{"advisories":{"in2code\/powermail":[{"advisoryId":"PKSA-dhfp-j236-nf9h","packageName":"in2code\/powermail","remoteId":"in2code\/powermail\/CVE-2026-77136.yaml","title":"TYPO3-EXT-SA-2026-022: Server-Side Template Injection in extension \u0022powermail\u0022 (powermail)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-022","cve":"CVE-2026-77136","affectedVersions":"\u003E=13.0.0,\u003C13.2.1|\u003E=11.0.0,\u003C12.6.1|\u003C10.9.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"in2code\/powermail\/CVE-2026-77136.yaml"}]}],"in2code\/femanager":[{"advisoryId":"PKSA-d8yc-sp4m-wsqx","packageName":"in2code\/femanager","remoteId":"in2code\/femanager\/CVE-2026-77146.yaml","title":"TYPO3-EXT-SA-2026-024: Broken Access Control in extension \u0022femanager\u0022 (femanager)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-024","cve":"CVE-2026-77146","affectedVersions":"\u003E=8.0.0,\u003C8.4.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"in2code\/femanager\/CVE-2026-77146.yaml"}]},{"advisoryId":"PKSA-ys21-4vkn-ktz8","packageName":"in2code\/femanager","remoteId":"in2code\/femanager\/CVE-2026-77133.yaml","title":"TYPO3-EXT-SA-2026-024: Broken Access Control in extension \u0022femanager\u0022 (femanager)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-024","cve":"CVE-2026-77133","affectedVersions":"\u003E=13.0.0,\u003C13.3.5|\u003E=8.0.0,\u003C8.4.2|\u003E=7.0.0,\u003C7.5.5|\u003C6.4.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"in2code\/femanager\/CVE-2026-77133.yaml"}]},{"advisoryId":"PKSA-8rwj-778x-wr3q","packageName":"in2code\/femanager","remoteId":"in2code\/femanager\/CVE-2026-77135.yaml","title":"TYPO3-EXT-SA-2026-024: Information Disclosure in extension \u0022femanager\u0022 (femanager)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-024","cve":"CVE-2026-77135","affectedVersions":"\u003E=13.0.0,\u003C13.3.5|\u003E=8.0.0,\u003C8.4.2|\u003E=7.0.0,\u003C7.5.5|\u003C6.4.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"in2code\/femanager\/CVE-2026-77135.yaml"}]},{"advisoryId":"PKSA-2nc4-qstv-j2k4","packageName":"in2code\/femanager","remoteId":"in2code\/femanager\/CVE-2026-77134.yaml","title":"TYPO3-EXT-SA-2026-024: Broken Access Control in extension \u0022femanager\u0022 (femanager)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-024","cve":"CVE-2026-77134","affectedVersions":"\u003E=13.0.0,\u003C13.3.5|\u003E=8.0.0,\u003C8.4.2|\u003E=7.0.0,\u003C7.5.5|\u003C6.4.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"in2code\/femanager\/CVE-2026-77134.yaml"}]}],"jweiland\/yellowpages2":[{"advisoryId":"PKSA-18gt-2dzk-y4sf","packageName":"jweiland\/yellowpages2","remoteId":"jweiland\/yellowpages2\/CVE-2026-77142.yaml","title":"TYPO3-EXT-SA-2026-020: Broken Access Control in extension \u0022Industry Directory\u0022 (yellowpages2)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-020","cve":"CVE-2026-77142","affectedVersions":"\u003C8.1.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/yellowpages2\/CVE-2026-77142.yaml"}]}],"jweiland\/pforum":[{"advisoryId":"PKSA-j6mc-zgry-j2jj","packageName":"jweiland\/pforum","remoteId":"jweiland\/pforum\/CVE-2026-77143.yaml","title":"TYPO3-EXT-SA-2026-021: Broken Access Control in extension \u0022Forum\u0022 (pforum)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-021","cve":"CVE-2026-77143","affectedVersions":"\u003C6.2.4","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/pforum\/CVE-2026-77143.yaml"}]}],"jweiland\/events2":[{"advisoryId":"PKSA-j7f2-fsqf-djzr","packageName":"jweiland\/events2","remoteId":"jweiland\/events2\/CVE-2026-77145.yaml","title":"TYPO3-EXT-SA-2026-026: Broken Access Control in extension \u0022Events 2\u0022 (events2)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-026","cve":"CVE-2026-77145","affectedVersions":"\u003C10.2.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/events2\/CVE-2026-77145.yaml"}]},{"advisoryId":"PKSA-yh4t-fxmy-jygr","packageName":"jweiland\/events2","remoteId":"jweiland\/events2\/CVE-2026-77144.yaml","title":"TYPO3-EXT-SA-2026-026: Broken Access Control in extension \u0022Events 2\u0022 (events2)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-026","cve":"CVE-2026-77144","affectedVersions":"\u003C10.2.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/events2\/CVE-2026-77144.yaml"}]}],"jweiland\/clubdirectory":[{"advisoryId":"PKSA-zj12-wn7w-mydt","packageName":"jweiland\/clubdirectory","remoteId":"jweiland\/clubdirectory\/CVE-2026-77141.yaml","title":"TYPO3-EXT-SA-2026-019: Broken Access Control in extension \u0022Club Directory\u0022 (clubdirectory)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-019","cve":"CVE-2026-77141","affectedVersions":"\u003C8.1.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/clubdirectory\/CVE-2026-77141.yaml"}]}],"jweiland\/telephonedirectory":[{"advisoryId":"PKSA-kq76-qzx4-zwwk","packageName":"jweiland\/telephonedirectory","remoteId":"jweiland\/telephonedirectory\/CVE-2026-77140.yaml","title":"TYPO3-EXT-SA-2026-018: Broken Access Control in extension \u0022Telephone Directory\u0022 (telephonedirectory)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-018","cve":"CVE-2026-77140","affectedVersions":"\u003C6.2.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/telephonedirectory\/CVE-2026-77140.yaml"}]}],"frappant\/frp-form-answers":[{"advisoryId":"PKSA-67bk-g8n5-47sq","packageName":"frappant\/frp-form-answers","remoteId":"frappant\/frp-form-answers\/CVE-2026-77137.yaml","title":"TYPO3-EXT-SA-2026-027: SQL Injection in extension \u0022Forms Export\u0022 (frp_form_answers)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-027","cve":"CVE-2026-77137","affectedVersions":"\u003E=7.0.0,\u003C7.1.1|\u003E=6.0.0,\u003C6.1.3|\u003C5.0.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"frappant\/frp-form-answers\/CVE-2026-77137.yaml"}]}],"derhansen\/sf_event_mgt":[{"advisoryId":"PKSA-zn9v-7dk7-9n62","packageName":"derhansen\/sf_event_mgt","remoteId":"derhansen\/sf_event_mgt\/CVE-2026-77128.yaml","title":"TYPO3-EXT-SA-2026-023: Broken Access Control in extension \u0022Event management and registration\u0022 (sf_event_mgt)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-023","cve":"CVE-2026-77128","affectedVersions":"\u003E=9.0.0,\u003C9.0.3|\u003E=8.0.0,\u003C8.6.2|\u003E=7.0.0,\u003C7.9.3|\u003E=6.0.0,\u003C6.7.2|\u003C5.9.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"derhansen\/sf_event_mgt\/CVE-2026-77128.yaml"}]},{"advisoryId":"PKSA-xn4n-zch1-3zsy","packageName":"derhansen\/sf_event_mgt","remoteId":"derhansen\/sf_event_mgt\/CVE-2026-77129.yaml","title":"TYPO3-EXT-SA-2026-023: Server-Side Template Injection in extension \u0022Event management and registration\u0022 (sf_event_mgt)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-023","cve":"CVE-2026-77129","affectedVersions":"\u003E=9.0.0,\u003C9.0.3|\u003E=8.0.0,\u003C8.6.2|\u003E=7.0.0,\u003C7.9.3|\u003E=6.0.0,\u003C6.7.2|\u003C5.9.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"derhansen\/sf_event_mgt\/CVE-2026-77129.yaml"}]}],"apache-solr-for-typo3\/solr":[{"advisoryId":"PKSA-f58b-fgg4-r9xs","packageName":"apache-solr-for-typo3\/solr","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56093.yaml","title":"TYPO3-EXT-SA-2026-025: Broken Access Control in extension \u0022Apache Solr for TYPO3 - Enterprise Search\u0022 (solr)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-025","cve":"CVE-2026-56093","affectedVersions":"\u003E=13.0.0,\u003C13.1.4|\u003E=12.0.0,\u003C12.1.4|\u003C11.6.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56093.yaml"}]},{"advisoryId":"PKSA-h6s2-79xk-1xwg","packageName":"apache-solr-for-typo3\/solr","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56092.yaml","title":"TYPO3-EXT-SA-2026-025: Broken Access Control in extension \u0022Apache Solr for TYPO3 - Enterprise Search\u0022 (solr)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-025","cve":"CVE-2026-56092","affectedVersions":"\u003E=13.0.0,\u003C13.1.4|\u003E=12.0.0,\u003C12.1.4|\u003C11.6.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56092.yaml"}]},{"advisoryId":"PKSA-nmhg-n7vm-6z1n","packageName":"apache-solr-for-typo3\/solr","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56095.yaml","title":"TYPO3-EXT-SA-2026-025: Insecure Deserialization in extension \u0022Apache Solr for TYPO3 - Enterprise Search\u0022 (solr)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-025","cve":"CVE-2026-56095","affectedVersions":"\u003E=13.0.0,\u003C13.1.4|\u003E=12.0.0,\u003C12.1.4|\u003C11.6.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56095.yaml"}]},{"advisoryId":"PKSA-218x-ph2q-d2nf","packageName":"apache-solr-for-typo3\/solr","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56096.yaml","title":"TYPO3-EXT-SA-2026-025: Information Disclosure in extension \u0022Apache Solr for TYPO3 - Enterprise Search\u0022 (solr)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-025","cve":"CVE-2026-56096","affectedVersions":"\u003E=13.0.0,\u003C13.1.4|\u003E=12.0.0,\u003C12.1.4|\u003C11.6.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56096.yaml"}]},{"advisoryId":"PKSA-xyyb-y2c3-k558","packageName":"apache-solr-for-typo3\/solr","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56094.yaml","title":"TYPO3-EXT-SA-2026-025: Information Disclosure in extension \u0022Apache Solr for TYPO3 - Enterprise Search\u0022 (solr)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-025","cve":"CVE-2026-56094","affectedVersions":"\u003E=13.0.0,\u003C13.1.4|\u003E=12.0.0,\u003C12.1.4|\u003C11.6.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56094.yaml"}]}],"mask\/mask":[{"advisoryId":"PKSA-vwmg-xq1p-q4cz","packageName":"mask\/mask","remoteId":"mask\/mask\/CVE-2026-77139.yaml","title":"TYPO3-EXT-SA-2026-017: Path Traversal in extension \u0022Mask\u0022 (mask)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-017","cve":"CVE-2026-77139","affectedVersions":"\u003E=9.0.0,\u003C9.0.11|\u003C8.3.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"mask\/mask\/CVE-2026-77139.yaml"}]}],"syssy\/syssy-typo3-extension":[{"advisoryId":"PKSA-p17b-6gjj-m8kp","packageName":"syssy\/syssy-typo3-extension","remoteId":"syssy\/syssy-typo3-extension\/CVE-2026-77131.yaml","title":"TYPO3-EXT-SA-2026-015: Cleartext Transmission of Sensitive Information in extension \u0022SYSSY - TYPO3 Monitoring \u0026 Security Checks\u0022 (syssy)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-015","cve":"CVE-2026-77131","affectedVersions":"\u003C3.0.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"syssy\/syssy-typo3-extension\/CVE-2026-77131.yaml"}]},{"advisoryId":"PKSA-xf71-q2f9-j6qg","packageName":"syssy\/syssy-typo3-extension","remoteId":"syssy\/syssy-typo3-extension\/CVE-2026-77130.yaml","title":"TYPO3-EXT-SA-2026-015: Insufficient Session Expiration in extension \u0022SYSSY - TYPO3 Monitoring \u0026 Security Checks\u0022 (syssy)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-015","cve":"CVE-2026-77130","affectedVersions":"\u003C3.0.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"syssy\/syssy-typo3-extension\/CVE-2026-77130.yaml"}]}],"codingms\/modules":[{"advisoryId":"PKSA-8bb5-r84n-24n7","packageName":"codingms\/modules","remoteId":"codingms\/modules\/CVE-2026-77127.yaml","title":"TYPO3-EXT-SA-2026-016: Information Disclosure in extension \u0022Modules\u0022 (modules)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-016","cve":"CVE-2026-77127","affectedVersions":"\u003E=8.0.0,\u003C8.1.4|\u003C7.10.4","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"codingms\/modules\/CVE-2026-77127.yaml"}]}],"lochmueller\/html5videoplayer-powermail":[{"advisoryId":"PKSA-6xxy-q4qw-wtq1","packageName":"lochmueller\/html5videoplayer-powermail","remoteId":"lochmueller\/html5videoplayer-powermail\/CVE-2026-77138.yaml","title":"TYPO3-EXT-SA-2026-014: Remote Code Execution in extension \u0022HTML5 Video Player vs. Powermail\u0022 (html5videoplayer_powermail)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-014","cve":"CVE-2026-77138","affectedVersions":"\u003C=0.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-01-01 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"lochmueller\/html5videoplayer-powermail\/CVE-2026-77138.yaml"}]}],"contao-components\/colorbox":[{"advisoryId":"PKSA-vz5f-wd4z-2kf4","packageName":"contao-components\/colorbox","remoteId":"contao-components\/colorbox\/2026-08-25.yaml","title":"Cross-site scripting in the Colorbox caption (see GHSA-rr85-7j77-pppg)","link":"https:\/\/github.com\/contao-components\/colorbox\/security\/advisories\/GHSA-rr85-7j77-pppg","cve":null,"affectedVersions":"\u003E=1.0.0,\u003C1.6.4.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao-components\/colorbox\/2026-08-25.yaml"}]}],"contao\/comments-bundle":[{"advisoryId":"PKSA-xbg5-kkqv-jb9y","packageName":"contao\/comments-bundle","remoteId":"contao\/comments-bundle\/2026-08-25.yaml","title":"Cross-site scripting in the comments bundle (see GHSA-628f-v4f6-p37r)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-scripting-in-the-comments-bundle","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/comments-bundle\/2026-08-25.yaml"}]}],"contao\/contao":[{"advisoryId":"PKSA-6gsv-pjvq-z35p","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-5.yaml","title":"Improper access control in the preview links module (see GHSA-q6wp-fr43-gm9v)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-preview-links-module","cve":null,"affectedVersions":"\u003E=5.7.1,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-5.yaml"}]},{"advisoryId":"PKSA-rfnv-mh54-2pc9","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-2.yaml","title":"Improper access control in the CSV import wizard (see GHSA-23w9-4pg3-xwm3)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-csv-import-wizard","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-2.yaml"}]},{"advisoryId":"PKSA-2s8k-hn9c-bkvy","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-6.yaml","title":"Path traversal in the images controller (see GHSA-mrvp-7wmx-5m4h)","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-images-controller","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-6.yaml"}]},{"advisoryId":"PKSA-vy31-xjc7-3g2h","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-9.yaml","title":"Exposure of sensitive information through a stale search index (see GHSA-x2rp-9qf7-2fmq)","link":"https:\/\/contao.org\/en\/security-advisories\/exposure-of-sensitive-information-through-a-stale-search-index","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-9.yaml"}]},{"advisoryId":"PKSA-8zc2-xpjt-dfrb","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-7.yaml","title":"Cross-site request forgery in custom backend actions (see GHSA-9ff2-p842-45wq)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-request-forgery-in-custom-backend-actions","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-7.yaml"}]},{"advisoryId":"PKSA-3fqv-nq39-s3wg","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-10.yaml","title":"Cross-site scripting in the comments bundle (see GHSA-628f-v4f6-p37r)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-scripting-in-the-comments-bundle","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-10.yaml"}]},{"advisoryId":"PKSA-nqyj-w4wy-fs47","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-3.yaml","title":"Non-admin users can self-grant permissions that implicitly make them administrators (see GHSA-r9qp-pqx5-8369)","link":"https:\/\/contao.org\/en\/security-advisories\/non-admin-users-can-self-grant-permissions-that-implicitly-make-them-administrators","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-3.yaml"}]},{"advisoryId":"PKSA-ws7m-s1y9-vkw6","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-11.yaml","title":"Improper access control in the newsletter module (see GHSA-3r9g-pfhv-3228)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-newsletter-module","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-11.yaml"}]},{"advisoryId":"PKSA-dtqn-wjcr-pw7c","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-8.yaml","title":"Unrestricted activation email resending (see GHSA-mfxh-vp55-7gc6)","link":"https:\/\/contao.org\/en\/security-advisories\/unrestricted-activation-email-resending","cve":null,"affectedVersions":"\u003E=4.1.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-8.yaml"}]},{"advisoryId":"PKSA-ncw3-bhm6-s2mg","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-4.yaml","title":"Cross-site scripting in the frontend search results (see GHSA-h57j-5f5m-789v)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-scripting-in-the-frontend-search-results","cve":null,"affectedVersions":"\u003E=4.9.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-4.yaml"}]},{"advisoryId":"PKSA-vtsh-c9df-2j1j","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-1.yaml","title":"Improper access control in the table access voter (see GHSA-5974-gfqc-wrcm)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-table-access-voter","cve":null,"affectedVersions":"\u003E=5.7.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-1.yaml"}]},{"advisoryId":"PKSA-8pr1-zw9p-tzyx","packageName":"contao\/contao","remoteId":"contao\/contao\/CVE-2026-55824.yaml","title":"Credentials disclosure in the crawler","link":"https:\/\/contao.org\/en\/security-advisories\/credentials-disclosure-in-the-crawler","cve":"CVE-2026-55824","affectedVersions":"\u003E=4.13.0,\u003C5.3.47|\u003E=5.4.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/CVE-2026-55824.yaml"},{"name":"GitHub","remoteId":"GHSA-3mr9-p497-58f6"}]},{"advisoryId":"PKSA-311q-qrt9-s2k4","packageName":"contao\/contao","remoteId":"contao\/contao\/CVE-2026-55825.yaml","title":"Path traversal in the jobs module","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-jobs-module","cve":"CVE-2026-55825","affectedVersions":"\u003E=5.7.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/CVE-2026-55825.yaml"},{"name":"GitHub","remoteId":"GHSA-grm4-wm43-9jh5"}]}],"contao\/core-bundle":[{"advisoryId":"PKSA-yksm-8fg2-dsvs","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-5.yaml","title":"Improper access control in the preview links module (see GHSA-q6wp-fr43-gm9v)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-preview-links-module","cve":null,"affectedVersions":"\u003E=5.7.1,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-5.yaml"}]},{"advisoryId":"PKSA-t5k3-41dk-f7y5","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-2.yaml","title":"Improper access control in the CSV import wizard (see GHSA-23w9-4pg3-xwm3)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-csv-import-wizard","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-2.yaml"}]},{"advisoryId":"PKSA-zm5t-426r-gfpx","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-6.yaml","title":"Path traversal in the images controller (see GHSA-mrvp-7wmx-5m4h)","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-images-controller","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-6.yaml"}]},{"advisoryId":"PKSA-cvfh-n5dv-w5t9","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-9.yaml","title":"Exposure of sensitive information through a stale search index (see GHSA-x2rp-9qf7-2fmq)","link":"https:\/\/contao.org\/en\/security-advisories\/exposure-of-sensitive-information-through-a-stale-search-index","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-9.yaml"}]},{"advisoryId":"PKSA-4788-1fwx-c4gc","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-7.yaml","title":"Cross-site request forgery in custom backend actions (see GHSA-9ff2-p842-45wq)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-request-forgery-in-custom-backend-actions","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-7.yaml"}]},{"advisoryId":"PKSA-335s-36s8-mdj4","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-3.yaml","title":"Non-admin users can self-grant permissions that implicitly make them administrators (see GHSA-r9qp-pqx5-8369)","link":"https:\/\/contao.org\/en\/security-advisories\/non-admin-users-can-self-grant-permissions-that-implicitly-make-them-administrators","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-3.yaml"}]},{"advisoryId":"PKSA-wrr4-414y-fqmj","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-8.yaml","title":"Unrestricted activation email resending (see GHSA-mfxh-vp55-7gc6)","link":"https:\/\/contao.org\/en\/security-advisories\/unrestricted-activation-email-resending","cve":null,"affectedVersions":"\u003E=4.1.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-8.yaml"}]},{"advisoryId":"PKSA-snk8-7c3n-1x4z","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-4.yaml","title":"Cross-site scripting in the frontend search results (see GHSA-h57j-5f5m-789v)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-scripting-in-the-frontend-search-results","cve":null,"affectedVersions":"\u003E=4.9.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-4.yaml"}]},{"advisoryId":"PKSA-xtw6-fy62-6vn3","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-1.yaml","title":"Improper access control in the table access voter (see GHSA-5974-gfqc-wrcm)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-table-access-voter","cve":null,"affectedVersions":"\u003E=5.7.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-1.yaml"}]},{"advisoryId":"PKSA-f8tt-pn3h-s2tw","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/CVE-2026-55824.yaml","title":"Credentials disclosure in the crawler","link":"https:\/\/contao.org\/en\/security-advisories\/credentials-disclosure-in-the-crawler","cve":"CVE-2026-55824","affectedVersions":"\u003E=4.13.0,\u003C5.3.47|\u003E=5.4.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/CVE-2026-55824.yaml"},{"name":"GitHub","remoteId":"GHSA-3mr9-p497-58f6"}]},{"advisoryId":"PKSA-4ps2-832y-6pns","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/CVE-2026-55825.yaml","title":"Path traversal in the jobs module","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-jobs-module","cve":"CVE-2026-55825","affectedVersions":"\u003E=5.7.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/CVE-2026-55825.yaml"},{"name":"GitHub","remoteId":"GHSA-grm4-wm43-9jh5"}]}],"contao\/newsletter-bundle":[{"advisoryId":"PKSA-r5wh-6cgq-ck8m","packageName":"contao\/newsletter-bundle","remoteId":"contao\/newsletter-bundle\/2026-08-25.yaml","title":"Improper access control in the newsletter module (see GHSA-3r9g-pfhv-3228)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-newsletter-module","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/newsletter-bundle\/2026-08-25.yaml"}]}],"phalcon\/cphalcon":[{"advisoryId":"PKSA-n2s8-x5tr-m78t","packageName":"phalcon\/cphalcon","remoteId":"GHSA-hrwp-4hh9-c8r8","title":"Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)","link":"https:\/\/github.com\/advisories\/GHSA-hrwp-4hh9-c8r8","cve":"CVE-2026-59989","affectedVersions":"\u003C=5.15.0","source":"GitHub","reportedAt":"2026-08-21 20:55:56","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-hrwp-4hh9-c8r8"}]}],"yourls\/yourls":[{"advisoryId":"PKSA-v9p2-y9c7-y991","packageName":"yourls\/yourls","remoteId":"GHSA-5h77-88j3-r659","title":"YOURLS has stored XSS in referrer statistics chart via crafted Referer header","link":"https:\/\/github.com\/advisories\/GHSA-5h77-88j3-r659","cve":"CVE-2026-63135","affectedVersions":"\u003E=1.5.1,\u003C=1.10.3","source":"GitHub","reportedAt":"2026-08-21 20:57:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5h77-88j3-r659"}]}],"getgrav\/grav":[{"advisoryId":"PKSA-rjzr-vkvg-cvmf","packageName":"getgrav\/grav","remoteId":"GHSA-8hgv-xc77-jmcr","title":"Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox\u0027s assets.addJs\/addCss allowlist, escalating to super-admin","link":"https:\/\/github.com\/advisories\/GHSA-8hgv-xc77-jmcr","cve":null,"affectedVersions":"\u003C=2.0.19","source":"GitHub","reportedAt":"2026-08-21 19:14:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8hgv-xc77-jmcr"}]},{"advisoryId":"PKSA-wh99-p4gt-7bkp","packageName":"getgrav\/grav","remoteId":"GHSA-vwg3-w8w3-pc79","title":"Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems","link":"https:\/\/github.com\/advisories\/GHSA-vwg3-w8w3-pc79","cve":"CVE-2026-62673","affectedVersions":"\u003C2.0.4","source":"GitHub","reportedAt":"2026-08-19 19:32:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vwg3-w8w3-pc79"}]},{"advisoryId":"PKSA-pv12-m6cp-m9cd","packageName":"getgrav\/grav","remoteId":"GHSA-4x9g-vw65-vvf9","title":"Grav: Unauthenticated denial of service via unbounded image derivative dimensions","link":"https:\/\/github.com\/advisories\/GHSA-4x9g-vw65-vvf9","cve":"CVE-2026-53653","affectedVersions":"\u003C1.7.53|\u003E=2.0.0-beta.1,\u003C2.0.0-rc.8","source":"GitHub","reportedAt":"2026-08-14 19:23:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4x9g-vw65-vvf9"}]}],"backpack\/crud":[{"advisoryId":"PKSA-1hj4-7f8v-mbzt","packageName":"backpack\/crud","remoteId":"GHSA-42vx-43vc-x6pr","title":"Laravel Backpack CRUD: HasMany\/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelation","link":"https:\/\/github.com\/advisories\/GHSA-42vx-43vc-x6pr","cve":"CVE-2026-57570","affectedVersions":"\u003E=6.0.0,\u003C6.8.15|\u003E=7.0.0,\u003C7.0.47","source":"GitHub","reportedAt":"2026-08-20 18:42:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-42vx-43vc-x6pr"}]},{"advisoryId":"PKSA-x88v-wcq5-j3kt","packageName":"backpack\/crud","remoteId":"GHSA-xpv2-hrfc-hw62","title":"Laravel Backpack CRUD: Unverified password change in MyAccountController via mass assignment","link":"https:\/\/github.com\/advisories\/GHSA-xpv2-hrfc-hw62","cve":"CVE-2026-54175","affectedVersions":"\u003E=7.0.0-alpha.1,\u003C7.0.34|\u003C6.8.11","source":"GitHub","reportedAt":"2026-08-20 18:38:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xpv2-hrfc-hw62"}]},{"advisoryId":"PKSA-wb9h-r8p2-f7xj","packageName":"backpack\/crud","remoteId":"GHSA-9fw9-8c49-qch8","title":"Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check","link":"https:\/\/github.com\/advisories\/GHSA-9fw9-8c49-qch8","cve":"CVE-2026-54176","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9fw9-8c49-qch8"}]},{"advisoryId":"PKSA-4pjj-nc36-rj91","packageName":"backpack\/crud","remoteId":"GHSA-8q2w-pv9p-mjvc","title":"Laravel Backpack CRUD: HasUploadFields keeps the attacker-supplied file extension \u2014 public-disk uploads of `shell.php` reach the webserver","link":"https:\/\/github.com\/advisories\/GHSA-8q2w-pv9p-mjvc","cve":"CVE-2026-54177","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8q2w-pv9p-mjvc"}]},{"advisoryId":"PKSA-kbc2-vykn-d61h","packageName":"backpack\/crud","remoteId":"GHSA-8xjm-wqrp-2f25","title":"Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_\u003Cattr\u003E[] in HasUploadFields::uploadMultipleFilesToDisk","link":"https:\/\/github.com\/advisories\/GHSA-8xjm-wqrp-2f25","cve":"CVE-2026-54178","affectedVersions":"\u003E=7.0.0,\u003C7.0.35|\u003E=6.0.0,\u003C6.8.12|\u003E=5.0.0,\u003C6.0.0","source":"GitHub","reportedAt":"2026-08-20 18:38:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8xjm-wqrp-2f25"}]},{"advisoryId":"PKSA-gr8y-xsj7-jw48","packageName":"backpack\/crud","remoteId":"GHSA-8hw4-7qjr-3wxg","title":"Laravel Backpack CRUD: SingleBase64Image accepts any base64 payload behind a `data:image` prefix \u2014 SVG-with-script lands on the public disk","link":"https:\/\/github.com\/advisories\/GHSA-8hw4-7qjr-3wxg","cve":"CVE-2026-54179","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8hw4-7qjr-3wxg"}]},{"advisoryId":"PKSA-s7xs-gg49-zwxc","packageName":"backpack\/crud","remoteId":"GHSA-vgmv-8xjc-6rch","title":"Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)","link":"https:\/\/github.com\/advisories\/GHSA-vgmv-8xjc-6rch","cve":"CVE-2026-54180","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vgmv-8xjc-6rch"}]},{"advisoryId":"PKSA-5phc-pmxf-y81y","packageName":"backpack\/crud","remoteId":"GHSA-mmg4-322v-6jvc","title":"Laravel Backpack CRUD: Stored XSS in the color column \u2014 the `@if($column[\u0027escaped\u0027])` branches are inverted","link":"https:\/\/github.com\/advisories\/GHSA-mmg4-322v-6jvc","cve":"CVE-2026-54181","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mmg4-322v-6jvc"}]},{"advisoryId":"PKSA-qrrt-7bj6-f81q","packageName":"backpack\/crud","remoteId":"GHSA-mrc5-3mm3-45c5","title":"Laravel Backpack CRUD: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)","link":"https:\/\/github.com\/advisories\/GHSA-mrc5-3mm3-45c5","cve":"CVE-2026-54182","affectedVersions":"\u003E=7.0.0,\u003C7.0.36|\u003E=6.0.0,\u003C6.8.13|\u003E=5.0.0,\u003C5.6.2|\u003E=4.1.0,\u003C4.1.72","source":"GitHub","reportedAt":"2026-08-20 18:38:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mrc5-3mm3-45c5"}]}],"winter\/wn-system-module":[{"advisoryId":"PKSA-xv7p-39zk-tqqd","packageName":"winter\/wn-system-module","remoteId":"GHSA-2223-f22x-24cq","title":"Winter: Local File Inclusion through =include directives in JavaScript asset compilation","link":"https:\/\/github.com\/advisories\/GHSA-2223-f22x-24cq","cve":null,"affectedVersions":"\u003C1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2223-f22x-24cq"}]},{"advisoryId":"PKSA-wtw3-z7vh-tcrk","packageName":"winter\/wn-system-module","remoteId":"GHSA-8cfw-pcwh-v63w","title":"Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)","link":"https:\/\/github.com\/advisories\/GHSA-8cfw-pcwh-v63w","cve":null,"affectedVersions":"\u003E=1.2.7,\u003C1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8cfw-pcwh-v63w"}]}],"winter\/wn-backend-module":[{"advisoryId":"PKSA-54hz-1x12-hy82","packageName":"winter\/wn-backend-module","remoteId":"GHSA-58fp-mcx6-7qf9","title":"Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets","link":"https:\/\/github.com\/advisories\/GHSA-58fp-mcx6-7qf9","cve":"CVE-2026-63179","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-20 18:43:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-58fp-mcx6-7qf9"}]},{"advisoryId":"PKSA-b1tx-fpj9-bp5n","packageName":"winter\/wn-backend-module","remoteId":"GHSA-7mpf-4465-7fc2","title":"Winter: Stored XSS through Backend List widget image columns","link":"https:\/\/github.com\/advisories\/GHSA-7mpf-4465-7fc2","cve":null,"affectedVersions":"\u003E=1.1.0,\u003C1.2.14","source":"GitHub","reportedAt":"2026-08-20 18:44:41","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7mpf-4465-7fc2"}]},{"advisoryId":"PKSA-g4kv-c5yp-h2rm","packageName":"winter\/wn-backend-module","remoteId":"GHSA-mpmw-f6h6-3g26","title":"Winter: My Account preview exposes another backend user\u0027s profile by record ID","link":"https:\/\/github.com\/advisories\/GHSA-mpmw-f6h6-3g26","cve":null,"affectedVersions":"=1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mpmw-f6h6-3g26"}]},{"advisoryId":"PKSA-kk7w-bn2w-32z8","packageName":"winter\/wn-backend-module","remoteId":"GHSA-fm29-4mq3-phg6","title":"Winter: ImportExportController AJAX handlers bypass granular import\/export permission gate","link":"https:\/\/github.com\/advisories\/GHSA-fm29-4mq3-phg6","cve":null,"affectedVersions":"\u003C=1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fm29-4mq3-phg6"}]},{"advisoryId":"PKSA-qr5m-g14w-86df","packageName":"winter\/wn-backend-module","remoteId":"GHSA-5cwr-5jxg-pcf6","title":"Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles","link":"https:\/\/github.com\/advisories\/GHSA-5cwr-5jxg-pcf6","cve":null,"affectedVersions":"\u003C=1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5cwr-5jxg-pcf6"}]},{"advisoryId":"PKSA-r35b-91gt-bn2p","packageName":"winter\/wn-backend-module","remoteId":"GHSA-p2ch-c2c3-4xm5","title":"Winter: CSRF through AJAX handler names reachable as backend page actions","link":"https:\/\/github.com\/advisories\/GHSA-p2ch-c2c3-4xm5","cve":null,"affectedVersions":"\u003E=1.0.319,\u003C1.2.14","source":"GitHub","reportedAt":"2026-08-20 18:44:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-p2ch-c2c3-4xm5"}]},{"advisoryId":"PKSA-5ts5-4cbq-8ssk","packageName":"winter\/wn-backend-module","remoteId":"GHSA-hq84-x37p-j6q5","title":"Winter: Reflected XSS through the search query parameter in the backend Table widget","link":"https:\/\/github.com\/advisories\/GHSA-hq84-x37p-j6q5","cve":null,"affectedVersions":"\u003E=1.0.420,\u003C=1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:45:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hq84-x37p-j6q5"}]},{"advisoryId":"PKSA-dbvq-twhc-nj83","packageName":"winter\/wn-backend-module","remoteId":"GHSA-3277-h8g9-qj5f","title":"Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata","link":"https:\/\/github.com\/advisories\/GHSA-3277-h8g9-qj5f","cve":"CVE-2026-54256","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-20 18:39:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3277-h8g9-qj5f"}]},{"advisoryId":"PKSA-kh9g-dm85-trgm","packageName":"winter\/wn-backend-module","remoteId":"GHSA-j5jq-cr68-v2xx","title":"Winter: Authenticated backend users can bypass Users controller permission checks","link":"https:\/\/github.com\/advisories\/GHSA-j5jq-cr68-v2xx","cve":"CVE-2026-35445","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-12 15:15:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j5jq-cr68-v2xx"}]},{"advisoryId":"PKSA-8fbj-xdrm-f43z","packageName":"winter\/wn-backend-module","remoteId":"GHSA-v7cf-8gh9-gxmj","title":"Winter: Stored XSS through Brand Settings custom styles","link":"https:\/\/github.com\/advisories\/GHSA-v7cf-8gh9-gxmj","cve":"CVE-2026-32257","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-12 14:40:21","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v7cf-8gh9-gxmj"}]},{"advisoryId":"PKSA-g651-qxh9-xb57","packageName":"winter\/wn-backend-module","remoteId":"GHSA-vgp4-2fc4-qff2","title":"Winter: Stored XSS through Editor Settings custom styles","link":"https:\/\/github.com\/advisories\/GHSA-vgp4-2fc4-qff2","cve":"CVE-2026-32258","affectedVersions":"\u003E=1.2.10,\u003C1.2.13","source":"GitHub","reportedAt":"2026-08-12 14:40:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vgp4-2fc4-qff2"}]},{"advisoryId":"PKSA-rw8y-31yz-4tck","packageName":"winter\/wn-backend-module","remoteId":"GHSA-m7jc-g4rc-jmvh","title":"Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax","link":"https:\/\/github.com\/advisories\/GHSA-m7jc-g4rc-jmvh","cve":"CVE-2026-32593","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-12 14:41:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m7jc-g4rc-jmvh"}]}],"snipe\/snipe-it":[{"advisoryId":"PKSA-9n96-zyz7-nxh9","packageName":"snipe\/snipe-it","remoteId":"GHSA-3hgv-jr5j-cg9x","title":"Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover","link":"https:\/\/github.com\/advisories\/GHSA-3hgv-jr5j-cg9x","cve":"CVE-2026-55694","affectedVersions":"\u003C8.6.3","source":"GitHub","reportedAt":"2026-08-19 19:32:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3hgv-jr5j-cg9x"}]},{"advisoryId":"PKSA-2v9y-4jt3-bxpm","packageName":"snipe\/snipe-it","remoteId":"GHSA-r9r3-g9fp-3q4q","title":"Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET","link":"https:\/\/github.com\/advisories\/GHSA-r9r3-g9fp-3q4q","cve":"CVE-2026-55703","affectedVersions":"\u003C8.6.3","source":"GitHub","reportedAt":"2026-08-19 19:32:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r9r3-g9fp-3q4q"}]},{"advisoryId":"PKSA-9ywr-ywdr-gcrt","packageName":"snipe\/snipe-it","remoteId":"GHSA-c8qc-wf67-342w","title":"Snipe-IT: Stored DOM XSS via table selected-count IDs","link":"https:\/\/github.com\/advisories\/GHSA-c8qc-wf67-342w","cve":"CVE-2026-61807","affectedVersions":"\u003C8.6.2","source":"GitHub","reportedAt":"2026-08-19 19:32:32","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c8qc-wf67-342w"}]}],"librenms\/librenms":[{"advisoryId":"PKSA-m3bp-hsvq-mjs5","packageName":"librenms\/librenms","remoteId":"GHSA-jf24-8g2h-2wg7","title":"LibreNMS Vulnerable to Remote Code Execution via AboutController","link":"https:\/\/github.com\/advisories\/GHSA-jf24-8g2h-2wg7","cve":null,"affectedVersions":"\u003C26.5.0","source":"GitHub","reportedAt":"2026-08-18 21:17:11","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jf24-8g2h-2wg7"}]},{"advisoryId":"PKSA-jmpz-3j3j-881p","packageName":"librenms\/librenms","remoteId":"GHSA-7cj5-v4pp-v632","title":"LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users","link":"https:\/\/github.com\/advisories\/GHSA-7cj5-v4pp-v632","cve":null,"affectedVersions":"\u003C26.7.0","source":"GitHub","reportedAt":"2026-08-18 21:17:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7cj5-v4pp-v632"}]},{"advisoryId":"PKSA-9d1b-7dzj-kkfs","packageName":"librenms\/librenms","remoteId":"GHSA-7gww-x7fh-jf9j","title":"LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page","link":"https:\/\/github.com\/advisories\/GHSA-7gww-x7fh-jf9j","cve":null,"affectedVersions":"\u003C26.7.0","source":"GitHub","reportedAt":"2026-08-18 21:17:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7gww-x7fh-jf9j"}]},{"advisoryId":"PKSA-8dtq-rfyc-264h","packageName":"librenms\/librenms","remoteId":"GHSA-c9fv-cgmm-2wg7","title":"LibreNMS Vulnerable to Remote Code Execution by Signal Alert Transportation module","link":"https:\/\/github.com\/advisories\/GHSA-c9fv-cgmm-2wg7","cve":"CVE-2026-55182","affectedVersions":"\u003E=21.6.0,\u003C26.5.0","source":"GitHub","reportedAt":"2026-08-18 17:59:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c9fv-cgmm-2wg7"}]},{"advisoryId":"PKSA-63gx-s9j2-62yc","packageName":"librenms\/librenms","remoteId":"GHSA-jmqm-f8q4-v7wx","title":"LibreNMS: Reflected XSS via Proxmox instance\/vmid GET parameters injected into document.title JavaScript assignment","link":"https:\/\/github.com\/advisories\/GHSA-jmqm-f8q4-v7wx","cve":"CVE-2026-45694","affectedVersions":"\u003C=26.4.0","source":"GitHub","reportedAt":"2026-08-12 15:16:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jmqm-f8q4-v7wx"}]}],"mineadmin\/mineadmin":[{"advisoryId":"PKSA-56hm-hvjp-d16p","packageName":"mineadmin\/mineadmin","remoteId":"GHSA-59xm-4m8c-g3xj","title":"MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install\/Uninstall","link":"https:\/\/github.com\/advisories\/GHSA-59xm-4m8c-g3xj","cve":"CVE-2026-55224","affectedVersions":"\u003C3.2.0-alpha.2","source":"GitHub","reportedAt":"2026-08-18 20:40:37","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-59xm-4m8c-g3xj"}]}],"froxlor\/froxlor":[{"advisoryId":"PKSA-nrnn-2mjw-x29c","packageName":"froxlor\/froxlor","remoteId":"GHSA-43gm-9rr3-cx7g","title":"Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover","link":"https:\/\/github.com\/advisories\/GHSA-43gm-9rr3-cx7g","cve":"CVE-2026-54347","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2026-08-18 20:47:53","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-43gm-9rr3-cx7g"}]},{"advisoryId":"PKSA-tbmy-ntqq-5hz6","packageName":"froxlor\/froxlor","remoteId":"GHSA-w27m-rmmf-g5w4","title":"Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration","link":"https:\/\/github.com\/advisories\/GHSA-w27m-rmmf-g5w4","cve":"CVE-2026-54348","affectedVersions":"\u003C2.3.8","source":"GitHub","reportedAt":"2026-08-18 20:47:59","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w27m-rmmf-g5w4"}]},{"advisoryId":"PKSA-prvy-3kk5-2fyv","packageName":"froxlor\/froxlor","remoteId":"GHSA-5rw4-4665-cvwf","title":"Froxlor DomainZones.add allows DNS zone-file RR injection via record\/type fields","link":"https:\/\/github.com\/advisories\/GHSA-5rw4-4665-cvwf","cve":"CVE-2026-54543","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2026-08-18 20:48:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5rw4-4665-cvwf"}]},{"advisoryId":"PKSA-2y9n-tpcf-96wh","packageName":"froxlor\/froxlor","remoteId":"GHSA-xpr4-8vp6-c87j","title":"Froxlor has CSRF Vulnerability in AJAX Endpoint \u2014 Missing Cross-Site Request Forgery Protection","link":"https:\/\/github.com\/advisories\/GHSA-xpr4-8vp6-c87j","cve":"CVE-2026-55593","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2026-08-18 20:48:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xpr4-8vp6-c87j"}]},{"advisoryId":"PKSA-bk7h-s9s3-p5rt","packageName":"froxlor\/froxlor","remoteId":"GHSA-7788-ghfq-c6mh","title":"Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints","link":"https:\/\/github.com\/advisories\/GHSA-7788-ghfq-c6mh","cve":"CVE-2026-62988","affectedVersions":"\u003C2.3.8","source":"GitHub","reportedAt":"2026-08-18 20:48:35","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-7788-ghfq-c6mh"}]}],"paragonie\/sodium_compat":[{"advisoryId":"PKSA-32g2-byr9-drtw","packageName":"paragonie\/sodium_compat","remoteId":"paragonie\/sodium_compat\/2026-08-18.yaml","title":"Incorrect Ed25519 public key validation","link":"https:\/\/github.com\/paragonie\/sodium_compat\/pull\/206","cve":null,"affectedVersions":"\u003E=2,\u003C2.5.1|\u003C1.24.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-18 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"paragonie\/sodium_compat\/2026-08-18.yaml"}]}],"mcp\/sdk":[{"advisoryId":"PKSA-p9gd-j6gr-6f9t","packageName":"mcp\/sdk","remoteId":"mcp\/sdk\/CVE-2026-53965.yaml","title":"Client HttpTransport SSE buffer grows unbounded when server withholds the event delimiter","link":"https:\/\/github.com\/modelcontextprotocol\/php-sdk\/security\/advisories\/GHSA-7m52-jw36-44r3","cve":"CVE-2026-53965","affectedVersions":"\u003E=0.5.0,\u003C0.7.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-14 06:19:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7m52-jw36-44r3"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"mcp\/sdk\/CVE-2026-53965.yaml"}]}],"plank\/laravel-mediable":[{"advisoryId":"PKSA-7xqc-8t8n-q551","packageName":"plank\/laravel-mediable","remoteId":"GHSA-xv8g-76mx-2rxc","title":"Laravel-Mediable: path traversal vulnerability in the File::sanitizePath()","link":"https:\/\/github.com\/advisories\/GHSA-xv8g-76mx-2rxc","cve":"CVE-2026-49970","affectedVersions":"\u003C7.0.0","source":"GitHub","reportedAt":"2026-07-13 21:31:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xv8g-76mx-2rxc"}]}],"pimcore\/pimcore":[{"advisoryId":"PKSA-fpxc-s2d8-24zv","packageName":"pimcore\/pimcore","remoteId":"GHSA-2mhj-fhvg-v428","title":"Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name","link":"https:\/\/github.com\/advisories\/GHSA-2mhj-fhvg-v428","cve":"CVE-2026-55072","affectedVersions":"\u003C12.3.9|\u003E=2026.1.0,\u003C=2026.1.4","source":"GitHub","reportedAt":"2026-08-13 13:44:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2mhj-fhvg-v428"}]}],"typo3\/cms-core":[{"advisoryId":"PKSA-hf64-fs5s-6k3h","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-19418.yaml","title":"TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-core-sa-2026-021","cve":"CVE-2026-19418","affectedVersions":"\u003E=13.0.0,\u003C13.4.34|\u003E=14.0.0,\u003C14.3.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-11 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-19418.yaml"}]}],"concrete5\/concrete5":[{"advisoryId":"PKSA-bm9s-qzpp-vx3v","packageName":"concrete5\/concrete5","remoteId":"GHSA-g82f-9pw7-773w","title":"Concrete CMS: PHP Object Injection via\u00a0unserialize()\u00a0calls","link":"https:\/\/github.com\/advisories\/GHSA-g82f-9pw7-773w","cve":"CVE-2026-10721","affectedVersions":"\u003C9.5.2","source":"GitHub","reportedAt":"2026-06-10 09:31:57","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g82f-9pw7-773w"}]}],"buddypress\/buddypress":[{"advisoryId":"PKSA-16rx-1nsm-bg1c","packageName":"buddypress\/buddypress","remoteId":"GHSA-wmjr-58rf-xgrc","title":"BuddyPress: Any authenticated attacker can enumerate another user\u0027s complete friend list via IDOR","link":"https:\/\/github.com\/advisories\/GHSA-wmjr-58rf-xgrc","cve":"CVE-2026-53675","affectedVersions":"\u003C=14.4.0","source":"GitHub","reportedAt":"2026-06-10 00:31:53","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wmjr-58rf-xgrc"}]},{"advisoryId":"PKSA-dkkm-zjdb-8pmc","packageName":"buddypress\/buddypress","remoteId":"GHSA-j3j5-5m8v-7gvc","title":"BuddyPress: Authenticated attackers can access arbitrary private message threads via user_id request parameter","link":"https:\/\/github.com\/advisories\/GHSA-j3j5-5m8v-7gvc","cve":"CVE-2026-53673","affectedVersions":"\u003C14.5.0","source":"GitHub","reportedAt":"2026-06-10 00:31:53","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j3j5-5m8v-7gvc"}]}],"winter\/wn-cms-module":[{"advisoryId":"PKSA-m75m-ptnr-6hhr","packageName":"winter\/wn-cms-module","remoteId":"GHSA-5c4f-9pq9-6c77","title":"Winter: Broken access control in `Cms\\Controllers\\Index` allows cross-template actions and unauthorized asset uploads","link":"https:\/\/github.com\/advisories\/GHSA-5c4f-9pq9-6c77","cve":"CVE-2026-32639","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-12 15:14:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5c4f-9pq9-6c77"}]}],"thorsten\/phpmyfaq":[{"advisoryId":"PKSA-cz4f-38kk-4ywj","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-6pvm-2vjj-rx4w","title":"phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration","link":"https:\/\/github.com\/advisories\/GHSA-6pvm-2vjj-rx4w","cve":"CVE-2026-47132","affectedVersions":"\u003C4.2.0-alpha","source":"GitHub","reportedAt":"2026-08-12 15:17:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6pvm-2vjj-rx4w"}]}],"easycorp\/easyadmin-bundle":[{"advisoryId":"PKSA-7ck7-y4vp-mmcz","packageName":"easycorp\/easyadmin-bundle","remoteId":"easycorp\/easyadmin-bundle\/GHSA-g2fm-8hr4-j82h.yaml","title":"Custom action dispatcher bypasses access_control on other routes","link":"https:\/\/github.com\/EasyCorp\/EasyAdminBundle\/security\/advisories\/GHSA-g2fm-8hr4-j82h","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C4.29.16|\u003E=5.0.0,\u003C5.5.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-11 06:38:40","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"easycorp\/easyadmin-bundle\/GHSA-g2fm-8hr4-j82h.yaml"}]},{"advisoryId":"PKSA-8yhb-cz5n-f41h","packageName":"easycorp\/easyadmin-bundle","remoteId":"easycorp\/easyadmin-bundle\/CVE-2026-54087.yaml","title":"Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField","link":"https:\/\/github.com\/EasyCorp\/EasyAdminBundle\/security\/advisories\/GHSA-8559-gwj3-q37r","cve":"CVE-2026-54087","affectedVersions":"\u003E=5.0.0,\u003C5.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-04 06:43:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"easycorp\/easyadmin-bundle\/CVE-2026-54087.yaml"},{"name":"GitHub","remoteId":"GHSA-8559-gwj3-q37r"}]}],"phpcsstandards\/phpcsutils":[{"advisoryId":"PKSA-kh6k-gs3g-dgr6","packageName":"phpcsstandards\/phpcsutils","remoteId":"phpcsstandards\/phpcsutils\/CVE-2026-65954.yaml","title":"Arbitrary code execution","link":"https:\/\/github.com\/PHPCSStandards\/PHPCSUtils\/security\/advisories\/GHSA-r6hr-vr92-vv28","cve":"CVE-2026-65954","affectedVersions":"\u003E=1.0.0-alpha1,\u003C1.2.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-27 09:13:28","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"phpcsstandards\/phpcsutils\/CVE-2026-65954.yaml"}]}],"codeigniter4\/framework":[{"advisoryId":"PKSA-kcc6-gffv-vchj","packageName":"codeigniter4\/framework","remoteId":"GHSA-7wmf-pw8j-mc78","title":"CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()","link":"https:\/\/github.com\/advisories\/GHSA-7wmf-pw8j-mc78","cve":"CVE-2026-63220","affectedVersions":"\u003C4.7.4","source":"GitHub","reportedAt":"2026-08-07 18:21:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7wmf-pw8j-mc78"}]},{"advisoryId":"PKSA-t8h5-ngj8-z43w","packageName":"codeigniter4\/framework","remoteId":"GHSA-c9w5-rwh3-7pm9","title":"CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions","link":"https:\/\/github.com\/advisories\/GHSA-c9w5-rwh3-7pm9","cve":"CVE-2026-63221","affectedVersions":"\u003E=4.3.0,\u003C4.7.4","source":"GitHub","reportedAt":"2026-08-07 18:22:59","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-c9w5-rwh3-7pm9"}]},{"advisoryId":"PKSA-ykyc-889h-7jxf","packageName":"codeigniter4\/framework","remoteId":"GHSA-hhmc-q9hp-r662","title":"CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames","link":"https:\/\/github.com\/advisories\/GHSA-hhmc-q9hp-r662","cve":"CVE-2026-63222","affectedVersions":"\u003C4.7.4","source":"GitHub","reportedAt":"2026-08-07 18:23:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hhmc-q9hp-r662"}]},{"advisoryId":"PKSA-kcm9-w3rf-jxsk","packageName":"codeigniter4\/framework","remoteId":"GHSA-mmj4-63m4-r6h5","title":"CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules","link":"https:\/\/github.com\/advisories\/GHSA-mmj4-63m4-r6h5","cve":"CVE-2026-63223","affectedVersions":"\u003C4.7.4","source":"GitHub","reportedAt":"2026-08-07 18:24:21","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-mmj4-63m4-r6h5"}]}],"craftcms\/cms":[{"advisoryId":"PKSA-gh5w-x99g-b53n","packageName":"craftcms\/cms","remoteId":"GHSA-xxpx-f366-4xpq","title":"Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures\/move-element","link":"https:\/\/github.com\/advisories\/GHSA-xxpx-f366-4xpq","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:43:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xxpx-f366-4xpq"}]},{"advisoryId":"PKSA-jk69-ryht-534b","packageName":"craftcms\/cms","remoteId":"GHSA-wg23-69c2-gjc8","title":"Craft CMS: Passkey login accepts replayed WebAuthn assertions","link":"https:\/\/github.com\/advisories\/GHSA-wg23-69c2-gjc8","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.5","source":"GitHub","reportedAt":"2026-08-07 14:57:29","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-wg23-69c2-gjc8"}]},{"advisoryId":"PKSA-4q3g-gxhk-813s","packageName":"craftcms\/cms","remoteId":"GHSA-596p-6jv8-775v","title":"Craft CMS: Authenticated leak of secret environment variables","link":"https:\/\/github.com\/advisories\/GHSA-596p-6jv8-775v","cve":null,"affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:53:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-596p-6jv8-775v"}]},{"advisoryId":"PKSA-19kf-75v5-vy76","packageName":"craftcms\/cms","remoteId":"GHSA-957r-qf9p-67xw","title":"Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts","link":"https:\/\/github.com\/advisories\/GHSA-957r-qf9p-67xw","cve":null,"affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:54:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-957r-qf9p-67xw"}]},{"advisoryId":"PKSA-1412-5vdy-cd6w","packageName":"craftcms\/cms","remoteId":"GHSA-rvmm-v933-jgxq","title":"Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics","link":"https:\/\/github.com\/advisories\/GHSA-rvmm-v933-jgxq","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.3|\u003E=4.0.0-RC1,\u003C4.18.1","source":"GitHub","reportedAt":"2026-08-06 21:42:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rvmm-v933-jgxq"}]},{"advisoryId":"PKSA-x767-zzvx-956t","packageName":"craftcms\/cms","remoteId":"GHSA-2rp4-x2j7-qmcc","title":"Craft CMS: Stored XSS in the control panel via unescaped draft name","link":"https:\/\/github.com\/advisories\/GHSA-2rp4-x2j7-qmcc","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.8","source":"GitHub","reportedAt":"2026-08-06 21:33:15","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2rp4-x2j7-qmcc"}]},{"advisoryId":"PKSA-82nd-44zr-vpmz","packageName":"craftcms\/cms","remoteId":"GHSA-7hxc-f267-h5q7","title":"Craft CMS: Incorrect path validation could potentially lead to path traversal","link":"https:\/\/github.com\/advisories\/GHSA-7hxc-f267-h5q7","cve":null,"affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:36:11","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7hxc-f267-h5q7"}]},{"advisoryId":"PKSA-d48x-nyby-nphv","packageName":"craftcms\/cms","remoteId":"GHSA-f5wm-88jv-g5hx","title":"Craft CMS: Authenticated RCE through Twig sandbox escape","link":"https:\/\/github.com\/advisories\/GHSA-f5wm-88jv-g5hx","cve":null,"affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.3|\u003E=5.0.0-RC1,\u003C5.10.7","source":"GitHub","reportedAt":"2026-08-06 21:02:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f5wm-88jv-g5hx"}]},{"advisoryId":"PKSA-s5dz-k87m-97ms","packageName":"craftcms\/cms","remoteId":"GHSA-p8x7-9vfw-p7vc","title":"Craft CMS: Arbitrary user password reset leading to administrator account takeover","link":"https:\/\/github.com\/advisories\/GHSA-p8x7-9vfw-p7vc","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.8","source":"GitHub","reportedAt":"2026-08-06 21:04:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-p8x7-9vfw-p7vc"}]},{"advisoryId":"PKSA-x2qp-qkxh-fw67","packageName":"craftcms\/cms","remoteId":"GHSA-9p7c-v5x3-rfx8","title":"Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets","link":"https:\/\/github.com\/advisories\/GHSA-9p7c-v5x3-rfx8","cve":"CVE-2026-14793","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.3|\u003E=4.0.0-RC1,\u003C4.18.1","source":"GitHub","reportedAt":"2026-08-06 20:55:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9p7c-v5x3-rfx8"}]},{"advisoryId":"PKSA-4tjq-33kk-ghq8","packageName":"craftcms\/cms","remoteId":"GHSA-265m-7826-wjqm","title":"Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass","link":"https:\/\/github.com\/advisories\/GHSA-265m-7826-wjqm","cve":null,"affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 20:45:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-265m-7826-wjqm"}]},{"advisoryId":"PKSA-5x6f-x35f-73db","packageName":"craftcms\/cms","remoteId":"GHSA-c43v-4cr8-6mvp","title":"Craft CMS has authenticated path traversal in `assets\/icon`, allowing local `.svg` file read","link":"https:\/\/github.com\/advisories\/GHSA-c43v-4cr8-6mvp","cve":"CVE-2026-56394","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.12|\u003E=4.0.0-RC1,\u003C=4.17.6","source":"GitHub","reportedAt":"2026-07-09 13:44:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-c43v-4cr8-6mvp"}]},{"advisoryId":"PKSA-r87g-h2pd-9vq1","packageName":"craftcms\/cms","remoteId":"GHSA-86vw-x4ww-x467","title":"Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview","link":"https:\/\/github.com\/advisories\/GHSA-86vw-x4ww-x467","cve":"CVE-2026-56382","affectedVersions":"\u003E=5.5.0,\u003C=5.9.13","source":"GitHub","reportedAt":"2026-07-09 13:44:12","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-86vw-x4ww-x467"}]},{"advisoryId":"PKSA-pqnm-5q4k-cx7j","packageName":"craftcms\/cms","remoteId":"GHSA-x76w-8c62-48mg","title":"Craft CMS: Authenticated \u0022assets\/preview-thumb\u0022 discloses signed fallback transform preview link to CP users without asset-view permission","link":"https:\/\/github.com\/advisories\/GHSA-x76w-8c62-48mg","cve":"CVE-2026-56384","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.13|\u003E=4.0.0-RC1,\u003C=4.17.7","source":"GitHub","reportedAt":"2026-07-06 20:28:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x76w-8c62-48mg"}]},{"advisoryId":"PKSA-hq3k-cthz-b9zn","packageName":"craftcms\/cms","remoteId":"GHSA-44px-qjjc-xrhq","title":"Craft CMS: Authorized asset \u0022preview file\u0022 requests bypass allows users without asset access to retrieve private preview metadata","link":"https:\/\/github.com\/advisories\/GHSA-44px-qjjc-xrhq","cve":"CVE-2026-56385","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.17.7|\u003E=5.0.0-RC1,\u003C=5.9.13","source":"GitHub","reportedAt":"2026-03-26 17:12:21","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-44px-qjjc-xrhq"}]},{"advisoryId":"PKSA-sc5m-6n1y-h7vz","packageName":"craftcms\/cms","remoteId":"GHSA-g3hp-vvqf-8vw6","title":"Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page","link":"https:\/\/github.com\/advisories\/GHSA-g3hp-vvqf-8vw6","cve":"CVE-2026-56381","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.8.21","source":"GitHub","reportedAt":"2026-03-11 14:56:59","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-g3hp-vvqf-8vw6"}]},{"advisoryId":"PKSA-skz7-x8dk-h7t1","packageName":"craftcms\/cms","remoteId":"GHSA-4mgv-366x-qxvx","title":"Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options","link":"https:\/\/github.com\/advisories\/GHSA-4mgv-366x-qxvx","cve":"CVE-2026-56393","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.0-beta.1|\u003E=5.0.0-RC1,\u003C5.9.0-beta.1","source":"GitHub","reportedAt":"2026-03-03 20:58:07","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-4mgv-366x-qxvx"}]},{"advisoryId":"PKSA-cf9h-wtzj-5nwd","packageName":"craftcms\/cms","remoteId":"GHSA-6j87-m5qx-9fqp","title":"Craft CMS has Stored XSS in Table Field in its \u0022Row Heading\u0022 Column Type","link":"https:\/\/github.com\/advisories\/GHSA-6j87-m5qx-9fqp","cve":"CVE-2026-56383","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.8.22|\u003E=4.5.0-beta.1,\u003C=4.16.18","source":"GitHub","reportedAt":"2026-02-25 19:11:31","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-6j87-m5qx-9fqp"}]}],"api-platform\/core":[{"advisoryId":"PKSA-8kfs-m8zw-ggzs","packageName":"api-platform\/core","remoteId":"GHSA-9rjg-x2p2-h68h","title":"API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)","link":"https:\/\/github.com\/advisories\/GHSA-9rjg-x2p2-h68h","cve":"CVE-2026-54164","affectedVersions":"\u003E=4.3.0,\u003C4.3.12|\u003E=4.2.0,\u003C4.2.26|\u003C4.1.30","source":"GitHub","reportedAt":"2026-08-07 16:54:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9rjg-x2p2-h68h"}]}],"smarty\/smarty":[{"advisoryId":"PKSA-7cg9-1cz1-3qff","packageName":"smarty\/smarty","remoteId":"GHSA-rjhh-76wf-8xmw","title":"Smarty Security stream restriction bypass through stream: resource","link":"https:\/\/github.com\/advisories\/GHSA-rjhh-76wf-8xmw","cve":"CVE-2026-62996","affectedVersions":"\u003E=5.0.0,\u003C5.8.4","source":"GitHub","reportedAt":"2026-08-07 15:10:51","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rjhh-76wf-8xmw"}]},{"advisoryId":"PKSA-zw1q-6h4d-mf1m","packageName":"smarty\/smarty","remoteId":"GHSA-f6wf-28g6-769x","title":"Smarty: Symlink path traversal out of trusted directories","link":"https:\/\/github.com\/advisories\/GHSA-f6wf-28g6-769x","cve":"CVE-2026-62992","affectedVersions":"\u003C4.5.7|\u003E=5.0.0,\u003C5.8.2","source":"GitHub","reportedAt":"2026-08-07 15:02:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f6wf-28g6-769x"}]}],"league\/commonmark":[{"advisoryId":"PKSA-cqd6-fg4n-nxpf","packageName":"league\/commonmark","remoteId":"GHSA-mh25-x5hq-wrqp","title":"league\/commonmark: Denial of service via colliding heading slugs","link":"https:\/\/github.com\/advisories\/GHSA-mh25-x5hq-wrqp","cve":null,"affectedVersions":"\u003E=2.0.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:41:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mh25-x5hq-wrqp"}]},{"advisoryId":"PKSA-1q6p-sqkj-8mmj","packageName":"league\/commonmark","remoteId":"GHSA-jfm3-95jq-q3rf","title":"league\/commonmark:  Denial of service via duplicate footnote definitions","link":"https:\/\/github.com\/advisories\/GHSA-jfm3-95jq-q3rf","cve":null,"affectedVersions":"\u003E=1.5.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:40:53","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jfm3-95jq-q3rf"}]},{"advisoryId":"PKSA-5mzr-szzf-z6cn","packageName":"league\/commonmark","remoteId":"GHSA-mj63-m3rc-8ppr","title":"league\/commonmark: Denial of service via deeply nested XML output","link":"https:\/\/github.com\/advisories\/GHSA-mj63-m3rc-8ppr","cve":null,"affectedVersions":"\u003E=2.0.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:42:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mj63-m3rc-8ppr"}]},{"advisoryId":"PKSA-scnn-p8mm-jbft","packageName":"league\/commonmark","remoteId":"GHSA-29pj-957v-52mc","title":"league\/commonmark: AttributesExtension href\/src unsafe-link filter bypass via embedded control bytes","link":"https:\/\/github.com\/advisories\/GHSA-29pj-957v-52mc","cve":"CVE-2026-71478","affectedVersions":"\u003E=1.5.0,\u003C=2.8.3","source":"GitHub","reportedAt":"2026-08-06 20:30:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-29pj-957v-52mc"}]},{"advisoryId":"PKSA-t21r-vtr5-3mdz","packageName":"league\/commonmark","remoteId":"GHSA-2q4p-g7hv-5rgv","title":"league\/commonmark: Quadratic-time denial of service when parsing crafted Markdown","link":"https:\/\/github.com\/advisories\/GHSA-2q4p-g7hv-5rgv","cve":"CVE-2026-71488","affectedVersions":"\u003E=0.6.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:37:20","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2q4p-g7hv-5rgv"}]},{"advisoryId":"PKSA-mc58-w91n-f5gv","packageName":"league\/commonmark","remoteId":"GHSA-g2gp-3wwq-f4ph","title":"league\/commonmark: Denial of service via adjacent inline attribute blocks","link":"https:\/\/github.com\/advisories\/GHSA-g2gp-3wwq-f4ph","cve":null,"affectedVersions":"\u003E=1.5.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:39:52","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g2gp-3wwq-f4ph"}]}],"statamic\/cms":[{"advisoryId":"PKSA-yprw-4kcc-73cg","packageName":"statamic\/cms","remoteId":"GHSA-qh8c-7588-qfrv","title":"Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries","link":"https:\/\/github.com\/advisories\/GHSA-qh8c-7588-qfrv","cve":"CVE-2026-64662","affectedVersions":"\u003E=6.0.0,\u003C6.24.0|\u003C5.74.1","source":"GitHub","reportedAt":"2026-08-06 19:30:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qh8c-7588-qfrv"}]},{"advisoryId":"PKSA-htv4-42tq-8d9c","packageName":"statamic\/cms","remoteId":"GHSA-qhr7-v3xp-vw9m","title":"Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types","link":"https:\/\/github.com\/advisories\/GHSA-qhr7-v3xp-vw9m","cve":"CVE-2026-71434","affectedVersions":"\u003E=6.0.0,\u003C6.24.2|\u003C5.74.3","source":"GitHub","reportedAt":"2026-08-06 19:35:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qhr7-v3xp-vw9m"}]},{"advisoryId":"PKSA-h7t4-kgpy-prgj","packageName":"statamic\/cms","remoteId":"GHSA-vx89-p3j7-8xqc","title":"Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template","link":"https:\/\/github.com\/advisories\/GHSA-vx89-p3j7-8xqc","cve":"CVE-2026-71435","affectedVersions":"\u003E=6.0.0,\u003C6.24.2|\u003C5.74.3","source":"GitHub","reportedAt":"2026-08-06 19:37:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vx89-p3j7-8xqc"}]},{"advisoryId":"PKSA-691k-v8bf-zdg7","packageName":"statamic\/cms","remoteId":"GHSA-225x-3jhx-wh4q","title":"Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence","link":"https:\/\/github.com\/advisories\/GHSA-225x-3jhx-wh4q","cve":"CVE-2026-64664","affectedVersions":"\u003E=6.0.0,\u003C6.24.0|\u003C5.74.1","source":"GitHub","reportedAt":"2026-08-06 19:22:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-225x-3jhx-wh4q"}]},{"advisoryId":"PKSA-vbqf-w9v5-8bfs","packageName":"statamic\/cms","remoteId":"GHSA-93qh-5269-9wcf","title":"Statamic: Account takeover via OAuth email matching without email-verification check","link":"https:\/\/github.com\/advisories\/GHSA-93qh-5269-9wcf","cve":"CVE-2026-64665","affectedVersions":"\u003E=6.0.0,\u003C6.24.0|\u003C5.74.1","source":"GitHub","reportedAt":"2026-08-06 19:25:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-93qh-5269-9wcf"}]},{"advisoryId":"PKSA-p8hp-2yrt-f2d6","packageName":"statamic\/cms","remoteId":"GHSA-j2vp-f2pv-5rj4","title":"Statamic: Unsafe method invocation via Antlers template resolution allows data destruction","link":"https:\/\/github.com\/advisories\/GHSA-j2vp-f2pv-5rj4","cve":"CVE-2026-64663","affectedVersions":"\u003E=6.0.0,\u003C6.24.0|\u003C5.74.1","source":"GitHub","reportedAt":"2026-08-06 19:28:08","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j2vp-f2pv-5rj4"}]}],"squizlabs\/php_codesniffer":[{"advisoryId":"PKSA-rdkp-vv9z-mjkg","packageName":"squizlabs\/php_codesniffer","remoteId":"squizlabs\/php_codesniffer\/CVE-2026-67434.yaml","title":"OS Command injection","link":"https:\/\/github.com\/PHPCSStandards\/PHP_CodeSniffer\/security\/advisories\/GHSA-hmqg-cxww-wqhq","cve":"CVE-2026-67434","affectedVersions":"\u003C3.13.6|\u003E=4.0.0,\u003C4.0.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-05 23:53:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hmqg-cxww-wqhq"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"squizlabs\/php_codesniffer\/CVE-2026-67434.yaml"}]}],"guzzlehttp\/guzzle":[{"advisoryId":"PKSA-cnw1-2ytm-cgr8","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-f7vp-7xgx-4w4r","title":"Guzzle: Noncanonical cookie domain keeps subdomain scope","link":"https:\/\/github.com\/advisories\/GHSA-f7vp-7xgx-4w4r","cve":"CVE-2026-69245","affectedVersions":"\u003E=8.0.0,\u003C8.0.1|\u003C7.15.2","source":"GitHub","reportedAt":"2026-08-03 21:05:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f7vp-7xgx-4w4r"}]},{"advisoryId":"PKSA-gcrk-3vtt-1r14","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-v5mv-p594-2x33","title":"Guzzle: Noncanonical host can bypass host-based checks","link":"https:\/\/github.com\/advisories\/GHSA-v5mv-p594-2x33","cve":"CVE-2026-69246","affectedVersions":"\u003E=8.0.0,\u003C8.0.1|\u003C7.15.2","source":"GitHub","reportedAt":"2026-08-03 21:07:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v5mv-p594-2x33"}]},{"advisoryId":"PKSA-bbs6-q5q9-f3t4","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-f283-ghqc-fg79","title":"Guzzle: Unbounded response cookies risk denial of service","link":"https:\/\/github.com\/advisories\/GHSA-f283-ghqc-fg79","cve":"CVE-2026-67353","affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:27:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f283-ghqc-fg79"}]},{"advisoryId":"PKSA-qxvb-2bpp-dnk6","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-wm3w-8rrp-j577","title":"Guzzle: Host-only cookie scope is not preserved","link":"https:\/\/github.com\/advisories\/GHSA-wm3w-8rrp-j577","cve":"CVE-2026-67355","affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:27:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wm3w-8rrp-j577"}]},{"advisoryId":"PKSA-fy2t-3c5f-827y","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-h95v-h523-3mw8","title":"Guzzle: URI fragments disclosed in redirect Referer headers","link":"https:\/\/github.com\/advisories\/GHSA-h95v-h523-3mw8","cve":"CVE-2026-67354","affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:28:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h95v-h523-3mw8"}]},{"advisoryId":"PKSA-pwsk-hy21-4gby","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-94pj-82f3-465w","title":"Guzzle: Proxy-Authorization headers can be sent to origin servers","link":"https:\/\/github.com\/advisories\/GHSA-94pj-82f3-465w","cve":"CVE-2026-67339","affectedVersions":"\u003C7.14.2","source":"GitHub","reportedAt":"2026-07-20 21:46:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-94pj-82f3-465w"}]}],"wp-coding-standards\/wpcs":[{"advisoryId":"PKSA-mh9b-91zm-m1gy","packageName":"wp-coding-standards\/wpcs","remoteId":"wp-coding-standards\/wpcs\/CVE-2026-45293.yaml","title":"Arbitrary code execution","link":"https:\/\/github.com\/WordPress\/WordPress-Coding-Standards\/security\/advisories\/GHSA-3pwp-g2mj-5p3v","cve":"CVE-2026-45293","affectedVersions":"\u003E=0.14.1,\u003C3.4.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-27 11:42:13","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3pwp-g2mj-5p3v"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"wp-coding-standards\/wpcs\/CVE-2026-45293.yaml"}]}],"simplesamlphp\/saml2":[{"advisoryId":"PKSA-yk3g-3g3t-ts6q","packageName":"simplesamlphp\/saml2","remoteId":"GHSA-6929-8p9f-26jx","title":"SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass","link":"https:\/\/github.com\/advisories\/GHSA-6929-8p9f-26jx","cve":"CVE-2026-49283","affectedVersions":"\u003C4.19.3|\u003E=4.20.0,\u003C4.20.2|\u003E=5.0.0,\u003C5.0.6|\u003E=6.0.0,\u003C6.2.1","source":"GitHub","reportedAt":"2026-07-02 20:25:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6929-8p9f-26jx"}]},{"advisoryId":"PKSA-1fc7-xrz7-vw78","packageName":"simplesamlphp\/saml2","remoteId":"GHSA-5cjr-mxj5-wmrx","title":"SimpleSAMLphp has Possible DoS via XPath Transform","link":"https:\/\/github.com\/advisories\/GHSA-5cjr-mxj5-wmrx","cve":"CVE-2026-49289","affectedVersions":"\u003C=4.19.2|\u003E=4.20.0,\u003C=4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:27:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5cjr-mxj5-wmrx"}]}],"simplesamlphp\/saml2-legacy":[{"advisoryId":"PKSA-4y26-97zb-p98g","packageName":"simplesamlphp\/saml2-legacy","remoteId":"GHSA-6929-8p9f-26jx","title":"SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass","link":"https:\/\/github.com\/advisories\/GHSA-6929-8p9f-26jx","cve":"CVE-2026-49283","affectedVersions":"\u003C4.19.3|\u003E=4.20.0,\u003C4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:25:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6929-8p9f-26jx"}]},{"advisoryId":"PKSA-11bv-m3wk-h9sn","packageName":"simplesamlphp\/saml2-legacy","remoteId":"GHSA-5cjr-mxj5-wmrx","title":"SimpleSAMLphp has Possible DoS via XPath Transform","link":"https:\/\/github.com\/advisories\/GHSA-5cjr-mxj5-wmrx","cve":"CVE-2026-49289","affectedVersions":"\u003C=4.19.2|\u003E=4.20.0,\u003C=4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:27:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5cjr-mxj5-wmrx"}]}],"silverstripe\/cms":[{"advisoryId":"PKSA-pjvm-vnw2-n3m2","packageName":"silverstripe\/cms","remoteId":"silverstripe\/cms\/CVE-2026-54717.yaml","title":"CVE-2026-54717 - XSS in breadcrumbs in page list view","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-54717","cve":"CVE-2026-54717","affectedVersions":"\u003C6.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 02:39:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w3cp-g2pf-65wh"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/cms\/CVE-2026-54717.yaml"}]}],"mtdowling\/jmespath.php":[{"advisoryId":"PKSA-mnyp-475s-ywph","packageName":"mtdowling\/jmespath.php","remoteId":"mtdowling\/jmespath.php\/CVE-2026-54133.yaml","title":"CompilerRuntime code injection via unescaped function names","link":"https:\/\/github.com\/jmespath\/jmespath.php\/security\/advisories\/GHSA-pcw8-m77r-2528","cve":"CVE-2026-54133","affectedVersions":"\u003C2.9.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-11 10:41:50","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-pcw8-m77r-2528"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"mtdowling\/jmespath.php\/CVE-2026-54133.yaml"}]}],"cakephp\/authentication":[{"advisoryId":"PKSA-bz6x-t8z8-r26p","packageName":"cakephp\/authentication","remoteId":"GHSA-hhpq-7wg4-36jm","title":"CakePHP Authentication: Open redirect weakness via backslash bypass","link":"https:\/\/github.com\/advisories\/GHSA-hhpq-7wg4-36jm","cve":"CVE-2026-55590","affectedVersions":"\u003C2.11.1|\u003E=3.0.0,\u003C3.3.6|\u003E=4.0.0,\u003C4.1.1","source":"GitHub","reportedAt":"2026-06-17 18:52:09","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hhpq-7wg4-36jm"}]}]}}