{"advisories":{"getgrav\/grav":[{"advisoryId":"PKSA-p6yn-thc9-dbs3","packageName":"getgrav\/grav","remoteId":"GHSA-7mgc-c7pq-3rr3","title":"Grav: 2FA Bypass via \u0027login.regenerate2FASecret\u0027 - Secret Rotation During Pending Challenge","link":"https:\/\/github.com\/advisories\/GHSA-7mgc-c7pq-3rr3","cve":"CVE-2026-62669","affectedVersions":"\u003C2.0.4","source":"GitHub","reportedAt":"2026-09-02 22:01:25","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7mgc-c7pq-3rr3"}]},{"advisoryId":"PKSA-sq15-xbtt-m678","packageName":"getgrav\/grav","remoteId":"GHSA-mc5q-6hpj-rp7j","title":"Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)","link":"https:\/\/github.com\/advisories\/GHSA-mc5q-6hpj-rp7j","cve":"CVE-2026-61842","affectedVersions":"\u003C2.0.2","source":"GitHub","reportedAt":"2026-09-02 21:41:12","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mc5q-6hpj-rp7j"}]},{"advisoryId":"PKSA-2vrn-cxz9-yg23","packageName":"getgrav\/grav","remoteId":"GHSA-928x-9mpw-8h56","title":"Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits","link":"https:\/\/github.com\/advisories\/GHSA-928x-9mpw-8h56","cve":"CVE-2026-61690","affectedVersions":"\u003C2.0.1","source":"GitHub","reportedAt":"2026-09-02 21:35:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-928x-9mpw-8h56"}]},{"advisoryId":"PKSA-1q9r-bgms-91mf","packageName":"getgrav\/grav","remoteId":"GHSA-fj2p-qj2f-74v5","title":"Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()","link":"https:\/\/github.com\/advisories\/GHSA-fj2p-qj2f-74v5","cve":"CVE-2026-64850","affectedVersions":"\u003C2.0.7","source":"GitHub","reportedAt":"2026-09-02 14:51:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fj2p-qj2f-74v5"}]},{"advisoryId":"PKSA-rjzr-vkvg-cvmf","packageName":"getgrav\/grav","remoteId":"GHSA-8hgv-xc77-jmcr","title":"Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox\u0027s assets.addJs\/addCss allowlist, escalating to super-admin","link":"https:\/\/github.com\/advisories\/GHSA-8hgv-xc77-jmcr","cve":null,"affectedVersions":"\u003C=2.0.19","source":"GitHub","reportedAt":"2026-08-21 19:14:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8hgv-xc77-jmcr"}]},{"advisoryId":"PKSA-wh99-p4gt-7bkp","packageName":"getgrav\/grav","remoteId":"GHSA-vwg3-w8w3-pc79","title":"Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems","link":"https:\/\/github.com\/advisories\/GHSA-vwg3-w8w3-pc79","cve":"CVE-2026-62673","affectedVersions":"\u003C2.0.4","source":"GitHub","reportedAt":"2026-08-19 19:32:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vwg3-w8w3-pc79"}]},{"advisoryId":"PKSA-pv12-m6cp-m9cd","packageName":"getgrav\/grav","remoteId":"GHSA-4x9g-vw65-vvf9","title":"Grav: Unauthenticated denial of service via unbounded image derivative dimensions","link":"https:\/\/github.com\/advisories\/GHSA-4x9g-vw65-vvf9","cve":"CVE-2026-53653","affectedVersions":"\u003C1.7.53|\u003E=2.0.0-beta.1,\u003C2.0.0-rc.8","source":"GitHub","reportedAt":"2026-08-14 19:23:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4x9g-vw65-vvf9"}]}],"snipe\/snipe-it":[{"advisoryId":"PKSA-g91f-rycz-yjcf","packageName":"snipe\/snipe-it","remoteId":"GHSA-c6w2-j4wq-mvwg","title":"Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode","link":"https:\/\/github.com\/advisories\/GHSA-c6w2-j4wq-mvwg","cve":"CVE-2026-55643","affectedVersions":"\u003C8.6.3","source":"GitHub","reportedAt":"2026-08-19 19:32:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c6w2-j4wq-mvwg"}]},{"advisoryId":"PKSA-dysn-9smy-t3nb","packageName":"snipe\/snipe-it","remoteId":"GHSA-j5g3-42wp-gqm3","title":"Snipe-IT has an Improper Privilege Management issue","link":"https:\/\/github.com\/advisories\/GHSA-j5g3-42wp-gqm3","cve":"CVE-2026-55843","affectedVersions":"\u003C8.6.0","source":"GitHub","reportedAt":"2026-08-28 22:37:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j5g3-42wp-gqm3"}]},{"advisoryId":"PKSA-4bks-zvdb-53gs","packageName":"snipe\/snipe-it","remoteId":"GHSA-xr9m-gphc-9p63","title":"Snipe-IT has a path traversal vulnerability via CSV import `image` field","link":"https:\/\/github.com\/advisories\/GHSA-xr9m-gphc-9p63","cve":"CVE-2026-55469","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:00:38","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xr9m-gphc-9p63"}]},{"advisoryId":"PKSA-wsms-bsnd-yhwp","packageName":"snipe\/snipe-it","remoteId":"GHSA-8w8c-8mx9-52cw","title":"Snipe-IT\u0027s API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation","link":"https:\/\/github.com\/advisories\/GHSA-8w8c-8mx9-52cw","cve":"CVE-2026-55472","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:01:06","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8w8c-8mx9-52cw"}]},{"advisoryId":"PKSA-b2sw-ngv6-5kt1","packageName":"snipe\/snipe-it","remoteId":"GHSA-c6f4-wj38-m3g3","title":"Snipe-IT vulnerable to directory traversal in displaySig","link":"https:\/\/github.com\/advisories\/GHSA-c6f4-wj38-m3g3","cve":"CVE-2026-55474","affectedVersions":"\u003C8.5.0","source":"GitHub","reportedAt":"2026-08-28 18:01:32","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c6f4-wj38-m3g3"}]},{"advisoryId":"PKSA-spdd-pnpq-79f1","packageName":"snipe\/snipe-it","remoteId":"GHSA-5wx7-xq8j-v4qm","title":"Snipe-IT\u0027s import created_by can be overwritten","link":"https:\/\/github.com\/advisories\/GHSA-5wx7-xq8j-v4qm","cve":"CVE-2026-55475","affectedVersions":"\u003C=8.6.0","source":"GitHub","reportedAt":"2026-08-28 18:01:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5wx7-xq8j-v4qm"}]},{"advisoryId":"PKSA-3ybt-zv27-1tk1","packageName":"snipe\/snipe-it","remoteId":"GHSA-53jc-27pc-x8r8","title":"Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter","link":"https:\/\/github.com\/advisories\/GHSA-53jc-27pc-x8r8","cve":"CVE-2026-55476","affectedVersions":"\u003C8.6.0","source":"GitHub","reportedAt":"2026-08-28 18:02:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-53jc-27pc-x8r8"}]},{"advisoryId":"PKSA-3nxv-xvdx-984d","packageName":"snipe\/snipe-it","remoteId":"GHSA-crv3-j83j-f3r6","title":"Snipe-IT has missing object-level authorization in Kits API","link":"https:\/\/github.com\/advisories\/GHSA-crv3-j83j-f3r6","cve":"CVE-2026-55478","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:02:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-crv3-j83j-f3r6"}]},{"advisoryId":"PKSA-j17x-hbvs-1cxn","packageName":"snipe\/snipe-it","remoteId":"GHSA-8frh-vhgh-64cf","title":"Snipe-IT has incorrect permission for legacy license checkin API ","link":"https:\/\/github.com\/advisories\/GHSA-8frh-vhgh-64cf","cve":"CVE-2026-55479","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:02:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8frh-vhgh-64cf"}]},{"advisoryId":"PKSA-78g8-kyjb-j6v1","packageName":"snipe\/snipe-it","remoteId":"GHSA-w7qw-5wfv-gwx9","title":"Snipe-IT has CSS Injection via `header_color` Setting","link":"https:\/\/github.com\/advisories\/GHSA-w7qw-5wfv-gwx9","cve":"CVE-2026-55481","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:04:29","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w7qw-5wfv-gwx9"}]},{"advisoryId":"PKSA-mtr1-kyd4-dpz1","packageName":"snipe\/snipe-it","remoteId":"GHSA-35cr-9hqq-p2mg","title":"Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint","link":"https:\/\/github.com\/advisories\/GHSA-35cr-9hqq-p2mg","cve":"CVE-2026-55515","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:04:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-35cr-9hqq-p2mg"}]},{"advisoryId":"PKSA-9w68-kyxd-kgh7","packageName":"snipe\/snipe-it","remoteId":"GHSA-575r-357h-fhch","title":"Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update","link":"https:\/\/github.com\/advisories\/GHSA-575r-357h-fhch","cve":"CVE-2026-55516","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:06:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-575r-357h-fhch"}]},{"advisoryId":"PKSA-3b5d-jjsk-z4w4","packageName":"snipe\/snipe-it","remoteId":"GHSA-wg2f-x2c2-c4rp","title":"Snipe-IT has an Open Redirect After User Edit","link":"https:\/\/github.com\/advisories\/GHSA-wg2f-x2c2-c4rp","cve":"CVE-2026-55461","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:57:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wg2f-x2c2-c4rp"}]},{"advisoryId":"PKSA-2vjy-7jj7-vvq3","packageName":"snipe\/snipe-it","remoteId":"GHSA-fc33-6w3q-538h","title":"Snipe-IT has an authorization bypass on print inventory page","link":"https:\/\/github.com\/advisories\/GHSA-fc33-6w3q-538h","cve":"CVE-2026-55462","affectedVersions":"\u003C=8.6.0","source":"GitHub","reportedAt":"2026-08-28 17:57:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fc33-6w3q-538h"}]},{"advisoryId":"PKSA-6ddj-s9z1-gtxr","packageName":"snipe\/snipe-it","remoteId":"GHSA-r52f-r9v5-66xr","title":"Snipe-IT vulnerable to stored XSS via Markdown custom field ","link":"https:\/\/github.com\/advisories\/GHSA-r52f-r9v5-66xr","cve":"CVE-2026-55464","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:58:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r52f-r9v5-66xr"}]},{"advisoryId":"PKSA-3mmm-zfys-jjqm","packageName":"snipe\/snipe-it","remoteId":"GHSA-jhph-5q74-pmfx","title":"Snipe-IT vulnerable to stored XSS via inline-served attachment","link":"https:\/\/github.com\/advisories\/GHSA-jhph-5q74-pmfx","cve":"CVE-2026-55466","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:59:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jhph-5q74-pmfx"}]},{"advisoryId":"PKSA-cj32-qmb9-vwgy","packageName":"snipe\/snipe-it","remoteId":"GHSA-whrx-mmgr-gpcf","title":"Snipe-IT has CSV formula injection in Activity Report export","link":"https:\/\/github.com\/advisories\/GHSA-whrx-mmgr-gpcf","cve":"CVE-2026-55452","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:46:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-whrx-mmgr-gpcf"}]},{"advisoryId":"PKSA-n99m-2gcm-8bc6","packageName":"snipe\/snipe-it","remoteId":"GHSA-vgx7-c78r-69w9","title":"Snipe-IT has an authorization bypass on bulk editing users","link":"https:\/\/github.com\/advisories\/GHSA-vgx7-c78r-69w9","cve":"CVE-2026-55460","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:48:36","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vgx7-c78r-69w9"}]},{"advisoryId":"PKSA-9n96-zyz7-nxh9","packageName":"snipe\/snipe-it","remoteId":"GHSA-3hgv-jr5j-cg9x","title":"Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover","link":"https:\/\/github.com\/advisories\/GHSA-3hgv-jr5j-cg9x","cve":"CVE-2026-55694","affectedVersions":"\u003C8.6.3","source":"GitHub","reportedAt":"2026-08-19 19:32:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3hgv-jr5j-cg9x"}]},{"advisoryId":"PKSA-2v9y-4jt3-bxpm","packageName":"snipe\/snipe-it","remoteId":"GHSA-r9r3-g9fp-3q4q","title":"Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET","link":"https:\/\/github.com\/advisories\/GHSA-r9r3-g9fp-3q4q","cve":"CVE-2026-55703","affectedVersions":"\u003C8.6.3","source":"GitHub","reportedAt":"2026-08-19 19:32:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r9r3-g9fp-3q4q"}]},{"advisoryId":"PKSA-9ywr-ywdr-gcrt","packageName":"snipe\/snipe-it","remoteId":"GHSA-c8qc-wf67-342w","title":"Snipe-IT: Stored DOM XSS via table selected-count IDs","link":"https:\/\/github.com\/advisories\/GHSA-c8qc-wf67-342w","cve":"CVE-2026-61807","affectedVersions":"\u003C8.6.2","source":"GitHub","reportedAt":"2026-08-19 19:32:32","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c8qc-wf67-342w"}]}],"sulu\/sulu":[{"advisoryId":"PKSA-nbbf-nf63-19vd","packageName":"sulu\/sulu","remoteId":"GHSA-pp4x-ccxq-6r33","title":"Sulu: Stored XSS via media download inline-disposition override","link":"https:\/\/github.com\/advisories\/GHSA-pp4x-ccxq-6r33","cve":"CVE-2026-82396","affectedVersions":"\u003E=3.0.0-alpha1,\u003C3.0.8|\u003C=2.6.24","source":"GitHub","reportedAt":"2026-09-02 15:10:19","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pp4x-ccxq-6r33"}]},{"advisoryId":"PKSA-2gwf-7fts-yzvv","packageName":"sulu\/sulu","remoteId":"GHSA-65cv-w493-7vhq","title":"Sulu: Fix authorization bypass when creating preview links","link":"https:\/\/github.com\/advisories\/GHSA-65cv-w493-7vhq","cve":"CVE-2026-82394","affectedVersions":"\u003E=3.0.0-alpha1,\u003C3.0.8|\u003C=2.6.24","source":"GitHub","reportedAt":"2026-09-02 15:09:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-65cv-w493-7vhq"}]},{"advisoryId":"PKSA-zmfc-sgjt-9gmb","packageName":"sulu\/sulu","remoteId":"GHSA-h6cx-gjxx-v25c","title":"Sulu: Media move\/update authorization bypass (IDOR)","link":"https:\/\/github.com\/advisories\/GHSA-h6cx-gjxx-v25c","cve":"CVE-2026-82395","affectedVersions":"\u003E=3.0.0-alpha1,\u003C3.0.8|\u003C=2.6.24","source":"GitHub","reportedAt":"2026-09-02 14:57:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h6cx-gjxx-v25c"}]}],"getkirby\/cms":[{"advisoryId":"PKSA-cmzk-n5t6-2v3k","packageName":"getkirby\/cms","remoteId":"GHSA-6j4c-mgqr-qv76","title":"Kirby: Access to image files outside of the site root via path traversal in the media handling","link":"https:\/\/github.com\/advisories\/GHSA-6j4c-mgqr-qv76","cve":"CVE-2026-75592","affectedVersions":"\u003E=5.0.0,\u003C5.5.2|\u003C4.9.5","source":"GitHub","reportedAt":"2026-09-02 14:55:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6j4c-mgqr-qv76"}]},{"advisoryId":"PKSA-wq8z-fxnn-1fxz","packageName":"getkirby\/cms","remoteId":"GHSA-rf2p-vh74-7vvh","title":"Kirby: System path exposure from error messages in the REST API","link":"https:\/\/github.com\/advisories\/GHSA-rf2p-vh74-7vvh","cve":"CVE-2026-69127","affectedVersions":"\u003E=5.0.0,\u003C5.5.2|\u003C=4.9.4","source":"GitHub","reportedAt":"2026-09-01 16:37:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rf2p-vh74-7vvh"}]},{"advisoryId":"PKSA-n74d-ghht-18nt","packageName":"getkirby\/cms","remoteId":"GHSA-9vx2-j98c-p72w","title":"Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling","link":"https:\/\/github.com\/advisories\/GHSA-9vx2-j98c-p72w","cve":"CVE-2026-75594","affectedVersions":"\u003E=5.0.0,\u003C5.5.2|\u003C=4.9.4","source":"GitHub","reportedAt":"2026-08-31 22:12:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9vx2-j98c-p72w"}]},{"advisoryId":"PKSA-cxg1-n9gs-z2t6","packageName":"getkirby\/cms","remoteId":"GHSA-67mx-6wf2-92xp","title":"Kirby: File upload permissions are not checked during processing of chunk data","link":"https:\/\/github.com\/advisories\/GHSA-67mx-6wf2-92xp","cve":"CVE-2026-71415","affectedVersions":"\u003E=5.0.0,\u003C5.5.2","source":"GitHub","reportedAt":"2026-08-31 22:14:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-67mx-6wf2-92xp"}]}],"apache\/thrift":[{"advisoryId":"PKSA-t5dt-c9kk-znks","packageName":"apache\/thrift","remoteId":"GHSA-8wv5-x4w7-5gww","title":"Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop","link":"https:\/\/github.com\/advisories\/GHSA-8wv5-x4w7-5gww","cve":"CVE-2026-43871","affectedVersions":"\u003C0.24.0","source":"GitHub","reportedAt":"2026-07-27 12:31:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8wv5-x4w7-5gww"}]}],"studio-42\/elfinder":[{"advisoryId":"PKSA-th2b-2jzf-hmp6","packageName":"studio-42\/elfinder","remoteId":"GHSA-9hjf-w35w-6vx2","title":"elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections","link":"https:\/\/github.com\/advisories\/GHSA-9hjf-w35w-6vx2","cve":"CVE-2026-81890","affectedVersions":"\u003C2.1.70","source":"GitHub","reportedAt":"2026-09-02 14:37:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9hjf-w35w-6vx2"}]},{"advisoryId":"PKSA-71vn-d2sp-v1x4","packageName":"studio-42\/elfinder","remoteId":"GHSA-gxmj-r5rf-ggwq","title":"elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)","link":"https:\/\/github.com\/advisories\/GHSA-gxmj-r5rf-ggwq","cve":"CVE-2026-81891","affectedVersions":"\u003C2.1.70","source":"GitHub","reportedAt":"2026-09-02 14:37:54","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gxmj-r5rf-ggwq"}]},{"advisoryId":"PKSA-r7xr-47v5-58tx","packageName":"studio-42\/elfinder","remoteId":"GHSA-8x3q-jpjh-qh5c","title":"elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback","link":"https:\/\/github.com\/advisories\/GHSA-8x3q-jpjh-qh5c","cve":"CVE-2026-81889","affectedVersions":"\u003C=2.1.69","source":"GitHub","reportedAt":"2026-08-31 20:28:06","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8x3q-jpjh-qh5c"}]}],"livewire\/livewire":[{"advisoryId":"PKSA-bgw4-5zmg-2njg","packageName":"livewire\/livewire","remoteId":"GHSA-g3hc-697w-wm82","title":"Livewire DOM-based cross-site scripting during client-side state handling","link":"https:\/\/github.com\/advisories\/GHSA-g3hc-697w-wm82","cve":"CVE-2026-81887","affectedVersions":"\u003E=4.0.0-beta.1,\u003C=4.3.3|\u003E=3.0.0-beta.1,\u003C=3.8.2","source":"GitHub","reportedAt":"2026-09-02 14:38:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g3hc-697w-wm82"}]}],"typo3\/cms-backend":[{"advisoryId":"PKSA-nmd9-kc7m-nsvr","packageName":"typo3\/cms-backend","remoteId":"GHSA-68jx-f42c-7599","title":"TYPO3 CMS - Broken Access Control in Backend and Install Tool","link":"https:\/\/github.com\/advisories\/GHSA-68jx-f42c-7599","cve":"CVE-2026-19418","affectedVersions":"\u003E=13.0.0,\u003C13.4.34","source":"GitHub","reportedAt":"2026-09-01 21:31:42","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-68jx-f42c-7599"}]}],"filament\/filament":[{"advisoryId":"PKSA-wst7-5d23-qy5j","packageName":"filament\/filament","remoteId":"GHSA-52xp-w8hr-xv3c","title":"Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled","link":"https:\/\/github.com\/advisories\/GHSA-52xp-w8hr-xv3c","cve":"CVE-2026-77567","affectedVersions":"\u003E=5.0.0,\u003C5.7.0|\u003E=4.0.0,\u003C4.12.0","source":"GitHub","reportedAt":"2026-09-01 21:28:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-52xp-w8hr-xv3c"}]},{"advisoryId":"PKSA-r2v2-7j3d-th1m","packageName":"filament\/filament","remoteId":"GHSA-xwpv-pqxp-5v36","title":"Filament: Password validity disclosure for accounts denied panel access on login page","link":"https:\/\/github.com\/advisories\/GHSA-xwpv-pqxp-5v36","cve":"CVE-2026-84307","affectedVersions":"\u003E=5.0.0,\u003C5.7.5|\u003E=4.0.0,\u003C4.12.5","source":"GitHub","reportedAt":"2026-09-01 21:29:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xwpv-pqxp-5v36"}]},{"advisoryId":"PKSA-fwm5-nrzy-yd41","packageName":"filament\/filament","remoteId":"GHSA-r3j6-gpjw-qfjr","title":"Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used","link":"https:\/\/github.com\/advisories\/GHSA-r3j6-gpjw-qfjr","cve":"CVE-2026-84306","affectedVersions":"\u003E=5.0.0,\u003C5.7.6|\u003E=4.0.0,\u003C4.12.6","source":"GitHub","reportedAt":"2026-09-01 21:29:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r3j6-gpjw-qfjr"}]}],"league\/commonmark":[{"advisoryId":"PKSA-nv44-1b4d-6gjg","packageName":"league\/commonmark","remoteId":"GHSA-jjv6-8j6v-6j52","title":"league\/commonmark: Denial of service in the SmartPunct and Attributes extensions","link":"https:\/\/github.com\/advisories\/GHSA-jjv6-8j6v-6j52","cve":null,"affectedVersions":"\u003E=1.5.0,\u003C2.9.1","source":"GitHub","reportedAt":"2026-09-01 20:21:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jjv6-8j6v-6j52"}]},{"advisoryId":"PKSA-zyf5-hrxv-hrd7","packageName":"league\/commonmark","remoteId":"GHSA-8rr7-cvq3-gmfh","title":"league\/commonmark: Denial of service via distinctly-named attributes in the Attributes extension","link":"https:\/\/github.com\/advisories\/GHSA-8rr7-cvq3-gmfh","cve":null,"affectedVersions":"\u003E=1.5.0,\u003C2.10.0","source":"GitHub","reportedAt":"2026-09-01 20:28:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8rr7-cvq3-gmfh"}]},{"advisoryId":"PKSA-kr3s-894t-g5w2","packageName":"league\/commonmark","remoteId":"GHSA-f8fg-pg57-v4j8","title":"league\/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed","link":"https:\/\/github.com\/advisories\/GHSA-f8fg-pg57-v4j8","cve":null,"affectedVersions":"\u003E=2.7.0,\u003C2.9.1","source":"GitHub","reportedAt":"2026-09-01 20:18:29","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f8fg-pg57-v4j8"}]},{"advisoryId":"PKSA-9q1p-3s19-bp1q","packageName":"league\/commonmark","remoteId":"GHSA-j8pm-gj4c-rq4x","title":"league\/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters","link":"https:\/\/github.com\/advisories\/GHSA-j8pm-gj4c-rq4x","cve":null,"affectedVersions":"\u003E=0.6.0,\u003C2.9.1","source":"GitHub","reportedAt":"2026-09-01 20:17:59","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j8pm-gj4c-rq4x"}]},{"advisoryId":"PKSA-cqd6-fg4n-nxpf","packageName":"league\/commonmark","remoteId":"GHSA-mh25-x5hq-wrqp","title":"league\/commonmark: Denial of service via colliding heading slugs","link":"https:\/\/github.com\/advisories\/GHSA-mh25-x5hq-wrqp","cve":null,"affectedVersions":"\u003E=2.0.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:41:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mh25-x5hq-wrqp"}]},{"advisoryId":"PKSA-1q6p-sqkj-8mmj","packageName":"league\/commonmark","remoteId":"GHSA-jfm3-95jq-q3rf","title":"league\/commonmark:  Denial of service via duplicate footnote definitions","link":"https:\/\/github.com\/advisories\/GHSA-jfm3-95jq-q3rf","cve":null,"affectedVersions":"\u003E=1.5.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:40:53","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jfm3-95jq-q3rf"}]},{"advisoryId":"PKSA-5mzr-szzf-z6cn","packageName":"league\/commonmark","remoteId":"GHSA-mj63-m3rc-8ppr","title":"league\/commonmark: Denial of service via deeply nested XML output","link":"https:\/\/github.com\/advisories\/GHSA-mj63-m3rc-8ppr","cve":null,"affectedVersions":"\u003E=2.0.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:42:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mj63-m3rc-8ppr"}]},{"advisoryId":"PKSA-scnn-p8mm-jbft","packageName":"league\/commonmark","remoteId":"GHSA-29pj-957v-52mc","title":"league\/commonmark: AttributesExtension href\/src unsafe-link filter bypass via embedded control bytes","link":"https:\/\/github.com\/advisories\/GHSA-29pj-957v-52mc","cve":"CVE-2026-71478","affectedVersions":"\u003E=1.5.0,\u003C=2.8.3","source":"GitHub","reportedAt":"2026-08-06 20:30:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-29pj-957v-52mc"}]},{"advisoryId":"PKSA-t21r-vtr5-3mdz","packageName":"league\/commonmark","remoteId":"GHSA-2q4p-g7hv-5rgv","title":"league\/commonmark: Quadratic-time denial of service when parsing crafted Markdown","link":"https:\/\/github.com\/advisories\/GHSA-2q4p-g7hv-5rgv","cve":"CVE-2026-71488","affectedVersions":"\u003E=0.6.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:37:20","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2q4p-g7hv-5rgv"}]},{"advisoryId":"PKSA-mc58-w91n-f5gv","packageName":"league\/commonmark","remoteId":"GHSA-g2gp-3wwq-f4ph","title":"league\/commonmark: Denial of service via adjacent inline attribute blocks","link":"https:\/\/github.com\/advisories\/GHSA-g2gp-3wwq-f4ph","cve":null,"affectedVersions":"\u003E=1.5.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:39:52","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g2gp-3wwq-f4ph"}]}],"statamic\/cms":[{"advisoryId":"PKSA-rsd9-mj5m-pj4f","packageName":"statamic\/cms","remoteId":"GHSA-jppw-r5j3-xf7x","title":"Statamic CMS exposes two-factor recovery codes through dynamic Antlers rendering","link":"https:\/\/github.com\/advisories\/GHSA-jppw-r5j3-xf7x","cve":"CVE-2026-71293","affectedVersions":"\u003E=6.0.0-alpha.1,\u003C=6.30.0","source":"GitHub","reportedAt":"2026-08-05 15:32:21","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jppw-r5j3-xf7x"}]},{"advisoryId":"PKSA-yprw-4kcc-73cg","packageName":"statamic\/cms","remoteId":"GHSA-qh8c-7588-qfrv","title":"Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries","link":"https:\/\/github.com\/advisories\/GHSA-qh8c-7588-qfrv","cve":"CVE-2026-64662","affectedVersions":"\u003E=6.0.0,\u003C6.24.0|\u003C5.74.1","source":"GitHub","reportedAt":"2026-08-06 19:30:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qh8c-7588-qfrv"}]},{"advisoryId":"PKSA-htv4-42tq-8d9c","packageName":"statamic\/cms","remoteId":"GHSA-qhr7-v3xp-vw9m","title":"Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types","link":"https:\/\/github.com\/advisories\/GHSA-qhr7-v3xp-vw9m","cve":"CVE-2026-71434","affectedVersions":"\u003E=6.0.0,\u003C6.24.2|\u003C5.74.3","source":"GitHub","reportedAt":"2026-08-06 19:35:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qhr7-v3xp-vw9m"}]},{"advisoryId":"PKSA-h7t4-kgpy-prgj","packageName":"statamic\/cms","remoteId":"GHSA-vx89-p3j7-8xqc","title":"Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template","link":"https:\/\/github.com\/advisories\/GHSA-vx89-p3j7-8xqc","cve":"CVE-2026-71435","affectedVersions":"\u003E=6.0.0,\u003C6.24.2|\u003C5.74.3","source":"GitHub","reportedAt":"2026-08-06 19:37:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vx89-p3j7-8xqc"}]},{"advisoryId":"PKSA-691k-v8bf-zdg7","packageName":"statamic\/cms","remoteId":"GHSA-225x-3jhx-wh4q","title":"Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence","link":"https:\/\/github.com\/advisories\/GHSA-225x-3jhx-wh4q","cve":"CVE-2026-64664","affectedVersions":"\u003E=6.0.0,\u003C6.24.0|\u003C5.74.1","source":"GitHub","reportedAt":"2026-08-06 19:22:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-225x-3jhx-wh4q"}]},{"advisoryId":"PKSA-vbqf-w9v5-8bfs","packageName":"statamic\/cms","remoteId":"GHSA-93qh-5269-9wcf","title":"Statamic: Account takeover via OAuth email matching without email-verification check","link":"https:\/\/github.com\/advisories\/GHSA-93qh-5269-9wcf","cve":"CVE-2026-64665","affectedVersions":"\u003E=6.0.0,\u003C6.24.0|\u003C5.74.1","source":"GitHub","reportedAt":"2026-08-06 19:25:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-93qh-5269-9wcf"}]},{"advisoryId":"PKSA-p8hp-2yrt-f2d6","packageName":"statamic\/cms","remoteId":"GHSA-j2vp-f2pv-5rj4","title":"Statamic: Unsafe method invocation via Antlers template resolution allows data destruction","link":"https:\/\/github.com\/advisories\/GHSA-j2vp-f2pv-5rj4","cve":"CVE-2026-64663","affectedVersions":"\u003E=6.0.0,\u003C6.24.0|\u003C5.74.1","source":"GitHub","reportedAt":"2026-08-06 19:28:08","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j2vp-f2pv-5rj4"}]}],"smarty\/smarty":[{"advisoryId":"PKSA-mz8k-7h5s-m8kh","packageName":"smarty\/smarty","remoteId":"GHSA-cq55-c7wv-pxmq","title":"Smarty: SSRF via redirect bypass of trusted_uri using {fetch}","link":"https:\/\/github.com\/advisories\/GHSA-cq55-c7wv-pxmq","cve":"CVE-2026-62993","affectedVersions":"\u003C4.5.7|\u003E=5.0.0,\u003C5.8.2","source":"GitHub","reportedAt":"2026-09-01 16:38:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cq55-c7wv-pxmq"}]},{"advisoryId":"PKSA-7cg9-1cz1-3qff","packageName":"smarty\/smarty","remoteId":"GHSA-rjhh-76wf-8xmw","title":"Smarty Security stream restriction bypass through stream: resource","link":"https:\/\/github.com\/advisories\/GHSA-rjhh-76wf-8xmw","cve":"CVE-2026-62996","affectedVersions":"\u003E=5.0.0,\u003C5.8.4","source":"GitHub","reportedAt":"2026-08-07 15:10:51","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rjhh-76wf-8xmw"}]},{"advisoryId":"PKSA-zw1q-6h4d-mf1m","packageName":"smarty\/smarty","remoteId":"GHSA-f6wf-28g6-769x","title":"Smarty: Symlink path traversal out of trusted directories","link":"https:\/\/github.com\/advisories\/GHSA-f6wf-28g6-769x","cve":"CVE-2026-62992","affectedVersions":"\u003C4.5.7|\u003E=5.0.0,\u003C5.8.2","source":"GitHub","reportedAt":"2026-08-07 15:02:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f6wf-28g6-769x"}]}],"privatebin\/privatebin":[{"advisoryId":"PKSA-ysv6-x4qh-fd9v","packageName":"privatebin\/privatebin","remoteId":"GHSA-f2xf-7x3g-4272","title":"PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction","link":"https:\/\/github.com\/advisories\/GHSA-f2xf-7x3g-4272","cve":"CVE-2026-55696","affectedVersions":"\u003C=2.0.4","source":"GitHub","reportedAt":"2026-08-28 20:22:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f2xf-7x3g-4272"}]},{"advisoryId":"PKSA-t55m-4nf3-277t","packageName":"privatebin\/privatebin","remoteId":"GHSA-xrjc-c68j-hp7w","title":"PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI","link":"https:\/\/github.com\/advisories\/GHSA-xrjc-c68j-hp7w","cve":"CVE-2026-55891","affectedVersions":"\u003C=2.0.4","source":"GitHub","reportedAt":"2026-08-28 20:25:34","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xrjc-c68j-hp7w"}]}],"pimcore\/pimcore":[{"advisoryId":"PKSA-kkjc-bw16-f3kq","packageName":"pimcore\/pimcore","remoteId":"GHSA-w23p-wrp7-ch38","title":"Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502)","link":"https:\/\/github.com\/advisories\/GHSA-w23p-wrp7-ch38","cve":"CVE-2026-55220","affectedVersions":"\u003C=12.3.9|\u003E=2026.1.0,\u003C=2026.1.5","source":"GitHub","reportedAt":"2026-08-28 19:13:25","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-w23p-wrp7-ch38"}]},{"advisoryId":"PKSA-vgg9-cbdg-s4xt","packageName":"pimcore\/pimcore","remoteId":"GHSA-9x44-4gxf-8c25","title":"Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name","link":"https:\/\/github.com\/advisories\/GHSA-9x44-4gxf-8c25","cve":"CVE-2026-55634","affectedVersions":"\u003E=2026.1.0,\u003C=2026.1.5|\u003C=12.3.9","source":"GitHub","reportedAt":"2026-08-28 19:17:42","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-9x44-4gxf-8c25"}]},{"advisoryId":"PKSA-fpxc-s2d8-24zv","packageName":"pimcore\/pimcore","remoteId":"GHSA-2mhj-fhvg-v428","title":"Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name","link":"https:\/\/github.com\/advisories\/GHSA-2mhj-fhvg-v428","cve":"CVE-2026-55072","affectedVersions":"\u003C12.3.9|\u003E=2026.1.0,\u003C=2026.1.4","source":"GitHub","reportedAt":"2026-08-13 13:44:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2mhj-fhvg-v428"}]},{"advisoryId":"PKSA-6dhb-gq75-qpgr","packageName":"pimcore\/pimcore","remoteId":"GHSA-7p36-fq2r-4h7r","title":"Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed","link":"https:\/\/github.com\/advisories\/GHSA-7p36-fq2r-4h7r","cve":"CVE-2026-11407","affectedVersions":"\u003C=11.5.14.1|\u003E=12.0.0-RC1,\u003C=12.3.8","source":"GitHub","reportedAt":"2026-06-17 21:34:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7p36-fq2r-4h7r"}]}],"pimcore\/studio-backend-bundle":[{"advisoryId":"PKSA-spw3-r32w-35m6","packageName":"pimcore\/studio-backend-bundle","remoteId":"GHSA-h854-c3m3-mh5v","title":"Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass","link":"https:\/\/github.com\/advisories\/GHSA-h854-c3m3-mh5v","cve":"CVE-2026-55207","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.6|\u003C2025.4.6","source":"GitHub","reportedAt":"2026-08-28 19:04:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h854-c3m3-mh5v"}]},{"advisoryId":"PKSA-pq1q-v29r-6xp5","packageName":"pimcore\/studio-backend-bundle","remoteId":"GHSA-79cw-hfcc-7mw9","title":"Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes","link":"https:\/\/github.com\/advisories\/GHSA-79cw-hfcc-7mw9","cve":"CVE-2026-55208","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.6|\u003C2025.4.6","source":"GitHub","reportedAt":"2026-08-28 19:04:54","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-79cw-hfcc-7mw9"}]},{"advisoryId":"PKSA-89fg-v2s3-x29j","packageName":"pimcore\/studio-backend-bundle","remoteId":"GHSA-f97c-ph8j-8vff","title":"Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation","link":"https:\/\/github.com\/advisories\/GHSA-f97c-ph8j-8vff","cve":"CVE-2026-55212","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.6|\u003C2025.4.6","source":"GitHub","reportedAt":"2026-08-28 19:05:25","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f97c-ph8j-8vff"}]}],"phpsysinfo\/phpsysinfo":[{"advisoryId":"PKSA-m4bq-bq4t-zzsh","packageName":"phpsysinfo\/phpsysinfo","remoteId":"GHSA-786w-p5pm-cvgh","title":"phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For \/ Client-IP headers","link":"https:\/\/github.com\/advisories\/GHSA-786w-p5pm-cvgh","cve":"CVE-2026-55584","affectedVersions":"\u003C=3.4.5","source":"GitHub","reportedAt":"2026-08-28 18:30:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-786w-p5pm-cvgh"}]}],"phalcon\/cphalcon":[{"advisoryId":"PKSA-65xj-m5g6-56k1","packageName":"phalcon\/cphalcon","remoteId":"GHSA-8jqh-95g6-7jpj","title":"Phalcon: Non-constant-time HMAC verification in `Encryption\\Crypt::decrypt` (timing side-channel)","link":"https:\/\/github.com\/advisories\/GHSA-8jqh-95g6-7jpj","cve":"CVE-2026-54736","affectedVersions":"\u003C=5.14.0","source":"GitHub","reportedAt":"2026-08-28 16:01:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8jqh-95g6-7jpj"}]},{"advisoryId":"PKSA-5stm-rfkw-zjbb","packageName":"phalcon\/cphalcon","remoteId":"GHSA-x7rj-f32v-7jjg","title":"Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS","link":"https:\/\/github.com\/advisories\/GHSA-x7rj-f32v-7jjg","cve":"CVE-2026-57584","affectedVersions":"\u003C=5.14.2","source":"GitHub","reportedAt":"2026-08-28 16:06:31","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-x7rj-f32v-7jjg"}]},{"advisoryId":"PKSA-n2s8-x5tr-m78t","packageName":"phalcon\/cphalcon","remoteId":"GHSA-hrwp-4hh9-c8r8","title":"Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)","link":"https:\/\/github.com\/advisories\/GHSA-hrwp-4hh9-c8r8","cve":"CVE-2026-59989","affectedVersions":"\u003C=5.15.0","source":"GitHub","reportedAt":"2026-08-21 20:55:56","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-hrwp-4hh9-c8r8"}]}],"cakephp\/queue":[{"advisoryId":"PKSA-tgsp-smx2-wtkc","packageName":"cakephp\/queue","remoteId":"GHSA-r5pm-vrc5-3m73","title":"cakephp\/queue\u0027s Incomplete Comparison in getUniqueId vulnerable to collisions","link":"https:\/\/github.com\/advisories\/GHSA-r5pm-vrc5-3m73","cve":"CVE-2026-54713","affectedVersions":"\u003E=0.1.10,\u003C2.3.1","source":"GitHub","reportedAt":"2026-08-27 17:03:56","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-r5pm-vrc5-3m73"}]}],"grumpydictator\/firefly-iii":[{"advisoryId":"PKSA-1kzk-15h2-h7dj","packageName":"grumpydictator\/firefly-iii","remoteId":"GHSA-9mmg-q95p-gp67","title":"Project Firefly III has incorrect access control in the webhook management component","link":"https:\/\/github.com\/advisories\/GHSA-9mmg-q95p-gp67","cve":"CVE-2026-50886","affectedVersions":"\u003C=6.5.9","source":"GitHub","reportedAt":"2026-06-15 21:30:41","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-9mmg-q95p-gp67"}]}],"shlinkio\/shlink":[{"advisoryId":"PKSA-wdxh-t7c7-2k2p","packageName":"shlinkio\/shlink","remoteId":"GHSA-p85r-x2wj-mxqj","title":"shlink has a Server-Side Request Forgery issue","link":"https:\/\/github.com\/advisories\/GHSA-p85r-x2wj-mxqj","cve":"CVE-2026-50887","affectedVersions":"\u003C=5.0.1","source":"GitHub","reportedAt":"2026-06-15 21:30:41","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-p85r-x2wj-mxqj"}]}],"koillection\/koillection":[{"advisoryId":"PKSA-r52z-frv4-qfxy","packageName":"koillection\/koillection","remoteId":"GHSA-gmxh-hjfv-qc2w","title":"Koillection has an authenticated Server-Side Request Forgery issue","link":"https:\/\/github.com\/advisories\/GHSA-gmxh-hjfv-qc2w","cve":"CVE-2026-50888","affectedVersions":"\u003C1.8.4","source":"GitHub","reportedAt":"2026-06-15 21:30:41","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gmxh-hjfv-qc2w"}]}],"devcode-it\/openstamanager":[{"advisoryId":"PKSA-nvw4-h4ry-dgt3","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-crx4-7mmq-j74j","title":"OpenSTAManager has HTML Injection in modules\/utenti\/edit.php","link":"https:\/\/github.com\/advisories\/GHSA-crx4-7mmq-j74j","cve":"CVE-2026-44701","affectedVersions":"\u003C=2.10.1","source":"GitHub","reportedAt":"2026-08-26 18:12:25","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-crx4-7mmq-j74j"}]}],"librenms\/librenms":[{"advisoryId":"PKSA-pcg8-3qh7-w8k9","packageName":"librenms\/librenms","remoteId":"GHSA-7w8c-qgxg-m7jx","title":"LibreNMS \u2014 Stored XSS via SNMP\/Syslog Data in Legacy Templates","link":"https:\/\/github.com\/advisories\/GHSA-7w8c-qgxg-m7jx","cve":null,"affectedVersions":"\u003C26.5.0","source":"GitHub","reportedAt":"2026-08-26 18:05:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7w8c-qgxg-m7jx"}]},{"advisoryId":"PKSA-m3bp-hsvq-mjs5","packageName":"librenms\/librenms","remoteId":"GHSA-jf24-8g2h-2wg7","title":"LibreNMS Vulnerable to Remote Code Execution via AboutController","link":"https:\/\/github.com\/advisories\/GHSA-jf24-8g2h-2wg7","cve":null,"affectedVersions":"\u003C26.5.0","source":"GitHub","reportedAt":"2026-08-18 21:17:11","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jf24-8g2h-2wg7"}]},{"advisoryId":"PKSA-jmpz-3j3j-881p","packageName":"librenms\/librenms","remoteId":"GHSA-7cj5-v4pp-v632","title":"LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users","link":"https:\/\/github.com\/advisories\/GHSA-7cj5-v4pp-v632","cve":null,"affectedVersions":"\u003C26.7.0","source":"GitHub","reportedAt":"2026-08-18 21:17:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7cj5-v4pp-v632"}]},{"advisoryId":"PKSA-9d1b-7dzj-kkfs","packageName":"librenms\/librenms","remoteId":"GHSA-7gww-x7fh-jf9j","title":"LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page","link":"https:\/\/github.com\/advisories\/GHSA-7gww-x7fh-jf9j","cve":null,"affectedVersions":"\u003C26.7.0","source":"GitHub","reportedAt":"2026-08-18 21:17:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7gww-x7fh-jf9j"}]},{"advisoryId":"PKSA-8dtq-rfyc-264h","packageName":"librenms\/librenms","remoteId":"GHSA-c9fv-cgmm-2wg7","title":"LibreNMS Vulnerable to Remote Code Execution by Signal Alert Transportation module","link":"https:\/\/github.com\/advisories\/GHSA-c9fv-cgmm-2wg7","cve":"CVE-2026-55182","affectedVersions":"\u003E=21.6.0,\u003C26.5.0","source":"GitHub","reportedAt":"2026-08-18 17:59:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c9fv-cgmm-2wg7"}]},{"advisoryId":"PKSA-63gx-s9j2-62yc","packageName":"librenms\/librenms","remoteId":"GHSA-jmqm-f8q4-v7wx","title":"LibreNMS: Reflected XSS via Proxmox instance\/vmid GET parameters injected into document.title JavaScript assignment","link":"https:\/\/github.com\/advisories\/GHSA-jmqm-f8q4-v7wx","cve":"CVE-2026-45694","affectedVersions":"\u003C=26.4.0","source":"GitHub","reportedAt":"2026-08-12 15:16:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jmqm-f8q4-v7wx"}]}],"cakephp\/debug_kit":[{"advisoryId":"PKSA-8d84-6pxy-6g1s","packageName":"cakephp\/debug_kit","remoteId":"GHSA-p46m-g734-vpc4","title":"cakephp\/debug_kit: MailPreview contains unsafe reflection","link":"https:\/\/github.com\/advisories\/GHSA-p46m-g734-vpc4","cve":"CVE-2026-54614","affectedVersions":"\u003E=5.0.0,\u003C5.2.4|\u003C4.10.3","source":"GitHub","reportedAt":"2026-08-26 15:31:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-p46m-g734-vpc4"}]}],"microweber\/microweber":[{"advisoryId":"PKSA-y3dv-vpbg-vs2t","packageName":"microweber\/microweber","remoteId":"GHSA-vv4x-qcpq-wgrg","title":"Microweber vulnerable to Path Traversal","link":"https:\/\/github.com\/advisories\/GHSA-vv4x-qcpq-wgrg","cve":"CVE-2026-12198","affectedVersions":"\u003C=2.0.20","source":"GitHub","reportedAt":"2026-06-15 00:31:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vv4x-qcpq-wgrg"}]}],"intelliants\/subrion":[{"advisoryId":"PKSA-9dbm-kft4-ck43","packageName":"intelliants\/subrion","remoteId":"GHSA-wrcg-234w-hfhq","title":"Subrion CMS vulnerable to Cross-site Scripting","link":"https:\/\/github.com\/advisories\/GHSA-wrcg-234w-hfhq","cve":"CVE-2026-12202","affectedVersions":"\u003C=4.0.3","source":"GitHub","reportedAt":"2026-06-15 03:30:32","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-wrcg-234w-hfhq"}]}],"phpmyfaq\/phpmyfaq":[{"advisoryId":"PKSA-g5hk-s1sp-5tnd","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-mf8r-wm2w-f8c5","title":"phpMyFAQ public FAQ APIs expose inactive FAQ content","link":"https:\/\/github.com\/advisories\/GHSA-mf8r-wm2w-f8c5","cve":null,"affectedVersions":"\u003E=4.1.0,\u003C=4.1.4","source":"GitHub","reportedAt":"2026-08-25 17:30:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mf8r-wm2w-f8c5"}]},{"advisoryId":"PKSA-p7rj-kmfh-92s9","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-pg62-f8g4-4wqh","title":"phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold","link":"https:\/\/github.com\/advisories\/GHSA-pg62-f8g4-4wqh","cve":null,"affectedVersions":"\u003C=4.1.4","source":"GitHub","reportedAt":"2026-08-25 17:32:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pg62-f8g4-4wqh"}]},{"advisoryId":"PKSA-wjc4-72dv-h8tm","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-88g4-74f3-63x9","title":"phpMyFAQ has Potential Authenticated Path Traversal in PDF Export","link":"https:\/\/github.com\/advisories\/GHSA-88g4-74f3-63x9","cve":null,"affectedVersions":"\u003E=4.0.0-alpha,\u003C=4.1.4","source":"GitHub","reportedAt":"2026-08-25 17:28:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-88g4-74f3-63x9"}]}],"thorsten\/phpmyfaq":[{"advisoryId":"PKSA-5ym8-q7sn-cqmx","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-mf8r-wm2w-f8c5","title":"phpMyFAQ public FAQ APIs expose inactive FAQ content","link":"https:\/\/github.com\/advisories\/GHSA-mf8r-wm2w-f8c5","cve":null,"affectedVersions":"\u003E=4.1.0,\u003C=4.1.4","source":"GitHub","reportedAt":"2026-08-25 17:30:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mf8r-wm2w-f8c5"}]},{"advisoryId":"PKSA-hycs-5t33-gw1y","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-pg62-f8g4-4wqh","title":"phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold","link":"https:\/\/github.com\/advisories\/GHSA-pg62-f8g4-4wqh","cve":null,"affectedVersions":"\u003C=4.1.4","source":"GitHub","reportedAt":"2026-08-25 17:32:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pg62-f8g4-4wqh"}]},{"advisoryId":"PKSA-wqvs-f8jk-pt53","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-88g4-74f3-63x9","title":"phpMyFAQ has Potential Authenticated Path Traversal in PDF Export","link":"https:\/\/github.com\/advisories\/GHSA-88g4-74f3-63x9","cve":null,"affectedVersions":"\u003E=4.0.0-alpha,\u003C=4.1.4","source":"GitHub","reportedAt":"2026-08-25 17:28:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-88g4-74f3-63x9"}]},{"advisoryId":"PKSA-cz4f-38kk-4ywj","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-6pvm-2vjj-rx4w","title":"phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration","link":"https:\/\/github.com\/advisories\/GHSA-6pvm-2vjj-rx4w","cve":"CVE-2026-47132","affectedVersions":"\u003C4.2.0-alpha","source":"GitHub","reportedAt":"2026-08-12 15:17:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6pvm-2vjj-rx4w"}]}],"in2code\/powermail":[{"advisoryId":"PKSA-dhfp-j236-nf9h","packageName":"in2code\/powermail","remoteId":"in2code\/powermail\/CVE-2026-77136.yaml","title":"TYPO3-EXT-SA-2026-022: Server-Side Template Injection in extension \u0022powermail\u0022 (powermail)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-022","cve":"CVE-2026-77136","affectedVersions":"\u003E=13.0.0,\u003C13.2.1|\u003E=11.0.0,\u003C12.6.1|\u003C10.9.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"in2code\/powermail\/CVE-2026-77136.yaml"}]}],"in2code\/femanager":[{"advisoryId":"PKSA-d8yc-sp4m-wsqx","packageName":"in2code\/femanager","remoteId":"in2code\/femanager\/CVE-2026-77146.yaml","title":"TYPO3-EXT-SA-2026-024: Broken Access Control in extension \u0022femanager\u0022 (femanager)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-024","cve":"CVE-2026-77146","affectedVersions":"\u003E=8.0.0,\u003C8.4.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"in2code\/femanager\/CVE-2026-77146.yaml"}]},{"advisoryId":"PKSA-ys21-4vkn-ktz8","packageName":"in2code\/femanager","remoteId":"in2code\/femanager\/CVE-2026-77133.yaml","title":"TYPO3-EXT-SA-2026-024: Broken Access Control in extension \u0022femanager\u0022 (femanager)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-024","cve":"CVE-2026-77133","affectedVersions":"\u003E=13.0.0,\u003C13.3.5|\u003E=8.0.0,\u003C8.4.2|\u003E=7.0.0,\u003C7.5.5|\u003C6.4.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"in2code\/femanager\/CVE-2026-77133.yaml"}]},{"advisoryId":"PKSA-8rwj-778x-wr3q","packageName":"in2code\/femanager","remoteId":"in2code\/femanager\/CVE-2026-77135.yaml","title":"TYPO3-EXT-SA-2026-024: Information Disclosure in extension \u0022femanager\u0022 (femanager)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-024","cve":"CVE-2026-77135","affectedVersions":"\u003E=13.0.0,\u003C13.3.5|\u003E=8.0.0,\u003C8.4.2|\u003E=7.0.0,\u003C7.5.5|\u003C6.4.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"in2code\/femanager\/CVE-2026-77135.yaml"}]},{"advisoryId":"PKSA-2nc4-qstv-j2k4","packageName":"in2code\/femanager","remoteId":"in2code\/femanager\/CVE-2026-77134.yaml","title":"TYPO3-EXT-SA-2026-024: Broken Access Control in extension \u0022femanager\u0022 (femanager)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-024","cve":"CVE-2026-77134","affectedVersions":"\u003E=13.0.0,\u003C13.3.5|\u003E=8.0.0,\u003C8.4.2|\u003E=7.0.0,\u003C7.5.5|\u003C6.4.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"in2code\/femanager\/CVE-2026-77134.yaml"}]}],"jweiland\/yellowpages2":[{"advisoryId":"PKSA-18gt-2dzk-y4sf","packageName":"jweiland\/yellowpages2","remoteId":"jweiland\/yellowpages2\/CVE-2026-77142.yaml","title":"TYPO3-EXT-SA-2026-020: Broken Access Control in extension \u0022Industry Directory\u0022 (yellowpages2)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-020","cve":"CVE-2026-77142","affectedVersions":"\u003C6.1.6|\u003E=7.0.0,\u003C7.0.3|\u003E=8.0.0,\u003C8.1.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/yellowpages2\/CVE-2026-77142.yaml"}]}],"jweiland\/pforum":[{"advisoryId":"PKSA-j6mc-zgry-j2jj","packageName":"jweiland\/pforum","remoteId":"jweiland\/pforum\/CVE-2026-77143.yaml","title":"TYPO3-EXT-SA-2026-021: Broken Access Control in extension \u0022Forum\u0022 (pforum)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-021","cve":"CVE-2026-77143","affectedVersions":"\u003C4.0.4|\u003E=5.0.0,\u003C5.0.1|\u003E=6.0.0,\u003C6.2.4","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/pforum\/CVE-2026-77143.yaml"}]}],"jweiland\/events2":[{"advisoryId":"PKSA-j7f2-fsqf-djzr","packageName":"jweiland\/events2","remoteId":"jweiland\/events2\/CVE-2026-77145.yaml","title":"TYPO3-EXT-SA-2026-026: Broken Access Control in extension \u0022Events 2\u0022 (events2)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-026","cve":"CVE-2026-77145","affectedVersions":"\u003C8.6.3|\u003E=9.0.0,\u003C9.4.2|\u003E=10.0.0,\u003C10.2.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/events2\/CVE-2026-77145.yaml"}]},{"advisoryId":"PKSA-yh4t-fxmy-jygr","packageName":"jweiland\/events2","remoteId":"jweiland\/events2\/CVE-2026-77144.yaml","title":"TYPO3-EXT-SA-2026-026: Broken Access Control in extension \u0022Events 2\u0022 (events2)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-026","cve":"CVE-2026-77144","affectedVersions":"\u003C8.6.3|\u003E=9.0.0,\u003C9.4.2|\u003E=10.0.0,\u003C10.2.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/events2\/CVE-2026-77144.yaml"}]}],"jweiland\/clubdirectory":[{"advisoryId":"PKSA-zj12-wn7w-mydt","packageName":"jweiland\/clubdirectory","remoteId":"jweiland\/clubdirectory\/CVE-2026-77141.yaml","title":"TYPO3-EXT-SA-2026-019: Broken Access Control in extension \u0022Club Directory\u0022 (clubdirectory)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-019","cve":"CVE-2026-77141","affectedVersions":"\u003C6.0.2|\u003E=7.0.0,\u003C7.0.2|\u003E=8.0.0,\u003C8.1.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/clubdirectory\/CVE-2026-77141.yaml"}]}],"jweiland\/telephonedirectory":[{"advisoryId":"PKSA-kq76-qzx4-zwwk","packageName":"jweiland\/telephonedirectory","remoteId":"jweiland\/telephonedirectory\/CVE-2026-77140.yaml","title":"TYPO3-EXT-SA-2026-018: Broken Access Control in extension \u0022Telephone Directory\u0022 (telephonedirectory)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-018","cve":"CVE-2026-77140","affectedVersions":"\u003C4.1.1|\u003E=5.0.0,\u003C5.0.1|\u003E=6.0.0,\u003C6.2.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/telephonedirectory\/CVE-2026-77140.yaml"}]}],"frappant\/frp-form-answers":[{"advisoryId":"PKSA-67bk-g8n5-47sq","packageName":"frappant\/frp-form-answers","remoteId":"frappant\/frp-form-answers\/CVE-2026-77137.yaml","title":"TYPO3-EXT-SA-2026-027: SQL Injection in extension \u0022Forms Export\u0022 (frp_form_answers)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-027","cve":"CVE-2026-77137","affectedVersions":"\u003E=7.0.0,\u003C7.1.1|\u003E=6.0.0,\u003C6.1.3|\u003C5.0.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"frappant\/frp-form-answers\/CVE-2026-77137.yaml"}]}],"derhansen\/sf_event_mgt":[{"advisoryId":"PKSA-zn9v-7dk7-9n62","packageName":"derhansen\/sf_event_mgt","remoteId":"derhansen\/sf_event_mgt\/CVE-2026-77128.yaml","title":"TYPO3-EXT-SA-2026-023: Broken Access Control in extension \u0022Event management and registration\u0022 (sf_event_mgt)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-023","cve":"CVE-2026-77128","affectedVersions":"\u003E=9.0.0,\u003C9.0.3|\u003E=8.0.0,\u003C8.6.2|\u003E=7.0.0,\u003C7.9.3|\u003E=6.0.0,\u003C6.7.2|\u003C5.9.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"derhansen\/sf_event_mgt\/CVE-2026-77128.yaml"}]},{"advisoryId":"PKSA-xn4n-zch1-3zsy","packageName":"derhansen\/sf_event_mgt","remoteId":"derhansen\/sf_event_mgt\/CVE-2026-77129.yaml","title":"TYPO3-EXT-SA-2026-023: Server-Side Template Injection in extension \u0022Event management and registration\u0022 (sf_event_mgt)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-023","cve":"CVE-2026-77129","affectedVersions":"\u003E=9.0.0,\u003C9.0.3|\u003E=8.0.0,\u003C8.6.2|\u003E=7.0.0,\u003C7.9.3|\u003E=6.0.0,\u003C6.7.2|\u003C5.9.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"derhansen\/sf_event_mgt\/CVE-2026-77129.yaml"}]}],"apache-solr-for-typo3\/solr":[{"advisoryId":"PKSA-f58b-fgg4-r9xs","packageName":"apache-solr-for-typo3\/solr","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56093.yaml","title":"TYPO3-EXT-SA-2026-025: Broken Access Control in extension \u0022Apache Solr for TYPO3 - Enterprise Search\u0022 (solr)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-025","cve":"CVE-2026-56093","affectedVersions":"\u003E=13.0.0,\u003C13.1.4|\u003E=12.0.0,\u003C12.1.4|\u003C11.6.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56093.yaml"}]},{"advisoryId":"PKSA-h6s2-79xk-1xwg","packageName":"apache-solr-for-typo3\/solr","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56092.yaml","title":"TYPO3-EXT-SA-2026-025: Broken Access Control in extension \u0022Apache Solr for TYPO3 - Enterprise Search\u0022 (solr)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-025","cve":"CVE-2026-56092","affectedVersions":"\u003E=13.0.0,\u003C13.1.4|\u003E=12.0.0,\u003C12.1.4|\u003C11.6.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56092.yaml"}]},{"advisoryId":"PKSA-nmhg-n7vm-6z1n","packageName":"apache-solr-for-typo3\/solr","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56095.yaml","title":"TYPO3-EXT-SA-2026-025: Insecure Deserialization in extension \u0022Apache Solr for TYPO3 - Enterprise Search\u0022 (solr)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-025","cve":"CVE-2026-56095","affectedVersions":"\u003E=13.0.0,\u003C13.1.4|\u003E=12.0.0,\u003C12.1.4|\u003C11.6.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56095.yaml"}]},{"advisoryId":"PKSA-218x-ph2q-d2nf","packageName":"apache-solr-for-typo3\/solr","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56096.yaml","title":"TYPO3-EXT-SA-2026-025: Information Disclosure in extension \u0022Apache Solr for TYPO3 - Enterprise Search\u0022 (solr)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-025","cve":"CVE-2026-56096","affectedVersions":"\u003E=13.0.0,\u003C13.1.4|\u003E=12.0.0,\u003C12.1.4|\u003C11.6.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56096.yaml"}]},{"advisoryId":"PKSA-xyyb-y2c3-k558","packageName":"apache-solr-for-typo3\/solr","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56094.yaml","title":"TYPO3-EXT-SA-2026-025: Information Disclosure in extension \u0022Apache Solr for TYPO3 - Enterprise Search\u0022 (solr)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-025","cve":"CVE-2026-56094","affectedVersions":"\u003E=13.0.0,\u003C13.1.4|\u003E=12.0.0,\u003C12.1.4|\u003C11.6.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56094.yaml"}]}],"mask\/mask":[{"advisoryId":"PKSA-vwmg-xq1p-q4cz","packageName":"mask\/mask","remoteId":"mask\/mask\/CVE-2026-77139.yaml","title":"TYPO3-EXT-SA-2026-017: Path Traversal in extension \u0022Mask\u0022 (mask)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-017","cve":"CVE-2026-77139","affectedVersions":"\u003E=9.0.0,\u003C9.0.11|\u003C8.3.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"mask\/mask\/CVE-2026-77139.yaml"}]}],"syssy\/syssy-typo3-extension":[{"advisoryId":"PKSA-p17b-6gjj-m8kp","packageName":"syssy\/syssy-typo3-extension","remoteId":"syssy\/syssy-typo3-extension\/CVE-2026-77131.yaml","title":"TYPO3-EXT-SA-2026-015: Cleartext Transmission of Sensitive Information in extension \u0022SYSSY - TYPO3 Monitoring \u0026 Security Checks\u0022 (syssy)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-015","cve":"CVE-2026-77131","affectedVersions":"\u003C3.0.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"syssy\/syssy-typo3-extension\/CVE-2026-77131.yaml"}]},{"advisoryId":"PKSA-xf71-q2f9-j6qg","packageName":"syssy\/syssy-typo3-extension","remoteId":"syssy\/syssy-typo3-extension\/CVE-2026-77130.yaml","title":"TYPO3-EXT-SA-2026-015: Insufficient Session Expiration in extension \u0022SYSSY - TYPO3 Monitoring \u0026 Security Checks\u0022 (syssy)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-015","cve":"CVE-2026-77130","affectedVersions":"\u003C3.0.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"syssy\/syssy-typo3-extension\/CVE-2026-77130.yaml"}]}],"codingms\/modules":[{"advisoryId":"PKSA-8bb5-r84n-24n7","packageName":"codingms\/modules","remoteId":"codingms\/modules\/CVE-2026-77127.yaml","title":"TYPO3-EXT-SA-2026-016: Information Disclosure in extension \u0022Modules\u0022 (modules)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-016","cve":"CVE-2026-77127","affectedVersions":"\u003E=8.0.0,\u003C8.1.4|\u003C7.10.4","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"codingms\/modules\/CVE-2026-77127.yaml"}]}],"lochmueller\/html5videoplayer-powermail":[{"advisoryId":"PKSA-6xxy-q4qw-wtq1","packageName":"lochmueller\/html5videoplayer-powermail","remoteId":"lochmueller\/html5videoplayer-powermail\/CVE-2026-77138.yaml","title":"TYPO3-EXT-SA-2026-014: Remote Code Execution in extension \u0022HTML5 Video Player vs. Powermail\u0022 (html5videoplayer_powermail)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-014","cve":"CVE-2026-77138","affectedVersions":"\u003C=0.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-01-01 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"lochmueller\/html5videoplayer-powermail\/CVE-2026-77138.yaml"}]}],"contao-components\/colorbox":[{"advisoryId":"PKSA-vz5f-wd4z-2kf4","packageName":"contao-components\/colorbox","remoteId":"contao-components\/colorbox\/2026-08-25.yaml","title":"Cross-site scripting in the Colorbox caption (see GHSA-rr85-7j77-pppg)","link":"https:\/\/github.com\/contao-components\/colorbox\/security\/advisories\/GHSA-rr85-7j77-pppg","cve":null,"affectedVersions":"\u003E=1.0.0,\u003C1.6.4.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao-components\/colorbox\/2026-08-25.yaml"}]}],"contao\/comments-bundle":[{"advisoryId":"PKSA-xbg5-kkqv-jb9y","packageName":"contao\/comments-bundle","remoteId":"contao\/comments-bundle\/2026-08-25.yaml","title":"Cross-site scripting in the comments bundle (see GHSA-628f-v4f6-p37r)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-scripting-in-the-comments-bundle","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/comments-bundle\/2026-08-25.yaml"}]}],"contao\/contao":[{"advisoryId":"PKSA-6gsv-pjvq-z35p","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-5.yaml","title":"Improper access control in the preview links module (see GHSA-q6wp-fr43-gm9v)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-preview-links-module","cve":null,"affectedVersions":"\u003E=5.7.1,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-5.yaml"}]},{"advisoryId":"PKSA-rfnv-mh54-2pc9","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-2.yaml","title":"Improper access control in the CSV import wizard (see GHSA-23w9-4pg3-xwm3)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-csv-import-wizard","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-2.yaml"}]},{"advisoryId":"PKSA-2s8k-hn9c-bkvy","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-6.yaml","title":"Path traversal in the images controller (see GHSA-mrvp-7wmx-5m4h)","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-images-controller","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-6.yaml"}]},{"advisoryId":"PKSA-vy31-xjc7-3g2h","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-9.yaml","title":"Exposure of sensitive information through a stale search index (see GHSA-x2rp-9qf7-2fmq)","link":"https:\/\/contao.org\/en\/security-advisories\/exposure-of-sensitive-information-through-a-stale-search-index","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-9.yaml"}]},{"advisoryId":"PKSA-8zc2-xpjt-dfrb","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-7.yaml","title":"Cross-site request forgery in custom backend actions (see GHSA-9ff2-p842-45wq)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-request-forgery-in-custom-backend-actions","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-7.yaml"}]},{"advisoryId":"PKSA-3fqv-nq39-s3wg","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-10.yaml","title":"Cross-site scripting in the comments bundle (see GHSA-628f-v4f6-p37r)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-scripting-in-the-comments-bundle","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-10.yaml"}]},{"advisoryId":"PKSA-nqyj-w4wy-fs47","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-3.yaml","title":"Non-admin users can self-grant permissions that implicitly make them administrators (see GHSA-r9qp-pqx5-8369)","link":"https:\/\/contao.org\/en\/security-advisories\/non-admin-users-can-self-grant-permissions-that-implicitly-make-them-administrators","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-3.yaml"}]},{"advisoryId":"PKSA-ws7m-s1y9-vkw6","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-11.yaml","title":"Improper access control in the newsletter module (see GHSA-3r9g-pfhv-3228)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-newsletter-module","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-11.yaml"}]},{"advisoryId":"PKSA-dtqn-wjcr-pw7c","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-8.yaml","title":"Unrestricted activation email resending (see GHSA-mfxh-vp55-7gc6)","link":"https:\/\/contao.org\/en\/security-advisories\/unrestricted-activation-email-resending","cve":null,"affectedVersions":"\u003E=4.1.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-8.yaml"}]},{"advisoryId":"PKSA-ncw3-bhm6-s2mg","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-4.yaml","title":"Cross-site scripting in the frontend search results (see GHSA-h57j-5f5m-789v)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-scripting-in-the-frontend-search-results","cve":null,"affectedVersions":"\u003E=4.9.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-4.yaml"}]},{"advisoryId":"PKSA-vtsh-c9df-2j1j","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-1.yaml","title":"Improper access control in the table access voter (see GHSA-5974-gfqc-wrcm)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-table-access-voter","cve":null,"affectedVersions":"\u003E=5.7.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-1.yaml"}]},{"advisoryId":"PKSA-8pr1-zw9p-tzyx","packageName":"contao\/contao","remoteId":"contao\/contao\/CVE-2026-55824.yaml","title":"Credentials disclosure in the crawler","link":"https:\/\/contao.org\/en\/security-advisories\/credentials-disclosure-in-the-crawler","cve":"CVE-2026-55824","affectedVersions":"\u003E=4.13.0,\u003C5.3.47|\u003E=5.4.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/CVE-2026-55824.yaml"},{"name":"GitHub","remoteId":"GHSA-3mr9-p497-58f6"}]},{"advisoryId":"PKSA-311q-qrt9-s2k4","packageName":"contao\/contao","remoteId":"contao\/contao\/CVE-2026-55825.yaml","title":"Path traversal in the jobs module","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-jobs-module","cve":"CVE-2026-55825","affectedVersions":"\u003E=5.7.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/CVE-2026-55825.yaml"},{"name":"GitHub","remoteId":"GHSA-grm4-wm43-9jh5"}]}],"contao\/core-bundle":[{"advisoryId":"PKSA-yksm-8fg2-dsvs","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-5.yaml","title":"Improper access control in the preview links module (see GHSA-q6wp-fr43-gm9v)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-preview-links-module","cve":null,"affectedVersions":"\u003E=5.7.1,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-5.yaml"}]},{"advisoryId":"PKSA-t5k3-41dk-f7y5","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-2.yaml","title":"Improper access control in the CSV import wizard (see GHSA-23w9-4pg3-xwm3)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-csv-import-wizard","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-2.yaml"}]},{"advisoryId":"PKSA-zm5t-426r-gfpx","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-6.yaml","title":"Path traversal in the images controller (see GHSA-mrvp-7wmx-5m4h)","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-images-controller","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-6.yaml"}]},{"advisoryId":"PKSA-cvfh-n5dv-w5t9","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-9.yaml","title":"Exposure of sensitive information through a stale search index (see GHSA-x2rp-9qf7-2fmq)","link":"https:\/\/contao.org\/en\/security-advisories\/exposure-of-sensitive-information-through-a-stale-search-index","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-9.yaml"}]},{"advisoryId":"PKSA-4788-1fwx-c4gc","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-7.yaml","title":"Cross-site request forgery in custom backend actions (see GHSA-9ff2-p842-45wq)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-request-forgery-in-custom-backend-actions","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-7.yaml"}]},{"advisoryId":"PKSA-335s-36s8-mdj4","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-3.yaml","title":"Non-admin users can self-grant permissions that implicitly make them administrators (see GHSA-r9qp-pqx5-8369)","link":"https:\/\/contao.org\/en\/security-advisories\/non-admin-users-can-self-grant-permissions-that-implicitly-make-them-administrators","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-3.yaml"}]},{"advisoryId":"PKSA-wrr4-414y-fqmj","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-8.yaml","title":"Unrestricted activation email resending (see GHSA-mfxh-vp55-7gc6)","link":"https:\/\/contao.org\/en\/security-advisories\/unrestricted-activation-email-resending","cve":null,"affectedVersions":"\u003E=4.1.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-8.yaml"}]},{"advisoryId":"PKSA-snk8-7c3n-1x4z","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-4.yaml","title":"Cross-site scripting in the frontend search results (see GHSA-h57j-5f5m-789v)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-scripting-in-the-frontend-search-results","cve":null,"affectedVersions":"\u003E=4.9.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-4.yaml"}]},{"advisoryId":"PKSA-xtw6-fy62-6vn3","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-1.yaml","title":"Improper access control in the table access voter (see GHSA-5974-gfqc-wrcm)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-table-access-voter","cve":null,"affectedVersions":"\u003E=5.7.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-1.yaml"}]},{"advisoryId":"PKSA-f8tt-pn3h-s2tw","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/CVE-2026-55824.yaml","title":"Credentials disclosure in the crawler","link":"https:\/\/contao.org\/en\/security-advisories\/credentials-disclosure-in-the-crawler","cve":"CVE-2026-55824","affectedVersions":"\u003E=4.13.0,\u003C5.3.47|\u003E=5.4.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/CVE-2026-55824.yaml"},{"name":"GitHub","remoteId":"GHSA-3mr9-p497-58f6"}]},{"advisoryId":"PKSA-4ps2-832y-6pns","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/CVE-2026-55825.yaml","title":"Path traversal in the jobs module","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-jobs-module","cve":"CVE-2026-55825","affectedVersions":"\u003E=5.7.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/CVE-2026-55825.yaml"},{"name":"GitHub","remoteId":"GHSA-grm4-wm43-9jh5"}]}],"contao\/newsletter-bundle":[{"advisoryId":"PKSA-r5wh-6cgq-ck8m","packageName":"contao\/newsletter-bundle","remoteId":"contao\/newsletter-bundle\/2026-08-25.yaml","title":"Improper access control in the newsletter module (see GHSA-3r9g-pfhv-3228)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-newsletter-module","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/newsletter-bundle\/2026-08-25.yaml"}]}],"yourls\/yourls":[{"advisoryId":"PKSA-v9p2-y9c7-y991","packageName":"yourls\/yourls","remoteId":"GHSA-5h77-88j3-r659","title":"YOURLS has stored XSS in referrer statistics chart via crafted Referer header","link":"https:\/\/github.com\/advisories\/GHSA-5h77-88j3-r659","cve":"CVE-2026-63135","affectedVersions":"\u003E=1.5.1,\u003C=1.10.3","source":"GitHub","reportedAt":"2026-08-21 20:57:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5h77-88j3-r659"}]}],"backpack\/crud":[{"advisoryId":"PKSA-1hj4-7f8v-mbzt","packageName":"backpack\/crud","remoteId":"GHSA-42vx-43vc-x6pr","title":"Laravel Backpack CRUD: HasMany\/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelation","link":"https:\/\/github.com\/advisories\/GHSA-42vx-43vc-x6pr","cve":"CVE-2026-57570","affectedVersions":"\u003E=6.0.0,\u003C6.8.15|\u003E=7.0.0,\u003C7.0.47","source":"GitHub","reportedAt":"2026-08-20 18:42:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-42vx-43vc-x6pr"}]},{"advisoryId":"PKSA-x88v-wcq5-j3kt","packageName":"backpack\/crud","remoteId":"GHSA-xpv2-hrfc-hw62","title":"Laravel Backpack CRUD: Unverified password change in MyAccountController via mass assignment","link":"https:\/\/github.com\/advisories\/GHSA-xpv2-hrfc-hw62","cve":"CVE-2026-54175","affectedVersions":"\u003E=7.0.0-alpha.1,\u003C7.0.34|\u003C6.8.11","source":"GitHub","reportedAt":"2026-08-20 18:38:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xpv2-hrfc-hw62"}]},{"advisoryId":"PKSA-wb9h-r8p2-f7xj","packageName":"backpack\/crud","remoteId":"GHSA-9fw9-8c49-qch8","title":"Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check","link":"https:\/\/github.com\/advisories\/GHSA-9fw9-8c49-qch8","cve":"CVE-2026-54176","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9fw9-8c49-qch8"}]},{"advisoryId":"PKSA-4pjj-nc36-rj91","packageName":"backpack\/crud","remoteId":"GHSA-8q2w-pv9p-mjvc","title":"Laravel Backpack CRUD: HasUploadFields keeps the attacker-supplied file extension \u2014 public-disk uploads of `shell.php` reach the webserver","link":"https:\/\/github.com\/advisories\/GHSA-8q2w-pv9p-mjvc","cve":"CVE-2026-54177","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8q2w-pv9p-mjvc"}]},{"advisoryId":"PKSA-kbc2-vykn-d61h","packageName":"backpack\/crud","remoteId":"GHSA-8xjm-wqrp-2f25","title":"Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_\u003Cattr\u003E[] in HasUploadFields::uploadMultipleFilesToDisk","link":"https:\/\/github.com\/advisories\/GHSA-8xjm-wqrp-2f25","cve":"CVE-2026-54178","affectedVersions":"\u003E=7.0.0,\u003C7.0.35|\u003E=6.0.0,\u003C6.8.12|\u003E=5.0.0,\u003C6.0.0","source":"GitHub","reportedAt":"2026-08-20 18:38:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8xjm-wqrp-2f25"}]},{"advisoryId":"PKSA-gr8y-xsj7-jw48","packageName":"backpack\/crud","remoteId":"GHSA-8hw4-7qjr-3wxg","title":"Laravel Backpack CRUD: SingleBase64Image accepts any base64 payload behind a `data:image` prefix \u2014 SVG-with-script lands on the public disk","link":"https:\/\/github.com\/advisories\/GHSA-8hw4-7qjr-3wxg","cve":"CVE-2026-54179","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8hw4-7qjr-3wxg"}]},{"advisoryId":"PKSA-s7xs-gg49-zwxc","packageName":"backpack\/crud","remoteId":"GHSA-vgmv-8xjc-6rch","title":"Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)","link":"https:\/\/github.com\/advisories\/GHSA-vgmv-8xjc-6rch","cve":"CVE-2026-54180","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vgmv-8xjc-6rch"}]},{"advisoryId":"PKSA-5phc-pmxf-y81y","packageName":"backpack\/crud","remoteId":"GHSA-mmg4-322v-6jvc","title":"Laravel Backpack CRUD: Stored XSS in the color column \u2014 the `@if($column[\u0027escaped\u0027])` branches are inverted","link":"https:\/\/github.com\/advisories\/GHSA-mmg4-322v-6jvc","cve":"CVE-2026-54181","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mmg4-322v-6jvc"}]},{"advisoryId":"PKSA-qrrt-7bj6-f81q","packageName":"backpack\/crud","remoteId":"GHSA-mrc5-3mm3-45c5","title":"Laravel Backpack CRUD: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)","link":"https:\/\/github.com\/advisories\/GHSA-mrc5-3mm3-45c5","cve":"CVE-2026-54182","affectedVersions":"\u003E=7.0.0,\u003C7.0.36|\u003E=6.0.0,\u003C6.8.13|\u003E=5.0.0,\u003C5.6.2|\u003E=4.1.0,\u003C4.1.72","source":"GitHub","reportedAt":"2026-08-20 18:38:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mrc5-3mm3-45c5"}]}],"winter\/wn-system-module":[{"advisoryId":"PKSA-xv7p-39zk-tqqd","packageName":"winter\/wn-system-module","remoteId":"GHSA-2223-f22x-24cq","title":"Winter: Local File Inclusion through =include directives in JavaScript asset compilation","link":"https:\/\/github.com\/advisories\/GHSA-2223-f22x-24cq","cve":null,"affectedVersions":"\u003C1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2223-f22x-24cq"}]},{"advisoryId":"PKSA-wtw3-z7vh-tcrk","packageName":"winter\/wn-system-module","remoteId":"GHSA-8cfw-pcwh-v63w","title":"Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)","link":"https:\/\/github.com\/advisories\/GHSA-8cfw-pcwh-v63w","cve":null,"affectedVersions":"\u003E=1.2.7,\u003C1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8cfw-pcwh-v63w"}]}],"winter\/wn-backend-module":[{"advisoryId":"PKSA-54hz-1x12-hy82","packageName":"winter\/wn-backend-module","remoteId":"GHSA-58fp-mcx6-7qf9","title":"Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets","link":"https:\/\/github.com\/advisories\/GHSA-58fp-mcx6-7qf9","cve":"CVE-2026-63179","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-20 18:43:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-58fp-mcx6-7qf9"}]},{"advisoryId":"PKSA-b1tx-fpj9-bp5n","packageName":"winter\/wn-backend-module","remoteId":"GHSA-7mpf-4465-7fc2","title":"Winter: Stored XSS through Backend List widget image columns","link":"https:\/\/github.com\/advisories\/GHSA-7mpf-4465-7fc2","cve":null,"affectedVersions":"\u003E=1.1.0,\u003C1.2.14","source":"GitHub","reportedAt":"2026-08-20 18:44:41","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7mpf-4465-7fc2"}]},{"advisoryId":"PKSA-g4kv-c5yp-h2rm","packageName":"winter\/wn-backend-module","remoteId":"GHSA-mpmw-f6h6-3g26","title":"Winter: My Account preview exposes another backend user\u0027s profile by record ID","link":"https:\/\/github.com\/advisories\/GHSA-mpmw-f6h6-3g26","cve":null,"affectedVersions":"=1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mpmw-f6h6-3g26"}]},{"advisoryId":"PKSA-kk7w-bn2w-32z8","packageName":"winter\/wn-backend-module","remoteId":"GHSA-fm29-4mq3-phg6","title":"Winter: ImportExportController AJAX handlers bypass granular import\/export permission gate","link":"https:\/\/github.com\/advisories\/GHSA-fm29-4mq3-phg6","cve":null,"affectedVersions":"\u003C=1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fm29-4mq3-phg6"}]},{"advisoryId":"PKSA-qr5m-g14w-86df","packageName":"winter\/wn-backend-module","remoteId":"GHSA-5cwr-5jxg-pcf6","title":"Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles","link":"https:\/\/github.com\/advisories\/GHSA-5cwr-5jxg-pcf6","cve":null,"affectedVersions":"\u003C=1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5cwr-5jxg-pcf6"}]},{"advisoryId":"PKSA-r35b-91gt-bn2p","packageName":"winter\/wn-backend-module","remoteId":"GHSA-p2ch-c2c3-4xm5","title":"Winter: CSRF through AJAX handler names reachable as backend page actions","link":"https:\/\/github.com\/advisories\/GHSA-p2ch-c2c3-4xm5","cve":null,"affectedVersions":"\u003E=1.0.319,\u003C1.2.14","source":"GitHub","reportedAt":"2026-08-20 18:44:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-p2ch-c2c3-4xm5"}]},{"advisoryId":"PKSA-5ts5-4cbq-8ssk","packageName":"winter\/wn-backend-module","remoteId":"GHSA-hq84-x37p-j6q5","title":"Winter: Reflected XSS through the search query parameter in the backend Table widget","link":"https:\/\/github.com\/advisories\/GHSA-hq84-x37p-j6q5","cve":null,"affectedVersions":"\u003E=1.0.420,\u003C=1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:45:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hq84-x37p-j6q5"}]},{"advisoryId":"PKSA-dbvq-twhc-nj83","packageName":"winter\/wn-backend-module","remoteId":"GHSA-3277-h8g9-qj5f","title":"Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata","link":"https:\/\/github.com\/advisories\/GHSA-3277-h8g9-qj5f","cve":"CVE-2026-54256","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-20 18:39:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3277-h8g9-qj5f"}]},{"advisoryId":"PKSA-kh9g-dm85-trgm","packageName":"winter\/wn-backend-module","remoteId":"GHSA-j5jq-cr68-v2xx","title":"Winter: Authenticated backend users can bypass Users controller permission checks","link":"https:\/\/github.com\/advisories\/GHSA-j5jq-cr68-v2xx","cve":"CVE-2026-35445","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-12 15:15:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j5jq-cr68-v2xx"}]},{"advisoryId":"PKSA-8fbj-xdrm-f43z","packageName":"winter\/wn-backend-module","remoteId":"GHSA-v7cf-8gh9-gxmj","title":"Winter: Stored XSS through Brand Settings custom styles","link":"https:\/\/github.com\/advisories\/GHSA-v7cf-8gh9-gxmj","cve":"CVE-2026-32257","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-12 14:40:21","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v7cf-8gh9-gxmj"}]},{"advisoryId":"PKSA-g651-qxh9-xb57","packageName":"winter\/wn-backend-module","remoteId":"GHSA-vgp4-2fc4-qff2","title":"Winter: Stored XSS through Editor Settings custom styles","link":"https:\/\/github.com\/advisories\/GHSA-vgp4-2fc4-qff2","cve":"CVE-2026-32258","affectedVersions":"\u003E=1.2.10,\u003C1.2.13","source":"GitHub","reportedAt":"2026-08-12 14:40:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vgp4-2fc4-qff2"}]},{"advisoryId":"PKSA-rw8y-31yz-4tck","packageName":"winter\/wn-backend-module","remoteId":"GHSA-m7jc-g4rc-jmvh","title":"Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax","link":"https:\/\/github.com\/advisories\/GHSA-m7jc-g4rc-jmvh","cve":"CVE-2026-32593","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-12 14:41:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m7jc-g4rc-jmvh"}]}],"mineadmin\/mineadmin":[{"advisoryId":"PKSA-56hm-hvjp-d16p","packageName":"mineadmin\/mineadmin","remoteId":"GHSA-59xm-4m8c-g3xj","title":"MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install\/Uninstall","link":"https:\/\/github.com\/advisories\/GHSA-59xm-4m8c-g3xj","cve":"CVE-2026-55224","affectedVersions":"\u003C3.2.0-alpha.2","source":"GitHub","reportedAt":"2026-08-18 20:40:37","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-59xm-4m8c-g3xj"}]}],"froxlor\/froxlor":[{"advisoryId":"PKSA-nrnn-2mjw-x29c","packageName":"froxlor\/froxlor","remoteId":"GHSA-43gm-9rr3-cx7g","title":"Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover","link":"https:\/\/github.com\/advisories\/GHSA-43gm-9rr3-cx7g","cve":"CVE-2026-54347","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2026-08-18 20:47:53","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-43gm-9rr3-cx7g"}]},{"advisoryId":"PKSA-tbmy-ntqq-5hz6","packageName":"froxlor\/froxlor","remoteId":"GHSA-w27m-rmmf-g5w4","title":"Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration","link":"https:\/\/github.com\/advisories\/GHSA-w27m-rmmf-g5w4","cve":"CVE-2026-54348","affectedVersions":"\u003C2.3.8","source":"GitHub","reportedAt":"2026-08-18 20:47:59","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w27m-rmmf-g5w4"}]},{"advisoryId":"PKSA-prvy-3kk5-2fyv","packageName":"froxlor\/froxlor","remoteId":"GHSA-5rw4-4665-cvwf","title":"Froxlor DomainZones.add allows DNS zone-file RR injection via record\/type fields","link":"https:\/\/github.com\/advisories\/GHSA-5rw4-4665-cvwf","cve":"CVE-2026-54543","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2026-08-18 20:48:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5rw4-4665-cvwf"}]},{"advisoryId":"PKSA-2y9n-tpcf-96wh","packageName":"froxlor\/froxlor","remoteId":"GHSA-xpr4-8vp6-c87j","title":"Froxlor has CSRF Vulnerability in AJAX Endpoint \u2014 Missing Cross-Site Request Forgery Protection","link":"https:\/\/github.com\/advisories\/GHSA-xpr4-8vp6-c87j","cve":"CVE-2026-55593","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2026-08-18 20:48:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xpr4-8vp6-c87j"}]},{"advisoryId":"PKSA-bk7h-s9s3-p5rt","packageName":"froxlor\/froxlor","remoteId":"GHSA-7788-ghfq-c6mh","title":"Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints","link":"https:\/\/github.com\/advisories\/GHSA-7788-ghfq-c6mh","cve":"CVE-2026-62988","affectedVersions":"\u003C2.3.8","source":"GitHub","reportedAt":"2026-08-18 20:48:35","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-7788-ghfq-c6mh"}]}],"paragonie\/sodium_compat":[{"advisoryId":"PKSA-32g2-byr9-drtw","packageName":"paragonie\/sodium_compat","remoteId":"paragonie\/sodium_compat\/2026-08-18.yaml","title":"Incorrect Ed25519 public key validation","link":"https:\/\/github.com\/paragonie\/sodium_compat\/pull\/206","cve":null,"affectedVersions":"\u003E=2,\u003C2.5.1|\u003C1.24.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-18 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"paragonie\/sodium_compat\/2026-08-18.yaml"}]}],"mcp\/sdk":[{"advisoryId":"PKSA-p9gd-j6gr-6f9t","packageName":"mcp\/sdk","remoteId":"mcp\/sdk\/CVE-2026-53965.yaml","title":"Client HttpTransport SSE buffer grows unbounded when server withholds the event delimiter","link":"https:\/\/github.com\/modelcontextprotocol\/php-sdk\/security\/advisories\/GHSA-7m52-jw36-44r3","cve":"CVE-2026-53965","affectedVersions":"\u003E=0.5.0,\u003C0.7.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-14 06:19:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7m52-jw36-44r3"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"mcp\/sdk\/CVE-2026-53965.yaml"}]}],"plank\/laravel-mediable":[{"advisoryId":"PKSA-7xqc-8t8n-q551","packageName":"plank\/laravel-mediable","remoteId":"GHSA-xv8g-76mx-2rxc","title":"Laravel-Mediable: path traversal vulnerability in the File::sanitizePath()","link":"https:\/\/github.com\/advisories\/GHSA-xv8g-76mx-2rxc","cve":"CVE-2026-49970","affectedVersions":"\u003C7.0.0","source":"GitHub","reportedAt":"2026-07-13 21:31:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xv8g-76mx-2rxc"}]}],"typo3\/cms-core":[{"advisoryId":"PKSA-hf64-fs5s-6k3h","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-19418.yaml","title":"TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-core-sa-2026-021","cve":"CVE-2026-19418","affectedVersions":"\u003E=13.0.0,\u003C13.4.34|\u003E=14.0.0,\u003C14.3.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-11 09:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-68jx-f42c-7599"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-19418.yaml"}]}],"concrete5\/concrete5":[{"advisoryId":"PKSA-bm9s-qzpp-vx3v","packageName":"concrete5\/concrete5","remoteId":"GHSA-g82f-9pw7-773w","title":"Concrete CMS: PHP Object Injection via\u00a0unserialize()\u00a0calls","link":"https:\/\/github.com\/advisories\/GHSA-g82f-9pw7-773w","cve":"CVE-2026-10721","affectedVersions":"\u003C9.5.2","source":"GitHub","reportedAt":"2026-06-10 09:31:57","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g82f-9pw7-773w"}]}],"buddypress\/buddypress":[{"advisoryId":"PKSA-16rx-1nsm-bg1c","packageName":"buddypress\/buddypress","remoteId":"GHSA-wmjr-58rf-xgrc","title":"BuddyPress: Any authenticated attacker can enumerate another user\u0027s complete friend list via IDOR","link":"https:\/\/github.com\/advisories\/GHSA-wmjr-58rf-xgrc","cve":"CVE-2026-53675","affectedVersions":"\u003C=14.4.0","source":"GitHub","reportedAt":"2026-06-10 00:31:53","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wmjr-58rf-xgrc"}]},{"advisoryId":"PKSA-dkkm-zjdb-8pmc","packageName":"buddypress\/buddypress","remoteId":"GHSA-j3j5-5m8v-7gvc","title":"BuddyPress: Authenticated attackers can access arbitrary private message threads via user_id request parameter","link":"https:\/\/github.com\/advisories\/GHSA-j3j5-5m8v-7gvc","cve":"CVE-2026-53673","affectedVersions":"\u003C14.5.0","source":"GitHub","reportedAt":"2026-06-10 00:31:53","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j3j5-5m8v-7gvc"}]}],"winter\/wn-cms-module":[{"advisoryId":"PKSA-m75m-ptnr-6hhr","packageName":"winter\/wn-cms-module","remoteId":"GHSA-5c4f-9pq9-6c77","title":"Winter: Broken access control in `Cms\\Controllers\\Index` allows cross-template actions and unauthorized asset uploads","link":"https:\/\/github.com\/advisories\/GHSA-5c4f-9pq9-6c77","cve":"CVE-2026-32639","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-12 15:14:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5c4f-9pq9-6c77"}]}],"easycorp\/easyadmin-bundle":[{"advisoryId":"PKSA-7ck7-y4vp-mmcz","packageName":"easycorp\/easyadmin-bundle","remoteId":"easycorp\/easyadmin-bundle\/CVE-2026-81892.yaml","title":"Custom action dispatcher bypasses access_control on other routes","link":"https:\/\/github.com\/EasyCorp\/EasyAdminBundle\/security\/advisories\/GHSA-g2fm-8hr4-j82h","cve":"CVE-2026-81892","affectedVersions":"\u003E=4.0.0,\u003C4.29.16|\u003E=5.0.0,\u003C5.5.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-11 06:38:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"easycorp\/easyadmin-bundle\/CVE-2026-81892.yaml"},{"name":"GitHub","remoteId":"GHSA-g2fm-8hr4-j82h"}]},{"advisoryId":"PKSA-8yhb-cz5n-f41h","packageName":"easycorp\/easyadmin-bundle","remoteId":"easycorp\/easyadmin-bundle\/CVE-2026-54087.yaml","title":"Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField","link":"https:\/\/github.com\/EasyCorp\/EasyAdminBundle\/security\/advisories\/GHSA-8559-gwj3-q37r","cve":"CVE-2026-54087","affectedVersions":"\u003E=5.0.0,\u003C5.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-04 06:43:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"easycorp\/easyadmin-bundle\/CVE-2026-54087.yaml"},{"name":"GitHub","remoteId":"GHSA-8559-gwj3-q37r"}]}],"phpcsstandards\/phpcsutils":[{"advisoryId":"PKSA-kh6k-gs3g-dgr6","packageName":"phpcsstandards\/phpcsutils","remoteId":"phpcsstandards\/phpcsutils\/CVE-2026-65954.yaml","title":"Arbitrary code execution","link":"https:\/\/github.com\/PHPCSStandards\/PHPCSUtils\/security\/advisories\/GHSA-r6hr-vr92-vv28","cve":"CVE-2026-65954","affectedVersions":"\u003E=1.0.0-alpha1,\u003C1.2.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-27 09:13:28","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"phpcsstandards\/phpcsutils\/CVE-2026-65954.yaml"}]}],"codeigniter4\/framework":[{"advisoryId":"PKSA-kcc6-gffv-vchj","packageName":"codeigniter4\/framework","remoteId":"GHSA-7wmf-pw8j-mc78","title":"CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()","link":"https:\/\/github.com\/advisories\/GHSA-7wmf-pw8j-mc78","cve":"CVE-2026-63220","affectedVersions":"\u003C4.7.4","source":"GitHub","reportedAt":"2026-08-07 18:21:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7wmf-pw8j-mc78"}]},{"advisoryId":"PKSA-t8h5-ngj8-z43w","packageName":"codeigniter4\/framework","remoteId":"GHSA-c9w5-rwh3-7pm9","title":"CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions","link":"https:\/\/github.com\/advisories\/GHSA-c9w5-rwh3-7pm9","cve":"CVE-2026-63221","affectedVersions":"\u003E=4.3.0,\u003C4.7.4","source":"GitHub","reportedAt":"2026-08-07 18:22:59","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-c9w5-rwh3-7pm9"}]},{"advisoryId":"PKSA-ykyc-889h-7jxf","packageName":"codeigniter4\/framework","remoteId":"GHSA-hhmc-q9hp-r662","title":"CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames","link":"https:\/\/github.com\/advisories\/GHSA-hhmc-q9hp-r662","cve":"CVE-2026-63222","affectedVersions":"\u003C4.7.4","source":"GitHub","reportedAt":"2026-08-07 18:23:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hhmc-q9hp-r662"}]},{"advisoryId":"PKSA-kcm9-w3rf-jxsk","packageName":"codeigniter4\/framework","remoteId":"GHSA-mmj4-63m4-r6h5","title":"CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules","link":"https:\/\/github.com\/advisories\/GHSA-mmj4-63m4-r6h5","cve":"CVE-2026-63223","affectedVersions":"\u003C4.7.4","source":"GitHub","reportedAt":"2026-08-07 18:24:21","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-mmj4-63m4-r6h5"}]}],"craftcms\/cms":[{"advisoryId":"PKSA-gh5w-x99g-b53n","packageName":"craftcms\/cms","remoteId":"GHSA-xxpx-f366-4xpq","title":"Craft CMS: Authorization bypass: view-only Categories user can modify category structure via structures\/move-element","link":"https:\/\/github.com\/advisories\/GHSA-xxpx-f366-4xpq","cve":"CVE-2026-72785","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:43:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xxpx-f366-4xpq"}]},{"advisoryId":"PKSA-jk69-ryht-534b","packageName":"craftcms\/cms","remoteId":"GHSA-wg23-69c2-gjc8","title":"Craft CMS: Passkey login accepts replayed WebAuthn assertions","link":"https:\/\/github.com\/advisories\/GHSA-wg23-69c2-gjc8","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.5","source":"GitHub","reportedAt":"2026-08-07 14:57:29","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-wg23-69c2-gjc8"}]},{"advisoryId":"PKSA-4q3g-gxhk-813s","packageName":"craftcms\/cms","remoteId":"GHSA-596p-6jv8-775v","title":"Craft CMS: Authenticated leak of secret environment variables","link":"https:\/\/github.com\/advisories\/GHSA-596p-6jv8-775v","cve":"CVE-2026-72782","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:53:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-596p-6jv8-775v"}]},{"advisoryId":"PKSA-19kf-75v5-vy76","packageName":"craftcms\/cms","remoteId":"GHSA-957r-qf9p-67xw","title":"Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts","link":"https:\/\/github.com\/advisories\/GHSA-957r-qf9p-67xw","cve":"CVE-2026-72779","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:54:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-957r-qf9p-67xw"}]},{"advisoryId":"PKSA-1412-5vdy-cd6w","packageName":"craftcms\/cms","remoteId":"GHSA-rvmm-v933-jgxq","title":"Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics","link":"https:\/\/github.com\/advisories\/GHSA-rvmm-v933-jgxq","cve":"CVE-2026-14794","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.3|\u003E=4.0.0-RC1,\u003C4.18.1","source":"GitHub","reportedAt":"2026-08-06 21:42:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rvmm-v933-jgxq"}]},{"advisoryId":"PKSA-x767-zzvx-956t","packageName":"craftcms\/cms","remoteId":"GHSA-2rp4-x2j7-qmcc","title":"Craft CMS: Stored XSS in the control panel via unescaped draft name","link":"https:\/\/github.com\/advisories\/GHSA-2rp4-x2j7-qmcc","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.8","source":"GitHub","reportedAt":"2026-08-06 21:33:15","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2rp4-x2j7-qmcc"}]},{"advisoryId":"PKSA-82nd-44zr-vpmz","packageName":"craftcms\/cms","remoteId":"GHSA-7hxc-f267-h5q7","title":"Craft CMS: Incorrect path validation could potentially lead to path traversal","link":"https:\/\/github.com\/advisories\/GHSA-7hxc-f267-h5q7","cve":"CVE-2026-72783","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:36:11","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7hxc-f267-h5q7"}]},{"advisoryId":"PKSA-d48x-nyby-nphv","packageName":"craftcms\/cms","remoteId":"GHSA-f5wm-88jv-g5hx","title":"Craft CMS: Authenticated RCE through Twig sandbox escape","link":"https:\/\/github.com\/advisories\/GHSA-f5wm-88jv-g5hx","cve":"CVE-2026-72781","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.3|\u003E=5.0.0-RC1,\u003C5.10.7","source":"GitHub","reportedAt":"2026-08-06 21:02:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f5wm-88jv-g5hx"}]},{"advisoryId":"PKSA-s5dz-k87m-97ms","packageName":"craftcms\/cms","remoteId":"GHSA-p8x7-9vfw-p7vc","title":"Craft CMS: Arbitrary user password reset leading to administrator account takeover","link":"https:\/\/github.com\/advisories\/GHSA-p8x7-9vfw-p7vc","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.8","source":"GitHub","reportedAt":"2026-08-06 21:04:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-p8x7-9vfw-p7vc"}]},{"advisoryId":"PKSA-x2qp-qkxh-fw67","packageName":"craftcms\/cms","remoteId":"GHSA-9p7c-v5x3-rfx8","title":"Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets","link":"https:\/\/github.com\/advisories\/GHSA-9p7c-v5x3-rfx8","cve":"CVE-2026-14793","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.3|\u003E=4.0.0-RC1,\u003C4.18.1","source":"GitHub","reportedAt":"2026-08-06 20:55:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9p7c-v5x3-rfx8"}]},{"advisoryId":"PKSA-4tjq-33kk-ghq8","packageName":"craftcms\/cms","remoteId":"GHSA-265m-7826-wjqm","title":"Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass","link":"https:\/\/github.com\/advisories\/GHSA-265m-7826-wjqm","cve":"CVE-2026-72778","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 20:45:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-265m-7826-wjqm"}]},{"advisoryId":"PKSA-5x6f-x35f-73db","packageName":"craftcms\/cms","remoteId":"GHSA-c43v-4cr8-6mvp","title":"Craft CMS has authenticated path traversal in `assets\/icon`, allowing local `.svg` file read","link":"https:\/\/github.com\/advisories\/GHSA-c43v-4cr8-6mvp","cve":"CVE-2026-56394","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.12|\u003E=4.0.0-RC1,\u003C=4.17.6","source":"GitHub","reportedAt":"2026-07-09 13:44:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-c43v-4cr8-6mvp"}]},{"advisoryId":"PKSA-r87g-h2pd-9vq1","packageName":"craftcms\/cms","remoteId":"GHSA-86vw-x4ww-x467","title":"Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview","link":"https:\/\/github.com\/advisories\/GHSA-86vw-x4ww-x467","cve":"CVE-2026-56382","affectedVersions":"\u003E=5.5.0,\u003C=5.9.13","source":"GitHub","reportedAt":"2026-07-09 13:44:12","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-86vw-x4ww-x467"}]},{"advisoryId":"PKSA-pqnm-5q4k-cx7j","packageName":"craftcms\/cms","remoteId":"GHSA-x76w-8c62-48mg","title":"Craft CMS: Authenticated \u0022assets\/preview-thumb\u0022 discloses signed fallback transform preview link to CP users without asset-view permission","link":"https:\/\/github.com\/advisories\/GHSA-x76w-8c62-48mg","cve":"CVE-2026-56384","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.13|\u003E=4.0.0-RC1,\u003C=4.17.7","source":"GitHub","reportedAt":"2026-07-06 20:28:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x76w-8c62-48mg"}]},{"advisoryId":"PKSA-hq3k-cthz-b9zn","packageName":"craftcms\/cms","remoteId":"GHSA-44px-qjjc-xrhq","title":"Craft CMS: Authorized asset \u0022preview file\u0022 requests bypass allows users without asset access to retrieve private preview metadata","link":"https:\/\/github.com\/advisories\/GHSA-44px-qjjc-xrhq","cve":"CVE-2026-56385","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.17.7|\u003E=5.0.0-RC1,\u003C=5.9.13","source":"GitHub","reportedAt":"2026-03-26 17:12:21","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-44px-qjjc-xrhq"}]},{"advisoryId":"PKSA-sc5m-6n1y-h7vz","packageName":"craftcms\/cms","remoteId":"GHSA-g3hp-vvqf-8vw6","title":"Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page","link":"https:\/\/github.com\/advisories\/GHSA-g3hp-vvqf-8vw6","cve":"CVE-2026-56381","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.8.21","source":"GitHub","reportedAt":"2026-03-11 14:56:59","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-g3hp-vvqf-8vw6"}]},{"advisoryId":"PKSA-24yr-dkzm-n9v5","packageName":"craftcms\/cms","remoteId":"GHSA-vg3j-hpm9-8v5v","title":"Craft CMS has a potential information disclosure vulnerability in preview tokens","link":"https:\/\/github.com\/advisories\/GHSA-vg3j-hpm9-8v5v","cve":"CVE-2026-29113","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.9.7|\u003E=4.0.0-RC1,\u003C4.17.3","source":"GitHub","reportedAt":"2026-03-10 18:22:02","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-vg3j-hpm9-8v5v"}]},{"advisoryId":"PKSA-skz7-x8dk-h7t1","packageName":"craftcms\/cms","remoteId":"GHSA-4mgv-366x-qxvx","title":"Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options","link":"https:\/\/github.com\/advisories\/GHSA-4mgv-366x-qxvx","cve":"CVE-2026-56393","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.0-beta.1|\u003E=5.0.0-RC1,\u003C5.9.0-beta.1","source":"GitHub","reportedAt":"2026-03-03 20:58:07","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-4mgv-366x-qxvx"}]},{"advisoryId":"PKSA-cf9h-wtzj-5nwd","packageName":"craftcms\/cms","remoteId":"GHSA-6j87-m5qx-9fqp","title":"Craft CMS has Stored XSS in Table Field in its \u0022Row Heading\u0022 Column Type","link":"https:\/\/github.com\/advisories\/GHSA-6j87-m5qx-9fqp","cve":"CVE-2026-56383","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.8.22|\u003E=4.5.0-beta.1,\u003C=4.16.18","source":"GitHub","reportedAt":"2026-02-25 19:11:31","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-6j87-m5qx-9fqp"}]}],"api-platform\/core":[{"advisoryId":"PKSA-8kfs-m8zw-ggzs","packageName":"api-platform\/core","remoteId":"GHSA-9rjg-x2p2-h68h","title":"API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)","link":"https:\/\/github.com\/advisories\/GHSA-9rjg-x2p2-h68h","cve":"CVE-2026-54164","affectedVersions":"\u003E=4.3.0,\u003C4.3.12|\u003E=4.2.0,\u003C4.2.26|\u003C4.1.30","source":"GitHub","reportedAt":"2026-08-07 16:54:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9rjg-x2p2-h68h"}]}],"squizlabs\/php_codesniffer":[{"advisoryId":"PKSA-rdkp-vv9z-mjkg","packageName":"squizlabs\/php_codesniffer","remoteId":"squizlabs\/php_codesniffer\/CVE-2026-67434.yaml","title":"OS Command injection","link":"https:\/\/github.com\/PHPCSStandards\/PHP_CodeSniffer\/security\/advisories\/GHSA-hmqg-cxww-wqhq","cve":"CVE-2026-67434","affectedVersions":"\u003C3.13.6|\u003E=4.0.0,\u003C4.0.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-05 23:53:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hmqg-cxww-wqhq"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"squizlabs\/php_codesniffer\/CVE-2026-67434.yaml"}]}],"guzzlehttp\/guzzle":[{"advisoryId":"PKSA-cnw1-2ytm-cgr8","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-f7vp-7xgx-4w4r","title":"Guzzle: Noncanonical cookie domain keeps subdomain scope","link":"https:\/\/github.com\/advisories\/GHSA-f7vp-7xgx-4w4r","cve":"CVE-2026-69245","affectedVersions":"\u003E=8.0.0,\u003C8.0.1|\u003C7.15.2","source":"GitHub","reportedAt":"2026-08-03 21:05:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f7vp-7xgx-4w4r"}]},{"advisoryId":"PKSA-gcrk-3vtt-1r14","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-v5mv-p594-2x33","title":"Guzzle: Noncanonical host can bypass host-based checks","link":"https:\/\/github.com\/advisories\/GHSA-v5mv-p594-2x33","cve":"CVE-2026-69246","affectedVersions":"\u003E=8.0.0,\u003C8.0.1|\u003C7.15.2","source":"GitHub","reportedAt":"2026-08-03 21:07:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v5mv-p594-2x33"}]},{"advisoryId":"PKSA-bbs6-q5q9-f3t4","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-f283-ghqc-fg79","title":"Guzzle: Unbounded response cookies risk denial of service","link":"https:\/\/github.com\/advisories\/GHSA-f283-ghqc-fg79","cve":"CVE-2026-67353","affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:27:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f283-ghqc-fg79"}]},{"advisoryId":"PKSA-qxvb-2bpp-dnk6","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-wm3w-8rrp-j577","title":"Guzzle: Host-only cookie scope is not preserved","link":"https:\/\/github.com\/advisories\/GHSA-wm3w-8rrp-j577","cve":"CVE-2026-67355","affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:27:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wm3w-8rrp-j577"}]},{"advisoryId":"PKSA-fy2t-3c5f-827y","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-h95v-h523-3mw8","title":"Guzzle: URI fragments disclosed in redirect Referer headers","link":"https:\/\/github.com\/advisories\/GHSA-h95v-h523-3mw8","cve":"CVE-2026-67354","affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:28:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h95v-h523-3mw8"}]},{"advisoryId":"PKSA-pwsk-hy21-4gby","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-94pj-82f3-465w","title":"Guzzle: Proxy-Authorization headers can be sent to origin servers","link":"https:\/\/github.com\/advisories\/GHSA-94pj-82f3-465w","cve":"CVE-2026-67339","affectedVersions":"\u003C7.14.2","source":"GitHub","reportedAt":"2026-07-20 21:46:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-94pj-82f3-465w"}]}],"wp-coding-standards\/wpcs":[{"advisoryId":"PKSA-mh9b-91zm-m1gy","packageName":"wp-coding-standards\/wpcs","remoteId":"wp-coding-standards\/wpcs\/CVE-2026-45293.yaml","title":"Arbitrary code execution","link":"https:\/\/github.com\/WordPress\/WordPress-Coding-Standards\/security\/advisories\/GHSA-3pwp-g2mj-5p3v","cve":"CVE-2026-45293","affectedVersions":"\u003E=0.14.1,\u003C3.4.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-27 11:42:13","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3pwp-g2mj-5p3v"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"wp-coding-standards\/wpcs\/CVE-2026-45293.yaml"}]}],"typo3\/cms-form":[{"advisoryId":"PKSA-d4vj-m6hn-xm1j","packageName":"typo3\/cms-form","remoteId":"typo3\/cms-form\/CVE-2026-15305.yaml","title":"TYPO3-CORE-SA-2026-020: TYPO3 CMS - Unrestricted File Upload in Form Framework","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-core-sa-2026-020","cve":"CVE-2026-15305","affectedVersions":"\u003E=14.2.0,\u003C14.3.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-14 12:08:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mfqj-cqv3-h7xw"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-form\/CVE-2026-15305.yaml"}]}],"simplesamlphp\/saml2":[{"advisoryId":"PKSA-yk3g-3g3t-ts6q","packageName":"simplesamlphp\/saml2","remoteId":"GHSA-6929-8p9f-26jx","title":"SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass","link":"https:\/\/github.com\/advisories\/GHSA-6929-8p9f-26jx","cve":"CVE-2026-49283","affectedVersions":"\u003C4.19.3|\u003E=4.20.0,\u003C4.20.2|\u003E=5.0.0,\u003C5.0.6|\u003E=6.0.0,\u003C6.2.1","source":"GitHub","reportedAt":"2026-07-02 20:25:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6929-8p9f-26jx"}]},{"advisoryId":"PKSA-1fc7-xrz7-vw78","packageName":"simplesamlphp\/saml2","remoteId":"GHSA-5cjr-mxj5-wmrx","title":"SimpleSAMLphp has Possible DoS via XPath Transform","link":"https:\/\/github.com\/advisories\/GHSA-5cjr-mxj5-wmrx","cve":"CVE-2026-49289","affectedVersions":"\u003C=4.19.2|\u003E=4.20.0,\u003C=4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:27:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5cjr-mxj5-wmrx"}]}],"simplesamlphp\/saml2-legacy":[{"advisoryId":"PKSA-4y26-97zb-p98g","packageName":"simplesamlphp\/saml2-legacy","remoteId":"GHSA-6929-8p9f-26jx","title":"SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass","link":"https:\/\/github.com\/advisories\/GHSA-6929-8p9f-26jx","cve":"CVE-2026-49283","affectedVersions":"\u003C4.19.3|\u003E=4.20.0,\u003C4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:25:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6929-8p9f-26jx"}]},{"advisoryId":"PKSA-11bv-m3wk-h9sn","packageName":"simplesamlphp\/saml2-legacy","remoteId":"GHSA-5cjr-mxj5-wmrx","title":"SimpleSAMLphp has Possible DoS via XPath Transform","link":"https:\/\/github.com\/advisories\/GHSA-5cjr-mxj5-wmrx","cve":"CVE-2026-49289","affectedVersions":"\u003C=4.19.2|\u003E=4.20.0,\u003C=4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:27:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5cjr-mxj5-wmrx"}]}],"symbiote\/silverstripe-advancedworkflow":[{"advisoryId":"PKSA-x4kf-7gbb-fh93","packageName":"symbiote\/silverstripe-advancedworkflow","remoteId":"symbiote\/silverstripe-advancedworkflow\/CVE-2026-54718.yaml","title":"CVE-2026-54718 - Remote code execution via advanced workflow email template","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-54718","cve":"CVE-2026-54718","affectedVersions":"\u003C6.4.5|\u003E=7.0.0,\u003C7.1.3|\u003E=7.2.0,\u003C7.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 04:12:03","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-39mm-rwm3-29jp"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symbiote\/silverstripe-advancedworkflow\/CVE-2026-54718.yaml"}]}],"silverstripe\/cms":[{"advisoryId":"PKSA-pjvm-vnw2-n3m2","packageName":"silverstripe\/cms","remoteId":"silverstripe\/cms\/CVE-2026-54717.yaml","title":"CVE-2026-54717 - XSS in breadcrumbs in page list view","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-54717","cve":"CVE-2026-54717","affectedVersions":"\u003C6.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 02:39:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w3cp-g2pf-65wh"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/cms\/CVE-2026-54717.yaml"}]}],"silverstripe\/versioned":[{"advisoryId":"PKSA-nksq-cxj8-zb32","packageName":"silverstripe\/versioned","remoteId":"silverstripe\/versioned\/CVE-2026-55779.yaml","title":"CVE-2026-55779 - XSS in archive admin restore","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-55779","cve":"CVE-2026-55779","affectedVersions":"\u003C3.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 02:53:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m4g4-86qc-v8w7"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/versioned\/CVE-2026-55779.yaml"}]}],"silverstripe\/framework":[{"advisoryId":"PKSA-x6tz-s6v3-ynk3","packageName":"silverstripe\/framework","remoteId":"silverstripe\/framework\/CVE-2026-54720.yaml","title":"CVE-2026-54720 - XSS attack through media embed","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-54720","cve":"CVE-2026-54720","affectedVersions":"\u003C6.2.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 02:45:19","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gvrw-qqp5-jgc5"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/framework\/CVE-2026-54720.yaml"}]}],"silverstripe\/userforms":[{"advisoryId":"PKSA-g6zg-78xs-c8r8","packageName":"silverstripe\/userforms","remoteId":"silverstripe\/userforms\/CVE-2026-54721.yaml","title":"CVE-2026-54721 - Remote code execution via userforms email subject","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-54721","cve":"CVE-2026-54721","affectedVersions":"\u003C6.4.9|\u003E=7.0.0,\u003C7.0.7|\u003E=7.1.0,\u003C7.1.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 04:05:09","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g8wr-r2v2-vqc6"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/userforms\/CVE-2026-54721.yaml"}]}],"mtdowling\/jmespath.php":[{"advisoryId":"PKSA-mnyp-475s-ywph","packageName":"mtdowling\/jmespath.php","remoteId":"mtdowling\/jmespath.php\/CVE-2026-54133.yaml","title":"CompilerRuntime code injection via unescaped function names","link":"https:\/\/github.com\/jmespath\/jmespath.php\/security\/advisories\/GHSA-pcw8-m77r-2528","cve":"CVE-2026-54133","affectedVersions":"\u003C2.9.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-11 10:41:50","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-pcw8-m77r-2528"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"mtdowling\/jmespath.php\/CVE-2026-54133.yaml"}]}],"cakephp\/authentication":[{"advisoryId":"PKSA-bz6x-t8z8-r26p","packageName":"cakephp\/authentication","remoteId":"GHSA-hhpq-7wg4-36jm","title":"CakePHP Authentication: Open redirect weakness via backslash bypass","link":"https:\/\/github.com\/advisories\/GHSA-hhpq-7wg4-36jm","cve":"CVE-2026-55590","affectedVersions":"\u003C2.11.1|\u003E=3.0.0,\u003C3.3.6|\u003E=4.0.0,\u003C4.1.1","source":"GitHub","reportedAt":"2026-06-17 18:52:09","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hhpq-7wg4-36jm"}]}],"wwbn\/avideo":[{"advisoryId":"PKSA-mpqq-rw7h-r6qr","packageName":"wwbn\/avideo","remoteId":"GHSA-h39h-7cvg-q7j6","title":"AVideo has Authenticated Server-Side Request Forgery via downloadURL in aVideoEncoder.json.php","link":"https:\/\/github.com\/advisories\/GHSA-h39h-7cvg-q7j6","cve":"CVE-2026-27732","affectedVersions":"\u003C=21.0","source":"GitHub","reportedAt":"2026-02-25 18:57:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h39h-7cvg-q7j6"}]}]}}