-Site Scripting (XSS) vulnerability ","link":"https:\/\/github.com\/advisories\/GHSA-mmp7-8cg4-9wrg","cve":"CVE-2024-39403","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mmp7-8cg4-9wrg"}]},{"advisoryId":"PKSA-634t-hn1n-jy9s","packageName":"magento\/project-community-edition","remoteId":"GHSA-5g9f-7gqc-8hj4","title":"Magento Improper Authorization vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-5g9f-7gqc-8hj4","cve":"CVE-2024-39405","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5g9f-7gqc-8hj4"}]},{"advisoryId":"PKSA-88dh-sqwk-yrn8","packageName":"magento\/project-community-edition","remoteId":"GHSA-8frp-pxq2-3gpq","title":"Magento OS Command (\u0027OS Command Injection\u0027) vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-8frp-pxq2-3gpq","cve":"CVE-2024-39401","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8frp-pxq2-3gpq"}]},{"advisoryId":"PKSA-gtqw-8tn8-f1mj","packageName":"magento\/project-community-edition","remoteId":"GHSA-2ff6-837j-hg5x","title":"Magento OS Command (\u0027OS Command Injection\u0027) vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-2ff6-837j-hg5x","cve":"CVE-2024-39402","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2ff6-837j-hg5x"}]},{"advisoryId":"PKSA-7d9n-ggqz-zmxp","packageName":"magento\/project-community-edition","remoteId":"GHSA-gvgf-pvh5-vjh4","title":"Magento Improper Authorization vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-gvgf-pvh5-vjh4","cve":"CVE-2024-39418","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gvgf-pvh5-vjh4"}]},{"advisoryId":"PKSA-j2rz-rvx4-k296","packageName":"magento\/project-community-edition","remoteId":"GHSA-qrh3-vxjg-h9h6","title":"Magento Improper Authorization vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-qrh3-vxjg-h9h6","cve":"CVE-2024-39404","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qrh3-vxjg-h9h6"}]},{"advisoryId":"PKSA-ksk8-hxyg-xvfg","packageName":"magento\/project-community-edition","remoteId":"GHSA-cjm6-8mw8-2f8c","title":"Magento Improper Authorization vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-cjm6-8mw8-2f8c","cve":"CVE-2024-39407","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cjm6-8mw8-2f8c"}]},{"advisoryId":"PKSA-bwdz-tnp6-hk5k","packageName":"magento\/project-community-edition","remoteId":"GHSA-8w5f-8992-g86j","title":"Magento Improper Authorization vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-8w5f-8992-g86j","cve":"CVE-2024-39413","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8w5f-8992-g86j"}]},{"advisoryId":"PKSA-j33z-72k7-nwyn","packageName":"magento\/project-community-edition","remoteId":"GHSA-vhcq-4xrm-2cr2","title":"Magento Improper Access Control leads to Security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-vhcq-4xrm-2cr2","cve":"CVE-2025-27191","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-04-08 21:31:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vhcq-4xrm-2cr2"}]},{"advisoryId":"PKSA-gkkr-yrmf-9dcm","packageName":"magento\/project-community-edition","remoteId":"GHSA-2r94-wm5v-4prx","title":"Magento does not properly protect credentials","link":"https:\/\/github.com\/advisories\/GHSA-2r94-wm5v-4prx","cve":"CVE-2025-27192","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-04-08 21:31:41","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-2r94-wm5v-4prx"}]},{"advisoryId":"PKSA-9h42-hjp4-8jwg","packageName":"magento\/project-community-edition","remoteId":"GHSA-qm77-mqf3-fmhq","title":"Magento Improper Authorization leads to security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-qm77-mqf3-fmhq","cve":"CVE-2024-39411","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qm77-mqf3-fmhq"}]},{"advisoryId":"PKSA-5h2h-vm5k-6mnx","packageName":"magento\/project-community-edition","remoteId":"GHSA-x6f9-hv9r-fgq4","title":"Magento Improper Access Control Leads to Privilege escalation","link":"https:\/\/github.com\/advisories\/GHSA-x6f9-hv9r-fgq4","cve":"CVE-2024-39414","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x6f9-hv9r-fgq4"}]},{"advisoryId":"PKSA-xrrt-bvvw-hr76","packageName":"magento\/project-community-edition","remoteId":"GHSA-gj93-84g5-mcjq","title":"Magento Improper Authorization Leading to Security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-gj93-84g5-mcjq","cve":"CVE-2024-39415","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gj93-84g5-mcjq"}]},{"advisoryId":"PKSA-x9mx-cg6q-dbr6","packageName":"magento\/project-community-edition","remoteId":"GHSA-4xgg-rw35-7mv5","title":"Magento Improper Authorization leads to Security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-4xgg-rw35-7mv5","cve":"CVE-2024-39416","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4xgg-rw35-7mv5"}]},{"advisoryId":"PKSA-6bv3-f1pv-tkg6","packageName":"magento\/project-community-edition","remoteId":"GHSA-4xmj-f664-hv98","title":"Magento Improper Authorization leads to Security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-4xmj-f664-hv98","cve":"CVE-2024-39417","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4xmj-f664-hv98"}]},{"advisoryId":"PKSA-bfjj-vfzz-pgc4","packageName":"magento\/project-community-edition","remoteId":"GHSA-74w7-cr4v-wf2v","title":"Magento Improper Access Control Leads to Privilege escalation","link":"https:\/\/github.com\/advisories\/GHSA-74w7-cr4v-wf2v","cve":"CVE-2024-39419","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-74w7-cr4v-wf2v"}]},{"advisoryId":"PKSA-dgwq-v9zk-5py2","packageName":"magento\/project-community-edition","remoteId":"GHSA-6wq7-cg9h-mj6q","title":"Magento Improper Access Control leads to Security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-6wq7-cg9h-mj6q","cve":"CVE-2025-27190","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-04-08 21:31:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6wq7-cg9h-mj6q"}]},{"advisoryId":"PKSA-msyb-69yd-tmh2","packageName":"magento\/project-community-edition","remoteId":"GHSA-85jx-x9r4-45m2","title":"Magento Authenticated Security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-85jx-x9r4-45m2","cve":"CVE-2025-49549","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-06-26 21:31:13","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-85jx-x9r4-45m2"}]},{"advisoryId":"PKSA-2yx1-9c32-fgbb","packageName":"magento\/project-community-edition","remoteId":"GHSA-r487-9vv5-75gg","title":"Magento Improper Authorization leading to security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-r487-9vv5-75gg","cve":"CVE-2025-43585","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-06-10 18:32:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r487-9vv5-75gg"}]},{"advisoryId":"PKSA-frp2-4m6z-72bk","packageName":"magento\/project-community-edition","remoteId":"GHSA-g2pj-xmxq-3r9q","title":"Magento Improper Access Control leads to security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-g2pj-xmxq-3r9q","cve":"CVE-2025-27206","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-06-10 18:32:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g2pj-xmxq-3r9q"}]},{"advisoryId":"PKSA-qrtj-1wyx-bhtk","packageName":"magento\/project-community-edition","remoteId":"GHSA-8hcx-xvww-6c6h","title":"Magento Security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-8hcx-xvww-6c6h","cve":"CVE-2025-49550","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-06-26 21:31:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8hcx-xvww-6c6h"}]},{"advisoryId":"PKSA-7z2m-9t27-jsqm","packageName":"magento\/project-community-edition","remoteId":"GHSA-wcmw-8xpp-rwfj","title":"Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-wcmw-8xpp-rwfj","cve":"CVE-2025-49558","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-08-12 18:31:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wcmw-8xpp-rwfj"}]},{"advisoryId":"PKSA-j4c6-522w-d5w2","packageName":"magento\/project-community-edition","remoteId":"GHSA-5777-jj7p-mpqw","title":"Magento Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-5777-jj7p-mpqw","cve":"CVE-2025-49555","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-08-12 18:31:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5777-jj7p-mpqw"}]},{"advisoryId":"PKSA-48kk-sh8q-28n5","packageName":"magento\/project-community-edition","remoteId":"GHSA-7hrj-3c9x-xv5h","title":"Magento has incorrect authorization issue that leads to arbitrary file system read","link":"https:\/\/github.com\/advisories\/GHSA-7hrj-3c9x-xv5h","cve":"CVE-2025-49556","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-08-12 18:31:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7hrj-3c9x-xv5h"}]},{"advisoryId":"PKSA-qxt1-qvkm-ccm7","packageName":"magento\/project-community-edition","remoteId":"GHSA-h4f4-gv6h-x824","title":"Magento vulnerable to path traversal","link":"https:\/\/github.com\/advisories\/GHSA-h4f4-gv6h-x824","cve":"CVE-2025-49559","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-08-12 18:31:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h4f4-gv6h-x824"}]},{"advisoryId":"PKSA-xpgt-hwzp-z42c","packageName":"magento\/project-community-edition","remoteId":"GHSA-xgfm-992v-h2hr","title":"Magento vulnerable to denial of service","link":"https:\/\/github.com\/advisories\/GHSA-xgfm-992v-h2hr","cve":"CVE-2025-49554","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-08-12 18:31:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xgfm-992v-h2hr"}]},{"advisoryId":"PKSA-f7yq-1gbd-c3rr","packageName":"magento\/project-community-edition","remoteId":"GHSA-2768-5wmv-cfff","title":"Magento vulnerable to stored Cross-Site Scripting (XSS)","link":"https:\/\/github.com\/advisories\/GHSA-2768-5wmv-cfff","cve":"CVE-2025-54264","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-10-14 21:30:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2768-5wmv-cfff"}]},{"advisoryId":"PKSA-z14p-xqf4-7sm6","packageName":"magento\/project-community-edition","remoteId":"GHSA-pcrx-r49h-x2w5","title":"Magento vulnerable to stored Cross-Site Scripting (XSS)","link":"https:\/\/github.com\/advisories\/GHSA-pcrx-r49h-x2w5","cve":"CVE-2025-54266","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-10-14 21:30:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pcrx-r49h-x2w5"}]},{"advisoryId":"PKSA-yfky-scjc-qkj4","packageName":"magento\/project-community-edition","remoteId":"GHSA-qvwr-p3hj-j6jf","title":"Magento vulnerable to privilege escalation due to incorrect authorization","link":"https:\/\/github.com\/advisories\/GHSA-qvwr-p3hj-j6jf","cve":"CVE-2025-54267","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-10-14 21:30:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qvwr-p3hj-j6jf"}]},{"advisoryId":"PKSA-4r9t-ghqm-cxfc","packageName":"magento\/project-community-edition","remoteId":"GHSA-69x9-xp2j-w8g8","title":"Magento provides incorrect authorization through a security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-69x9-xp2j-w8g8","cve":"CVE-2025-54263","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-10-14 21:30:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-69x9-xp2j-w8g8"}]},{"advisoryId":"PKSA-56cd-891c-qkty","packageName":"magento\/project-community-edition","remoteId":"GHSA-r355-75hw-r8jf","title":"Magento allows incorrect authorization","link":"https:\/\/github.com\/advisories\/GHSA-r355-75hw-r8jf","cve":"CVE-2025-54265","affectedVersions":"\u003C=2.0.2","source":"GitHub","reportedAt":"2025-10-14 21:30:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r355-75hw-r8jf"}]}],"magento\/community-edition":[{"advisoryId":"PKSA-zht9-r6rq-73xf","packageName":"magento\/community-edition","remoteId":"GHSA-gvfx-9m9v-h839","title":"Magento is affected by an improper input validation vulnerability while saving a customer\u0027s details","link":"https:\/\/github.com\/advisories\/GHSA-gvfx-9m9v-h839","cve":"CVE-2021-36025","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 19:12:47","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-gvfx-9m9v-h839"}]},{"advisoryId":"PKSA-8f3p-62qz-tqg4","packageName":"magento\/community-edition","remoteId":"GHSA-qmq6-jpvg-j547","title":"Magento is affected by an os command injection via the Data collection endpoint","link":"https:\/\/github.com\/advisories\/GHSA-qmq6-jpvg-j547","cve":"CVE-2021-36024","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 19:12:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qmq6-jpvg-j547"}]},{"advisoryId":"PKSA-cyyp-q7gm-jnyf","packageName":"magento\/community-edition","remoteId":"GHSA-3g7m-g8qm-x6j5","title":"Magento discloses sensitive information","link":"https:\/\/github.com\/advisories\/GHSA-3g7m-g8qm-x6j5","cve":"CVE-2021-36039","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 19:12:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3g7m-g8qm-x6j5"}]},{"advisoryId":"PKSA-jvct-y28v-8gvh","packageName":"magento\/community-edition","remoteId":"GHSA-vrq2-w7r7-3fp2","title":"Magento is affected by an improper authorization vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-vrq2-w7r7-3fp2","cve":"CVE-2021-36037","affectedVersions":"\u003C2.3.7-p1|=2.3.7|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.4.2","source":"GitHub","reportedAt":"2022-05-24 19:12:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vrq2-w7r7-3fp2"}]},{"advisoryId":"PKSA-v8mk-r9pr-d7y4","packageName":"magento\/community-edition","remoteId":"GHSA-j46h-qjjv-cxfj","title":"Magento affected by remote code execution via a file upload","link":"https:\/\/github.com\/advisories\/GHSA-j46h-qjjv-cxfj","cve":"CVE-2021-36034","affectedVersions":"\u003C2.3.7-p1|=2.3.7|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.4.2","source":"GitHub","reportedAt":"2022-05-24 19:12:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j46h-qjjv-cxfj"}]},{"advisoryId":"PKSA-qv71-rttf-m6qx","packageName":"magento\/community-edition","remoteId":"GHSA-wgpr-9675-8r67","title":"Magento discloses sensitive information via the Multishipping Module","link":"https:\/\/github.com\/advisories\/GHSA-wgpr-9675-8r67","cve":"CVE-2021-36038","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 19:12:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wgpr-9675-8r67"}]},{"advisoryId":"PKSA-4q5r-zm57-6btb","packageName":"magento\/community-edition","remoteId":"GHSA-2pq5-gpqf-g4r3","title":"Magento has a  file extension restrictions bypass","link":"https:\/\/github.com\/advisories\/GHSA-2pq5-gpqf-g4r3","cve":"CVE-2021-36040","affectedVersions":"\u003C2.3.7-p1|=2.3.7|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.4.2","source":"GitHub","reportedAt":"2022-05-24 19:12:46","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-2pq5-gpqf-g4r3"}]},{"advisoryId":"PKSA-r6q1-zcdh-wwwf","packageName":"magento\/community-edition","remoteId":"GHSA-mx5m-j5xr-jg8c","title":"Magento vulnerable to file upload attack","link":"https:\/\/github.com\/advisories\/GHSA-mx5m-j5xr-jg8c","cve":"CVE-2021-36041","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 19:12:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mx5m-j5xr-jg8c"}]},{"advisoryId":"PKSA-fzqz-5fm3-ff6f","packageName":"magento\/community-edition","remoteId":"GHSA-36xq-7w8w-xp68","title":"Magento affected by a blind SSRF vulnerability in the bundled dotmailer extension","link":"https:\/\/github.com\/advisories\/GHSA-36xq-7w8w-xp68","cve":"CVE-2021-36043","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 19:12:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-36xq-7w8w-xp68"}]},{"advisoryId":"PKSA-9d3t-ck81-vgdm","packageName":"magento\/community-edition","remoteId":"GHSA-6cwv-wj7v-73xp","title":"Magento executes code via the API File Option Upload Extension","link":"https:\/\/github.com\/advisories\/GHSA-6cwv-wj7v-73xp","cve":"CVE-2021-36042","affectedVersions":"\u003C2.3.7-p1|=2.3.7|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.4.2","source":"GitHub","reportedAt":"2022-05-24 19:12:46","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-6cwv-wj7v-73xp"}]},{"advisoryId":"PKSA-drxd-4kz8-ss7r","packageName":"magento\/community-edition","remoteId":"GHSA-wr57-3h2f-3q95","title":"Magento affected by a server-side denial-of-service using a GraphQL field","link":"https:\/\/github.com\/advisories\/GHSA-wr57-3h2f-3q95","cve":"CVE-2021-36044","affectedVersions":"\u003C2.3.7-p1|=2.3.7|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.4.2","source":"GitHub","reportedAt":"2022-05-24 19:12:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wr57-3h2f-3q95"}]},{"advisoryId":"PKSA-vk2g-xd67-4rwx","packageName":"magento\/community-edition","remoteId":"GHSA-5pjj-7fq8-9gpf","title":"Magento has an XML Injection vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-5pjj-7fq8-9gpf","cve":"CVE-2021-36028","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 19:12:47","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-5pjj-7fq8-9gpf"}]},{"advisoryId":"PKSA-z7f9-76hn-g136","packageName":"magento\/community-edition","remoteId":"GHSA-5vw8-r55w-f4q4","title":"Magento is affected by an improper input validation vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-5vw8-r55w-f4q4","cve":"CVE-2021-36032","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 19:12:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5vw8-r55w-f4q4"}]},{"advisoryId":"PKSA-53wg-ss27-pyh4","packageName":"magento\/community-edition","remoteId":"GHSA-m8wx-whpp-q283","title":"Magento improper authorization vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-m8wx-whpp-q283","cve":"CVE-2021-36029","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 19:12:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-m8wx-whpp-q283"}]},{"advisoryId":"PKSA-t6pt-nhyj-f147","packageName":"magento\/community-edition","remoteId":"GHSA-p746-qw73-qmmx","title":"Magento XML Injection vulnerability in the Widgets Module","link":"https:\/\/github.com\/advisories\/GHSA-p746-qw73-qmmx","cve":"CVE-2021-36033","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 19:12:47","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-p746-qw73-qmmx"}]},{"advisoryId":"PKSA-x26k-wchg-q8r4","packageName":"magento\/community-edition","remoteId":"GHSA-7w95-qwhh-q9p3","title":"Magento Path Traversal vulnerability via the `theme[preview_image]` parameter","link":"https:\/\/github.com\/advisories\/GHSA-7w95-qwhh-q9p3","cve":"CVE-2021-36031","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 19:12:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7w95-qwhh-q9p3"}]},{"advisoryId":"PKSA-cbsq-4n7d-nspt","packageName":"magento\/community-edition","remoteId":"GHSA-rhff-65hp-55rw","title":"Magento allows attackers to alter the price of items","link":"https:\/\/github.com\/advisories\/GHSA-rhff-65hp-55rw","cve":"CVE-2021-36030","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 19:12:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-rhff-65hp-55rw"}]},{"advisoryId":"PKSA-vnmf-mdtb-nkx3","packageName":"magento\/community-edition","remoteId":"GHSA-xvpx-6hh8-7h72","title":"Magento XML Injection vulnerability in the \u0027City\u0027 field","link":"https:\/\/github.com\/advisories\/GHSA-xvpx-6hh8-7h72","cve":"CVE-2021-36020","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 19:12:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xvpx-6hh8-7h72"}]},{"advisoryId":"PKSA-92m7-qj1w-j75w","packageName":"magento\/community-edition","remoteId":"GHSA-3x9x-vhqj-cv27","title":"Magento XML Injection vulnerability in the Widgets Update Layout","link":"https:\/\/github.com\/advisories\/GHSA-3x9x-vhqj-cv27","cve":"CVE-2021-36022","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 19:12:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3x9x-vhqj-cv27"}]},{"advisoryId":"PKSA-9twq-r6bn-pvjw","packageName":"magento\/community-edition","remoteId":"GHSA-x2v2-2jhp-c5hv","title":"Magento stored cross-site scripting vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-x2v2-2jhp-c5hv","cve":"CVE-2021-36027","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 22:29:05","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x2v2-2jhp-c5hv"}]},{"advisoryId":"PKSA-mpyd-zybm-5215","packageName":"magento\/community-edition","remoteId":"GHSA-8gfq-m4cf-w975","title":"Magento stored cross-site scripting vulnerability in the customer address upload feature","link":"https:\/\/github.com\/advisories\/GHSA-8gfq-m4cf-w975","cve":"CVE-2021-36026","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 22:28:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8gfq-m4cf-w975"}]},{"advisoryId":"PKSA-mp3d-tp64-1b25","packageName":"magento\/community-edition","remoteId":"GHSA-3f97-7pgv-gmgr","title":"Magento affected by a business logic error in the placeOrder graphql mutation","link":"https:\/\/github.com\/advisories\/GHSA-3f97-7pgv-gmgr","cve":"CVE-2021-36012","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2022-05-24 19:12:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3f97-7pgv-gmgr"}]},{"advisoryId":"PKSA-m1kf-kvd7-wsq8","packageName":"magento\/community-edition","remoteId":"GHSA-7r99-8wqp-h7pc","title":"Magento Path Traversal vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-7r99-8wqp-h7pc","cve":"CVE-2024-39399","affectedVersions":"=2.4.4|=2.4.5|=2.4.6|=2.4.7|\u003E=2.4.4-p1,\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7r99-8wqp-h7pc"}]},{"advisoryId":"PKSA-f7sg-yvfp-56f5","packageName":"magento\/community-edition","remoteId":"GHSA-52fg-wjxm-pp44","title":"Magento DOM-based Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-52fg-wjxm-pp44","cve":"CVE-2024-39400","affectedVersions":"=2.4.4|=2.4.5|=2.4.6|=2.4.7|\u003E=2.4.4-p1,\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-52fg-wjxm-pp44"}]},{"advisoryId":"PKSA-1qyf-659f-dtx3","packageName":"magento\/community-edition","remoteId":"GHSA-4g27-q2w9-m8m8","title":"Magento affected by remote code execution vulnerability in the CMS page scheduled update feature","link":"https:\/\/github.com\/advisories\/GHSA-4g27-q2w9-m8m8","cve":"CVE-2021-36021","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2023-09-06 15:30:27","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-4g27-q2w9-m8m8"}]},{"advisoryId":"PKSA-9bmk-r19v-6qhr","packageName":"magento\/community-edition","remoteId":"GHSA-wqr6-wv6c-p8fx","title":"Magento improper access control vulnerability within Magento\u0027s Media Gallery Upload workflow","link":"https:\/\/github.com\/advisories\/GHSA-wqr6-wv6c-p8fx","cve":"CVE-2021-36036","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2023-09-06 15:30:27","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-wqr6-wv6c-p8fx"}]},{"advisoryId":"PKSA-536b-9m7h-tqdk","packageName":"magento\/community-edition","remoteId":"GHSA-8cjg-f53m-8m9q","title":"Magento XML Injection vulnerability in the Widgets Update Layout","link":"https:\/\/github.com\/advisories\/GHSA-8cjg-f53m-8m9q","cve":"CVE-2021-36023","affectedVersions":"=2.4.2|\u003E=2.4.2-p1,\u003C2.4.2-p2|=2.3.7|\u003C2.3.7-p1","source":"GitHub","reportedAt":"2023-09-06 15:30:27","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-8cjg-f53m-8m9q"}]},{"advisoryId":"PKSA-ngw6-6q5w-v2rf","packageName":"magento\/community-edition","remoteId":"GHSA-q628-54wg-4r5q","title":"Magento does not properly restrict excessive authentication attempts","link":"https:\/\/github.com\/advisories\/GHSA-q628-54wg-4r5q","cve":"CVE-2024-39398","affectedVersions":"=2.4.4|=2.4.5|=2.4.6|=2.4.7|\u003E=2.4.4-p1,\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-q628-54wg-4r5q"}]},{"advisoryId":"PKSA-959j-1rp5-wgsz","packageName":"magento\/community-edition","remoteId":"GHSA-mmp7-8cg4-9wrg","title":"Magento Stored Cross-Site Scripting (XSS) vulnerability ","link":"https:\/\/github.com\/advisories\/GHSA-mmp7-8cg4-9wrg","cve":"CVE-2024-39403","affectedVersions":"=2.4.4|=2.4.5|=2.4.6|=2.4.7|\u003E=2.4.4-p1,\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mmp7-8cg4-9wrg"}]},{"advisoryId":"PKSA-hz4c-r4k2-54z6","packageName":"magento\/community-edition","remoteId":"GHSA-5g9f-7gqc-8hj4","title":"Magento Improper Authorization vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-5g9f-7gqc-8hj4","cve":"CVE-2024-39405","affectedVersions":"=2.4.4|=2.4.5|=2.4.6|=2.4.7|\u003E=2.4.4-p1,\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5g9f-7gqc-8hj4"}]},{"advisoryId":"PKSA-wtr2-936v-d71r","packageName":"magento\/community-edition","remoteId":"GHSA-8frp-pxq2-3gpq","title":"Magento OS Command (\u0027OS Command Injection\u0027) vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-8frp-pxq2-3gpq","cve":"CVE-2024-39401","affectedVersions":"=2.4.4|=2.4.5|=2.4.6|=2.4.7|\u003E=2.4.4-p1,\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8frp-pxq2-3gpq"}]},{"advisoryId":"PKSA-5p75-gsg6-13w9","packageName":"magento\/community-edition","remoteId":"GHSA-2ff6-837j-hg5x","title":"Magento OS Command (\u0027OS Command Injection\u0027) vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-2ff6-837j-hg5x","cve":"CVE-2024-39402","affectedVersions":"=2.4.4|=2.4.5|=2.4.6|=2.4.7|\u003E=2.4.4-p1,\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2ff6-837j-hg5x"}]},{"advisoryId":"PKSA-pd5g-z9m9-j3v5","packageName":"magento\/community-edition","remoteId":"GHSA-gvgf-pvh5-vjh4","title":"Magento Improper Authorization vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-gvgf-pvh5-vjh4","cve":"CVE-2024-39418","affectedVersions":"=2.4.4|=2.4.5|=2.4.6|=2.4.7|\u003E=2.4.4-p1,\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gvgf-pvh5-vjh4"}]},{"advisoryId":"PKSA-bjwx-9g5b-wmt6","packageName":"magento\/community-edition","remoteId":"GHSA-qrh3-vxjg-h9h6","title":"Magento Improper Authorization vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-qrh3-vxjg-h9h6","cve":"CVE-2024-39404","affectedVersions":"=2.4.4|=2.4.5|=2.4.6|=2.4.7|\u003E=2.4.4-p1,\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qrh3-vxjg-h9h6"}]},{"advisoryId":"PKSA-yjbs-rrw5-sqdn","packageName":"magento\/community-edition","remoteId":"GHSA-cjm6-8mw8-2f8c","title":"Magento Improper Authorization vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-cjm6-8mw8-2f8c","cve":"CVE-2024-39407","affectedVersions":"=2.4.4|=2.4.5|=2.4.6|=2.4.7|\u003E=2.4.4-p1,\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cjm6-8mw8-2f8c"}]},{"advisoryId":"PKSA-4h72-5zp2-d3d4","packageName":"magento\/community-edition","remoteId":"GHSA-8w5f-8992-g86j","title":"Magento Improper Authorization vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-8w5f-8992-g86j","cve":"CVE-2024-39413","affectedVersions":"=2.4.4|=2.4.5|=2.4.6|=2.4.7|\u003E=2.4.4-p1,\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8w5f-8992-g86j"}]},{"advisoryId":"PKSA-x76v-gf6x-15jx","packageName":"magento\/community-edition","remoteId":"GHSA-vhcq-4xrm-2cr2","title":"Magento Improper Access Control leads to Security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-vhcq-4xrm-2cr2","cve":"CVE-2025-27191","affectedVersions":"=2.4.7|=2.4.6|=2.4.4|=2.4.5|\u003E=2.4.8-beta1,\u003C2.4.8-beta2|\u003C2.4.4-p13|\u003E=2.4.5-p1,\u003C2.4.5-p12|\u003E=2.4.6-p1,\u003C2.4.6-p10|\u003E=2.4.7-beta1,\u003C2.4.7-p5","source":"GitHub","reportedAt":"2025-04-08 21:31:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vhcq-4xrm-2cr2"}]},{"advisoryId":"PKSA-r73x-rxyx-dytq","packageName":"magento\/community-edition","remoteId":"GHSA-2r94-wm5v-4prx","title":"Magento does not properly protect credentials","link":"https:\/\/github.com\/advisories\/GHSA-2r94-wm5v-4prx","cve":"CVE-2025-27192","affectedVersions":"=2.4.7|=2.4.6|=2.4.4|=2.4.5|\u003E=2.4.8-beta1,\u003C2.4.8-beta2|\u003C2.4.4-p13|\u003E=2.4.5-p1,\u003C2.4.5-p12|\u003E=2.4.6-p1,\u003C2.4.6-p10|\u003E=2.4.7-beta1,\u003C2.4.7-p5","source":"GitHub","reportedAt":"2025-04-08 21:31:41","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-2r94-wm5v-4prx"}]},{"advisoryId":"PKSA-4jrq-qp4c-nqw3","packageName":"magento\/community-edition","remoteId":"GHSA-qm77-mqf3-fmhq","title":"Magento Improper Authorization leads to security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-qm77-mqf3-fmhq","cve":"CVE-2024-39411","affectedVersions":"=2.4.7|=2.4.6|=2.4.5|=2.4.4|\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qm77-mqf3-fmhq"}]},{"advisoryId":"PKSA-3dsp-c62d-w319","packageName":"magento\/community-edition","remoteId":"GHSA-x6f9-hv9r-fgq4","title":"Magento Improper Access Control Leads to Privilege escalation","link":"https:\/\/github.com\/advisories\/GHSA-x6f9-hv9r-fgq4","cve":"CVE-2024-39414","affectedVersions":"=2.4.7|=2.4.6|=2.4.5|=2.4.4|\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x6f9-hv9r-fgq4"}]},{"advisoryId":"PKSA-dv99-1512-ggts","packageName":"magento\/community-edition","remoteId":"GHSA-gj93-84g5-mcjq","title":"Magento Improper Authorization Leading to Security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-gj93-84g5-mcjq","cve":"CVE-2024-39415","affectedVersions":"=2.4.7|=2.4.6|=2.4.5|=2.4.4|\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gj93-84g5-mcjq"}]},{"advisoryId":"PKSA-ym4p-zvby-x7kh","packageName":"magento\/community-edition","remoteId":"GHSA-4xgg-rw35-7mv5","title":"Magento Improper Authorization leads to Security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-4xgg-rw35-7mv5","cve":"CVE-2024-39416","affectedVersions":"=2.4.7|=2.4.6|=2.4.5|=2.4.4|\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4xgg-rw35-7mv5"}]},{"advisoryId":"PKSA-2wt1-rrt9-7zvv","packageName":"magento\/community-edition","remoteId":"GHSA-4xmj-f664-hv98","title":"Magento Improper Authorization leads to Security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-4xmj-f664-hv98","cve":"CVE-2024-39417","affectedVersions":"=2.4.7|=2.4.6|=2.4.5|=2.4.4|\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4xmj-f664-hv98"}]},{"advisoryId":"PKSA-8fss-fb1w-96f7","packageName":"magento\/community-edition","remoteId":"GHSA-74w7-cr4v-wf2v","title":"Magento Improper Access Control Leads to Privilege escalation","link":"https:\/\/github.com\/advisories\/GHSA-74w7-cr4v-wf2v","cve":"CVE-2024-39419","affectedVersions":"=2.4.7|=2.4.6|=2.4.5|=2.4.4|\u003C2.4.4-p10|\u003E=2.4.5-p1,\u003C2.4.5-p9|\u003E=2.4.6-p1,\u003C2.4.6-p7|\u003E=2.4.7-beta1,\u003C2.4.7-p2","source":"GitHub","reportedAt":"2024-08-14 12:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-74w7-cr4v-wf2v"}]},{"advisoryId":"PKSA-8xbp-3ytm-qmsr","packageName":"magento\/community-edition","remoteId":"GHSA-6wq7-cg9h-mj6q","title":"Magento Improper Access Control leads to Security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-6wq7-cg9h-mj6q","cve":"CVE-2025-27190","affectedVersions":"=2.4.7|=2.4.6|=2.4.4|=2.4.5|\u003E=2.4.8-beta1,\u003C2.4.8-beta2|\u003C2.4.4-p13|\u003E=2.4.5-p1,\u003C2.4.5-p12|\u003E=2.4.6-p1,\u003C2.4.6-p10|\u003E=2.4.7-beta1,\u003C2.4.7-p5","source":"GitHub","reportedAt":"2025-04-08 21:31:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6wq7-cg9h-mj6q"}]},{"advisoryId":"PKSA-z33d-78qh-jd88","packageName":"magento\/community-edition","remoteId":"GHSA-85jx-x9r4-45m2","title":"Magento Authenticated Security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-85jx-x9r4-45m2","cve":"CVE-2025-49549","affectedVersions":"=2.4.8|=2.4.7|=2.4.6|=2.4.5|\u003C2.4.5-p13|\u003E=2.4.6-p1,\u003C2.4.6-p11|\u003E=2.4.7-beta1,\u003C2.4.7-p6","source":"GitHub","reportedAt":"2025-06-26 21:31:13","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-85jx-x9r4-45m2"}]},{"advisoryId":"PKSA-25jg-bht9-cn5m","packageName":"magento\/community-edition","remoteId":"GHSA-r487-9vv5-75gg","title":"Magento Improper Authorization leading to security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-r487-9vv5-75gg","cve":"CVE-2025-43585","affectedVersions":"=2.4.8|=2.4.7|=2.4.6|=2.4.5|\u003C2.4.5-p13|\u003E=2.4.6-p1,\u003C2.4.6-p11|\u003E=2.4.7-beta1,\u003C2.4.7-p6","source":"GitHub","reportedAt":"2025-06-10 18:32:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r487-9vv5-75gg"}]},{"advisoryId":"PKSA-twxs-5jt6-zf4j","packageName":"magento\/community-edition","remoteId":"GHSA-g2pj-xmxq-3r9q","title":"Magento Improper Access Control leads to security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-g2pj-xmxq-3r9q","cve":"CVE-2025-27206","affectedVersions":"=2.4.8|=2.4.7|=2.4.6|=2.4.5|\u003C2.4.5-p13|\u003E=2.4.6-p1,\u003C2.4.6-p11|\u003E=2.4.7-beta1,\u003C2.4.7-p6","source":"GitHub","reportedAt":"2025-06-10 18:32:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g2pj-xmxq-3r9q"}]},{"advisoryId":"PKSA-w1hm-vgyt-d5ty","packageName":"magento\/community-edition","remoteId":"GHSA-8hcx-xvww-6c6h","title":"Magento Security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-8hcx-xvww-6c6h","cve":"CVE-2025-49550","affectedVersions":"=2.4.8|=2.4.7|=2.4.6|=2.4.5|\u003C2.4.5-p13|\u003E=2.4.6-p1,\u003C2.4.6-p11|\u003E=2.4.7-beta1,\u003C2.4.7-p6","source":"GitHub","reportedAt":"2025-06-26 21:31:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8hcx-xvww-6c6h"}]},{"advisoryId":"PKSA-jghm-1dxh-r2mf","packageName":"magento\/community-edition","remoteId":"GHSA-wcmw-8xpp-rwfj","title":"Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-wcmw-8xpp-rwfj","cve":"CVE-2025-49558","affectedVersions":"=2.4.8|=2.4.7|=2.4.6|=2.4.5|\u003C2.4.5-p14|\u003E=2.4.6-p1,\u003C2.4.6-p12|\u003E=2.4.7-beta1,\u003C2.4.7-p7|\u003E=2.4.8-beta1,\u003C2.4.8-p2|\u003E=2.4.9-alpha1,\u003C2.4.9-alpha2","source":"GitHub","reportedAt":"2025-08-12 18:31:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wcmw-8xpp-rwfj"}]},{"advisoryId":"PKSA-23gm-rmhm-83mc","packageName":"magento\/community-edition","remoteId":"GHSA-5777-jj7p-mpqw","title":"Magento Cross-Site Request Forgery (CSRF) vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-5777-jj7p-mpqw","cve":"CVE-2025-49555","affectedVersions":"=2.4.8|=2.4.7|=2.4.6|=2.4.5|\u003C2.4.5-p14|\u003E=2.4.6-p1,\u003C2.4.6-p12|\u003E=2.4.7-beta1,\u003C2.4.7-p7|\u003E=2.4.8-beta1,\u003C2.4.8-p2|\u003E=2.4.9-alpha1,\u003C2.4.9-alpha2","source":"GitHub","reportedAt":"2025-08-12 18:31:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5777-jj7p-mpqw"}]},{"advisoryId":"PKSA-br3d-5r49-ycpt","packageName":"magento\/community-edition","remoteId":"GHSA-7hrj-3c9x-xv5h","title":"Magento has incorrect authorization issue that leads to arbitrary file system read","link":"https:\/\/github.com\/advisories\/GHSA-7hrj-3c9x-xv5h","cve":"CVE-2025-49556","affectedVersions":"=2.4.8|=2.4.7|=2.4.6|=2.4.5|\u003C2.4.5-p14|\u003E=2.4.6-p1,\u003C2.4.6-p12|\u003E=2.4.7-beta1,\u003C2.4.7-p7|\u003E=2.4.8-beta1,\u003C2.4.8-p2|\u003E=2.4.9-alpha1,\u003C2.4.9-alpha2","source":"GitHub","reportedAt":"2025-08-12 18:31:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7hrj-3c9x-xv5h"}]},{"advisoryId":"PKSA-j661-47kj-8y19","packageName":"magento\/community-edition","remoteId":"GHSA-h4f4-gv6h-x824","title":"Magento vulnerable to path traversal","link":"https:\/\/github.com\/advisories\/GHSA-h4f4-gv6h-x824","cve":"CVE-2025-49559","affectedVersions":"=2.4.8|=2.4.7|=2.4.6|=2.4.5|\u003C2.4.5-p14|\u003E=2.4.6-p1,\u003C2.4.6-p12|\u003E=2.4.7-beta1,\u003C2.4.7-p7|\u003E=2.4.8-beta1,\u003C2.4.8-p2|\u003E=2.4.9-alpha1,\u003C2.4.9-alpha2","source":"GitHub","reportedAt":"2025-08-12 18:31:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h4f4-gv6h-x824"}]},{"advisoryId":"PKSA-pn21-84x4-fh3j","packageName":"magento\/community-edition","remoteId":"GHSA-xgfm-992v-h2hr","title":"Magento vulnerable to denial of service","link":"https:\/\/github.com\/advisories\/GHSA-xgfm-992v-h2hr","cve":"CVE-2025-49554","affectedVersions":"=2.4.8|=2.4.7|=2.4.6|=2.4.5|\u003C2.4.5-p14|\u003E=2.4.6-p1,\u003C2.4.6-p12|\u003E=2.4.7-beta1,\u003C2.4.7-p7|\u003E=2.4.8-beta1,\u003C2.4.8-p2|\u003E=2.4.9-alpha1,\u003C2.4.9-alpha2","source":"GitHub","reportedAt":"2025-08-12 18:31:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xgfm-992v-h2hr"}]},{"advisoryId":"PKSA-kfkq-dx9k-8hdv","packageName":"magento\/community-edition","remoteId":"GHSA-2768-5wmv-cfff","title":"Magento vulnerable to stored Cross-Site Scripting (XSS)","link":"https:\/\/github.com\/advisories\/GHSA-2768-5wmv-cfff","cve":"CVE-2025-54264","affectedVersions":"=2.4.6|=2.4.7|=2.4.8|\u003C2.4.6-p13|\u003E=2.4.7-beta1,\u003C2.4.7-p8|\u003E=2.4.8-beta1,\u003C2.4.8-p3|\u003E=2.4.9-alpha1,\u003C2.4.9-alpha3","source":"GitHub","reportedAt":"2025-10-14 21:30:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2768-5wmv-cfff"}]},{"advisoryId":"PKSA-k1pj-8rhw-k527","packageName":"magento\/community-edition","remoteId":"GHSA-pcrx-r49h-x2w5","title":"Magento vulnerable to stored Cross-Site Scripting (XSS)","link":"https:\/\/github.com\/advisories\/GHSA-pcrx-r49h-x2w5","cve":"CVE-2025-54266","affectedVersions":"=2.4.6|=2.4.7|=2.4.8|\u003C2.4.6-p13|\u003E=2.4.7-beta1,\u003C2.4.7-p8|\u003E=2.4.8-beta1,\u003C2.4.8-p3|\u003E=2.4.9-alpha1,\u003C2.4.9-alpha3","source":"GitHub","reportedAt":"2025-10-14 21:30:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pcrx-r49h-x2w5"}]},{"advisoryId":"PKSA-cdwr-82gv-fq4r","packageName":"magento\/community-edition","remoteId":"GHSA-qvwr-p3hj-j6jf","title":"Magento vulnerable to privilege escalation due to incorrect authorization","link":"https:\/\/github.com\/advisories\/GHSA-qvwr-p3hj-j6jf","cve":"CVE-2025-54267","affectedVersions":"=2.4.6|=2.4.7|=2.4.8|\u003C2.4.6-p13|\u003E=2.4.7-beta1,\u003C2.4.7-p8|\u003E=2.4.8-beta1,\u003C2.4.8-p3|\u003E=2.4.9-alpha1,\u003C2.4.9-alpha3","source":"GitHub","reportedAt":"2025-10-14 21:30:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qvwr-p3hj-j6jf"}]},{"advisoryId":"PKSA-sx8r-h4sj-cx12","packageName":"magento\/community-edition","remoteId":"GHSA-69x9-xp2j-w8g8","title":"Magento provides incorrect authorization through a security feature bypass","link":"https:\/\/github.com\/advisories\/GHSA-69x9-xp2j-w8g8","cve":"CVE-2025-54263","affectedVersions":"=2.4.6|=2.4.7|=2.4.8|\u003C2.4.6-p13|\u003E=2.4.7-beta1,\u003C2.4.7-p8|\u003E=2.4.8-beta1,\u003C2.4.8-p3|\u003E=2.4.9-alpha1,\u003C2.4.9-alpha3","source":"GitHub","reportedAt":"2025-10-14 21:30:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-69x9-xp2j-w8g8"}]},{"advisoryId":"PKSA-xbxj-3c74-rztg","packageName":"magento\/community-edition","remoteId":"GHSA-r355-75hw-r8jf","title":"Magento allows incorrect authorization","link":"https:\/\/github.com\/advisories\/GHSA-r355-75hw-r8jf","cve":"CVE-2025-54265","affectedVersions":"=2.4.6|=2.4.7|=2.4.8|\u003C2.4.6-p13|\u003E=2.4.7-beta1,\u003C2.4.7-p8|\u003E=2.4.8-beta1,\u003C2.4.8-p3|\u003E=2.4.9-alpha1,\u003C2.4.9-alpha3","source":"GitHub","reportedAt":"2025-10-14 21:30:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r355-75hw-r8jf"}]}],"drupal\/plausible_tracking":[{"advisoryId":"PKSA-8z3c-snh8-nf6s","packageName":"drupal\/plausible_tracking","remoteId":"GHSA-pr6m-qwrr-mrw9","title":"Drupal Plausible tracking is vulnerable to XSS","link":"https:\/\/github.com\/advisories\/GHSA-pr6m-qwrr-mrw9","cve":"CVE-2025-10927","affectedVersions":"\u003C1.0.2","source":"GitHub","reportedAt":"2025-10-30 00:31:03","composerRepository":null,"severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pr6m-qwrr-mrw9"}]}],"drupal\/json_field":[{"advisoryId":"PKSA-t9qv-pb7s-jf1n","packageName":"drupal\/json_field","remoteId":"GHSA-m3f2-xjgc-2wp2","title":"Drupal JSON Field is vulnerable to XSS","link":"https:\/\/github.com\/advisories\/GHSA-m3f2-xjgc-2wp2","cve":"CVE-2025-10926","affectedVersions":"\u003C1.5","source":"GitHub","reportedAt":"2025-10-30 00:31:03","composerRepository":null,"severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m3f2-xjgc-2wp2"}]}],"drupal\/access_code":[{"advisoryId":"PKSA-fdgf-8d3d-t118","packageName":"drupal\/access_code","remoteId":"GHSA-27mc-9399-r9mx","title":"Drupal Access code allows Brute Force Attempts","link":"https:\/\/github.com\/advisories\/GHSA-27mc-9399-r9mx","cve":"CVE-2025-10928","affectedVersions":"\u003C2.0.5","source":"GitHub","reportedAt":"2025-10-30 00:31:03","composerRepository":null,"severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-27mc-9399-r9mx"}]}],"drupal\/reverse_proxy_header":[{"advisoryId":"PKSA-zp2q-9sfp-d51m","packageName":"drupal\/reverse_proxy_header","remoteId":"GHSA-fg8x-q69g-4qp3","title":"Drupal Reverse Proxy Header allows Manipulating User-Controlled Variables","link":"https:\/\/github.com\/advisories\/GHSA-fg8x-q69g-4qp3","cve":"CVE-2025-10929","affectedVersions":"\u003C1.1.2","source":"GitHub","reportedAt":"2025-10-30 00:31:03","composerRepository":null,"severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fg8x-q69g-4qp3"}]}],"drupal\/currency":[{"advisoryId":"PKSA-d8sh-729j-6w84","packageName":"drupal\/currency","remoteId":"GHSA-27fv-rpgj-4c6m","title":"Drupal Currency allows Cross Site Request Forgery","link":"https:\/\/github.com\/advisories\/GHSA-27fv-rpgj-4c6m","cve":"CVE-2025-10930","affectedVersions":"\u003C3.5.0","source":"GitHub","reportedAt":"2025-10-30 00:31:03","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-27fv-rpgj-4c6m"}]}],"drupal\/umami_analytics":[{"advisoryId":"PKSA-x4r9-5mtv-mvfz","packageName":"drupal\/umami_analytics","remoteId":"GHSA-jxp8-4jw5-5xjc","title":"Drupal Umami Analytics allows Cross-Site Scripting (XSS)","link":"https:\/\/github.com\/advisories\/GHSA-jxp8-4jw5-5xjc","cve":"CVE-2025-10931","affectedVersions":"\u003C1.0.1","source":"GitHub","reportedAt":"2025-10-30 00:31:03","composerRepository":null,"severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-jxp8-4jw5-5xjc"}]}],"drupal\/civictheme":[{"advisoryId":"PKSA-m5mf-b7jq-1pd7","packageName":"drupal\/civictheme","remoteId":"GHSA-qxr9-f877-9842","title":"Drupal CivicTheme Design System allows Forceful Browsing","link":"https:\/\/github.com\/advisories\/GHSA-qxr9-f877-9842","cve":"CVE-2025-12082","affectedVersions":"\u003C1.12.0","source":"GitHub","reportedAt":"2025-10-30 00:31:03","composerRepository":null,"severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qxr9-f877-9842"}]},{"advisoryId":"PKSA-s44h-fq47-7818","packageName":"drupal\/civictheme","remoteId":"GHSA-h72q-cq3w-h3wc","title":"Drupal CivicTheme Design System allows Cross-Site Scripting (XSS)","link":"https:\/\/github.com\/advisories\/GHSA-h72q-cq3w-h3wc","cve":"CVE-2025-12083","affectedVersions":"\u003C1.12.0","source":"GitHub","reportedAt":"2025-10-30 00:31:04","composerRepository":null,"severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h72q-cq3w-h3wc"}]}],"drupal\/simple_oauth":[{"advisoryId":"PKSA-stzp-mdgx-vvfm","packageName":"drupal\/simple_oauth","remoteId":"GHSA-jqmq-fpwv-p925","title":"Drupal Simple OAuth (OAuth2) \u0026 OpenID Connect allows Authentication Bypass","link":"https:\/\/github.com\/advisories\/GHSA-jqmq-fpwv-p925","cve":"CVE-2025-12466","affectedVersions":"\u003E=6.0.0,\u003C6.0.7","source":"GitHub","reportedAt":"2025-10-30 00:31:04","composerRepository":null,"severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jqmq-fpwv-p925"}]}],"drupal\/acquia_dam":[{"advisoryId":"PKSA-16yb-bgv6-t7wn","packageName":"drupal\/acquia_dam","remoteId":"GHSA-x957-32v9-m7vg","title":"Drupal Acquia DAM allows Forceful Browsing","link":"https:\/\/github.com\/advisories\/GHSA-x957-32v9-m7vg","cve":"CVE-2025-9954","affectedVersions":"\u003C1.1.5","source":"GitHub","reportedAt":"2025-10-30 00:31:04","composerRepository":null,"severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-x957-32v9-m7vg"}]}],"spiral\/roadrunner":[{"advisoryId":"PKSA-xbp4-qwr2-cbjj","packageName":"spiral\/roadrunner","remoteId":"GHSA-g9pc-8g42-g6vq","title":"RoadRunner is at risk of HTTP Request\/Response Smuggling through vulnerable dependency","link":"https:\/\/github.com\/advisories\/GHSA-g9pc-8g42-g6vq","cve":"CVE-2025-22871","affectedVersions":"\u003C2025.1.0","source":"GitHub","reportedAt":"2025-04-08 21:31:40","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-g9pc-8g42-g6vq"}]}],"tastyigniter\/tastyigniter":[{"advisoryId":"PKSA-2j77-dkzc-fvh4","packageName":"tastyigniter\/tastyigniter","remoteId":"GHSA-4vrf-42cm-7xfw","title":"TastyIgniter vulnerable to Cross-Site Scripting","link":"https:\/\/github.com\/advisories\/GHSA-4vrf-42cm-7xfw","cve":"CVE-2025-61417","affectedVersions":"\u003C=3.7.7","source":"GitHub","reportedAt":"2025-10-20 15:30:25","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-4vrf-42cm-7xfw"}]}],"mediawiki\/cargo":[{"advisoryId":"PKSA-bb77-zfrc-vcxv","packageName":"mediawiki\/cargo","remoteId":"GHSA-gr6v-3pmp-996p","title":"Cargo Mediawiki Extension vulnerable to Cross-site Scripting","link":"https:\/\/github.com\/advisories\/GHSA-gr6v-3pmp-996p","cve":"CVE-2025-62671","affectedVersions":"\u003C3.8.3","source":"GitHub","reportedAt":"2025-10-18 06:30:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gr6v-3pmp-996p"}]},{"advisoryId":"PKSA-w6b2-2h1z-9nq4","packageName":"mediawiki\/cargo","remoteId":"GHSA-rhpm-63w5-79rg","title":"MediaWiki Cargo Extension Cross-site Scripting vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-rhpm-63w5-79rg","cve":"CVE-2024-23173","affectedVersions":"\u003E=1.40.0,\u003C1.40.2|\u003E=1.36.0,\u003C1.39.6|\u003C1.35.14","source":"GitHub","reportedAt":"2024-01-12 06:30:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rhpm-63w5-79rg"}]}],"starcitizentools\/citizen-skin":[{"advisoryId":"PKSA-cbz7-rhx5-jhnf","packageName":"starcitizentools\/citizen-skin","remoteId":"GHSA-g955-vw6w-v6pp","title":"Citizen vulnerable to stored XSS in sticky header button messages","link":"https:\/\/github.com\/advisories\/GHSA-g955-vw6w-v6pp","cve":"CVE-2025-62508","affectedVersions":"\u003E=3.3.0,\u003C3.9.0","source":"GitHub","reportedAt":"2025-10-20 15:31:06","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g955-vw6w-v6pp"}]}],"ibexa\/fieldtype-richtext":[{"advisoryId":"PKSA-v9dn-k1j5-qdf9","packageName":"ibexa\/fieldtype-richtext","remoteId":"GHSA-8c2g-f8jm-5cr7","title":"ibexa\/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text","link":"https:\/\/github.com\/advisories\/GHSA-8c2g-f8jm-5cr7","cve":null,"affectedVersions":"\u003E=4.6.0,\u003C4.6.25|\u003E=5.0.0,\u003C5.0.3","source":"GitHub","reportedAt":"2025-10-17 18:05:09","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8c2g-f8jm-5cr7"}]}],"ezsystems\/ezplatform-admin-ui":[{"advisoryId":"PKSA-h4qf-qt17-8928","packageName":"ezsystems\/ezplatform-admin-ui","remoteId":"GHSA-99c7-c3mw-mxhv","title":"ezsystems\/ezplatform-admin-ui has an XSS vulnerability in Cancel\/Reschedule future publication modal","link":"https:\/\/github.com\/advisories\/GHSA-99c7-c3mw-mxhv","cve":null,"affectedVersions":"\u003E=2.3.0,\u003C2.3.39","source":"GitHub","reportedAt":"2025-10-17 17:58:44","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-99c7-c3mw-mxhv"}]}],"ibexa\/admin-ui":[{"advisoryId":"PKSA-5whn-x73z-qrr9","packageName":"ibexa\/admin-ui","remoteId":"GHSA-2mx6-fq24-g2mh","title":"ibexa\/admin-ui has an XSS vulnerability in Cancel\/Reschedule future publication modal","link":"https:\/\/github.com\/advisories\/GHSA-2mx6-fq24-g2mh","cve":null,"affectedVersions":"\u003E=4.6.0,\u003C4.6.25|\u003E=5.0.0,\u003C5.0.3","source":"GitHub","reportedAt":"2025-10-17 17:59:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2mx6-fq24-g2mh"}]}],"alt-design\/alt-redirect":[{"advisoryId":"PKSA-hdkd-9mx9-ck1z","packageName":"alt-design\/alt-redirect","remoteId":"GHSA-rpjr-pcmr-9ppw","title":"Alt Redirect: Potential Authentication Bypass by Spoofing  through query-string stripping logic flaw","link":"https:\/\/github.com\/advisories\/GHSA-rpjr-pcmr-9ppw","cve":"CVE-2025-60868","affectedVersions":"\u003C1.6.4","source":"GitHub","reportedAt":"2025-10-10 15:31:28","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rpjr-pcmr-9ppw"}]}],"drupal-pattern-lab\/unified-twig-extensions":[{"advisoryId":"PKSA-6qhr-rbrh-wf1g","packageName":"drupal-pattern-lab\/unified-twig-extensions","remoteId":"GHSA-64mv-9655-37hx","title":"drupal-pattern-lab\/unified-twig-extensions is vulnerable to XXS","link":"https:\/\/github.com\/advisories\/GHSA-64mv-9655-37hx","cve":"CVE-2025-11570","affectedVersions":"\u003C=0.1.0","source":"GitHub","reportedAt":"2025-10-10 06:30:55","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-64mv-9655-37hx"}]}],"open-web-analytics\/open-web-analytics":[{"advisoryId":"PKSA-dqkz-nddh-xgmn","packageName":"open-web-analytics\/open-web-analytics","remoteId":"GHSA-6w8r-xgqq-qg6g","title":"Open Web Analytics Server is vulnerable to SQL Injection","link":"https:\/\/github.com\/advisories\/GHSA-6w8r-xgqq-qg6g","cve":"CVE-2025-59397","affectedVersions":"\u003C1.8.1","source":"GitHub","reportedAt":"2025-09-15 18:31:06","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6w8r-xgqq-qg6g"}]}],"melisplatform\/melis-cms-slider":[{"advisoryId":"PKSA-17wp-2fff-jd3r","packageName":"melisplatform\/melis-cms-slider","remoteId":"GHSA-chw4-gjvw-3gxc","title":"Melis Platform CMS Unauthenticated File Upload Leading to RCE","link":"https:\/\/github.com\/advisories\/GHSA-chw4-gjvw-3gxc","cve":"CVE-2025-10353","affectedVersions":"\u003C5.3.1","source":"GitHub","reportedAt":"2025-10-08 12:30:26","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-chw4-gjvw-3gxc"}]}],"melisplatform\/melis-cms":[{"advisoryId":"PKSA-3nd4-696g-321j","packageName":"melisplatform\/melis-cms","remoteId":"GHSA-mrmx-jfw8-qhgv","title":"Melis Platform CMS SQL Injection","link":"https:\/\/github.com\/advisories\/GHSA-mrmx-jfw8-qhgv","cve":"CVE-2025-10351","affectedVersions":"\u003C5.3.4","source":"GitHub","reportedAt":"2025-10-08 12:30:26","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-mrmx-jfw8-qhgv"}]}],"melisplatform\/melis-core":[{"advisoryId":"PKSA-4z78-5t59-ws2h","packageName":"melisplatform\/melis-core","remoteId":"GHSA-p3vc-g9f9-mgw4","title":"Melis Platform CMS Unauthenticated Admin Account Creation","link":"https:\/\/github.com\/advisories\/GHSA-p3vc-g9f9-mgw4","cve":"CVE-2025-10352","affectedVersions":"\u003C5.3.11","source":"GitHub","reportedAt":"2025-10-08 12:30:26","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-p3vc-g9f9-mgw4"}]}],"webreinvent\/vaahcms":[{"advisoryId":"PKSA-1567-r2np-36n6","packageName":"webreinvent\/vaahcms","remoteId":"GHSA-q769-phqg-263r","title":"VaahCMS is vulnerable to XSS through its Avatar Upload endpoint","link":"https:\/\/github.com\/advisories\/GHSA-q769-phqg-263r","cve":"CVE-2025-61183","affectedVersions":"\u003C=2.3.1","source":"GitHub","reportedAt":"2025-10-08 15:32:27","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q769-phqg-263r"}]}],"novosga\/novosga":[{"advisoryId":"PKSA-3wc8-k4ky-rszh","packageName":"novosga\/novosga","remoteId":"GHSA-xgr2-5837-hf48","title":"NovoSGA: Manipulation of User Creation Page can lead to weak password requirements","link":"https:\/\/github.com\/advisories\/GHSA-xgr2-5837-hf48","cve":"CVE-2025-11322","affectedVersions":"\u003C=2.2.12","source":"GitHub","reportedAt":"2025-10-06 06:32:58","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xgr2-5837-hf48"}]}],"joomla\/filter":[{"advisoryId":"PKSA-5x9t-bkbj-vmgp","packageName":"joomla\/filter","remoteId":"GHSA-fm22-g2q9-j3pw","title":"Joomla! CMS vulnerable to XSS via the input filter","link":"https:\/\/github.com\/advisories\/GHSA-fm22-g2q9-j3pw","cve":"CVE-2025-54476","affectedVersions":"\u003C2.0.6|\u003E=3.0.0,\u003C3.0.5|=4.0.0","source":"GitHub","reportedAt":"2025-09-30 18:30:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fm22-g2q9-j3pw"}]}],"macropay-solutions\/laravel-crud-wizard-free":[{"advisoryId":"PKSA-2qkb-kmvg-dvr2","packageName":"macropay-solutions\/laravel-crud-wizard-free","remoteId":"GHSA-3wgq-h4fr-cwg5","title":"laravel-crud-wizard-free has File Validation Bypass ","link":"https:\/\/github.com\/advisories\/GHSA-3wgq-h4fr-cwg5","cve":null,"affectedVersions":"\u003C3.4.17","source":"GitHub","reportedAt":"2025-03-12 15:56:23","composerRepository":null,"severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3wgq-h4fr-cwg5"}]}],"components\/jquery":[{"advisoryId":"PKSA-jvpv-pcrn-dfzc","packageName":"components\/jquery","remoteId":"GHSA-gxr4-xjj5-5px2","title":"Potential XSS vulnerability in jQuery","link":"https:\/\/github.com\/advisories\/GHSA-gxr4-xjj5-5px2","cve":"CVE-2020-11022","affectedVersions":"\u003E=1.12.0,\u003C3.5.0","source":"GitHub","reportedAt":"2020-04-29 22:18:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gxr4-xjj5-5px2"}]}],"guzzlehttp\/oauth-subscriber":[{"advisoryId":"PKSA-pg71-gz29-h5sq","packageName":"guzzlehttp\/oauth-subscriber","remoteId":"guzzlehttp\/oauth-subscriber\/CVE-2025-21617.yaml","title":"Insufficient nonce entropy","link":"https:\/\/github.com\/guzzle\/oauth-subscriber\/security\/advisories\/GHSA-237r-r8m4-4q88","cve":"CVE-2025-21617","affectedVersions":"\u003C0.8.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2025-01-06 19:15:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-237r-r8m4-4q88"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"guzzlehttp\/oauth-subscriber\/CVE-2025-21617.yaml"}]}],"bmarshall511\/wordpress_zero_spam":[{"advisoryId":"PKSA-jcz7-jd9z-h4sz","packageName":"bmarshall511\/wordpress_zero_spam","remoteId":"GHSA-pq2f-3fg3-rw99","title":"SQL Injection in WordPress Zero Spam WordPress plugin","link":"https:\/\/github.com\/advisories\/GHSA-pq2f-3fg3-rw99","cve":"CVE-2022-0254","affectedVersions":"\u003C5.2.13","source":"GitHub","reportedAt":"2022-03-15 00:00:57","composerRepository":null,"severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-pq2f-3fg3-rw99"}]}],"matyhtf\/framework":[{"advisoryId":"PKSA-vwwh-km91-p9cn","packageName":"matyhtf\/framework","remoteId":"matyhtf\/framework\/CVE-2021-43676.yaml","title":"Path manipulation","link":"https:\/\/github.com\/advisories\/GHSA-mh9j-v6mq-pfch","cve":"CVE-2021-43676","affectedVersions":"\u003C3.0.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2022-03-17 16:15:10","composerRepository":null,"severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-mh9j-v6mq-pfch"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"matyhtf\/framework\/CVE-2021-43676.yaml"}]}],"terminal42\/contao-tablelookupwizard":[{"advisoryId":"PKSA-g8yy-64fv-qdtr","packageName":"terminal42\/contao-tablelookupwizard","remoteId":"terminal42\/contao-tablelookupwizard\/2022-02-04-1.yaml","title":"Possible SQL injection in widget field value","link":"https:\/\/github.com\/terminal42\/contao-tablelookupwizard\/security\/advisories\/GHSA-v3mr-gp7j-pw5w","cve":null,"affectedVersions":"\u003E=1.0.0,\u003C3.3.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2022-02-04 00:00:00","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-v3mr-gp7j-pw5w"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"terminal42\/contao-tablelookupwizard\/2022-02-04-1.yaml"}]}],"friendsoftypo3\/mediace":[{"advisoryId":"PKSA-h7r9-7xjm-kxrb","packageName":"friendsoftypo3\/mediace","remoteId":"friendsoftypo3\/mediace\/CVE-2020-15086.yaml","title":"Sensitive Information Disclosure in extension \u0022Media Content Element\u0022 (mediace)","link":"https:\/\/typo3.org\/security\/advisory\/typo3-ext-sa-2020-014","cve":"CVE-2020-15086","affectedVersions":"\u003E=7.6.2,\u003C7.6.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2020-07-16 07:31:32","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"friendsoftypo3\/mediace\/CVE-2020-15086.yaml"},{"name":"GitHub","remoteId":"GHSA-4h44-w6fm-548g"}]}],"smarty\/smarty":[{"advisoryId":"PKSA-wc9h-gs49-76tm","packageName":"smarty\/smarty","remoteId":"smarty\/smarty\/CVE-2021-26119.yaml","title":"template_object Sandbox Escape PHP Code Injection","link":"https:\/\/srcincite.io\/blog\/2021\/02\/18\/smarty-template-engine-multiple-sandbox-escape-vulnerabilities.html","cve":"CVE-2021-26119","affectedVersions":"\u003C3.1.39","source":"FriendsOfPHP\/security-advisories","reportedAt":"2021-01-24 22:13:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w5hr-jm4j-9jvq"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"smarty\/smarty\/CVE-2021-26119.yaml"}]},{"advisoryId":"PKSA-t4kv-1sv2-1mzx","packageName":"smarty\/smarty","remoteId":"smarty\/smarty\/CVE-2021-26120.yaml","title":"Smarty_Internal_Runtime_TplFunction Sandbox Escape PHP Code Injection","link":"https:\/\/srcincite.io\/blog\/2021\/02\/18\/smarty-template-engine-multiple-sandbox-escape-vulnerabilities.html","cve":"CVE-2021-26120","affectedVersions":"\u003C3.1.39","source":"FriendsOfPHP\/security-advisories","reportedAt":"2021-01-24 22:44:07","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-3rpf-5rqv-689q"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"smarty\/smarty\/CVE-2021-26120.yaml"}]}],"cartalyst\/sentry":[{"advisoryId":"PKSA-p714-559s-qh89","packageName":"cartalyst\/sentry","remoteId":"cartalyst\/sentry\/2016-09-05.yaml","title":"Null reset codes were allowed","link":"https:\/\/haxx.ml\/post\/149975211631\/how-i-hacked-your-cfp-and-probably-some-other","cve":null,"affectedVersions":"\u003C2.1.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2016-09-05 00:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"cartalyst\/sentry\/2016-09-05.yaml"},{"name":"GitHub","remoteId":"GHSA-2m5g-8xpw-42vp"}]}],"doctrine\/doctrine-module":[{"advisoryId":"PKSA-hmqc-47pt-5r54","packageName":"doctrine\/doctrine-module","remoteId":"doctrine\/doctrine-module\/2013-05-16.yaml","title":"Authentication Vulnerability - possible attempt to login via zero-valued password credential","link":"https:\/\/github.com\/doctrine\/DoctrineModule\/issues\/249","cve":null,"affectedVersions":"\u003C0.7.2|\u003C0.7.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2013-05-16 00:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"doctrine\/doctrine-module\/2013-05-16.yaml"},{"name":"GitHub","remoteId":"GHSA-9wv8-3h8h-x2wc"}]}],"ezsystems\/ezpublish-kernel":[{"advisoryId":"PKSA-b8pq-brvg-3dyp","packageName":"ezsystems\/ezpublish-kernel","remoteId":"ezsystems\/ezpublish-kernel\/2020-05-20-1.yaml","title":"EZSA-2020-004 Object Injection in SiteAccessMatchListener","link":"https:\/\/ezplatform.com\/security-advisories\/ezsa-2020-004-object-injection-in-siteaccessmatchlistener","cve":null,"affectedVersions":"\u003E=7.5.0,\u003C7.5.7.1|\u003E=6.13.0,\u003C6.13.6.3|\u003E=5.4.0,\u003C5.4.14.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2020-05-20 00:00:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"ezsystems\/ezpublish-kernel\/2020-05-20-1.yaml"},{"name":"GitHub","remoteId":"GHSA-gmrf-99gw-vvwj"}]}],"propel\/propel":[{"advisoryId":"PKSA-7tyg-2kv3-kq8f","packageName":"propel\/propel","remoteId":"propel\/propel\/2018-02-14.yaml","title":"SQL injection possible with limit() on MySQL","link":"https:\/\/github.com\/propelorm\/Propel2\/issues\/1463","cve":null,"affectedVersions":"\u003E=2.0.0-alpha1,\u003C2.0.0-alpha8","source":"FriendsOfPHP\/security-advisories","reportedAt":"2018-02-14 00:00:00","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-7vw7-qx38-37vr"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"propel\/propel\/2018-02-14.yaml"}]}],"propel\/propel1":[{"advisoryId":"PKSA-8rvz-ck9f-yjrd","packageName":"propel\/propel1","remoteId":"propel\/propel1\/2018-02-14.yaml","title":"SQL injection possible with limit() on MySQL","link":"https:\/\/github.com\/propelorm\/Propel\/issues\/1052","cve":null,"affectedVersions":"\u003E=1,\u003C1.7.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2018-02-14 00:00:00","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-7g7c-qhf3-x59p"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"propel\/propel1\/2018-02-14.yaml"}]}],"codeigniter\/framework":[{"advisoryId":"PKSA-9441-xhqz-8m7y","packageName":"codeigniter\/framework","remoteId":"codeigniter\/framework\/2016-07-26-1.yaml","title":"Critical SQL injection bug in the ODBC database driver","link":"https:\/\/forum.codeigniter.com\/thread-65803.html","cve":null,"affectedVersions":"\u003C3.1.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2016-07-26 00:00:00","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"codeigniter\/framework\/2016-07-26-1.yaml"},{"name":"GitHub","remoteId":"GHSA-27qr-636m-wxg2"}]}],"silverstripe\/forum":[{"advisoryId":"PKSA-schn-2b2h-yczz","packageName":"silverstripe\/forum","remoteId":"silverstripe\/forum\/SS-2015-017-1.yaml","title":"SS-2015-017: Forum Module CSRF Vulnerability","link":"https:\/\/www.silverstripe.org\/software\/download\/security-releases\/ss-2015-017\/","cve":null,"affectedVersions":"\u003C0.6.2|\u003E=0.7.0,\u003C0.7.4","source":"FriendsOfPHP\/security-advisories","reportedAt":"2015-09-14 10:38:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w8fq-xgvh-cxc2"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/forum\/SS-2015-017-1.yaml"}]}],"gree\/jose":[{"advisoryId":"PKSA-2q89-6yb3-gktz","packageName":"gree\/jose","remoteId":"gree\/jose\/2016-08-30.yaml","title":"Critical vulnerabilities in JSON Web Token libraries","link":"https:\/\/auth0.com\/blog\/critical-vulnerabilities-in-json-web-token-libraries\/","cve":null,"affectedVersions":"\u003C2.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2016-08-30 00:00:00","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-9gxv-x7rp-r2hc"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"gree\/jose\/2016-08-30.yaml"}]}],"cart2quote\/module-quotation":[{"advisoryId":"PKSA-wnmd-jkgg-b2hj","packageName":"cart2quote\/module-quotation","remoteId":"cart2quote\/module-quotation\/2017-02-01.yaml","title":"Remote Code Execution in Qquoteadv\/controllers\/DownloadController.php","link":"https:\/\/cart2quote.zendesk.com\/hc\/en-us\/articles\/115000616303--FIXED-Security-Vulnerability-in-downloadCustomOptionAction","cve":null,"affectedVersions":"\u003E=4.1.6,\u003C4.4.6|\u003E=5.0.0,\u003C5.4.4","source":"FriendsOfPHP\/security-advisories","reportedAt":"2017-02-01 00:00:00","composerRepository":null,"severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"cart2quote\/module-quotation\/2017-02-01.yaml"}]}]}}