{"advisories":{"paymenter\/paymenter":[{"advisoryId":"PKSA-6cm2-46tz-5tjg","packageName":"paymenter\/paymenter","remoteId":"GHSA-5gmm-hjfj-8ff7","title":"Paymenter has a credit-refund double-spend race condition in service downgrade (doUpgrade)","link":"https:\/\/github.com\/advisories\/GHSA-5gmm-hjfj-8ff7","cve":"CVE-2026-71537","affectedVersions":"\u003C=1.5.6","source":"GitHub","reportedAt":"2026-09-18 17:58:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5gmm-hjfj-8ff7"}]}],"mediawiki\/semantic-media-wiki":[{"advisoryId":"PKSA-stqx-crkb-215f","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-7xv3-gf2g-498h","title":"Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS","link":"https:\/\/github.com\/advisories\/GHSA-7xv3-gf2g-498h","cve":"CVE-2026-77607","affectedVersions":"\u003C=7.1.0","source":"GitHub","reportedAt":"2026-09-18 16:50:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7xv3-gf2g-498h"}]},{"advisoryId":"PKSA-k3v8-z9j2-2f38","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-hw3m-8j5x-94ff","title":"Semantic MediaWiki has an open redirect in Special:URIResolver","link":"https:\/\/github.com\/advisories\/GHSA-hw3m-8j5x-94ff","cve":"CVE-2026-77609","affectedVersions":"\u003C=7.1.0","source":"GitHub","reportedAt":"2026-09-18 16:51:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hw3m-8j5x-94ff"}]},{"advisoryId":"PKSA-5kcn-7vbr-1pdw","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-q5fm-9mx6-44f4","title":"Semantic MediaWiki has a query debug output XSS (`DebugFormatter`)","link":"https:\/\/github.com\/advisories\/GHSA-q5fm-9mx6-44f4","cve":"CVE-2026-77610","affectedVersions":"\u003C=7.1.0","source":"GitHub","reportedAt":"2026-09-18 16:53:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q5fm-9mx6-44f4"}]},{"advisoryId":"PKSA-yxd8-n1ty-bgkg","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-cx86-7xwp-w9wf","title":"Semantic MediaWiki affected by reflected XSS in `Special:Ask` via a forged cursor pagination token","link":"https:\/\/github.com\/advisories\/GHSA-cx86-7xwp-w9wf","cve":"CVE-2026-77616","affectedVersions":"\u003E=7.0.0,\u003C=7.1.0","source":"GitHub","reportedAt":"2026-09-18 16:58:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cx86-7xwp-w9wf"}]},{"advisoryId":"PKSA-rt5h-3dwq-vdnx","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-9rcc-pmj8-ffhr","title":"Semantic MediaWiki\u0027s Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)","link":"https:\/\/github.com\/advisories\/GHSA-9rcc-pmj8-ffhr","cve":null,"affectedVersions":"\u003E=4.2.0,\u003C=7.2.0","source":"GitHub","reportedAt":"2026-09-18 16:59:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9rcc-pmj8-ffhr"}]},{"advisoryId":"PKSA-8k3f-637m-ptt7","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-jr78-w6w5-m8f8","title":"Semantic MediaWiki\u0027a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks","link":"https:\/\/github.com\/advisories\/GHSA-jr78-w6w5-m8f8","cve":null,"affectedVersions":"\u003E=3.0.0,\u003C=7.2.1","source":"GitHub","reportedAt":"2026-09-18 16:59:31","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jr78-w6w5-m8f8"}]},{"advisoryId":"PKSA-6xyn-p8dg-1kgj","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-3jp5-3h47-28qf","title":"Semantic MediaWiki has reflected XSS in Special:Ask plain table headers","link":"https:\/\/github.com\/advisories\/GHSA-3jp5-3h47-28qf","cve":"CVE-2026-77606","affectedVersions":"\u003C=7.1.0","source":"GitHub","reportedAt":"2026-09-18 16:40:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3jp5-3h47-28qf"}]},{"advisoryId":"PKSA-2trz-n7bz-xg2h","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-59xw-qv23-j3rc","title":"Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters)","link":"https:\/\/github.com\/advisories\/GHSA-59xw-qv23-j3rc","cve":"CVE-2026-77608","affectedVersions":"\u003C=7.1.0","source":"GitHub","reportedAt":"2026-09-18 16:42:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-59xw-qv23-j3rc"}]},{"advisoryId":"PKSA-q8ty-xz99-jhhj","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-hg8h-557g-q8pp","title":"Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes","link":"https:\/\/github.com\/advisories\/GHSA-hg8h-557g-q8pp","cve":"CVE-2025-61682","affectedVersions":"\u003E=3.1.0,\u003C7.0.0","source":"GitHub","reportedAt":"2026-09-18 16:07:29","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hg8h-557g-q8pp"}]}],"getgrav\/grav":[{"advisoryId":"PKSA-nc3c-xf26-g5gp","packageName":"getgrav\/grav","remoteId":"GHSA-f8wv-xp27-6gq7","title":"Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file write","link":"https:\/\/github.com\/advisories\/GHSA-f8wv-xp27-6gq7","cve":"CVE-2026-75827","affectedVersions":"\u003C=2.0.14","source":"GitHub","reportedAt":"2026-09-17 20:44:16","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-f8wv-xp27-6gq7"}]},{"advisoryId":"PKSA-ht1d-wm6t-8sdj","packageName":"getgrav\/grav","remoteId":"GHSA-q2j8-x8hf-63ch","title":"Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate","link":"https:\/\/github.com\/advisories\/GHSA-q2j8-x8hf-63ch","cve":"CVE-2026-75834","affectedVersions":"\u003C2.0.14","source":"GitHub","reportedAt":"2026-09-17 20:44:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q2j8-x8hf-63ch"}]},{"advisoryId":"PKSA-t3gq-ss3y-p7b7","packageName":"getgrav\/grav","remoteId":"GHSA-4v9q-p283-qc2m","title":"Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)","link":"https:\/\/github.com\/advisories\/GHSA-4v9q-p283-qc2m","cve":"CVE-2026-74907","affectedVersions":"\u003C=2.0.14","source":"GitHub","reportedAt":"2026-09-17 20:43:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4v9q-p283-qc2m"}]},{"advisoryId":"PKSA-dzhx-7r7k-p6cx","packageName":"getgrav\/grav","remoteId":"GHSA-xhfv-7758-r9hx","title":"Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin","link":"https:\/\/github.com\/advisories\/GHSA-xhfv-7758-r9hx","cve":"CVE-2026-75837","affectedVersions":"\u003C2.0.14","source":"GitHub","reportedAt":"2026-09-17 20:45:15","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xhfv-7758-r9hx"}]},{"advisoryId":"PKSA-tr1n-vmpf-rmt6","packageName":"getgrav\/grav","remoteId":"GHSA-vfmf-q6x9-cw96","title":"Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS","link":"https:\/\/github.com\/advisories\/GHSA-vfmf-q6x9-cw96","cve":"CVE-2026-75828","affectedVersions":"\u003C=2.0.14","source":"GitHub","reportedAt":"2026-09-17 20:43:43","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-vfmf-q6x9-cw96"}]},{"advisoryId":"PKSA-b2c2-gv41-gcc7","packageName":"getgrav\/grav","remoteId":"GHSA-r94f-hx44-8jqf","title":"Grav CMS vulnerable to remote code execution via .zip file upload","link":"https:\/\/github.com\/advisories\/GHSA-r94f-hx44-8jqf","cve":"CVE-2026-72819","affectedVersions":"\u003C2.0.13","source":"GitHub","reportedAt":"2026-09-17 20:45:57","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r94f-hx44-8jqf"}]},{"advisoryId":"PKSA-275t-x9d8-k5s3","packageName":"getgrav\/grav","remoteId":"GHSA-jq29-c7v8-rg55","title":"Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion","link":"https:\/\/github.com\/advisories\/GHSA-jq29-c7v8-rg55","cve":"CVE-2026-72695","affectedVersions":"\u003C=2.0.15","source":"GitHub","reportedAt":"2026-09-17 20:34:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jq29-c7v8-rg55"}]},{"advisoryId":"PKSA-ms14-tz6x-6sqm","packageName":"getgrav\/grav","remoteId":"GHSA-9ccq-2jfg-qw33","title":"Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match","link":"https:\/\/github.com\/advisories\/GHSA-9ccq-2jfg-qw33","cve":"CVE-2026-72702","affectedVersions":"\u003C=2.0.15","source":"GitHub","reportedAt":"2026-09-17 20:24:38","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-9ccq-2jfg-qw33"}]},{"advisoryId":"PKSA-xzd7-91fp-yh97","packageName":"getgrav\/grav","remoteId":"GHSA-38p6-h87p-r4cg","title":"Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection","link":"https:\/\/github.com\/advisories\/GHSA-38p6-h87p-r4cg","cve":"CVE-2026-72701","affectedVersions":"\u003C=2.0.15","source":"GitHub","reportedAt":"2026-09-17 20:25:05","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-38p6-h87p-r4cg"}]},{"advisoryId":"PKSA-wz98-fgrh-3wq2","packageName":"getgrav\/grav","remoteId":"GHSA-p597-crqc-m349","title":"Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths","link":"https:\/\/github.com\/advisories\/GHSA-p597-crqc-m349","cve":"CVE-2026-72698","affectedVersions":"\u003C2.0.16","source":"GitHub","reportedAt":"2026-09-17 20:25:42","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-p597-crqc-m349"}]},{"advisoryId":"PKSA-rk3g-1sfp-78gs","packageName":"getgrav\/grav","remoteId":"GHSA-xjw5-q542-3vmr","title":"Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled","link":"https:\/\/github.com\/advisories\/GHSA-xjw5-q542-3vmr","cve":"CVE-2026-76846","affectedVersions":"\u003C=2.0.15","source":"GitHub","reportedAt":"2026-09-17 20:27:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xjw5-q542-3vmr"}]},{"advisoryId":"PKSA-f7gk-wxm8-5j49","packageName":"getgrav\/grav","remoteId":"GHSA-3jhr-mxmx-38cx","title":"Grav: UserInterface offsetget\/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()","link":"https:\/\/github.com\/advisories\/GHSA-3jhr-mxmx-38cx","cve":"CVE-2026-76839","affectedVersions":"\u003C=2.0.15","source":"GitHub","reportedAt":"2026-09-17 20:27:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3jhr-mxmx-38cx"}]},{"advisoryId":"PKSA-9871-4yy4-mgt8","packageName":"getgrav\/grav","remoteId":"GHSA-47ch-6w46-6xm7","title":"Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content","link":"https:\/\/github.com\/advisories\/GHSA-47ch-6w46-6xm7","cve":"CVE-2026-72697","affectedVersions":"\u003C=2.0.15","source":"GitHub","reportedAt":"2026-09-17 20:27:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-47ch-6w46-6xm7"}]},{"advisoryId":"PKSA-12j4-4z12-p48k","packageName":"getgrav\/grav","remoteId":"GHSA-6qw9-4vv5-jr97","title":"Grav: Stored XSS via Markdown audio\/video media \u003Csource\u003E URL","link":"https:\/\/github.com\/advisories\/GHSA-6qw9-4vv5-jr97","cve":"CVE-2026-75831","affectedVersions":"\u003C=2.0.14","source":"GitHub","reportedAt":"2026-09-17 17:31:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6qw9-4vv5-jr97"}]},{"advisoryId":"PKSA-rstv-2c4g-sjjn","packageName":"getgrav\/grav","remoteId":"GHSA-269c-h76q-8cxw","title":"Grav: Stored XSS via quoted-attribute bypass in detectXss","link":"https:\/\/github.com\/advisories\/GHSA-269c-h76q-8cxw","cve":"CVE-2026-72832","affectedVersions":"\u003E=1.5.2,\u003C=2.0.12","source":"GitHub","reportedAt":"2026-09-17 17:28:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-269c-h76q-8cxw"}]},{"advisoryId":"PKSA-7hs4-c5nt-m1jh","packageName":"getgrav\/grav","remoteId":"GHSA-c4wf-2xxc-68qm","title":"Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation","link":"https:\/\/github.com\/advisories\/GHSA-c4wf-2xxc-68qm","cve":"CVE-2026-65608","affectedVersions":"\u003E=1.7.0,\u003C2.0.9","source":"GitHub","reportedAt":"2026-09-17 17:15:33","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c4wf-2xxc-68qm"}]},{"advisoryId":"PKSA-pr7b-2t3z-v8y8","packageName":"getgrav\/grav","remoteId":"GHSA-7pgq-cr25-xvc8","title":"Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure","link":"https:\/\/github.com\/advisories\/GHSA-7pgq-cr25-xvc8","cve":"CVE-2026-69088","affectedVersions":"\u003E=2.0.7,\u003C=2.0.10","source":"GitHub","reportedAt":"2026-09-17 17:16:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7pgq-cr25-xvc8"}]},{"advisoryId":"PKSA-89qq-5khy-n4c4","packageName":"getgrav\/grav","remoteId":"GHSA-w3f4-8pj2-599w","title":"Grav: Path Traversal in ImageMedium::watermark() \u2014 arbitrary file disclosure via publicly-cached images","link":"https:\/\/github.com\/advisories\/GHSA-w3f4-8pj2-599w","cve":"CVE-2026-69089","affectedVersions":"=2.0.10","source":"GitHub","reportedAt":"2026-09-17 17:16:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w3f4-8pj2-599w"}]},{"advisoryId":"PKSA-wwkm-grbv-93ck","packageName":"getgrav\/grav","remoteId":"GHSA-37f3-6p89-6qr9","title":"Grav: Authenticated ReDoS via regex_replace in Twig Sandbox","link":"https:\/\/github.com\/advisories\/GHSA-37f3-6p89-6qr9","cve":"CVE-2026-62672","affectedVersions":"\u003C2.0.4","source":"GitHub","reportedAt":"2026-09-02 14:50:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-37f3-6p89-6qr9"}]},{"advisoryId":"PKSA-yvdd-fpv6-9ncp","packageName":"getgrav\/grav","remoteId":"GHSA-8h9x-89f2-m7x3","title":"Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver\/Installer","link":"https:\/\/github.com\/advisories\/GHSA-8h9x-89f2-m7x3","cve":"CVE-2026-61449","affectedVersions":"=2.0.1","source":"GitHub","reportedAt":"2026-09-17 14:53:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8h9x-89f2-m7x3"}]},{"advisoryId":"PKSA-4j1y-b223-8d57","packageName":"getgrav\/grav","remoteId":"GHSA-2vcx-h8p2-9pg9","title":"Grav CMS \u2014 Improper Handling of Highly Compressed Data in Installer::unZip()","link":"https:\/\/github.com\/advisories\/GHSA-2vcx-h8p2-9pg9","cve":"CVE-2026-59193","affectedVersions":"\u003E=1.0.0,\u003C2.0.0","source":"GitHub","reportedAt":"2026-09-16 22:12:10","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2vcx-h8p2-9pg9"}]},{"advisoryId":"PKSA-y2jw-px84-6zx6","packageName":"getgrav\/grav","remoteId":"GHSA-2c4f-86xc-cr74","title":"Grav: XSS Blueprint Validation Bypass via Twig String Concatenation","link":"https:\/\/github.com\/advisories\/GHSA-2c4f-86xc-cr74","cve":"CVE-2026-61453","affectedVersions":"=2.0.0","source":"GitHub","reportedAt":"2026-09-16 22:13:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2c4f-86xc-cr74"}]},{"advisoryId":"PKSA-fkd8-syrt-878t","packageName":"getgrav\/grav","remoteId":"GHSA-ffmg-hfvg-jhg9","title":"Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav","link":"https:\/\/github.com\/advisories\/GHSA-ffmg-hfvg-jhg9","cve":"CVE-2026-58657","affectedVersions":"=2.0.0-rc.9","source":"GitHub","reportedAt":"2026-09-16 22:14:53","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-ffmg-hfvg-jhg9"}]},{"advisoryId":"PKSA-p6yn-thc9-dbs3","packageName":"getgrav\/grav","remoteId":"GHSA-7mgc-c7pq-3rr3","title":"Grav: 2FA Bypass via \u0027login.regenerate2FASecret\u0027 - Secret Rotation During Pending Challenge","link":"https:\/\/github.com\/advisories\/GHSA-7mgc-c7pq-3rr3","cve":"CVE-2026-62669","affectedVersions":"\u003C2.0.4","source":"GitHub","reportedAt":"2026-09-02 22:01:25","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7mgc-c7pq-3rr3"}]},{"advisoryId":"PKSA-sq15-xbtt-m678","packageName":"getgrav\/grav","remoteId":"GHSA-mc5q-6hpj-rp7j","title":"Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)","link":"https:\/\/github.com\/advisories\/GHSA-mc5q-6hpj-rp7j","cve":"CVE-2026-61842","affectedVersions":"\u003C2.0.2","source":"GitHub","reportedAt":"2026-09-02 21:41:12","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mc5q-6hpj-rp7j"}]},{"advisoryId":"PKSA-2vrn-cxz9-yg23","packageName":"getgrav\/grav","remoteId":"GHSA-928x-9mpw-8h56","title":"Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits","link":"https:\/\/github.com\/advisories\/GHSA-928x-9mpw-8h56","cve":"CVE-2026-61690","affectedVersions":"\u003C2.0.1","source":"GitHub","reportedAt":"2026-09-02 21:35:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-928x-9mpw-8h56"}]},{"advisoryId":"PKSA-1q9r-bgms-91mf","packageName":"getgrav\/grav","remoteId":"GHSA-fj2p-qj2f-74v5","title":"Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()","link":"https:\/\/github.com\/advisories\/GHSA-fj2p-qj2f-74v5","cve":"CVE-2026-64850","affectedVersions":"\u003C2.0.7","source":"GitHub","reportedAt":"2026-09-02 14:51:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fj2p-qj2f-74v5"}]}],"chamilo\/chamilo-lms":[{"advisoryId":"PKSA-m8ms-hgzz-8ddw","packageName":"chamilo\/chamilo-lms","remoteId":"GHSA-g4c3-4g96-6g4m","title":"Chamilo LMS CStudio upload flow allows unauthenticated remote code execution","link":"https:\/\/github.com\/advisories\/GHSA-g4c3-4g96-6g4m","cve":"CVE-2026-45140","affectedVersions":"\u003C=2.0.0","source":"GitHub","reportedAt":"2026-09-17 20:23:39","composerRepository":null,"severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-g4c3-4g96-6g4m"}]}],"cakephp\/database":[{"advisoryId":"PKSA-ny8z-1rqf-8z42","packageName":"cakephp\/database","remoteId":"GHSA-vjqc-q4mp-2rvf","title":"CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection","link":"https:\/\/github.com\/advisories\/GHSA-vjqc-q4mp-2rvf","cve":"CVE-2026-79752","affectedVersions":"\u003E=5.3.0,\u003C5.3.7|\u003E=5.2.0,\u003C5.2.14|\u003E=5.0.0,\u003C5.1.9|\u003E=4.6.0,\u003C4.6.5|\u003C4.5.12","source":"GitHub","reportedAt":"2026-09-17 20:28:14","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-vjqc-q4mp-2rvf"}]},{"advisoryId":"PKSA-xyyq-wf7k-89mv","packageName":"cakephp\/database","remoteId":"GHSA-fxf7-vhh8-7vpq","title":"CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver","link":"https:\/\/github.com\/advisories\/GHSA-fxf7-vhh8-7vpq","cve":"CVE-2026-77635","affectedVersions":"\u003E=5.1.0,\u003C5.1.10|\u003E=5.2.0,\u003C5.2.15|\u003E=5.3.0,\u003C5.3.7","source":"GitHub","reportedAt":"2026-09-08 20:56:41","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-fxf7-vhh8-7vpq"}]}],"cakephp\/cakephp":[{"advisoryId":"PKSA-vxgj-bmcq-9b6x","packageName":"cakephp\/cakephp","remoteId":"GHSA-vjqc-q4mp-2rvf","title":"CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection","link":"https:\/\/github.com\/advisories\/GHSA-vjqc-q4mp-2rvf","cve":"CVE-2026-79752","affectedVersions":"\u003E=5.3.0,\u003C5.3.7|\u003E=5.2.0,\u003C5.2.14|\u003E=5.0.0,\u003C5.1.9|\u003E=4.6.0,\u003C4.6.5|\u003C4.5.12","source":"GitHub","reportedAt":"2026-09-17 20:28:14","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-vjqc-q4mp-2rvf"}]},{"advisoryId":"PKSA-rdvp-7sns-1dvh","packageName":"cakephp\/cakephp","remoteId":"GHSA-2qh5-382h-3jpc","title":"CakePHP: SmtpTransport vulnerable to CRLF header injection","link":"https:\/\/github.com\/advisories\/GHSA-2qh5-382h-3jpc","cve":"CVE-2026-77634","affectedVersions":"\u003E=5.3.0,\u003C5.3.7|\u003E=5.2.0,\u003C5.2.14|\u003E=5.0.0,\u003C5.1.8|\u003E=4.6.0,\u003C4.6.5|\u003E=4.5.0,\u003C4.5.12","source":"GitHub","reportedAt":"2026-09-08 20:56:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2qh5-382h-3jpc"}]},{"advisoryId":"PKSA-d2h7-11vv-v66p","packageName":"cakephp\/cakephp","remoteId":"GHSA-fxf7-vhh8-7vpq","title":"CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver","link":"https:\/\/github.com\/advisories\/GHSA-fxf7-vhh8-7vpq","cve":"CVE-2026-77635","affectedVersions":"\u003E=5.1.0,\u003C5.1.10|\u003E=5.2.0,\u003C5.2.15|\u003E=5.3.0,\u003C5.3.7","source":"GitHub","reportedAt":"2026-09-08 20:56:41","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-fxf7-vhh8-7vpq"}]}],"october\/october":[{"advisoryId":"PKSA-dqgv-qnp4-9j5k","packageName":"october\/october","remoteId":"GHSA-2xmm-m4wv-3fjh","title":"October CMS: Incomplete Scheme Validation in Image Resizer","link":"https:\/\/github.com\/advisories\/GHSA-2xmm-m4wv-3fjh","cve":null,"affectedVersions":"\u003E=4.3.0,\u003C4.3.4","source":"GitHub","reportedAt":"2026-09-14 17:15:44","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-2xmm-m4wv-3fjh"}]}],"october\/system":[{"advisoryId":"PKSA-syjw-hb9p-2d5m","packageName":"october\/system","remoteId":"GHSA-2ff2-mx52-q8wp","title":"October CMS: PHP Object Injection via Backend Widget Session Storage","link":"https:\/\/github.com\/advisories\/GHSA-2ff2-mx52-q8wp","cve":"CVE-2026-49400","affectedVersions":"\u003E=4.0.0,\u003C4.2.23|\u003C3.7.17","source":"GitHub","reportedAt":"2026-09-14 17:08:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-2ff2-mx52-q8wp"}]},{"advisoryId":"PKSA-m19v-7rfv-5pmv","packageName":"october\/system","remoteId":"GHSA-xv9m-fm3w-8w5x","title":"October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls","link":"https:\/\/github.com\/advisories\/GHSA-xv9m-fm3w-8w5x","cve":"CVE-2026-46696","affectedVersions":"\u003E=4.0.0,\u003C4.2.23|\u003C3.7.17","source":"GitHub","reportedAt":"2026-09-14 16:02:35","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xv9m-fm3w-8w5x"}]}],"shopper\/framework":[{"advisoryId":"PKSA-xbk1-5yr7-c54k","packageName":"shopper\/framework","remoteId":"GHSA-99h5-jhh7-v3r3","title":"Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)","link":"https:\/\/github.com\/advisories\/GHSA-99h5-jhh7-v3r3","cve":"CVE-2026-56830","affectedVersions":"\u003C2.9.2","source":"GitHub","reportedAt":"2026-09-11 21:30:14","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-99h5-jhh7-v3r3"}]},{"advisoryId":"PKSA-b41c-cwpv-9733","packageName":"shopper\/framework","remoteId":"GHSA-2cg9-97gq-9mqp","title":"Shopper: Missing authorization on product removal actions in CollectionProducts component","link":"https:\/\/github.com\/advisories\/GHSA-2cg9-97gq-9mqp","cve":"CVE-2026-56825","affectedVersions":"\u003C2.9.2","source":"GitHub","reportedAt":"2026-09-11 21:31:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2cg9-97gq-9mqp"}]},{"advisoryId":"PKSA-j6gh-mr7c-jrwc","packageName":"shopper\/framework","remoteId":"GHSA-5vf4-452p-jjhf","title":"Shopper: Negative discount values accepted and propagated through order calculation pipeline","link":"https:\/\/github.com\/advisories\/GHSA-5vf4-452p-jjhf","cve":"CVE-2026-56831","affectedVersions":"\u003C2.9.0","source":"GitHub","reportedAt":"2026-09-11 21:28:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5vf4-452p-jjhf"}]},{"advisoryId":"PKSA-kzx5-8h8q-mx1w","packageName":"shopper\/framework","remoteId":"GHSA-f7h9-qv4x-9x57","title":"Shopping privilege escalation through missing authorization in Settings components","link":"https:\/\/github.com\/advisories\/GHSA-f7h9-qv4x-9x57","cve":"CVE-2026-56826","affectedVersions":"\u003E=2.0.0,\u003C2.9.2","source":"GitHub","reportedAt":"2026-09-11 21:28:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f7h9-qv4x-9x57"}]},{"advisoryId":"PKSA-5w3n-c3b1-mxqj","packageName":"shopper\/framework","remoteId":"GHSA-j328-xmgp-j4q3","title":"Shopper: privilege escalation via improper Livewire admin component authorization","link":"https:\/\/github.com\/advisories\/GHSA-j328-xmgp-j4q3","cve":"CVE-2026-56828","affectedVersions":"\u003E=2.8.0,\u003C2.9.2","source":"GitHub","reportedAt":"2026-09-11 21:28:54","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j328-xmgp-j4q3"}]},{"advisoryId":"PKSA-d6w1-f12g-cj15","packageName":"shopper\/framework","remoteId":"GHSA-g3f9-g5vj-p62f","title":"Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component","link":"https:\/\/github.com\/advisories\/GHSA-g3f9-g5vj-p62f","cve":"CVE-2026-56829","affectedVersions":"\u003C2.9.2","source":"GitHub","reportedAt":"2026-09-11 21:29:20","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g3f9-g5vj-p62f"}]},{"advisoryId":"PKSA-wj51-ggrn-qn6q","packageName":"shopper\/framework","remoteId":"GHSA-243p-f3cv-c5wh","title":"Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes\/tags and mass-toggle visibility of brands\/categories\/suppliers","link":"https:\/\/github.com\/advisories\/GHSA-243p-f3cv-c5wh","cve":"CVE-2026-56827","affectedVersions":"\u003C2.9.2","source":"GitHub","reportedAt":"2026-09-11 20:47:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-243p-f3cv-c5wh"}]}],"pimcore\/pimcore":[{"advisoryId":"PKSA-pmf2-z78s-582m","packageName":"pimcore\/pimcore","remoteId":"GHSA-23rh-xw42-fq82","title":"Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration","link":"https:\/\/github.com\/advisories\/GHSA-23rh-xw42-fq82","cve":"CVE-2026-55416","affectedVersions":"\u003C11.5.18|\u003E=12.0.0-RC1,\u003C=12.3.9|\u003E=2026.1.0,\u003C=2026.1.5","source":"GitHub","reportedAt":"2026-09-10 19:25:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-23rh-xw42-fq82"}]},{"advisoryId":"PKSA-kkjc-bw16-f3kq","packageName":"pimcore\/pimcore","remoteId":"GHSA-w23p-wrp7-ch38","title":"Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502)","link":"https:\/\/github.com\/advisories\/GHSA-w23p-wrp7-ch38","cve":"CVE-2026-55220","affectedVersions":"\u003C=12.3.9|\u003E=2026.1.0,\u003C=2026.1.5","source":"GitHub","reportedAt":"2026-08-28 19:13:25","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-w23p-wrp7-ch38"}]},{"advisoryId":"PKSA-vgg9-cbdg-s4xt","packageName":"pimcore\/pimcore","remoteId":"GHSA-9x44-4gxf-8c25","title":"Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name","link":"https:\/\/github.com\/advisories\/GHSA-9x44-4gxf-8c25","cve":"CVE-2026-55634","affectedVersions":"\u003E=2026.1.0,\u003C=2026.1.5|\u003C=12.3.9","source":"GitHub","reportedAt":"2026-08-28 19:17:42","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-9x44-4gxf-8c25"}]},{"advisoryId":"PKSA-6dhb-gq75-qpgr","packageName":"pimcore\/pimcore","remoteId":"GHSA-7p36-fq2r-4h7r","title":"Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed","link":"https:\/\/github.com\/advisories\/GHSA-7p36-fq2r-4h7r","cve":"CVE-2026-11407","affectedVersions":"\u003C=11.5.14.1|\u003E=12.0.0-RC1,\u003C=12.3.8","source":"GitHub","reportedAt":"2026-06-17 21:34:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7p36-fq2r-4h7r"}]}],"react\/http":[{"advisoryId":"PKSA-2zvc-7x4m-kphn","packageName":"react\/http","remoteId":"react\/http\/GHSA-g4f2-2pf3-2pwj.yaml","title":"Unbounded HTTP Client Response Header Buffering Leads to Memory Exhaustion DoS in react\/http","link":"https:\/\/github.com\/reactphp\/http\/security\/advisories\/GHSA-g4f2-2pf3-2pwj","cve":null,"affectedVersions":"\u003E=1.0.0,\u003C1.11.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-09-09 09:11:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"react\/http\/GHSA-g4f2-2pf3-2pwj.yaml"}]},{"advisoryId":"PKSA-7xc4-r5ry-fg9s","packageName":"react\/http","remoteId":"react\/http\/CVE-2026-84997.yaml","title":"A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU","link":"https:\/\/github.com\/reactphp\/http\/security\/advisories\/GHSA-x424-64qh-5j54","cve":"CVE-2026-84997","affectedVersions":"\u003E=0.6.0,\u003C1.11.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-09-09 09:11:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-x424-64qh-5j54"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"react\/http\/CVE-2026-84997.yaml"}]}],"phpseclib":[{"advisoryId":"PKSA-8ydg-yj6h-v5y7","packageName":"phpseclib","remoteId":"GHSA-q97c-8qh3-fpc6","title":"phpseclib \u2014 non-constant-time X25519 scalar multiplication permits full private-key recovery","link":"https:\/\/github.com\/advisories\/GHSA-q97c-8qh3-fpc6","cve":"CVE-2026-84308","affectedVersions":"\u003E=4.0.0,\u003C4.0.1|\u003C3.0.57","source":"GitHub","reportedAt":"2026-09-08 21:24:29","composerRepository":null,"severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q97c-8qh3-fpc6"}]}],"composer\/composer":[{"advisoryId":"PKSA-ym19-cy3j-z6df","packageName":"composer\/composer","remoteId":"GHSA-rvx4-ffvw-m9q3","title":"Composer arbitrary command execution via a malicious package\u0027s Perforce source URL","link":"https:\/\/github.com\/advisories\/GHSA-rvx4-ffvw-m9q3","cve":"CVE-2026-84361","affectedVersions":"\u003E=1.0,\u003C2.2.30|\u003E=2.3.0,\u003C2.10.3","source":"GitHub","reportedAt":"2026-09-08 21:25:41","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-rvx4-ffvw-m9q3"}]}],"mongodb\/mongodb":[{"advisoryId":"PKSA-61k5-cqr9-b8b4","packageName":"mongodb\/mongodb","remoteId":"GHSA-65fr-j4p9-vc33","title":"mongodb: Reject \u0022.\u0022 and NUL bytes in database and collection names","link":"https:\/\/github.com\/advisories\/GHSA-65fr-j4p9-vc33","cve":"CVE-2026-81525","affectedVersions":"\u003E=2.0.0,\u003C2.4.1|\u003C1.21.4","source":"GitHub","reportedAt":"2026-09-08 21:27:42","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-65fr-j4p9-vc33"}]}],"predis\/predis":[{"advisoryId":"PKSA-z888-whwt-brbj","packageName":"predis\/predis","remoteId":"GHSA-w6f5-v2h6-g786","title":"Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections","link":"https:\/\/github.com\/advisories\/GHSA-w6f5-v2h6-g786","cve":"CVE-2026-84372","affectedVersions":"\u003E=3.0.0-RC1,\u003C3.3.0","source":"GitHub","reportedAt":"2026-09-08 20:57:50","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-w6f5-v2h6-g786"}]}],"maatwebsite\/excel":[{"advisoryId":"PKSA-xgss-dh88-nswy","packageName":"maatwebsite\/excel","remoteId":"GHSA-c7r6-vx3h-w5g2","title":"Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path","link":"https:\/\/github.com\/advisories\/GHSA-c7r6-vx3h-w5g2","cve":"CVE-2026-84374","affectedVersions":"\u003E=3.1.8,\u003C3.1.70","source":"GitHub","reportedAt":"2026-09-08 20:40:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c7r6-vx3h-w5g2"}]}],"typo3\/cms-lowlevel":[{"advisoryId":"PKSA-t4m5-b2kz-hh4n","packageName":"typo3\/cms-lowlevel","remoteId":"typo3\/cms-lowlevel\/CVE-2026-85400.yaml","title":"TYPO3-CORE-SA-2026-023: Missing Authorization in lowlevel commands","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-core-sa-2026-023","cve":"CVE-2026-85400","affectedVersions":"\u003E=14.2.0,\u003C14.3.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-09-08 09:01:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-lowlevel\/CVE-2026-85400.yaml"}]}],"typo3\/cms-backend":[{"advisoryId":"PKSA-745m-816f-bzfy","packageName":"typo3\/cms-backend","remoteId":"typo3\/cms-backend\/CVE-2026-77132.yaml","title":"TYPO3-CORE-SA-2026-022: Information Disclosure via Backend Localization Wizard","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-core-sa-2026-022","cve":"CVE-2026-77132","affectedVersions":"\u003E=10.0.0,\u003C10.4.60|\u003E=11.0.0,\u003C11.5.54|\u003E=12.0.0,\u003C12.4.49|\u003E=13.0.0,\u003C13.4.35|\u003E=14.0.0,\u003C14.3.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-09-08 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-backend\/CVE-2026-77132.yaml"}]},{"advisoryId":"PKSA-nmd9-kc7m-nsvr","packageName":"typo3\/cms-backend","remoteId":"GHSA-68jx-f42c-7599","title":"TYPO3 CMS - Broken Access Control in Backend and Install Tool","link":"https:\/\/github.com\/advisories\/GHSA-68jx-f42c-7599","cve":"CVE-2026-19418","affectedVersions":"\u003E=13.0.0,\u003C13.4.34","source":"GitHub","reportedAt":"2026-09-01 21:31:42","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-68jx-f42c-7599"}]}],"snipe\/snipe-it":[{"advisoryId":"PKSA-g91f-rycz-yjcf","packageName":"snipe\/snipe-it","remoteId":"GHSA-c6w2-j4wq-mvwg","title":"Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode","link":"https:\/\/github.com\/advisories\/GHSA-c6w2-j4wq-mvwg","cve":"CVE-2026-55643","affectedVersions":"\u003C8.6.3","source":"GitHub","reportedAt":"2026-08-19 19:32:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c6w2-j4wq-mvwg"}]},{"advisoryId":"PKSA-dysn-9smy-t3nb","packageName":"snipe\/snipe-it","remoteId":"GHSA-j5g3-42wp-gqm3","title":"Snipe-IT has an Improper Privilege Management issue","link":"https:\/\/github.com\/advisories\/GHSA-j5g3-42wp-gqm3","cve":"CVE-2026-55843","affectedVersions":"\u003C8.6.0","source":"GitHub","reportedAt":"2026-08-28 22:37:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j5g3-42wp-gqm3"}]},{"advisoryId":"PKSA-4bks-zvdb-53gs","packageName":"snipe\/snipe-it","remoteId":"GHSA-xr9m-gphc-9p63","title":"Snipe-IT has a path traversal vulnerability via CSV import `image` field","link":"https:\/\/github.com\/advisories\/GHSA-xr9m-gphc-9p63","cve":"CVE-2026-55469","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:00:38","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xr9m-gphc-9p63"}]},{"advisoryId":"PKSA-wsms-bsnd-yhwp","packageName":"snipe\/snipe-it","remoteId":"GHSA-8w8c-8mx9-52cw","title":"Snipe-IT\u0027s API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation","link":"https:\/\/github.com\/advisories\/GHSA-8w8c-8mx9-52cw","cve":"CVE-2026-55472","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:01:06","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8w8c-8mx9-52cw"}]},{"advisoryId":"PKSA-b2sw-ngv6-5kt1","packageName":"snipe\/snipe-it","remoteId":"GHSA-c6f4-wj38-m3g3","title":"Snipe-IT vulnerable to directory traversal in displaySig","link":"https:\/\/github.com\/advisories\/GHSA-c6f4-wj38-m3g3","cve":"CVE-2026-55474","affectedVersions":"\u003C8.5.0","source":"GitHub","reportedAt":"2026-08-28 18:01:32","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c6f4-wj38-m3g3"}]},{"advisoryId":"PKSA-spdd-pnpq-79f1","packageName":"snipe\/snipe-it","remoteId":"GHSA-5wx7-xq8j-v4qm","title":"Snipe-IT\u0027s import created_by can be overwritten","link":"https:\/\/github.com\/advisories\/GHSA-5wx7-xq8j-v4qm","cve":"CVE-2026-55475","affectedVersions":"\u003C=8.6.0","source":"GitHub","reportedAt":"2026-08-28 18:01:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5wx7-xq8j-v4qm"}]},{"advisoryId":"PKSA-3ybt-zv27-1tk1","packageName":"snipe\/snipe-it","remoteId":"GHSA-53jc-27pc-x8r8","title":"Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter","link":"https:\/\/github.com\/advisories\/GHSA-53jc-27pc-x8r8","cve":"CVE-2026-55476","affectedVersions":"\u003C8.6.0","source":"GitHub","reportedAt":"2026-08-28 18:02:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-53jc-27pc-x8r8"}]},{"advisoryId":"PKSA-3nxv-xvdx-984d","packageName":"snipe\/snipe-it","remoteId":"GHSA-crv3-j83j-f3r6","title":"Snipe-IT has missing object-level authorization in Kits API","link":"https:\/\/github.com\/advisories\/GHSA-crv3-j83j-f3r6","cve":"CVE-2026-55478","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:02:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-crv3-j83j-f3r6"}]},{"advisoryId":"PKSA-j17x-hbvs-1cxn","packageName":"snipe\/snipe-it","remoteId":"GHSA-8frh-vhgh-64cf","title":"Snipe-IT has incorrect permission for legacy license checkin API ","link":"https:\/\/github.com\/advisories\/GHSA-8frh-vhgh-64cf","cve":"CVE-2026-55479","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:02:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8frh-vhgh-64cf"}]},{"advisoryId":"PKSA-78g8-kyjb-j6v1","packageName":"snipe\/snipe-it","remoteId":"GHSA-w7qw-5wfv-gwx9","title":"Snipe-IT has CSS Injection via `header_color` Setting","link":"https:\/\/github.com\/advisories\/GHSA-w7qw-5wfv-gwx9","cve":"CVE-2026-55481","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:04:29","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w7qw-5wfv-gwx9"}]},{"advisoryId":"PKSA-mtr1-kyd4-dpz1","packageName":"snipe\/snipe-it","remoteId":"GHSA-35cr-9hqq-p2mg","title":"Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint","link":"https:\/\/github.com\/advisories\/GHSA-35cr-9hqq-p2mg","cve":"CVE-2026-55515","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:04:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-35cr-9hqq-p2mg"}]},{"advisoryId":"PKSA-9w68-kyxd-kgh7","packageName":"snipe\/snipe-it","remoteId":"GHSA-575r-357h-fhch","title":"Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update","link":"https:\/\/github.com\/advisories\/GHSA-575r-357h-fhch","cve":"CVE-2026-55516","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:06:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-575r-357h-fhch"}]},{"advisoryId":"PKSA-3b5d-jjsk-z4w4","packageName":"snipe\/snipe-it","remoteId":"GHSA-wg2f-x2c2-c4rp","title":"Snipe-IT has an Open Redirect After User Edit","link":"https:\/\/github.com\/advisories\/GHSA-wg2f-x2c2-c4rp","cve":"CVE-2026-55461","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:57:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wg2f-x2c2-c4rp"}]},{"advisoryId":"PKSA-2vjy-7jj7-vvq3","packageName":"snipe\/snipe-it","remoteId":"GHSA-fc33-6w3q-538h","title":"Snipe-IT has an authorization bypass on print inventory page","link":"https:\/\/github.com\/advisories\/GHSA-fc33-6w3q-538h","cve":"CVE-2026-55462","affectedVersions":"\u003C=8.6.0","source":"GitHub","reportedAt":"2026-08-28 17:57:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fc33-6w3q-538h"}]},{"advisoryId":"PKSA-6ddj-s9z1-gtxr","packageName":"snipe\/snipe-it","remoteId":"GHSA-r52f-r9v5-66xr","title":"Snipe-IT vulnerable to stored XSS via Markdown custom field ","link":"https:\/\/github.com\/advisories\/GHSA-r52f-r9v5-66xr","cve":"CVE-2026-55464","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:58:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r52f-r9v5-66xr"}]},{"advisoryId":"PKSA-3mmm-zfys-jjqm","packageName":"snipe\/snipe-it","remoteId":"GHSA-jhph-5q74-pmfx","title":"Snipe-IT vulnerable to stored XSS via inline-served attachment","link":"https:\/\/github.com\/advisories\/GHSA-jhph-5q74-pmfx","cve":"CVE-2026-55466","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:59:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jhph-5q74-pmfx"}]},{"advisoryId":"PKSA-cj32-qmb9-vwgy","packageName":"snipe\/snipe-it","remoteId":"GHSA-whrx-mmgr-gpcf","title":"Snipe-IT has CSV formula injection in Activity Report export","link":"https:\/\/github.com\/advisories\/GHSA-whrx-mmgr-gpcf","cve":"CVE-2026-55452","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:46:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-whrx-mmgr-gpcf"}]},{"advisoryId":"PKSA-n99m-2gcm-8bc6","packageName":"snipe\/snipe-it","remoteId":"GHSA-vgx7-c78r-69w9","title":"Snipe-IT has an authorization bypass on bulk editing users","link":"https:\/\/github.com\/advisories\/GHSA-vgx7-c78r-69w9","cve":"CVE-2026-55460","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:48:36","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vgx7-c78r-69w9"}]}],"sulu\/sulu":[{"advisoryId":"PKSA-nbbf-nf63-19vd","packageName":"sulu\/sulu","remoteId":"GHSA-pp4x-ccxq-6r33","title":"Sulu: Stored XSS via media download inline-disposition override","link":"https:\/\/github.com\/advisories\/GHSA-pp4x-ccxq-6r33","cve":"CVE-2026-82396","affectedVersions":"\u003E=3.0.0-alpha1,\u003C3.0.8|\u003C=2.6.24","source":"GitHub","reportedAt":"2026-09-02 15:10:19","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pp4x-ccxq-6r33"}]},{"advisoryId":"PKSA-2gwf-7fts-yzvv","packageName":"sulu\/sulu","remoteId":"GHSA-65cv-w493-7vhq","title":"Sulu: Fix authorization bypass when creating preview links","link":"https:\/\/github.com\/advisories\/GHSA-65cv-w493-7vhq","cve":"CVE-2026-82394","affectedVersions":"\u003E=3.0.0-alpha1,\u003C3.0.8|\u003C=2.6.24","source":"GitHub","reportedAt":"2026-09-02 15:09:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-65cv-w493-7vhq"}]},{"advisoryId":"PKSA-zmfc-sgjt-9gmb","packageName":"sulu\/sulu","remoteId":"GHSA-h6cx-gjxx-v25c","title":"Sulu: Media move\/update authorization bypass (IDOR)","link":"https:\/\/github.com\/advisories\/GHSA-h6cx-gjxx-v25c","cve":"CVE-2026-82395","affectedVersions":"\u003E=3.0.0-alpha1,\u003C3.0.8|\u003C=2.6.24","source":"GitHub","reportedAt":"2026-09-02 14:57:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h6cx-gjxx-v25c"}]}],"getkirby\/cms":[{"advisoryId":"PKSA-cmzk-n5t6-2v3k","packageName":"getkirby\/cms","remoteId":"GHSA-6j4c-mgqr-qv76","title":"Kirby: Access to image files outside of the site root via path traversal in the media handling","link":"https:\/\/github.com\/advisories\/GHSA-6j4c-mgqr-qv76","cve":"CVE-2026-75592","affectedVersions":"\u003E=5.0.0,\u003C5.5.2|\u003C4.9.5","source":"GitHub","reportedAt":"2026-09-02 14:55:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6j4c-mgqr-qv76"}]},{"advisoryId":"PKSA-wq8z-fxnn-1fxz","packageName":"getkirby\/cms","remoteId":"GHSA-rf2p-vh74-7vvh","title":"Kirby: System path exposure from error messages in the REST API","link":"https:\/\/github.com\/advisories\/GHSA-rf2p-vh74-7vvh","cve":"CVE-2026-69127","affectedVersions":"\u003E=5.0.0,\u003C5.5.2|\u003C=4.9.4","source":"GitHub","reportedAt":"2026-09-01 16:37:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rf2p-vh74-7vvh"}]},{"advisoryId":"PKSA-n74d-ghht-18nt","packageName":"getkirby\/cms","remoteId":"GHSA-9vx2-j98c-p72w","title":"Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling","link":"https:\/\/github.com\/advisories\/GHSA-9vx2-j98c-p72w","cve":"CVE-2026-75594","affectedVersions":"\u003E=5.0.0,\u003C5.5.2|\u003C=4.9.4","source":"GitHub","reportedAt":"2026-08-31 22:12:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9vx2-j98c-p72w"}]},{"advisoryId":"PKSA-cxg1-n9gs-z2t6","packageName":"getkirby\/cms","remoteId":"GHSA-67mx-6wf2-92xp","title":"Kirby: File upload permissions are not checked during processing of chunk data","link":"https:\/\/github.com\/advisories\/GHSA-67mx-6wf2-92xp","cve":"CVE-2026-71415","affectedVersions":"\u003E=5.0.0,\u003C5.5.2","source":"GitHub","reportedAt":"2026-08-31 22:14:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-67mx-6wf2-92xp"}]}],"apache\/thrift":[{"advisoryId":"PKSA-t5dt-c9kk-znks","packageName":"apache\/thrift","remoteId":"GHSA-8wv5-x4w7-5gww","title":"Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop","link":"https:\/\/github.com\/advisories\/GHSA-8wv5-x4w7-5gww","cve":"CVE-2026-43871","affectedVersions":"\u003C0.24.0","source":"GitHub","reportedAt":"2026-07-27 12:31:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8wv5-x4w7-5gww"}]}],"studio-42\/elfinder":[{"advisoryId":"PKSA-th2b-2jzf-hmp6","packageName":"studio-42\/elfinder","remoteId":"GHSA-9hjf-w35w-6vx2","title":"elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections","link":"https:\/\/github.com\/advisories\/GHSA-9hjf-w35w-6vx2","cve":"CVE-2026-81890","affectedVersions":"\u003C2.1.70","source":"GitHub","reportedAt":"2026-09-02 14:37:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9hjf-w35w-6vx2"}]},{"advisoryId":"PKSA-71vn-d2sp-v1x4","packageName":"studio-42\/elfinder","remoteId":"GHSA-gxmj-r5rf-ggwq","title":"elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)","link":"https:\/\/github.com\/advisories\/GHSA-gxmj-r5rf-ggwq","cve":"CVE-2026-81891","affectedVersions":"\u003C2.1.70","source":"GitHub","reportedAt":"2026-09-02 14:37:54","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gxmj-r5rf-ggwq"}]},{"advisoryId":"PKSA-r7xr-47v5-58tx","packageName":"studio-42\/elfinder","remoteId":"GHSA-8x3q-jpjh-qh5c","title":"elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback","link":"https:\/\/github.com\/advisories\/GHSA-8x3q-jpjh-qh5c","cve":"CVE-2026-81889","affectedVersions":"\u003C=2.1.69","source":"GitHub","reportedAt":"2026-08-31 20:28:06","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8x3q-jpjh-qh5c"}]}],"livewire\/livewire":[{"advisoryId":"PKSA-bgw4-5zmg-2njg","packageName":"livewire\/livewire","remoteId":"GHSA-g3hc-697w-wm82","title":"Livewire DOM-based cross-site scripting during client-side state handling","link":"https:\/\/github.com\/advisories\/GHSA-g3hc-697w-wm82","cve":"CVE-2026-81887","affectedVersions":"\u003E=4.0.0-beta.1,\u003C=4.3.3|\u003E=3.0.0-beta.1,\u003C=3.8.2","source":"GitHub","reportedAt":"2026-09-02 14:38:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g3hc-697w-wm82"}]}],"filament\/filament":[{"advisoryId":"PKSA-wst7-5d23-qy5j","packageName":"filament\/filament","remoteId":"GHSA-52xp-w8hr-xv3c","title":"Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled","link":"https:\/\/github.com\/advisories\/GHSA-52xp-w8hr-xv3c","cve":"CVE-2026-77567","affectedVersions":"\u003E=5.0.0,\u003C5.7.0|\u003E=4.0.0,\u003C4.12.0","source":"GitHub","reportedAt":"2026-09-01 21:28:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-52xp-w8hr-xv3c"}]},{"advisoryId":"PKSA-r2v2-7j3d-th1m","packageName":"filament\/filament","remoteId":"GHSA-xwpv-pqxp-5v36","title":"Filament: Password validity disclosure for accounts denied panel access on login page","link":"https:\/\/github.com\/advisories\/GHSA-xwpv-pqxp-5v36","cve":"CVE-2026-84307","affectedVersions":"\u003E=5.0.0,\u003C5.7.5|\u003E=4.0.0,\u003C4.12.5","source":"GitHub","reportedAt":"2026-09-01 21:29:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xwpv-pqxp-5v36"}]},{"advisoryId":"PKSA-fwm5-nrzy-yd41","packageName":"filament\/filament","remoteId":"GHSA-r3j6-gpjw-qfjr","title":"Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used","link":"https:\/\/github.com\/advisories\/GHSA-r3j6-gpjw-qfjr","cve":"CVE-2026-84306","affectedVersions":"\u003E=5.0.0,\u003C5.7.6|\u003E=4.0.0,\u003C4.12.6","source":"GitHub","reportedAt":"2026-09-01 21:29:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r3j6-gpjw-qfjr"}]}],"league\/commonmark":[{"advisoryId":"PKSA-nv44-1b4d-6gjg","packageName":"league\/commonmark","remoteId":"GHSA-jjv6-8j6v-6j52","title":"league\/commonmark: Denial of service in the SmartPunct and Attributes extensions","link":"https:\/\/github.com\/advisories\/GHSA-jjv6-8j6v-6j52","cve":null,"affectedVersions":"\u003E=1.5.0,\u003C2.9.1","source":"GitHub","reportedAt":"2026-09-01 20:21:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jjv6-8j6v-6j52"}]},{"advisoryId":"PKSA-zyf5-hrxv-hrd7","packageName":"league\/commonmark","remoteId":"GHSA-8rr7-cvq3-gmfh","title":"league\/commonmark: Denial of service via distinctly-named attributes in the Attributes extension","link":"https:\/\/github.com\/advisories\/GHSA-8rr7-cvq3-gmfh","cve":null,"affectedVersions":"\u003E=1.5.0,\u003C2.10.0","source":"GitHub","reportedAt":"2026-09-01 20:28:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8rr7-cvq3-gmfh"}]},{"advisoryId":"PKSA-kr3s-894t-g5w2","packageName":"league\/commonmark","remoteId":"GHSA-f8fg-pg57-v4j8","title":"league\/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed","link":"https:\/\/github.com\/advisories\/GHSA-f8fg-pg57-v4j8","cve":null,"affectedVersions":"\u003E=2.7.0,\u003C2.9.1","source":"GitHub","reportedAt":"2026-09-01 20:18:29","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f8fg-pg57-v4j8"}]},{"advisoryId":"PKSA-9q1p-3s19-bp1q","packageName":"league\/commonmark","remoteId":"GHSA-j8pm-gj4c-rq4x","title":"league\/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters","link":"https:\/\/github.com\/advisories\/GHSA-j8pm-gj4c-rq4x","cve":null,"affectedVersions":"\u003E=0.6.0,\u003C2.9.1","source":"GitHub","reportedAt":"2026-09-01 20:17:59","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j8pm-gj4c-rq4x"}]}],"statamic\/cms":[{"advisoryId":"PKSA-rsd9-mj5m-pj4f","packageName":"statamic\/cms","remoteId":"GHSA-jppw-r5j3-xf7x","title":"Statamic CMS exposes two-factor recovery codes through dynamic Antlers rendering","link":"https:\/\/github.com\/advisories\/GHSA-jppw-r5j3-xf7x","cve":"CVE-2026-71293","affectedVersions":"\u003E=6.0.0-alpha.1,\u003C=6.30.0","source":"GitHub","reportedAt":"2026-08-05 15:32:21","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jppw-r5j3-xf7x"}]}],"smarty\/smarty":[{"advisoryId":"PKSA-mz8k-7h5s-m8kh","packageName":"smarty\/smarty","remoteId":"GHSA-cq55-c7wv-pxmq","title":"Smarty: SSRF via redirect bypass of trusted_uri using {fetch}","link":"https:\/\/github.com\/advisories\/GHSA-cq55-c7wv-pxmq","cve":"CVE-2026-62993","affectedVersions":"\u003C4.5.7|\u003E=5.0.0,\u003C5.8.2","source":"GitHub","reportedAt":"2026-09-01 16:38:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cq55-c7wv-pxmq"}]}],"privatebin\/privatebin":[{"advisoryId":"PKSA-ysv6-x4qh-fd9v","packageName":"privatebin\/privatebin","remoteId":"GHSA-f2xf-7x3g-4272","title":"PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction","link":"https:\/\/github.com\/advisories\/GHSA-f2xf-7x3g-4272","cve":"CVE-2026-55696","affectedVersions":"\u003C=2.0.4","source":"GitHub","reportedAt":"2026-08-28 20:22:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f2xf-7x3g-4272"}]},{"advisoryId":"PKSA-t55m-4nf3-277t","packageName":"privatebin\/privatebin","remoteId":"GHSA-xrjc-c68j-hp7w","title":"PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI","link":"https:\/\/github.com\/advisories\/GHSA-xrjc-c68j-hp7w","cve":"CVE-2026-55891","affectedVersions":"\u003C=2.0.4","source":"GitHub","reportedAt":"2026-08-28 20:25:34","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xrjc-c68j-hp7w"}]}],"pimcore\/studio-backend-bundle":[{"advisoryId":"PKSA-spw3-r32w-35m6","packageName":"pimcore\/studio-backend-bundle","remoteId":"GHSA-h854-c3m3-mh5v","title":"Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass","link":"https:\/\/github.com\/advisories\/GHSA-h854-c3m3-mh5v","cve":"CVE-2026-55207","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.6|\u003C2025.4.6","source":"GitHub","reportedAt":"2026-08-28 19:04:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h854-c3m3-mh5v"}]},{"advisoryId":"PKSA-pq1q-v29r-6xp5","packageName":"pimcore\/studio-backend-bundle","remoteId":"GHSA-79cw-hfcc-7mw9","title":"Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes","link":"https:\/\/github.com\/advisories\/GHSA-79cw-hfcc-7mw9","cve":"CVE-2026-55208","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.6|\u003C2025.4.6","source":"GitHub","reportedAt":"2026-08-28 19:04:54","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-79cw-hfcc-7mw9"}]},{"advisoryId":"PKSA-89fg-v2s3-x29j","packageName":"pimcore\/studio-backend-bundle","remoteId":"GHSA-f97c-ph8j-8vff","title":"Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation","link":"https:\/\/github.com\/advisories\/GHSA-f97c-ph8j-8vff","cve":"CVE-2026-55212","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.6|\u003C2025.4.6","source":"GitHub","reportedAt":"2026-08-28 19:05:25","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f97c-ph8j-8vff"}]}],"phpsysinfo\/phpsysinfo":[{"advisoryId":"PKSA-m4bq-bq4t-zzsh","packageName":"phpsysinfo\/phpsysinfo","remoteId":"GHSA-786w-p5pm-cvgh","title":"phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For \/ Client-IP headers","link":"https:\/\/github.com\/advisories\/GHSA-786w-p5pm-cvgh","cve":"CVE-2026-55584","affectedVersions":"\u003C=3.4.5","source":"GitHub","reportedAt":"2026-08-28 18:30:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-786w-p5pm-cvgh"}]}],"phalcon\/cphalcon":[{"advisoryId":"PKSA-65xj-m5g6-56k1","packageName":"phalcon\/cphalcon","remoteId":"GHSA-8jqh-95g6-7jpj","title":"Phalcon: Non-constant-time HMAC verification in `Encryption\\Crypt::decrypt` (timing side-channel)","link":"https:\/\/github.com\/advisories\/GHSA-8jqh-95g6-7jpj","cve":"CVE-2026-54736","affectedVersions":"\u003C=5.14.0","source":"GitHub","reportedAt":"2026-08-28 16:01:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8jqh-95g6-7jpj"}]},{"advisoryId":"PKSA-5stm-rfkw-zjbb","packageName":"phalcon\/cphalcon","remoteId":"GHSA-x7rj-f32v-7jjg","title":"Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS","link":"https:\/\/github.com\/advisories\/GHSA-x7rj-f32v-7jjg","cve":"CVE-2026-57584","affectedVersions":"\u003C=5.14.2","source":"GitHub","reportedAt":"2026-08-28 16:06:31","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-x7rj-f32v-7jjg"}]}],"typo3\/cms-core":[{"advisoryId":"PKSA-hf64-fs5s-6k3h","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-19418.yaml","title":"TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-core-sa-2026-021","cve":"CVE-2026-19418","affectedVersions":"\u003E=13.0.0,\u003C13.4.34|\u003E=14.0.0,\u003C14.3.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-11 09:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-68jx-f42c-7599"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-19418.yaml"}]}],"easycorp\/easyadmin-bundle":[{"advisoryId":"PKSA-7ck7-y4vp-mmcz","packageName":"easycorp\/easyadmin-bundle","remoteId":"easycorp\/easyadmin-bundle\/CVE-2026-81892.yaml","title":"Custom action dispatcher bypasses access_control on other routes","link":"https:\/\/github.com\/EasyCorp\/EasyAdminBundle\/security\/advisories\/GHSA-g2fm-8hr4-j82h","cve":"CVE-2026-81892","affectedVersions":"\u003E=4.0.0,\u003C4.29.16|\u003E=5.0.0,\u003C5.5.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-11 06:38:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"easycorp\/easyadmin-bundle\/CVE-2026-81892.yaml"},{"name":"GitHub","remoteId":"GHSA-g2fm-8hr4-j82h"}]}],"craftcms\/cms":[{"advisoryId":"PKSA-gh5w-x99g-b53n","packageName":"craftcms\/cms","remoteId":"GHSA-xxpx-f366-4xpq","title":"Craft CMS: Authorization bypass: view-only Categories user can modify category structure via structures\/move-element","link":"https:\/\/github.com\/advisories\/GHSA-xxpx-f366-4xpq","cve":"CVE-2026-72785","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:43:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xxpx-f366-4xpq"}]},{"advisoryId":"PKSA-4q3g-gxhk-813s","packageName":"craftcms\/cms","remoteId":"GHSA-596p-6jv8-775v","title":"Craft CMS: Authenticated leak of secret environment variables","link":"https:\/\/github.com\/advisories\/GHSA-596p-6jv8-775v","cve":"CVE-2026-72782","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:53:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-596p-6jv8-775v"}]},{"advisoryId":"PKSA-19kf-75v5-vy76","packageName":"craftcms\/cms","remoteId":"GHSA-957r-qf9p-67xw","title":"Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts","link":"https:\/\/github.com\/advisories\/GHSA-957r-qf9p-67xw","cve":"CVE-2026-72779","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:54:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-957r-qf9p-67xw"}]},{"advisoryId":"PKSA-1412-5vdy-cd6w","packageName":"craftcms\/cms","remoteId":"GHSA-rvmm-v933-jgxq","title":"Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics","link":"https:\/\/github.com\/advisories\/GHSA-rvmm-v933-jgxq","cve":"CVE-2026-14794","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.3|\u003E=4.0.0-RC1,\u003C4.18.1","source":"GitHub","reportedAt":"2026-08-06 21:42:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rvmm-v933-jgxq"}]},{"advisoryId":"PKSA-82nd-44zr-vpmz","packageName":"craftcms\/cms","remoteId":"GHSA-7hxc-f267-h5q7","title":"Craft CMS: Incorrect path validation could potentially lead to path traversal","link":"https:\/\/github.com\/advisories\/GHSA-7hxc-f267-h5q7","cve":"CVE-2026-72783","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:36:11","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7hxc-f267-h5q7"}]},{"advisoryId":"PKSA-d48x-nyby-nphv","packageName":"craftcms\/cms","remoteId":"GHSA-f5wm-88jv-g5hx","title":"Craft CMS: Authenticated RCE through Twig sandbox escape","link":"https:\/\/github.com\/advisories\/GHSA-f5wm-88jv-g5hx","cve":"CVE-2026-72781","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.3|\u003E=5.0.0-RC1,\u003C5.10.7","source":"GitHub","reportedAt":"2026-08-06 21:02:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f5wm-88jv-g5hx"}]},{"advisoryId":"PKSA-4tjq-33kk-ghq8","packageName":"craftcms\/cms","remoteId":"GHSA-265m-7826-wjqm","title":"Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass","link":"https:\/\/github.com\/advisories\/GHSA-265m-7826-wjqm","cve":"CVE-2026-72778","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 20:45:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-265m-7826-wjqm"}]},{"advisoryId":"PKSA-24yr-dkzm-n9v5","packageName":"craftcms\/cms","remoteId":"GHSA-vg3j-hpm9-8v5v","title":"Craft CMS has a potential information disclosure vulnerability in preview tokens","link":"https:\/\/github.com\/advisories\/GHSA-vg3j-hpm9-8v5v","cve":"CVE-2026-29113","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.9.7|\u003E=4.0.0-RC1,\u003C4.17.3","source":"GitHub","reportedAt":"2026-03-10 18:22:02","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-vg3j-hpm9-8v5v"}]}],"typo3\/cms-form":[{"advisoryId":"PKSA-d4vj-m6hn-xm1j","packageName":"typo3\/cms-form","remoteId":"typo3\/cms-form\/CVE-2026-15305.yaml","title":"TYPO3-CORE-SA-2026-020: TYPO3 CMS - Unrestricted File Upload in Form Framework","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-core-sa-2026-020","cve":"CVE-2026-15305","affectedVersions":"\u003E=14.2.0,\u003C14.3.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-14 12:08:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mfqj-cqv3-h7xw"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-form\/CVE-2026-15305.yaml"}]}],"silverstripe\/versioned":[{"advisoryId":"PKSA-nksq-cxj8-zb32","packageName":"silverstripe\/versioned","remoteId":"silverstripe\/versioned\/CVE-2026-55779.yaml","title":"CVE-2026-55779 - XSS in archive admin restore","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-55779","cve":"CVE-2026-55779","affectedVersions":"\u003C3.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 02:53:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m4g4-86qc-v8w7"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/versioned\/CVE-2026-55779.yaml"}]}],"wwbn\/avideo":[{"advisoryId":"PKSA-mhr2-p9hx-xy4j","packageName":"wwbn\/avideo","remoteId":"GHSA-wprj-9cvc-5w37","title":"AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records","link":"https:\/\/github.com\/advisories\/GHSA-wprj-9cvc-5w37","cve":"CVE-2026-56341","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-29 15:40:52","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wprj-9cvc-5w37"}]},{"advisoryId":"PKSA-3whn-q4tm-bwhh","packageName":"wwbn\/avideo","remoteId":"GHSA-5x2w-37xf-7962","title":"AVideo has Unauthenticated PGP Message Decryption via Public Endpoint","link":"https:\/\/github.com\/advisories\/GHSA-5x2w-37xf-7962","cve":"CVE-2026-56346","affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-19 12:46:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5x2w-37xf-7962"}]},{"advisoryId":"PKSA-mpqq-rw7h-r6qr","packageName":"wwbn\/avideo","remoteId":"GHSA-h39h-7cvg-q7j6","title":"AVideo has Authenticated Server-Side Request Forgery via downloadURL in aVideoEncoder.json.php","link":"https:\/\/github.com\/advisories\/GHSA-h39h-7cvg-q7j6","cve":"CVE-2026-27732","affectedVersions":"\u003C=21.0","source":"GitHub","reportedAt":"2026-02-25 18:57:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h39h-7cvg-q7j6"}]}]}}