{"advisories":{"verbb\/formie":[{"advisoryId":"PKSA-xm2v-2qmq-bmd3","packageName":"verbb\/formie","remoteId":"GHSA-cvpc-hccg-wmw4","title":"Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration","link":"https:\/\/github.com\/advisories\/GHSA-cvpc-hccg-wmw4","cve":null,"affectedVersions":"\u003C3.1.28","source":"GitHub","reportedAt":"2026-07-17 19:05:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cvpc-hccg-wmw4"}]},{"advisoryId":"PKSA-rm1g-8q6b-7djk","packageName":"verbb\/formie","remoteId":"GHSA-565m-g33j-jq96","title":"Formie Hidden field defaults vulnerable to Server-Side Template Injection","link":"https:\/\/github.com\/advisories\/GHSA-565m-g33j-jq96","cve":"CVE-2026-52889","affectedVersions":"\u003C3.1.27","source":"GitHub","reportedAt":"2026-07-06 16:52:16","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-565m-g33j-jq96"}]}],"pheditor\/pheditor":[{"advisoryId":"PKSA-c2s6-j4sd-8g42","packageName":"pheditor\/pheditor","remoteId":"GHSA-wg4w-wr5q-6vjc","title":"Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection","link":"https:\/\/github.com\/advisories\/GHSA-wg4w-wr5q-6vjc","cve":"CVE-2026-55578","affectedVersions":"\u003E=2.0.1,\u003C2.0.6","source":"GitHub","reportedAt":"2026-07-16 20:10:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wg4w-wr5q-6vjc"}]},{"advisoryId":"PKSA-fw3p-jbcz-gm98","packageName":"pheditor\/pheditor","remoteId":"GHSA-p4h7-p9rj-2pq2","title":"Pheditor: Hardcoded default password \u0027admin\u0027 with no forced change enables full application compromise","link":"https:\/\/github.com\/advisories\/GHSA-p4h7-p9rj-2pq2","cve":"CVE-2026-55579","affectedVersions":"\u003E=2.0.1,\u003C2.0.6","source":"GitHub","reportedAt":"2026-07-16 20:11:23","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-p4h7-p9rj-2pq2"}]},{"advisoryId":"PKSA-35mf-8p9f-f31c","packageName":"pheditor\/pheditor","remoteId":"GHSA-9643-6xjp-vx57","title":"Pheditor has an authenticated terminal command whitelist bypass","link":"https:\/\/github.com\/advisories\/GHSA-9643-6xjp-vx57","cve":"CVE-2026-54540","affectedVersions":"\u003C=2.0.4","source":"GitHub","reportedAt":"2026-07-16 20:01:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9643-6xjp-vx57"}]}],"typo3\/cms-fluid":[{"advisoryId":"PKSA-gq2f-sdxt-2mmr","packageName":"typo3\/cms-fluid","remoteId":"GHSA-22q7-cg4r-p9mx","title":"TYPO3 Cross-Site Scripting in Fluid ViewHelpers","link":"https:\/\/github.com\/advisories\/GHSA-22q7-cg4r-p9mx","cve":null,"affectedVersions":"\u003E=9.0.0,\u003C9.5.4|\u003E=8.0.0,\u003C8.7.23","source":"GitHub","reportedAt":"2024-05-30 15:46:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-22q7-cg4r-p9mx"}]}],"adawolfa\/isdoc":[{"advisoryId":"PKSA-zwm1-4dcx-xx1p","packageName":"adawolfa\/isdoc","remoteId":"GHSA-xg43-5579-qw6v","title":"adawolfa\/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files","link":"https:\/\/github.com\/advisories\/GHSA-xg43-5579-qw6v","cve":null,"affectedVersions":"\u003C1.4.0|\u003E=1.4.0,\u003C1.4.3|\u003E=1.5.0,\u003C1.5.1|\u003E=1.6.0,\u003C1.6.1","source":"GitHub","reportedAt":"2026-07-15 23:30:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xg43-5579-qw6v"}]}],"mantisbt\/mantisbt":[{"advisoryId":"PKSA-xw73-w41z-8sfx","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-4vpf-w7qv-5h3q","title":"MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs","link":"https:\/\/github.com\/advisories\/GHSA-4vpf-w7qv-5h3q","cve":"CVE-2026-52883","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 18:52:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4vpf-w7qv-5h3q"}]},{"advisoryId":"PKSA-vymf-gj2q-2bk6","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-h2wf-967x-gxvw","title":"MantisBT: Stored XSS in print_all_bug_page_word.php","link":"https:\/\/github.com\/advisories\/GHSA-h2wf-967x-gxvw","cve":"CVE-2026-62944","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 18:56:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h2wf-967x-gxvw"}]},{"advisoryId":"PKSA-2zcr-93ry-6511","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-3v2j-6fw9-f57c","title":"MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters","link":"https:\/\/github.com\/advisories\/GHSA-3v2j-6fw9-f57c","cve":"CVE-2026-52882","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 18:41:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3v2j-6fw9-f57c"}]},{"advisoryId":"PKSA-23vf-p9ny-hdcn","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-vcrw-4xvv-jh49","title":"MantisBT: Reflected XSS in admin\/install.php via unescaped printf ","link":"https:\/\/github.com\/advisories\/GHSA-vcrw-4xvv-jh49","cve":"CVE-2026-52881","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 18:34:36","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-vcrw-4xvv-jh49"}]},{"advisoryId":"PKSA-cgcp-ngm1-hmmf","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-77x8-3v3h-hrhv","title":"MantisBT: Reflected XSS in admin\/install.php","link":"https:\/\/github.com\/advisories\/GHSA-77x8-3v3h-hrhv","cve":"CVE-2026-52847","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 18:25:36","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-77x8-3v3h-hrhv"}]},{"advisoryId":"PKSA-6qcn-z5zm-cd63","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-m7ph-9558-mrx3","title":"MantisBT: REST API unauthorized Issue status change","link":"https:\/\/github.com\/advisories\/GHSA-m7ph-9558-mrx3","cve":"CVE-2026-49280","affectedVersions":"\u003E=2.8.0,\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 17:02:12","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m7ph-9558-mrx3"}]},{"advisoryId":"PKSA-5jjt-2py9-5v67","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-v84x-qvhg-f36r","title":"MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php","link":"https:\/\/github.com\/advisories\/GHSA-v84x-qvhg-f36r","cve":"CVE-2026-49273","affectedVersions":"\u003E=1.3.0,\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 16:52:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v84x-qvhg-f36r"}]},{"advisoryId":"PKSA-vcbb-b851-hxr5","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-c2xg-qjqw-2v98","title":"MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator","link":"https:\/\/github.com\/advisories\/GHSA-c2xg-qjqw-2v98","cve":"CVE-2026-47156","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 16:45:22","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-c2xg-qjqw-2v98"}]},{"advisoryId":"PKSA-3d2f-71dg-17ys","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-mw6p-33vw-46cc","title":"MantisBT: SQL Injection via history_order Configuration Value","link":"https:\/\/github.com\/advisories\/GHSA-mw6p-33vw-46cc","cve":"CVE-2026-47142","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 16:38:22","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mw6p-33vw-46cc"}]}],"phanan\/koel":[{"advisoryId":"PKSA-69y7-vwnx-px15","packageName":"phanan\/koel","remoteId":"GHSA-jr4p-4xjh-fwvw","title":"Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail","link":"https:\/\/github.com\/advisories\/GHSA-jr4p-4xjh-fwvw","cve":"CVE-2026-50552","affectedVersions":"\u003C=9.7.0","source":"GitHub","reportedAt":"2026-07-15 18:21:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jr4p-4xjh-fwvw"}]},{"advisoryId":"PKSA-nwpt-px6q-b5bv","packageName":"phanan\/koel","remoteId":"GHSA-rjg7-r26h-cfp2","title":"Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::\/96) or 6to4 (2002::\/16) IPv6-transition wrappers of internal IPv4","link":"https:\/\/github.com\/advisories\/GHSA-rjg7-r26h-cfp2","cve":"CVE-2026-54494","affectedVersions":"\u003C=9.7.0","source":"GitHub","reportedAt":"2026-07-15 18:21:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rjg7-r26h-cfp2"}]},{"advisoryId":"PKSA-1qtf-pcfh-kb47","packageName":"phanan\/koel","remoteId":"GHSA-6qvr-wjmv-v8mm","title":"Koel: Incomplete fix for CVE-2026-47260 \u2014 systemic SSRF in podcast \u0026 radio fetch paths","link":"https:\/\/github.com\/advisories\/GHSA-6qvr-wjmv-v8mm","cve":"CVE-2026-54491","affectedVersions":"\u003C=9.7.0","source":"GitHub","reportedAt":"2026-07-15 17:59:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6qvr-wjmv-v8mm"}]},{"advisoryId":"PKSA-74sr-w83z-r28d","packageName":"phanan\/koel","remoteId":"GHSA-8q6q-m837-fv64","title":" Koel has SSRF through Authenticated Subsonic podcast feed URLs","link":"https:\/\/github.com\/advisories\/GHSA-8q6q-m837-fv64","cve":null,"affectedVersions":"\u003C=9.6.0","source":"GitHub","reportedAt":"2026-07-15 17:31:12","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8q6q-m837-fv64"}]},{"advisoryId":"PKSA-gv41-hnht-9yhw","packageName":"phanan\/koel","remoteId":"GHSA-6p96-cfg5-4vhp","title":"Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations","link":"https:\/\/github.com\/advisories\/GHSA-6p96-cfg5-4vhp","cve":"CVE-2026-54493","affectedVersions":"\u003C=9.6.0","source":"GitHub","reportedAt":"2026-07-15 17:13:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6p96-cfg5-4vhp"}]},{"advisoryId":"PKSA-drvx-ht86-w4b7","packageName":"phanan\/koel","remoteId":"GHSA-w79m-f3jx-779v","title":"Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation","link":"https:\/\/github.com\/advisories\/GHSA-w79m-f3jx-779v","cve":"CVE-2026-54492","affectedVersions":"\u003C=9.6.0","source":"GitHub","reportedAt":"2026-07-15 17:07:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w79m-f3jx-779v"}]}],"typo3\/cms-form":[{"advisoryId":"PKSA-d4vj-m6hn-xm1j","packageName":"typo3\/cms-form","remoteId":"typo3\/cms-form\/CVE-2026-15305.yaml","title":"TYPO3-CORE-SA-2026-020: TYPO3 CMS - Unrestricted File Upload in Form Framework","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-core-sa-2026-020","cve":"CVE-2026-15305","affectedVersions":"\u003E=14.2.0,\u003C14.3.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-14 12:08:47","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-form\/CVE-2026-15305.yaml"}]}],"facturascripts\/facturascripts":[{"advisoryId":"PKSA-ckhc-1b7w-fbqb","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-hgjx-r89m-m7v4","title":"FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() \u2014 arbitrary file write outside MyFiles\/ leading to   RCE","link":"https:\/\/github.com\/advisories\/GHSA-hgjx-r89m-m7v4","cve":null,"affectedVersions":"\u003E=2025,\u003C=2026.2","source":"GitHub","reportedAt":"2026-07-14 20:52:00","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-hgjx-r89m-m7v4"}]},{"advisoryId":"PKSA-tj9x-5rgg-xzgk","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-3x7p-v8hj-xh5m","title":"FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`","link":"https:\/\/github.com\/advisories\/GHSA-3x7p-v8hj-xh5m","cve":"CVE-2026-45710","affectedVersions":"\u003C=2026.1","source":"GitHub","reportedAt":"2026-07-14 17:30:26","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-3x7p-v8hj-xh5m"}]},{"advisoryId":"PKSA-582m-pjr9-1vy2","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-5qmh-x653-g8qj","title":"FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`","link":"https:\/\/github.com\/advisories\/GHSA-5qmh-x653-g8qj","cve":"CVE-2026-45262","affectedVersions":"\u003C=2026.1","source":"GitHub","reportedAt":"2026-07-14 17:11:06","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-5qmh-x653-g8qj"}]},{"advisoryId":"PKSA-cphp-d9mj-j5ny","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-cv65-7cg8-r623","title":"FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents","link":"https:\/\/github.com\/advisories\/GHSA-cv65-7cg8-r623","cve":"CVE-2026-45693","affectedVersions":"\u003C=2026.2","source":"GitHub","reportedAt":"2026-07-14 17:12:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-cv65-7cg8-r623"}]},{"advisoryId":"PKSA-9nsq-164p-6ppm","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-2p5x-4jr6-x5jg","title":"FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export","link":"https:\/\/github.com\/advisories\/GHSA-2p5x-4jr6-x5jg","cve":"CVE-2026-45263","affectedVersions":"\u003C=2026.1","source":"GitHub","reportedAt":"2026-07-14 17:18:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2p5x-4jr6-x5jg"}]},{"advisoryId":"PKSA-dn8k-128k-8cz7","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-c67f-gmxw-mj93","title":"FacturaScripts: Account takeover of any 2FA-enabled user","link":"https:\/\/github.com\/advisories\/GHSA-c67f-gmxw-mj93","cve":"CVE-2026-47677","affectedVersions":"\u003C=2026.2","source":"GitHub","reportedAt":"2026-07-13 23:35:48","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-c67f-gmxw-mj93"}]}],"auth0\/symfony":[{"advisoryId":"PKSA-nrzm-zxwz-yhq9","packageName":"auth0\/symfony","remoteId":"GHSA-ffq7-hh2j-r24p","title":"Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter","link":"https:\/\/github.com\/advisories\/GHSA-ffq7-hh2j-r24p","cve":"CVE-2026-50157","affectedVersions":"\u003E=5.0.0-BETA0,\u003C=5.8.0","source":"GitHub","reportedAt":"2026-07-14 19:31:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-ffq7-hh2j-r24p"}]}],"concrete5\/concrete5":[{"advisoryId":"PKSA-93vh-t1hn-q1kn","packageName":"concrete5\/concrete5","remoteId":"GHSA-52pr-7vmf-2w7x","title":"Concrete CMS is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File\/Set components","link":"https:\/\/github.com\/advisories\/GHSA-52pr-7vmf-2w7x","cve":"CVE-2026-7888","affectedVersions":"\u003C9.5.2","source":"GitHub","reportedAt":"2026-06-03 21:30:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-52pr-7vmf-2w7x"}]}],"contao\/contao":[{"advisoryId":"PKSA-55tn-sgd6-9twh","packageName":"contao\/contao","remoteId":"contao\/contao\/CVE-2026-57232.yaml","title":"Server-side request forgery (SSRF) via unvalidated RSS feed URLs","link":"https:\/\/contao.org\/en\/security-advisories\/server-side-request-forgery-via-unvalidated-rss-feed-urls","cve":"CVE-2026-57232","affectedVersions":"\u003E=5.3.35,\u003C5.3.48|\u003E=5.4.0,\u003C5.7.9","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-13 09:10:22","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/CVE-2026-57232.yaml"}]},{"advisoryId":"PKSA-8pr1-zw9p-tzyx","packageName":"contao\/contao","remoteId":"contao\/contao\/CVE-2026-55824.yaml","title":"Credentials disclosure in the crawler","link":"https:\/\/contao.org\/en\/security-advisories\/credentials-disclosure-in-the-crawler","cve":"CVE-2026-55824","affectedVersions":"\u003E=4.13.0,\u003C5.3.47|\u003E=5.4.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/CVE-2026-55824.yaml"}]},{"advisoryId":"PKSA-311q-qrt9-s2k4","packageName":"contao\/contao","remoteId":"contao\/contao\/CVE-2026-55825.yaml","title":"Path traversal in the jobs module","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-jobs-module","cve":"CVE-2026-55825","affectedVersions":"\u003E=5.7.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/CVE-2026-55825.yaml"}]}],"contao\/core-bundle":[{"advisoryId":"PKSA-yx24-z15d-x2k7","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/CVE-2026-57232.yaml","title":"Server-side request forgery (SSRF) via unvalidated RSS feed URLs","link":"https:\/\/contao.org\/en\/security-advisories\/server-side-request-forgery-via-unvalidated-rss-feed-urls","cve":"CVE-2026-57232","affectedVersions":"\u003E=5.3.35,\u003C5.3.48|\u003E=5.4.0,\u003C5.7.9","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-13 09:10:22","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/CVE-2026-57232.yaml"}]},{"advisoryId":"PKSA-f8tt-pn3h-s2tw","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/CVE-2026-55824.yaml","title":"Credentials disclosure in the crawler","link":"https:\/\/contao.org\/en\/security-advisories\/credentials-disclosure-in-the-crawler","cve":"CVE-2026-55824","affectedVersions":"\u003E=4.13.0,\u003C5.3.47|\u003E=5.4.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/CVE-2026-55824.yaml"}]},{"advisoryId":"PKSA-4ps2-832y-6pns","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/CVE-2026-55825.yaml","title":"Path traversal in the jobs module","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-jobs-module","cve":"CVE-2026-55825","affectedVersions":"\u003E=5.7.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/CVE-2026-55825.yaml"}]}],"kimai\/kimai":[{"advisoryId":"PKSA-kznk-ncz5-wyws","packageName":"kimai\/kimai","remoteId":"GHSA-v8hx-4vx8-wc96","title":"Kimai: Pre-2FA KIMAI_SESSION\u00a0cookie grants full authenticated REST API access, bypassing TOTP","link":"https:\/\/github.com\/advisories\/GHSA-v8hx-4vx8-wc96","cve":"CVE-2026-52827","affectedVersions":"\u003C2.59.0","source":"GitHub","reportedAt":"2026-07-14 00:33:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v8hx-4vx8-wc96"}]},{"advisoryId":"PKSA-2sk3-y15b-6c7y","packageName":"kimai\/kimai","remoteId":"GHSA-rw46-qg69-vg6h","title":"Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access","link":"https:\/\/github.com\/advisories\/GHSA-rw46-qg69-vg6h","cve":"CVE-2026-52828","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-14 00:34:03","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rw46-qg69-vg6h"}]},{"advisoryId":"PKSA-r2bg-9v9s-cjfy","packageName":"kimai\/kimai","remoteId":"GHSA-3q6q-26vg-v97x","title":"Kimai: Improper Authorization Through Activity Creation with Preset Project Allows Creation Under Unauthorized Projects","link":"https:\/\/github.com\/advisories\/GHSA-3q6q-26vg-v97x","cve":"CVE-2026-52821","affectedVersions":"\u003C=2.56.0","source":"GitHub","reportedAt":"2026-07-14 00:03:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3q6q-26vg-v97x"}]},{"advisoryId":"PKSA-8c2d-bzrd-yygj","packageName":"kimai\/kimai","remoteId":"GHSA-c6w6-57jj-62vh","title":"Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access Revocation","link":"https:\/\/github.com\/advisories\/GHSA-c6w6-57jj-62vh","cve":"CVE-2026-52822","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-14 00:04:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c6w6-57jj-62vh"}]},{"advisoryId":"PKSA-st54-1y6x-76ks","packageName":"kimai\/kimai","remoteId":"GHSA-r8vr-m544-qh4h","title":"Kimai: Login CSRF in the Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes","link":"https:\/\/github.com\/advisories\/GHSA-r8vr-m544-qh4h","cve":"CVE-2026-52823","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-14 00:05:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r8vr-m544-qh4h"}]},{"advisoryId":"PKSA-rg27-2yxz-ng1q","packageName":"kimai\/kimai","remoteId":"GHSA-jr9p-4h4j-6c58","title":"Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover","link":"https:\/\/github.com\/advisories\/GHSA-jr9p-4h4j-6c58","cve":"CVE-2026-52824","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-14 00:07:59","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-jr9p-4h4j-6c58"}]},{"advisoryId":"PKSA-v6y1-r12h-qsx3","packageName":"kimai\/kimai","remoteId":"GHSA-xv4r-4885-gwpg","title":"Kimai has Improper Authorization in Team Member and Team Activity Assignment APIs Which Allows Expansion of Team Scope Beyond Authorized Visibility","link":"https:\/\/github.com\/advisories\/GHSA-xv4r-4885-gwpg","cve":"CVE-2026-52825","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-14 00:09:03","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xv4r-4885-gwpg"}]},{"advisoryId":"PKSA-zsy3-64rr-9k1n","packageName":"kimai\/kimai","remoteId":"GHSA-2xgg-2x8h-8xw4","title":"Kimai: Improper Authorization in Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate Manipulation","link":"https:\/\/github.com\/advisories\/GHSA-2xgg-2x8h-8xw4","cve":"CVE-2026-52826","affectedVersions":"\u003C=2.56.0","source":"GitHub","reportedAt":"2026-07-14 00:09:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2xgg-2x8h-8xw4"}]},{"advisoryId":"PKSA-35k6-pfzb-3chy","packageName":"kimai\/kimai","remoteId":"GHSA-pgcc-vfmc-7cw5","title":" Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes","link":"https:\/\/github.com\/advisories\/GHSA-pgcc-vfmc-7cw5","cve":"CVE-2026-49992","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-13 23:55:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pgcc-vfmc-7cw5"}]},{"advisoryId":"PKSA-mhmq-vzyg-sjjv","packageName":"kimai\/kimai","remoteId":"GHSA-4m8q-55qv-9pwp","title":"Kimai: Teamlead authorization bypass in GET \/api\/timesheets allows reading other users\u0027 timesheet records without being teamlead of the target","link":"https:\/\/github.com\/advisories\/GHSA-4m8q-55qv-9pwp","cve":"CVE-2026-52819","affectedVersions":"\u003C=2.56.0","source":"GitHub","reportedAt":"2026-07-13 23:55:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4m8q-55qv-9pwp"}]},{"advisoryId":"PKSA-q7f8-m7q7-t9t8","packageName":"kimai\/kimai","remoteId":"GHSA-vrr2-g9gh-c3jc","title":"Kimai: Timesheet PATCH\/POST allows assigning to project outside user\u0027s team via query_builder OR-bypass","link":"https:\/\/github.com\/advisories\/GHSA-vrr2-g9gh-c3jc","cve":"CVE-2026-52820","affectedVersions":"\u003C=2.56.0","source":"GitHub","reportedAt":"2026-07-13 23:55:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vrr2-g9gh-c3jc"}]},{"advisoryId":"PKSA-j8yw-pd54-qb9k","packageName":"kimai\/kimai","remoteId":"GHSA-pj8j-p4g4-4vw8","title":"Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs","link":"https:\/\/github.com\/advisories\/GHSA-pj8j-p4g4-4vw8","cve":"CVE-2026-49865","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-10 16:04:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pj8j-p4g4-4vw8"}]},{"advisoryId":"PKSA-c4rt-jt98-gvs8","packageName":"kimai\/kimai","remoteId":"GHSA-j5mc-p8qg-39j7","title":"Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation","link":"https:\/\/github.com\/advisories\/GHSA-j5mc-p8qg-39j7","cve":null,"affectedVersions":"\u003C=2.56.0","source":"GitHub","reportedAt":"2026-07-02 20:44:05","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-j5mc-p8qg-39j7"}]}],"nukeviet\/nukeviet":[{"advisoryId":"PKSA-npyr-6yvm-53qx","packageName":"nukeviet\/nukeviet","remoteId":"GHSA-465g-4q99-5x86","title":"NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module","link":"https:\/\/github.com\/advisories\/GHSA-465g-4q99-5x86","cve":"CVE-2026-54064","affectedVersions":"\u003C4.6.00","source":"GitHub","reportedAt":"2026-07-13 17:54:08","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-465g-4q99-5x86"}]},{"advisoryId":"PKSA-dsc1-qrmn-vnq5","packageName":"nukeviet\/nukeviet","remoteId":"GHSA-c9xg-64p9-f2jj","title":"NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function","link":"https:\/\/github.com\/advisories\/GHSA-c9xg-64p9-f2jj","cve":"CVE-2026-54065","affectedVersions":"\u003C4.6.00","source":"GitHub","reportedAt":"2026-07-13 17:55:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c9xg-64p9-f2jj"}]},{"advisoryId":"PKSA-x92d-g786-69f4","packageName":"nukeviet\/nukeviet","remoteId":"GHSA-4chg-4752-w88r","title":"NukeViet: Pre-authentication SSRF via X-Forwarded-Host","link":"https:\/\/github.com\/advisories\/GHSA-4chg-4752-w88r","cve":"CVE-2026-55372","affectedVersions":"\u003C4.6.00","source":"GitHub","reportedAt":"2026-07-13 17:58:44","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4chg-4752-w88r"}]},{"advisoryId":"PKSA-zhpy-zkp7-5p69","packageName":"nukeviet\/nukeviet","remoteId":"GHSA-mxpf-qgg6-v3ff","title":"NukeViet: Unauthenticated Reflected XSS in Comment Module","link":"https:\/\/github.com\/advisories\/GHSA-mxpf-qgg6-v3ff","cve":"CVE-2026-48118","affectedVersions":"\u003C4.5.09","source":"GitHub","reportedAt":"2026-07-13 17:21:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mxpf-qgg6-v3ff"}]},{"advisoryId":"PKSA-qw3x-tkjj-83zs","packageName":"nukeviet\/nukeviet","remoteId":"GHSA-w2w5-w2pw-r929","title":"NukeViet: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)","link":"https:\/\/github.com\/advisories\/GHSA-w2w5-w2pw-r929","cve":"CVE-2026-49259","affectedVersions":"\u003C4.5.09","source":"GitHub","reportedAt":"2026-07-13 17:22:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w2w5-w2pw-r929"}]}],"prestashop\/ps_facetedsearch":[{"advisoryId":"PKSA-36b6-kgzr-fpm3","packageName":"prestashop\/ps_facetedsearch","remoteId":"GHSA-m5f5-28qr-9g9r","title":"prestashop\/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE","link":"https:\/\/github.com\/advisories\/GHSA-m5f5-28qr-9g9r","cve":"CVE-2026-54159","affectedVersions":"\u003E=3.0.0,\u003C4.0.4","source":"GitHub","reportedAt":"2026-07-10 20:36:56","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-m5f5-28qr-9g9r"}]}],"notrinos\/notrinos-erp":[{"advisoryId":"PKSA-6c2y-dycw-7c38","packageName":"notrinos\/notrinos-erp","remoteId":"GHSA-qv4m-m73m-8hj7","title":"NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee \u0022Documents\u0022 (doc_file)","link":"https:\/\/github.com\/advisories\/GHSA-qv4m-m73m-8hj7","cve":null,"affectedVersions":"\u003C=1.0.0","source":"GitHub","reportedAt":"2026-07-10 19:34:03","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qv4m-m73m-8hj7"}]}],"api-platform\/core":[{"advisoryId":"PKSA-3ncz-km6v-5vjr","packageName":"api-platform\/core","remoteId":"GHSA-pjhx-3c3w-9v23","title":"API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate","link":"https:\/\/github.com\/advisories\/GHSA-pjhx-3c3w-9v23","cve":"CVE-2026-49858","affectedVersions":"\u003E=4.3.0,\u003C4.3.8|\u003E=4.2.0,\u003C4.2.25|\u003E=2.6.0,\u003C4.1.29","source":"GitHub","reportedAt":"2026-07-10 14:32:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pjhx-3c3w-9v23"}]}],"api-platform\/json-api":[{"advisoryId":"PKSA-scrq-f2mk-7bhq","packageName":"api-platform\/json-api","remoteId":"GHSA-pjhx-3c3w-9v23","title":"API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate","link":"https:\/\/github.com\/advisories\/GHSA-pjhx-3c3w-9v23","cve":"CVE-2026-49858","affectedVersions":"\u003E=4.3.0,\u003C4.3.8|\u003E=4.2.0,\u003C4.2.25|\u003E=4.0.0,\u003C4.1.29","source":"GitHub","reportedAt":"2026-07-10 14:32:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pjhx-3c3w-9v23"}]}],"api-platform\/hal":[{"advisoryId":"PKSA-9wr7-4vnk-wwmr","packageName":"api-platform\/hal","remoteId":"GHSA-pjhx-3c3w-9v23","title":"API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate","link":"https:\/\/github.com\/advisories\/GHSA-pjhx-3c3w-9v23","cve":"CVE-2026-49858","affectedVersions":"\u003E=4.3.0,\u003C4.3.8|\u003E=4.2.0,\u003C4.2.25|\u003E=4.0.0,\u003C4.1.29","source":"GitHub","reportedAt":"2026-07-10 14:32:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pjhx-3c3w-9v23"}]}],"yeswiki\/yeswiki":[{"advisoryId":"PKSA-7yf2-c2g9-7fm6","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-qg78-vmvc-fhjw","title":"YesWiki: SQL Injection possible through public Bazar entry-listing APIs via numeric `query`\/`queries` filters","link":"https:\/\/github.com\/advisories\/GHSA-qg78-vmvc-fhjw","cve":"CVE-2026-52770","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 21:00:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qg78-vmvc-fhjw"}]},{"advisoryId":"PKSA-tw5z-d3fj-nkdp","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-8f2v-2qhj-gfwg","title":"YesWiki: Second-Order SQL Injection in Page Delete API via Unescaped Page Tag (`ApiController::deletePage`)","link":"https:\/\/github.com\/advisories\/GHSA-8f2v-2qhj-gfwg","cve":"CVE-2026-52771","affectedVersions":"\u003E=4.2.0,\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 21:00:14","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8f2v-2qhj-gfwg"}]},{"advisoryId":"PKSA-p24r-4kjm-tm2m","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-xc7j-3g8q-9vh4","title":"YesWiki has stored XSS in Bazar form-field templates via unescaped field.label \/ field.hint (|raw(\u0027html\u0027))","link":"https:\/\/github.com\/advisories\/GHSA-xc7j-3g8q-9vh4","cve":"CVE-2026-52772","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 21:00:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xc7j-3g8q-9vh4"}]},{"advisoryId":"PKSA-g6jt-6wds-pck7","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-35f3-pg38-486f","title":"YesWiki Vulnerable to Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers\/page\/show.php`","link":"https:\/\/github.com\/advisories\/GHSA-35f3-pg38-486f","cve":"CVE-2026-52773","affectedVersions":"\u003E=4.1.0,\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 21:00:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-35f3-pg38-486f"}]},{"advisoryId":"PKSA-2dyc-2zkh-wzqj","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-r5xw-gcgw-hwp5","title":"YesWiki Vulnerable to Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes","link":"https:\/\/github.com\/advisories\/GHSA-r5xw-gcgw-hwp5","cve":"CVE-2026-52774","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 21:01:10","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r5xw-gcgw-hwp5"}]},{"advisoryId":"PKSA-d3nh-2b2t-1vs7","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-4pf7-cc4r-g63h","title":"YesWiki has Authenticated SQL Injection via ReactionManager ","link":"https:\/\/github.com\/advisories\/GHSA-4pf7-cc4r-g63h","cve":"CVE-2026-52775","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 21:02:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4pf7-cc4r-g63h"}]},{"advisoryId":"PKSA-24cb-kfcr-z2kg","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-9369-69wj-7m2f","title":"YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserialize","link":"https:\/\/github.com\/advisories\/GHSA-9369-69wj-7m2f","cve":"CVE-2026-52777","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 21:02:58","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-9369-69wj-7m2f"}]},{"advisoryId":"PKSA-hr3h-z8mz-dxgy","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-px5m-h76g-p7p8","title":"YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution \u0026 Denial of Service","link":"https:\/\/github.com\/advisories\/GHSA-px5m-h76g-p7p8","cve":"CVE-2026-52778","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 21:03:04","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-px5m-h76g-p7p8"}]},{"advisoryId":"PKSA-yfkg-9hwq-f446","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-65p8-9433-jpcp","title":"YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates","link":"https:\/\/github.com\/advisories\/GHSA-65p8-9433-jpcp","cve":"CVE-2026-52762","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 20:54:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-65p8-9433-jpcp"}]},{"advisoryId":"PKSA-qtt4-qmsv-g7gm","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-89v6-j5x6-cmj3","title":"YesWiki: SQL injection via the `recentchanges` action `period` argument leads to arbitrary DB read","link":"https:\/\/github.com\/advisories\/GHSA-89v6-j5x6-cmj3","cve":"CVE-2026-52763","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 20:54:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-89v6-j5x6-cmj3"}]},{"advisoryId":"PKSA-yjhk-d83g-23md","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-6x7x-gcmf-7r8x","title":"YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action","link":"https:\/\/github.com\/advisories\/GHSA-6x7x-gcmf-7r8x","cve":"CVE-2026-52766","affectedVersions":"\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 20:57:25","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-6x7x-gcmf-7r8x"}]},{"advisoryId":"PKSA-cyw7-d17n-rdq5","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-mv28-wj57-f57g","title":"YesWiki Vulnerable to Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`","link":"https:\/\/github.com\/advisories\/GHSA-mv28-wj57-f57g","cve":"CVE-2026-52767","affectedVersions":"\u003E=4.6.2,\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 20:58:12","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mv28-wj57-f57g"}]},{"advisoryId":"PKSA-hr6j-d2dr-68v5","packageName":"yeswiki\/yeswiki","remoteId":"GHSA-vw42-752g-5mrp","title":"YesWiki has Unauthenticated Server-Side Request Forgery via ActivityPub `Signature.keyId`","link":"https:\/\/github.com\/advisories\/GHSA-vw42-752g-5mrp","cve":"CVE-2026-52769","affectedVersions":"\u003E=4.6.2,\u003C4.6.6","source":"GitHub","reportedAt":"2026-07-09 20:58:33","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vw42-752g-5mrp"}]}],"sylius\/sylius":[{"advisoryId":"PKSA-kjm4-5dkr-g6q7","packageName":"sylius\/sylius","remoteId":"GHSA-5597-7rmh-97q5","title":"Sylius: Cart FormComponent allows modification or deletion of an already-completed order","link":"https:\/\/github.com\/advisories\/GHSA-5597-7rmh-97q5","cve":"CVE-2026-53637","affectedVersions":"\u003E=2.2.0,\u003C2.2.6|\u003E=2.1.0,\u003C2.1.15|\u003E=2.0.0,\u003C2.0.18","source":"GitHub","reportedAt":"2026-07-09 21:03:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5597-7rmh-97q5"}]},{"advisoryId":"PKSA-jgww-gsqm-zy1m","packageName":"sylius\/sylius","remoteId":"GHSA-6955-hrm5-c4qp","title":"Sylius: Channel-based payment method restriction bypass on shop account orders API endpoint","link":"https:\/\/github.com\/advisories\/GHSA-6955-hrm5-c4qp","cve":"CVE-2026-53638","affectedVersions":"\u003E=2.2.0,\u003C2.2.6|\u003E=2.1.0,\u003C2.1.15|\u003E=2.0.0,\u003C2.0.18","source":"GitHub","reportedAt":"2026-07-09 21:03:46","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6955-hrm5-c4qp"}]},{"advisoryId":"PKSA-6331-fbb1-grmz","packageName":"sylius\/sylius","remoteId":"GHSA-mr9r-h354-966r","title":"Sylius: IDOR on Shop Payment Request API endpoints","link":"https:\/\/github.com\/advisories\/GHSA-mr9r-h354-966r","cve":"CVE-2026-53639","affectedVersions":"\u003E=2.2.0,\u003C2.2.6|\u003E=2.1.0,\u003C2.1.15|\u003E=2.0.0,\u003C2.0.18","source":"GitHub","reportedAt":"2026-07-09 21:03:51","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mr9r-h354-966r"}]}],"wnx\/laravel-backup-restore":[{"advisoryId":"PKSA-c7fx-vfvm-h6fn","packageName":"wnx\/laravel-backup-restore","remoteId":"GHSA-w9mx-xmg4-gc4r","title":"laravel-backup-restore has an OS Command Injection during database restore","link":"https:\/\/github.com\/advisories\/GHSA-w9mx-xmg4-gc4r","cve":"CVE-2026-53932","affectedVersions":"\u003C=1.9.3","source":"GitHub","reportedAt":"2026-07-09 20:52:57","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w9mx-xmg4-gc4r"}]}],"craftcms\/cms":[{"advisoryId":"PKSA-5x6f-x35f-73db","packageName":"craftcms\/cms","remoteId":"GHSA-c43v-4cr8-6mvp","title":"Craft CMS has authenticated path traversal in `assets\/icon`, allowing local `.svg` file read","link":"https:\/\/github.com\/advisories\/GHSA-c43v-4cr8-6mvp","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.12|\u003E=4.0.0-RC1,\u003C=4.17.6","source":"GitHub","reportedAt":"2026-07-09 13:44:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-c43v-4cr8-6mvp"}]},{"advisoryId":"PKSA-r87g-h2pd-9vq1","packageName":"craftcms\/cms","remoteId":"GHSA-86vw-x4ww-x467","title":"Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview","link":"https:\/\/github.com\/advisories\/GHSA-86vw-x4ww-x467","cve":null,"affectedVersions":"\u003E=5.5.0,\u003C=5.9.13","source":"GitHub","reportedAt":"2026-07-09 13:44:12","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-86vw-x4ww-x467"}]},{"advisoryId":"PKSA-z4vj-1h29-pkrc","packageName":"craftcms\/cms","remoteId":"GHSA-xrqc-p465-2xvg","title":"Craft CMS: Stored XSS via Structure entry title in table view","link":"https:\/\/github.com\/advisories\/GHSA-xrqc-p465-2xvg","cve":"CVE-2026-55793","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.9.22","source":"GitHub","reportedAt":"2026-07-06 21:35:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xrqc-p465-2xvg"}]},{"advisoryId":"PKSA-hvdm-8k9p-kcdw","packageName":"craftcms\/cms","remoteId":"GHSA-f74w-488g-8x5r","title":"Craft CMS: Potential authenticated Remote Code Execution via referrer redirect","link":"https:\/\/github.com\/advisories\/GHSA-f74w-488g-8x5r","cve":"CVE-2026-55794","affectedVersions":"\u003E=5.9.0,\u003C5.10.0","source":"GitHub","reportedAt":"2026-07-06 21:37:06","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f74w-488g-8x5r"}]},{"advisoryId":"PKSA-hm4p-n9yk-nz2c","packageName":"craftcms\/cms","remoteId":"GHSA-24x4-j6x9-rfw5","title":"Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget","link":"https:\/\/github.com\/advisories\/GHSA-24x4-j6x9-rfw5","cve":"CVE-2026-55790","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.15|\u003E=5.0.0-RC1,\u003C5.9.22","source":"GitHub","reportedAt":"2026-07-06 21:29:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-24x4-j6x9-rfw5"}]},{"advisoryId":"PKSA-rvh7-y4k6-cn59","packageName":"craftcms\/cms","remoteId":"GHSA-287w-mxq6-x2cp","title":"Craft CMS: Sensitive File Disclosure \/ Server-Side File Read","link":"https:\/\/github.com\/advisories\/GHSA-287w-mxq6-x2cp","cve":"CVE-2026-55792","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.0|\u003E=4.0.0-RC1,\u003C4.18.0","source":"GitHub","reportedAt":"2026-07-06 21:29:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-287w-mxq6-x2cp"}]},{"advisoryId":"PKSA-pqnm-5q4k-cx7j","packageName":"craftcms\/cms","remoteId":"GHSA-x76w-8c62-48mg","title":"Craft CMS: Authenticated \u0022assets\/preview-thumb\u0022 discloses signed fallback transform preview link to CP users without asset-view permission","link":"https:\/\/github.com\/advisories\/GHSA-x76w-8c62-48mg","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.13|\u003E=4.0.0-RC1,\u003C=4.17.7","source":"GitHub","reportedAt":"2026-07-06 20:28:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x76w-8c62-48mg"}]},{"advisoryId":"PKSA-zn8p-45f7-kgv1","packageName":"craftcms\/cms","remoteId":"GHSA-x5m4-g2cq-52pq","title":"Craft CMS\u0027s mass assignment via id in newAttributes during bulk duplicate overwrites existing elements","link":"https:\/\/github.com\/advisories\/GHSA-x5m4-g2cq-52pq","cve":"CVE-2026-50281","affectedVersions":"\u003E=5.7.0,\u003C5.9.21","source":"GitHub","reportedAt":"2026-07-02 20:03:36","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-x5m4-g2cq-52pq"}]},{"advisoryId":"PKSA-9z7r-2kcf-76cf","packageName":"craftcms\/cms","remoteId":"GHSA-3w32-23wj-rxg3","title":"Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves","link":"https:\/\/github.com\/advisories\/GHSA-3w32-23wj-rxg3","cve":"CVE-2026-50282","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.14|\u003E=5.0.0-RC1,\u003C5.9.21","source":"GitHub","reportedAt":"2026-07-02 20:03:58","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3w32-23wj-rxg3"}]},{"advisoryId":"PKSA-rg3c-2r2k-sf93","packageName":"craftcms\/cms","remoteId":"GHSA-qq2c-2q8j-jh27","title":"Craft CMS: Authorship spoofing in `entries\/save-entry` via pre-check\/post-mutation authorization gap","link":"https:\/\/github.com\/advisories\/GHSA-qq2c-2q8j-jh27","cve":"CVE-2026-50279","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.9.21","source":"GitHub","reportedAt":"2026-07-02 18:45:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qq2c-2q8j-jh27"}]},{"advisoryId":"PKSA-nhns-q2yx-ct2v","packageName":"craftcms\/cms","remoteId":"GHSA-43cq-c2gq-pfpw","title":"Craft CMS: Authorization bypass in `entries\/move-to-section` via missing target-section save check","link":"https:\/\/github.com\/advisories\/GHSA-43cq-c2gq-pfpw","cve":"CVE-2026-50280","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.9.21","source":"GitHub","reportedAt":"2026-07-02 18:47:37","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-43cq-c2gq-pfpw"}]},{"advisoryId":"PKSA-68rr-18x7-w4gg","packageName":"craftcms\/cms","remoteId":"GHSA-qh45-9g5p-m2v4","title":"Craft CMS: Unauthorized Deletion of Source Assets During File Replacement","link":"https:\/\/github.com\/advisories\/GHSA-qh45-9g5p-m2v4","cve":"CVE-2026-50283","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.14|\u003E=5.0.0-RC1,\u003C5.9.21","source":"GitHub","reportedAt":"2026-07-02 18:48:27","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qh45-9g5p-m2v4"}]},{"advisoryId":"PKSA-fd42-dyd4-g3dq","packageName":"craftcms\/cms","remoteId":"GHSA-7h62-6v23-v8fm","title":"Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users\u0027 assets","link":"https:\/\/github.com\/advisories\/GHSA-7h62-6v23-v8fm","cve":"CVE-2026-50284","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.15|\u003E=5.0.0-RC1,\u003C5.9.22","source":"GitHub","reportedAt":"2026-07-02 18:49:04","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7h62-6v23-v8fm"}]}],"admidio\/admidio":[{"advisoryId":"PKSA-84pc-hcqd-7brb","packageName":"admidio\/admidio","remoteId":"GHSA-hm42-q32m-vj4f","title":"Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET Requests","link":"https:\/\/github.com\/advisories\/GHSA-hm42-q32m-vj4f","cve":"CVE-2026-53760","affectedVersions":"\u003C=5.0.11","source":"GitHub","reportedAt":"2026-07-09 13:44:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hm42-q32m-vj4f"}]}],"code16\/sharp":[{"advisoryId":"PKSA-krdf-j5zz-ky6v","packageName":"code16\/sharp","remoteId":"GHSA-vmwx-m75v-qvch","title":"Sharp Missing Authorization Check in Quick Creation Command Endpoints","link":"https:\/\/github.com\/advisories\/GHSA-vmwx-m75v-qvch","cve":"CVE-2026-53634","affectedVersions":"\u003E=9.0.0,\u003C9.22.3","source":"GitHub","reportedAt":"2026-07-08 20:24:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vmwx-m75v-qvch"}]}],"dolibarr\/dolibarr":[{"advisoryId":"PKSA-199z-kb1w-7qjg","packageName":"dolibarr\/dolibarr","remoteId":"GHSA-7fg5-vc77-69fp","title":"Dolibarr ERP CRM is vulnerable to Improper Authorization through its Leave Request REST API","link":"https:\/\/github.com\/advisories\/GHSA-7fg5-vc77-69fp","cve":"CVE-2026-10215","affectedVersions":"\u003C=15.0.3","source":"GitHub","reportedAt":"2026-06-01 03:30:26","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7fg5-vc77-69fp"}]}],"web-auth\/webauthn-lib":[{"advisoryId":"PKSA-zk1n-qbm6-d3rq","packageName":"web-auth\/webauthn-lib","remoteId":"GHSA-gq4g-fpc9-vjfq","title":"Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection","link":"https:\/\/github.com\/advisories\/GHSA-gq4g-fpc9-vjfq","cve":null,"affectedVersions":"\u003E=4.9.0,\u003C5.3.5","source":"GitHub","reportedAt":"2026-07-07 23:39:43","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-gq4g-fpc9-vjfq"}]}],"egroupware\/egroupware":[{"advisoryId":"PKSA-3pf5-qtx8-njsg","packageName":"egroupware\/egroupware","remoteId":"GHSA-h9qx-v5xp-ph8p","title":"EGroupware has a Remote Code Execution Vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-h9qx-v5xp-ph8p","cve":"CVE-2026-27823","affectedVersions":"\u003C23.1.20260224|\u003E=26.0.20251208,\u003C26.2.20260224","source":"GitHub","reportedAt":"2026-07-07 13:01:01","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-h9qx-v5xp-ph8p"}]},{"advisoryId":"PKSA-s1pv-qcq4-r5jv","packageName":"egroupware\/egroupware","remoteId":"GHSA-8737-2x9g-xjj7","title":"EGroupware has Authenticated RCE via Malicious eTemplate Upload","link":"https:\/\/github.com\/advisories\/GHSA-8737-2x9g-xjj7","cve":"CVE-2026-40187","affectedVersions":"\u003C23.1.20260601|\u003E=26.0.20251208,\u003C26.0.20260113","source":"GitHub","reportedAt":"2026-07-07 13:01:31","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8737-2x9g-xjj7"}]},{"advisoryId":"PKSA-pvm8-1tm1-jhwt","packageName":"egroupware\/egroupware","remoteId":"GHSA-c8m7-r2jv-rw63","title":"EGroupware Vulnerable to Local File Inclusion via file:\/\/ URI in Mail Compose","link":"https:\/\/github.com\/advisories\/GHSA-c8m7-r2jv-rw63","cve":"CVE-2026-45016","affectedVersions":"\u003C23.1.20260601|\u003E=26.0.20251208,\u003C26.5.20260507","source":"GitHub","reportedAt":"2026-07-07 13:02:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c8m7-r2jv-rw63"}]}],"web-token\/jwt-bundle":[{"advisoryId":"PKSA-5yb6-pjs2-zg93","packageName":"web-token\/jwt-bundle","remoteId":"GHSA-jc38-x7x8-2xc8","title":"PHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks","link":"https:\/\/github.com\/advisories\/GHSA-jc38-x7x8-2xc8","cve":null,"affectedVersions":"\u003E=4.1.0,\u003C4.1.7|\u003E=4.0.0,\u003C4.0.7|\u003C3.4.10","source":"GitHub","reportedAt":"2026-06-18 21:09:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jc38-x7x8-2xc8"}]}],"web-token\/jwt-experimental":[{"advisoryId":"PKSA-rq51-8s6h-13tp","packageName":"web-token\/jwt-experimental","remoteId":"GHSA-jc38-x7x8-2xc8","title":"PHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks","link":"https:\/\/github.com\/advisories\/GHSA-jc38-x7x8-2xc8","cve":null,"affectedVersions":"\u003E=4.1.0,\u003C4.1.7|\u003E=4.0.0,\u003C4.0.7|\u003C3.4.10","source":"GitHub","reportedAt":"2026-06-18 21:09:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jc38-x7x8-2xc8"}]}],"spatie\/laravel-medialibrary":[{"advisoryId":"PKSA-88bj-c5ky-3pr6","packageName":"spatie\/laravel-medialibrary","remoteId":"GHSA-fggg-964j-3j7h","title":"Spatie Laravel Media Library contains a server-side request forgery vulnerability","link":"https:\/\/github.com\/advisories\/GHSA-fggg-964j-3j7h","cve":"CVE-2026-48555","affectedVersions":"\u003C11.23.0","source":"GitHub","reportedAt":"2026-05-29 21:31:24","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fggg-964j-3j7h"}]},{"advisoryId":"PKSA-mrgr-9pdf-y591","packageName":"spatie\/laravel-medialibrary","remoteId":"GHSA-3ggm-c5m7-hfv5","title":"Spatie Laravel Media Library contains a file upload restriction bypass","link":"https:\/\/github.com\/advisories\/GHSA-3ggm-c5m7-hfv5","cve":"CVE-2026-48557","affectedVersions":"\u003C11.23.0","source":"GitHub","reportedAt":"2026-05-29 21:31:25","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3ggm-c5m7-hfv5"}]}],"simplesamlphp\/simplesamlphp":[{"advisoryId":"PKSA-569h-6vqh-5xr3","packageName":"simplesamlphp\/simplesamlphp","remoteId":"GHSA-q8r6-xj3f-wrrm","title":"SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response\/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData\/InResponseTo`","link":"https:\/\/github.com\/advisories\/GHSA-q8r6-xj3f-wrrm","cve":"CVE-2026-49284","affectedVersions":"\u003C=2.4.6|\u003E=2.5.0,\u003C=2.5.1","source":"GitHub","reportedAt":"2026-07-02 20:47:21","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-q8r6-xj3f-wrrm"}]}],"simplesamlphp\/saml2":[{"advisoryId":"PKSA-yk3g-3g3t-ts6q","packageName":"simplesamlphp\/saml2","remoteId":"GHSA-6929-8p9f-26jx","title":"SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass","link":"https:\/\/github.com\/advisories\/GHSA-6929-8p9f-26jx","cve":"CVE-2026-49283","affectedVersions":"\u003C4.20.2|\u003E=5.0.0,\u003C5.0.6|\u003E=6.0.0,\u003C6.2.1","source":"GitHub","reportedAt":"2026-07-02 20:25:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6929-8p9f-26jx"}]},{"advisoryId":"PKSA-1fc7-xrz7-vw78","packageName":"simplesamlphp\/saml2","remoteId":"GHSA-5cjr-mxj5-wmrx","title":"SimpleSAMLphp has Possible DoS via XPath Transform","link":"https:\/\/github.com\/advisories\/GHSA-5cjr-mxj5-wmrx","cve":"CVE-2026-49289","affectedVersions":"\u003C=4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:27:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5cjr-mxj5-wmrx"}]}],"simplesamlphp\/saml2-legacy":[{"advisoryId":"PKSA-4y26-97zb-p98g","packageName":"simplesamlphp\/saml2-legacy","remoteId":"GHSA-6929-8p9f-26jx","title":"SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass","link":"https:\/\/github.com\/advisories\/GHSA-6929-8p9f-26jx","cve":"CVE-2026-49283","affectedVersions":"\u003C4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:25:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6929-8p9f-26jx"}]},{"advisoryId":"PKSA-11bv-m3wk-h9sn","packageName":"simplesamlphp\/saml2-legacy","remoteId":"GHSA-5cjr-mxj5-wmrx","title":"SimpleSAMLphp has Possible DoS via XPath Transform","link":"https:\/\/github.com\/advisories\/GHSA-5cjr-mxj5-wmrx","cve":"CVE-2026-49289","affectedVersions":"\u003C=4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:27:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5cjr-mxj5-wmrx"}]}],"mautic\/core":[{"advisoryId":"PKSA-tmx3-5zmv-624c","packageName":"mautic\/core","remoteId":"GHSA-jmv8-8j9j-rcpc","title":"Mautic Focus component Vulnerable to SSRF","link":"https:\/\/github.com\/advisories\/GHSA-jmv8-8j9j-rcpc","cve":"CVE-2026-9557","affectedVersions":"\u003E=7.0.0,\u003C7.1.2|\u003E=6.0.0,\u003C6.0.9|\u003E=5.0.0,\u003C5.2.11|\u003E=4.0.0,\u003C=4.4.13","source":"GitHub","reportedAt":"2026-07-02 19:47:38","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jmv8-8j9j-rcpc"}]},{"advisoryId":"PKSA-5wpq-7gbm-cqxv","packageName":"mautic\/core","remoteId":"GHSA-9fx4-7cmj-47vg","title":"Mautic has Server-Side Template Injection (SSTI) in Theme Templates","link":"https:\/\/github.com\/advisories\/GHSA-9fx4-7cmj-47vg","cve":"CVE-2026-9558","affectedVersions":"\u003E=7.0.0,\u003C7.1.2|\u003E=6.0.0,\u003C6.0.9|\u003E=5.0.0,\u003C5.2.11|\u003E=1.3.0,\u003C4.4.13","source":"GitHub","reportedAt":"2026-07-02 19:48:08","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-9fx4-7cmj-47vg"}]},{"advisoryId":"PKSA-743g-7dzv-xbzg","packageName":"mautic\/core","remoteId":"GHSA-6r9h-4h75-7q4x","title":"Mautic vulnerable to Path Traversal via Campaign Import","link":"https:\/\/github.com\/advisories\/GHSA-6r9h-4h75-7q4x","cve":"CVE-2026-9559","affectedVersions":"\u003E=7.0.0,\u003C7.1.2","source":"GitHub","reportedAt":"2026-07-02 19:48:50","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-6r9h-4h75-7q4x"}]},{"advisoryId":"PKSA-199x-g3sb-2vrd","packageName":"mautic\/core","remoteId":"GHSA-2jrw-c95w-h43g","title":"Mautic has an Authorization Bypass in API v2 Endpoints","link":"https:\/\/github.com\/advisories\/GHSA-2jrw-c95w-h43g","cve":"CVE-2026-9808","affectedVersions":"\u003E=7.0.0,\u003C7.1.2","source":"GitHub","reportedAt":"2026-07-02 19:49:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2jrw-c95w-h43g"}]},{"advisoryId":"PKSA-xbvd-zmn4-s43b","packageName":"mautic\/core","remoteId":"GHSA-7h65-whp7-rgqf","title":"Mautic has Stored Cross-Site Scripting (XSS) in Projects Component","link":"https:\/\/github.com\/advisories\/GHSA-7h65-whp7-rgqf","cve":"CVE-2026-9809","affectedVersions":"\u003E=7.0.0,\u003C7.1.2","source":"GitHub","reportedAt":"2026-07-02 19:49:14","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7h65-whp7-rgqf"}]},{"advisoryId":"PKSA-mhxb-h64m-td2q","packageName":"mautic\/core","remoteId":"GHSA-5hvg-w58j-545m","title":"Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector","link":"https:\/\/github.com\/advisories\/GHSA-5hvg-w58j-545m","cve":"CVE-2026-9811","affectedVersions":"\u003E=7.0.0,\u003C7.1.2","source":"GitHub","reportedAt":"2026-07-02 19:49:27","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5hvg-w58j-545m"}]},{"advisoryId":"PKSA-pdn1-217f-vc3y","packageName":"mautic\/core","remoteId":"GHSA-fcmw-wx57-9p75","title":"Mautic has SQL Injection in API Contact Filtering","link":"https:\/\/github.com\/advisories\/GHSA-fcmw-wx57-9p75","cve":"CVE-2026-4776","affectedVersions":"\u003E=7.0.0,\u003C7.1.2|\u003E=6.0.0,\u003C6.0.9|\u003E=5.0.0,\u003C5.2.11|\u003E=2.6.0,\u003C=4.4.13","source":"GitHub","reportedAt":"2026-07-02 19:25:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fcmw-wx57-9p75"}]}],"froxlor\/froxlor":[{"advisoryId":"PKSA-q6mw-b5rg-dy2q","packageName":"froxlor\/froxlor","remoteId":"GHSA-mr9h-45p9-fg8h","title":"Froxlor: Authenticated customers can read other customers\u0027 allowed sender aliases","link":"https:\/\/github.com\/advisories\/GHSA-mr9h-45p9-fg8h","cve":null,"affectedVersions":"\u003C=2.3.6","source":"GitHub","reportedAt":"2026-07-02 19:23:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mr9h-45p9-fg8h"}]},{"advisoryId":"PKSA-54z7-97sf-f9k2","packageName":"froxlor\/froxlor","remoteId":"GHSA-q4rm-m6xh-5pv7","title":"Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API","link":"https:\/\/github.com\/advisories\/GHSA-q4rm-m6xh-5pv7","cve":null,"affectedVersions":"\u003C=2.3.6","source":"GitHub","reportedAt":"2026-07-02 19:23:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q4rm-m6xh-5pv7"}]}],"mediawiki\/maps":[{"advisoryId":"PKSA-hjtx-83wm-5fvj","packageName":"mediawiki\/maps","remoteId":"GHSA-4h7g-5542-v3fc","title":"mediawiki\/maps has stored XSS through the overlays parameter in the display_map parser function","link":"https:\/\/github.com\/advisories\/GHSA-4h7g-5542-v3fc","cve":"CVE-2026-52854","affectedVersions":"\u003C12.1.3","source":"GitHub","reportedAt":"2026-07-02 17:51:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4h7g-5542-v3fc"}]}],"phpseclib\/phpseclib":[{"advisoryId":"PKSA-432p-hv1d-chf7","packageName":"phpseclib\/phpseclib","remoteId":"GHSA-m557-wrgg-6rp4","title":"phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information Access","link":"https:\/\/github.com\/advisories\/GHSA-m557-wrgg-6rp4","cve":"CVE-2026-55599","affectedVersions":"\u003E=3.0.0,\u003C=3.0.53|\u003E=2.0.0,\u003C=2.0.54|\u003E=0.1.1,\u003C=1.0.29","source":"GitHub","reportedAt":"2026-06-16 15:03:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m557-wrgg-6rp4"}]}],"tinymce\/tinymce":[{"advisoryId":"PKSA-rf1b-835f-6yyv","packageName":"tinymce\/tinymce","remoteId":"GHSA-q742-qvgc-gc2f","title":"TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes","link":"https:\/\/github.com\/advisories\/GHSA-q742-qvgc-gc2f","cve":"CVE-2026-47759","affectedVersions":"\u003C=5.10.9|\u003E=8.0.0,\u003C8.5.1|\u003E=6.0.0,\u003C7.9.3","source":"GitHub","reportedAt":"2026-06-05 20:27:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-q742-qvgc-gc2f"}]},{"advisoryId":"PKSA-2v47-9p8y-4qt3","packageName":"tinymce\/tinymce","remoteId":"GHSA-v98h-vmpc-fpqv","title":"TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments","link":"https:\/\/github.com\/advisories\/GHSA-v98h-vmpc-fpqv","cve":"CVE-2026-47762","affectedVersions":"\u003C=5.10.9|\u003E=8.0.0,\u003C8.5.1|\u003E=6.0.0,\u003C7.9.3","source":"GitHub","reportedAt":"2026-06-05 20:29:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v98h-vmpc-fpqv"}]}],"easycorp\/easyadmin-bundle":[{"advisoryId":"PKSA-8yhb-cz5n-f41h","packageName":"easycorp\/easyadmin-bundle","remoteId":"easycorp\/easyadmin-bundle\/GHSA-8559-gwj3-q37r.yaml","title":"Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField","link":"https:\/\/github.com\/EasyCorp\/EasyAdminBundle\/security\/advisories\/GHSA-8559-gwj3-q37r","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-04 06:43:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"easycorp\/easyadmin-bundle\/GHSA-8559-gwj3-q37r.yaml"},{"name":"GitHub","remoteId":"GHSA-8559-gwj3-q37r"}]}],"pimcore\/pimcore":[{"advisoryId":"PKSA-vd5r-2gyh-m6cc","packageName":"pimcore\/pimcore","remoteId":"GHSA-jwcc-gv4m-93x6","title":"Pimcore has a CustomReports Share Bypass","link":"https:\/\/github.com\/advisories\/GHSA-jwcc-gv4m-93x6","cve":"CVE-2026-45704","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.2|\u003C=11.5.16|\u003E=12.0.0-RC1,\u003C=12.3.5","source":"GitHub","reportedAt":"2026-05-27 22:34:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jwcc-gv4m-93x6"}]},{"advisoryId":"PKSA-v5bg-33q7-q8zj","packageName":"pimcore\/pimcore","remoteId":"GHSA-332x-r494-54fq","title":"Pimcore has a WordExport Authorization Bypass for Unauthorized Document Export","link":"https:\/\/github.com\/advisories\/GHSA-332x-r494-54fq","cve":"CVE-2026-45703","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.3|\u003C=11.5.16|\u003E=12.0.0-RC1,\u003C=12.3.6","source":"GitHub","reportedAt":"2026-05-27 22:27:18","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-332x-r494-54fq"}]},{"advisoryId":"PKSA-y4yc-6g1b-qfqz","packageName":"pimcore\/pimcore","remoteId":"GHSA-wc7j-g8wx-m2qx","title":"Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling","link":"https:\/\/github.com\/advisories\/GHSA-wc7j-g8wx-m2qx","cve":"CVE-2026-45260","affectedVersions":"\u003C=11.5.16|\u003E=2026.1.0,\u003C2026.1.3|\u003E=12.0.0-RC1,\u003C=12.3.6","source":"GitHub","reportedAt":"2026-05-27 17:17:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wc7j-g8wx-m2qx"}]},{"advisoryId":"PKSA-882j-k212-wjbf","packageName":"pimcore\/pimcore","remoteId":"GHSA-36fc-7wjg-mfvj","title":"Pimcore has Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction","link":"https:\/\/github.com\/advisories\/GHSA-36fc-7wjg-mfvj","cve":"CVE-2026-45162","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.3|\u003C=11.5.16|\u003E=12.0.0-RC1,\u003C=12.3.6","source":"GitHub","reportedAt":"2026-05-27 16:57:04","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-36fc-7wjg-mfvj"}]},{"advisoryId":"PKSA-kp19-xmdp-rvyj","packageName":"pimcore\/pimcore","remoteId":"GHSA-3234-gxc3-pq6f","title":"Pimcore Vulnerable to SQL Injection in Custom Reports Column Configuration","link":"https:\/\/github.com\/advisories\/GHSA-3234-gxc3-pq6f","cve":"CVE-2026-44739","affectedVersions":"\u003E=12.0.0-RC1,\u003C=12.3.5|\u003C=11.5.16|\u003E=2026.1.0,\u003C2026.1.2","source":"GitHub","reportedAt":"2026-05-27 00:35:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3234-gxc3-pq6f"}]},{"advisoryId":"PKSA-vp19-ydt7-tws9","packageName":"pimcore\/pimcore","remoteId":"GHSA-r2f4-ff2p-xc64","title":"Pimcore Platform - SQL Injection in DataObject composite index handling during class definition import\/save","link":"https:\/\/github.com\/advisories\/GHSA-r2f4-ff2p-xc64","cve":"CVE-2026-5394","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.3|\u003C=11.5.16|\u003E=12.0.0-RC1,\u003C=12.3.6","source":"GitHub","reportedAt":"2026-05-28 20:47:10","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r2f4-ff2p-xc64"}]}],"pimcore\/admin-ui-classic-bundle":[{"advisoryId":"PKSA-v29g-sqpm-mznn","packageName":"pimcore\/admin-ui-classic-bundle","remoteId":"GHSA-h4ph-crvj-9h92","title":"Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter","link":"https:\/\/github.com\/advisories\/GHSA-h4ph-crvj-9h92","cve":"CVE-2026-44741","affectedVersions":"\u003C1.7.18|\u003E=2.0.0-RC1,\u003C=2.3.5","source":"GitHub","reportedAt":"2026-05-27 00:35:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h4ph-crvj-9h92"}]}],"symfony\/symfony":[{"advisoryId":"PKSA-xxm6-3p32-rqz7","packageName":"symfony\/symfony","remoteId":"symfony\/symfony\/CVE-2026-45075.yaml","title":"CVE-2026-45075: HEAD Request Bypasses methods: [\u0027GET\u0027] Filter in #[IsGranted] \/ #[IsSignatureValid] \/ #[IsCsrfTokenValid]","link":"https:\/\/symfony.com\/cve-2026-45075","cve":"CVE-2026-45075","affectedVersions":"\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6439-2f28-8p8q"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/symfony\/CVE-2026-45075.yaml"}]}],"symfony\/security-http":[{"advisoryId":"PKSA-4tmc-tz3m-9xpb","packageName":"symfony\/security-http","remoteId":"symfony\/security-http\/CVE-2026-45075.yaml","title":"CVE-2026-45075: HEAD Request Bypasses methods: [\u0027GET\u0027] Filter in #[IsGranted] \/ #[IsSignatureValid] \/ #[IsCsrfTokenValid]","link":"https:\/\/symfony.com\/cve-2026-45075","cve":"CVE-2026-45075","affectedVersions":"\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6439-2f28-8p8q"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/security-http\/CVE-2026-45075.yaml"}]}],"symfony\/http-kernel":[{"advisoryId":"PKSA-dw7n-x7f5-zf63","packageName":"symfony\/http-kernel","remoteId":"symfony\/http-kernel\/CVE-2026-45075.yaml","title":"CVE-2026-45075: HEAD Request Bypasses methods: [\u0027GET\u0027] Filter in #[IsGranted] \/ #[IsSignatureValid] \/ #[IsCsrfTokenValid]","link":"https:\/\/symfony.com\/cve-2026-45075","cve":"CVE-2026-45075","affectedVersions":"\u003E=7.4.0,\u003C7.4.12|\u003E=8.0.0,\u003C8.0.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-05-20 08:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6439-2f28-8p8q"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symfony\/http-kernel\/CVE-2026-45075.yaml"}]}],"typicms\/core":[{"advisoryId":"PKSA-4g4t-fqh1-f8mt","packageName":"typicms\/core","remoteId":"GHSA-xfvg-8v67-j7wp","title":"TypiCMS Core has Stored Cross-Site Scripting (XSS) via SVG File Upload","link":"https:\/\/github.com\/advisories\/GHSA-xfvg-8v67-j7wp","cve":"CVE-2026-27621","affectedVersions":"\u003C12.0.5|\u003E=13.0.0,\u003C13.0.9|\u003E=14.0.0,\u003C14.0.27|\u003E=15.0.0,\u003C15.0.29|\u003E=16.0.0,\u003C16.1.7","source":"GitHub","reportedAt":"2026-02-25 16:06:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xfvg-8v67-j7wp"}]}]}}