{"advisories":{"getgrav\/grav":[{"advisoryId":"PKSA-p6yn-thc9-dbs3","packageName":"getgrav\/grav","remoteId":"GHSA-7mgc-c7pq-3rr3","title":"Grav: 2FA Bypass via \u0027login.regenerate2FASecret\u0027 - Secret Rotation During Pending Challenge","link":"https:\/\/github.com\/advisories\/GHSA-7mgc-c7pq-3rr3","cve":"CVE-2026-62669","affectedVersions":"\u003C2.0.4","source":"GitHub","reportedAt":"2026-09-02 22:01:25","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7mgc-c7pq-3rr3"}]},{"advisoryId":"PKSA-sq15-xbtt-m678","packageName":"getgrav\/grav","remoteId":"GHSA-mc5q-6hpj-rp7j","title":"Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)","link":"https:\/\/github.com\/advisories\/GHSA-mc5q-6hpj-rp7j","cve":"CVE-2026-61842","affectedVersions":"\u003C2.0.2","source":"GitHub","reportedAt":"2026-09-02 21:41:12","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mc5q-6hpj-rp7j"}]},{"advisoryId":"PKSA-2vrn-cxz9-yg23","packageName":"getgrav\/grav","remoteId":"GHSA-928x-9mpw-8h56","title":"Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits","link":"https:\/\/github.com\/advisories\/GHSA-928x-9mpw-8h56","cve":"CVE-2026-61690","affectedVersions":"\u003C2.0.1","source":"GitHub","reportedAt":"2026-09-02 21:35:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-928x-9mpw-8h56"}]},{"advisoryId":"PKSA-1q9r-bgms-91mf","packageName":"getgrav\/grav","remoteId":"GHSA-fj2p-qj2f-74v5","title":"Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()","link":"https:\/\/github.com\/advisories\/GHSA-fj2p-qj2f-74v5","cve":"CVE-2026-64850","affectedVersions":"\u003C2.0.7","source":"GitHub","reportedAt":"2026-09-02 14:51:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fj2p-qj2f-74v5"}]}],"snipe\/snipe-it":[{"advisoryId":"PKSA-g91f-rycz-yjcf","packageName":"snipe\/snipe-it","remoteId":"GHSA-c6w2-j4wq-mvwg","title":"Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode","link":"https:\/\/github.com\/advisories\/GHSA-c6w2-j4wq-mvwg","cve":"CVE-2026-55643","affectedVersions":"\u003C8.6.3","source":"GitHub","reportedAt":"2026-08-19 19:32:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c6w2-j4wq-mvwg"}]},{"advisoryId":"PKSA-dysn-9smy-t3nb","packageName":"snipe\/snipe-it","remoteId":"GHSA-j5g3-42wp-gqm3","title":"Snipe-IT has an Improper Privilege Management issue","link":"https:\/\/github.com\/advisories\/GHSA-j5g3-42wp-gqm3","cve":"CVE-2026-55843","affectedVersions":"\u003C8.6.0","source":"GitHub","reportedAt":"2026-08-28 22:37:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j5g3-42wp-gqm3"}]},{"advisoryId":"PKSA-4bks-zvdb-53gs","packageName":"snipe\/snipe-it","remoteId":"GHSA-xr9m-gphc-9p63","title":"Snipe-IT has a path traversal vulnerability via CSV import `image` field","link":"https:\/\/github.com\/advisories\/GHSA-xr9m-gphc-9p63","cve":"CVE-2026-55469","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:00:38","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xr9m-gphc-9p63"}]},{"advisoryId":"PKSA-wsms-bsnd-yhwp","packageName":"snipe\/snipe-it","remoteId":"GHSA-8w8c-8mx9-52cw","title":"Snipe-IT\u0027s API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation","link":"https:\/\/github.com\/advisories\/GHSA-8w8c-8mx9-52cw","cve":"CVE-2026-55472","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:01:06","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8w8c-8mx9-52cw"}]},{"advisoryId":"PKSA-b2sw-ngv6-5kt1","packageName":"snipe\/snipe-it","remoteId":"GHSA-c6f4-wj38-m3g3","title":"Snipe-IT vulnerable to directory traversal in displaySig","link":"https:\/\/github.com\/advisories\/GHSA-c6f4-wj38-m3g3","cve":"CVE-2026-55474","affectedVersions":"\u003C8.5.0","source":"GitHub","reportedAt":"2026-08-28 18:01:32","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c6f4-wj38-m3g3"}]},{"advisoryId":"PKSA-spdd-pnpq-79f1","packageName":"snipe\/snipe-it","remoteId":"GHSA-5wx7-xq8j-v4qm","title":"Snipe-IT\u0027s import created_by can be overwritten","link":"https:\/\/github.com\/advisories\/GHSA-5wx7-xq8j-v4qm","cve":"CVE-2026-55475","affectedVersions":"\u003C=8.6.0","source":"GitHub","reportedAt":"2026-08-28 18:01:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5wx7-xq8j-v4qm"}]},{"advisoryId":"PKSA-3ybt-zv27-1tk1","packageName":"snipe\/snipe-it","remoteId":"GHSA-53jc-27pc-x8r8","title":"Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter","link":"https:\/\/github.com\/advisories\/GHSA-53jc-27pc-x8r8","cve":"CVE-2026-55476","affectedVersions":"\u003C8.6.0","source":"GitHub","reportedAt":"2026-08-28 18:02:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-53jc-27pc-x8r8"}]},{"advisoryId":"PKSA-3nxv-xvdx-984d","packageName":"snipe\/snipe-it","remoteId":"GHSA-crv3-j83j-f3r6","title":"Snipe-IT has missing object-level authorization in Kits API","link":"https:\/\/github.com\/advisories\/GHSA-crv3-j83j-f3r6","cve":"CVE-2026-55478","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:02:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-crv3-j83j-f3r6"}]},{"advisoryId":"PKSA-j17x-hbvs-1cxn","packageName":"snipe\/snipe-it","remoteId":"GHSA-8frh-vhgh-64cf","title":"Snipe-IT has incorrect permission for legacy license checkin API ","link":"https:\/\/github.com\/advisories\/GHSA-8frh-vhgh-64cf","cve":"CVE-2026-55479","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:02:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8frh-vhgh-64cf"}]},{"advisoryId":"PKSA-78g8-kyjb-j6v1","packageName":"snipe\/snipe-it","remoteId":"GHSA-w7qw-5wfv-gwx9","title":"Snipe-IT has CSS Injection via `header_color` Setting","link":"https:\/\/github.com\/advisories\/GHSA-w7qw-5wfv-gwx9","cve":"CVE-2026-55481","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:04:29","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w7qw-5wfv-gwx9"}]},{"advisoryId":"PKSA-mtr1-kyd4-dpz1","packageName":"snipe\/snipe-it","remoteId":"GHSA-35cr-9hqq-p2mg","title":"Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint","link":"https:\/\/github.com\/advisories\/GHSA-35cr-9hqq-p2mg","cve":"CVE-2026-55515","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:04:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-35cr-9hqq-p2mg"}]},{"advisoryId":"PKSA-9w68-kyxd-kgh7","packageName":"snipe\/snipe-it","remoteId":"GHSA-575r-357h-fhch","title":"Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update","link":"https:\/\/github.com\/advisories\/GHSA-575r-357h-fhch","cve":"CVE-2026-55516","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:06:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-575r-357h-fhch"}]},{"advisoryId":"PKSA-3b5d-jjsk-z4w4","packageName":"snipe\/snipe-it","remoteId":"GHSA-wg2f-x2c2-c4rp","title":"Snipe-IT has an Open Redirect After User Edit","link":"https:\/\/github.com\/advisories\/GHSA-wg2f-x2c2-c4rp","cve":"CVE-2026-55461","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:57:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wg2f-x2c2-c4rp"}]},{"advisoryId":"PKSA-2vjy-7jj7-vvq3","packageName":"snipe\/snipe-it","remoteId":"GHSA-fc33-6w3q-538h","title":"Snipe-IT has an authorization bypass on print inventory page","link":"https:\/\/github.com\/advisories\/GHSA-fc33-6w3q-538h","cve":"CVE-2026-55462","affectedVersions":"\u003C=8.6.0","source":"GitHub","reportedAt":"2026-08-28 17:57:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fc33-6w3q-538h"}]},{"advisoryId":"PKSA-6ddj-s9z1-gtxr","packageName":"snipe\/snipe-it","remoteId":"GHSA-r52f-r9v5-66xr","title":"Snipe-IT vulnerable to stored XSS via Markdown custom field ","link":"https:\/\/github.com\/advisories\/GHSA-r52f-r9v5-66xr","cve":"CVE-2026-55464","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:58:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r52f-r9v5-66xr"}]},{"advisoryId":"PKSA-3mmm-zfys-jjqm","packageName":"snipe\/snipe-it","remoteId":"GHSA-jhph-5q74-pmfx","title":"Snipe-IT vulnerable to stored XSS via inline-served attachment","link":"https:\/\/github.com\/advisories\/GHSA-jhph-5q74-pmfx","cve":"CVE-2026-55466","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:59:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jhph-5q74-pmfx"}]},{"advisoryId":"PKSA-cj32-qmb9-vwgy","packageName":"snipe\/snipe-it","remoteId":"GHSA-whrx-mmgr-gpcf","title":"Snipe-IT has CSV formula injection in Activity Report export","link":"https:\/\/github.com\/advisories\/GHSA-whrx-mmgr-gpcf","cve":"CVE-2026-55452","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:46:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-whrx-mmgr-gpcf"}]},{"advisoryId":"PKSA-n99m-2gcm-8bc6","packageName":"snipe\/snipe-it","remoteId":"GHSA-vgx7-c78r-69w9","title":"Snipe-IT has an authorization bypass on bulk editing users","link":"https:\/\/github.com\/advisories\/GHSA-vgx7-c78r-69w9","cve":"CVE-2026-55460","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:48:36","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vgx7-c78r-69w9"}]}],"sulu\/sulu":[{"advisoryId":"PKSA-nbbf-nf63-19vd","packageName":"sulu\/sulu","remoteId":"GHSA-pp4x-ccxq-6r33","title":"Sulu: Stored XSS via media download inline-disposition override","link":"https:\/\/github.com\/advisories\/GHSA-pp4x-ccxq-6r33","cve":"CVE-2026-82396","affectedVersions":"\u003E=3.0.0-alpha1,\u003C3.0.8|\u003C=2.6.24","source":"GitHub","reportedAt":"2026-09-02 15:10:19","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pp4x-ccxq-6r33"}]},{"advisoryId":"PKSA-2gwf-7fts-yzvv","packageName":"sulu\/sulu","remoteId":"GHSA-65cv-w493-7vhq","title":"Sulu: Fix authorization bypass when creating preview links","link":"https:\/\/github.com\/advisories\/GHSA-65cv-w493-7vhq","cve":"CVE-2026-82394","affectedVersions":"\u003E=3.0.0-alpha1,\u003C3.0.8|\u003C=2.6.24","source":"GitHub","reportedAt":"2026-09-02 15:09:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-65cv-w493-7vhq"}]},{"advisoryId":"PKSA-zmfc-sgjt-9gmb","packageName":"sulu\/sulu","remoteId":"GHSA-h6cx-gjxx-v25c","title":"Sulu: Media move\/update authorization bypass (IDOR)","link":"https:\/\/github.com\/advisories\/GHSA-h6cx-gjxx-v25c","cve":"CVE-2026-82395","affectedVersions":"\u003E=3.0.0-alpha1,\u003C3.0.8|\u003C=2.6.24","source":"GitHub","reportedAt":"2026-09-02 14:57:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h6cx-gjxx-v25c"}]}],"getkirby\/cms":[{"advisoryId":"PKSA-cmzk-n5t6-2v3k","packageName":"getkirby\/cms","remoteId":"GHSA-6j4c-mgqr-qv76","title":"Kirby: Access to image files outside of the site root via path traversal in the media handling","link":"https:\/\/github.com\/advisories\/GHSA-6j4c-mgqr-qv76","cve":"CVE-2026-75592","affectedVersions":"\u003E=5.0.0,\u003C5.5.2|\u003C4.9.5","source":"GitHub","reportedAt":"2026-09-02 14:55:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6j4c-mgqr-qv76"}]},{"advisoryId":"PKSA-wq8z-fxnn-1fxz","packageName":"getkirby\/cms","remoteId":"GHSA-rf2p-vh74-7vvh","title":"Kirby: System path exposure from error messages in the REST API","link":"https:\/\/github.com\/advisories\/GHSA-rf2p-vh74-7vvh","cve":"CVE-2026-69127","affectedVersions":"\u003E=5.0.0,\u003C5.5.2|\u003C=4.9.4","source":"GitHub","reportedAt":"2026-09-01 16:37:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rf2p-vh74-7vvh"}]},{"advisoryId":"PKSA-n74d-ghht-18nt","packageName":"getkirby\/cms","remoteId":"GHSA-9vx2-j98c-p72w","title":"Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling","link":"https:\/\/github.com\/advisories\/GHSA-9vx2-j98c-p72w","cve":"CVE-2026-75594","affectedVersions":"\u003E=5.0.0,\u003C5.5.2|\u003C=4.9.4","source":"GitHub","reportedAt":"2026-08-31 22:12:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9vx2-j98c-p72w"}]},{"advisoryId":"PKSA-cxg1-n9gs-z2t6","packageName":"getkirby\/cms","remoteId":"GHSA-67mx-6wf2-92xp","title":"Kirby: File upload permissions are not checked during processing of chunk data","link":"https:\/\/github.com\/advisories\/GHSA-67mx-6wf2-92xp","cve":"CVE-2026-71415","affectedVersions":"\u003E=5.0.0,\u003C5.5.2","source":"GitHub","reportedAt":"2026-08-31 22:14:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-67mx-6wf2-92xp"}]}],"apache\/thrift":[{"advisoryId":"PKSA-t5dt-c9kk-znks","packageName":"apache\/thrift","remoteId":"GHSA-8wv5-x4w7-5gww","title":"Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop","link":"https:\/\/github.com\/advisories\/GHSA-8wv5-x4w7-5gww","cve":"CVE-2026-43871","affectedVersions":"\u003C0.24.0","source":"GitHub","reportedAt":"2026-07-27 12:31:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8wv5-x4w7-5gww"}]}],"studio-42\/elfinder":[{"advisoryId":"PKSA-th2b-2jzf-hmp6","packageName":"studio-42\/elfinder","remoteId":"GHSA-9hjf-w35w-6vx2","title":"elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections","link":"https:\/\/github.com\/advisories\/GHSA-9hjf-w35w-6vx2","cve":"CVE-2026-81890","affectedVersions":"\u003C2.1.70","source":"GitHub","reportedAt":"2026-09-02 14:37:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9hjf-w35w-6vx2"}]},{"advisoryId":"PKSA-71vn-d2sp-v1x4","packageName":"studio-42\/elfinder","remoteId":"GHSA-gxmj-r5rf-ggwq","title":"elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)","link":"https:\/\/github.com\/advisories\/GHSA-gxmj-r5rf-ggwq","cve":"CVE-2026-81891","affectedVersions":"\u003C2.1.70","source":"GitHub","reportedAt":"2026-09-02 14:37:54","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gxmj-r5rf-ggwq"}]},{"advisoryId":"PKSA-r7xr-47v5-58tx","packageName":"studio-42\/elfinder","remoteId":"GHSA-8x3q-jpjh-qh5c","title":"elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback","link":"https:\/\/github.com\/advisories\/GHSA-8x3q-jpjh-qh5c","cve":"CVE-2026-81889","affectedVersions":"\u003C=2.1.69","source":"GitHub","reportedAt":"2026-08-31 20:28:06","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8x3q-jpjh-qh5c"}]}],"livewire\/livewire":[{"advisoryId":"PKSA-bgw4-5zmg-2njg","packageName":"livewire\/livewire","remoteId":"GHSA-g3hc-697w-wm82","title":"Livewire DOM-based cross-site scripting during client-side state handling","link":"https:\/\/github.com\/advisories\/GHSA-g3hc-697w-wm82","cve":"CVE-2026-81887","affectedVersions":"\u003E=4.0.0-beta.1,\u003C=4.3.3|\u003E=3.0.0-beta.1,\u003C=3.8.2","source":"GitHub","reportedAt":"2026-09-02 14:38:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g3hc-697w-wm82"}]}],"typo3\/cms-backend":[{"advisoryId":"PKSA-nmd9-kc7m-nsvr","packageName":"typo3\/cms-backend","remoteId":"GHSA-68jx-f42c-7599","title":"TYPO3 CMS - Broken Access Control in Backend and Install Tool","link":"https:\/\/github.com\/advisories\/GHSA-68jx-f42c-7599","cve":"CVE-2026-19418","affectedVersions":"\u003E=13.0.0,\u003C13.4.34","source":"GitHub","reportedAt":"2026-09-01 21:31:42","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-68jx-f42c-7599"}]}],"filament\/filament":[{"advisoryId":"PKSA-wst7-5d23-qy5j","packageName":"filament\/filament","remoteId":"GHSA-52xp-w8hr-xv3c","title":"Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled","link":"https:\/\/github.com\/advisories\/GHSA-52xp-w8hr-xv3c","cve":"CVE-2026-77567","affectedVersions":"\u003E=5.0.0,\u003C5.7.0|\u003E=4.0.0,\u003C4.12.0","source":"GitHub","reportedAt":"2026-09-01 21:28:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-52xp-w8hr-xv3c"}]},{"advisoryId":"PKSA-r2v2-7j3d-th1m","packageName":"filament\/filament","remoteId":"GHSA-xwpv-pqxp-5v36","title":"Filament: Password validity disclosure for accounts denied panel access on login page","link":"https:\/\/github.com\/advisories\/GHSA-xwpv-pqxp-5v36","cve":"CVE-2026-84307","affectedVersions":"\u003E=5.0.0,\u003C5.7.5|\u003E=4.0.0,\u003C4.12.5","source":"GitHub","reportedAt":"2026-09-01 21:29:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xwpv-pqxp-5v36"}]},{"advisoryId":"PKSA-fwm5-nrzy-yd41","packageName":"filament\/filament","remoteId":"GHSA-r3j6-gpjw-qfjr","title":"Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used","link":"https:\/\/github.com\/advisories\/GHSA-r3j6-gpjw-qfjr","cve":"CVE-2026-84306","affectedVersions":"\u003E=5.0.0,\u003C5.7.6|\u003E=4.0.0,\u003C4.12.6","source":"GitHub","reportedAt":"2026-09-01 21:29:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r3j6-gpjw-qfjr"}]}],"league\/commonmark":[{"advisoryId":"PKSA-nv44-1b4d-6gjg","packageName":"league\/commonmark","remoteId":"GHSA-jjv6-8j6v-6j52","title":"league\/commonmark: Denial of service in the SmartPunct and Attributes extensions","link":"https:\/\/github.com\/advisories\/GHSA-jjv6-8j6v-6j52","cve":null,"affectedVersions":"\u003E=1.5.0,\u003C2.9.1","source":"GitHub","reportedAt":"2026-09-01 20:21:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jjv6-8j6v-6j52"}]},{"advisoryId":"PKSA-zyf5-hrxv-hrd7","packageName":"league\/commonmark","remoteId":"GHSA-8rr7-cvq3-gmfh","title":"league\/commonmark: Denial of service via distinctly-named attributes in the Attributes extension","link":"https:\/\/github.com\/advisories\/GHSA-8rr7-cvq3-gmfh","cve":null,"affectedVersions":"\u003E=1.5.0,\u003C2.10.0","source":"GitHub","reportedAt":"2026-09-01 20:28:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8rr7-cvq3-gmfh"}]},{"advisoryId":"PKSA-kr3s-894t-g5w2","packageName":"league\/commonmark","remoteId":"GHSA-f8fg-pg57-v4j8","title":"league\/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed","link":"https:\/\/github.com\/advisories\/GHSA-f8fg-pg57-v4j8","cve":null,"affectedVersions":"\u003E=2.7.0,\u003C2.9.1","source":"GitHub","reportedAt":"2026-09-01 20:18:29","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f8fg-pg57-v4j8"}]},{"advisoryId":"PKSA-9q1p-3s19-bp1q","packageName":"league\/commonmark","remoteId":"GHSA-j8pm-gj4c-rq4x","title":"league\/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters","link":"https:\/\/github.com\/advisories\/GHSA-j8pm-gj4c-rq4x","cve":null,"affectedVersions":"\u003E=0.6.0,\u003C2.9.1","source":"GitHub","reportedAt":"2026-09-01 20:17:59","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j8pm-gj4c-rq4x"}]}],"statamic\/cms":[{"advisoryId":"PKSA-rsd9-mj5m-pj4f","packageName":"statamic\/cms","remoteId":"GHSA-jppw-r5j3-xf7x","title":"Statamic CMS exposes two-factor recovery codes through dynamic Antlers rendering","link":"https:\/\/github.com\/advisories\/GHSA-jppw-r5j3-xf7x","cve":"CVE-2026-71293","affectedVersions":"\u003E=6.0.0-alpha.1,\u003C=6.30.0","source":"GitHub","reportedAt":"2026-08-05 15:32:21","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jppw-r5j3-xf7x"}]}],"smarty\/smarty":[{"advisoryId":"PKSA-mz8k-7h5s-m8kh","packageName":"smarty\/smarty","remoteId":"GHSA-cq55-c7wv-pxmq","title":"Smarty: SSRF via redirect bypass of trusted_uri using {fetch}","link":"https:\/\/github.com\/advisories\/GHSA-cq55-c7wv-pxmq","cve":"CVE-2026-62993","affectedVersions":"\u003C4.5.7|\u003E=5.0.0,\u003C5.8.2","source":"GitHub","reportedAt":"2026-09-01 16:38:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cq55-c7wv-pxmq"}]}],"privatebin\/privatebin":[{"advisoryId":"PKSA-ysv6-x4qh-fd9v","packageName":"privatebin\/privatebin","remoteId":"GHSA-f2xf-7x3g-4272","title":"PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction","link":"https:\/\/github.com\/advisories\/GHSA-f2xf-7x3g-4272","cve":"CVE-2026-55696","affectedVersions":"\u003C=2.0.4","source":"GitHub","reportedAt":"2026-08-28 20:22:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f2xf-7x3g-4272"}]},{"advisoryId":"PKSA-t55m-4nf3-277t","packageName":"privatebin\/privatebin","remoteId":"GHSA-xrjc-c68j-hp7w","title":"PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI","link":"https:\/\/github.com\/advisories\/GHSA-xrjc-c68j-hp7w","cve":"CVE-2026-55891","affectedVersions":"\u003C=2.0.4","source":"GitHub","reportedAt":"2026-08-28 20:25:34","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xrjc-c68j-hp7w"}]}],"pimcore\/pimcore":[{"advisoryId":"PKSA-kkjc-bw16-f3kq","packageName":"pimcore\/pimcore","remoteId":"GHSA-w23p-wrp7-ch38","title":"Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502)","link":"https:\/\/github.com\/advisories\/GHSA-w23p-wrp7-ch38","cve":"CVE-2026-55220","affectedVersions":"\u003C=12.3.9|\u003E=2026.1.0,\u003C=2026.1.5","source":"GitHub","reportedAt":"2026-08-28 19:13:25","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-w23p-wrp7-ch38"}]},{"advisoryId":"PKSA-vgg9-cbdg-s4xt","packageName":"pimcore\/pimcore","remoteId":"GHSA-9x44-4gxf-8c25","title":"Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name","link":"https:\/\/github.com\/advisories\/GHSA-9x44-4gxf-8c25","cve":"CVE-2026-55634","affectedVersions":"\u003E=2026.1.0,\u003C=2026.1.5|\u003C=12.3.9","source":"GitHub","reportedAt":"2026-08-28 19:17:42","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-9x44-4gxf-8c25"}]},{"advisoryId":"PKSA-6dhb-gq75-qpgr","packageName":"pimcore\/pimcore","remoteId":"GHSA-7p36-fq2r-4h7r","title":"Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed","link":"https:\/\/github.com\/advisories\/GHSA-7p36-fq2r-4h7r","cve":"CVE-2026-11407","affectedVersions":"\u003C=11.5.14.1|\u003E=12.0.0-RC1,\u003C=12.3.8","source":"GitHub","reportedAt":"2026-06-17 21:34:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7p36-fq2r-4h7r"}]}],"pimcore\/studio-backend-bundle":[{"advisoryId":"PKSA-spw3-r32w-35m6","packageName":"pimcore\/studio-backend-bundle","remoteId":"GHSA-h854-c3m3-mh5v","title":"Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass","link":"https:\/\/github.com\/advisories\/GHSA-h854-c3m3-mh5v","cve":"CVE-2026-55207","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.6|\u003C2025.4.6","source":"GitHub","reportedAt":"2026-08-28 19:04:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h854-c3m3-mh5v"}]},{"advisoryId":"PKSA-pq1q-v29r-6xp5","packageName":"pimcore\/studio-backend-bundle","remoteId":"GHSA-79cw-hfcc-7mw9","title":"Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes","link":"https:\/\/github.com\/advisories\/GHSA-79cw-hfcc-7mw9","cve":"CVE-2026-55208","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.6|\u003C2025.4.6","source":"GitHub","reportedAt":"2026-08-28 19:04:54","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-79cw-hfcc-7mw9"}]},{"advisoryId":"PKSA-89fg-v2s3-x29j","packageName":"pimcore\/studio-backend-bundle","remoteId":"GHSA-f97c-ph8j-8vff","title":"Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation","link":"https:\/\/github.com\/advisories\/GHSA-f97c-ph8j-8vff","cve":"CVE-2026-55212","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.6|\u003C2025.4.6","source":"GitHub","reportedAt":"2026-08-28 19:05:25","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f97c-ph8j-8vff"}]}],"phpsysinfo\/phpsysinfo":[{"advisoryId":"PKSA-m4bq-bq4t-zzsh","packageName":"phpsysinfo\/phpsysinfo","remoteId":"GHSA-786w-p5pm-cvgh","title":"phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For \/ Client-IP headers","link":"https:\/\/github.com\/advisories\/GHSA-786w-p5pm-cvgh","cve":"CVE-2026-55584","affectedVersions":"\u003C=3.4.5","source":"GitHub","reportedAt":"2026-08-28 18:30:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-786w-p5pm-cvgh"}]}],"phalcon\/cphalcon":[{"advisoryId":"PKSA-65xj-m5g6-56k1","packageName":"phalcon\/cphalcon","remoteId":"GHSA-8jqh-95g6-7jpj","title":"Phalcon: Non-constant-time HMAC verification in `Encryption\\Crypt::decrypt` (timing side-channel)","link":"https:\/\/github.com\/advisories\/GHSA-8jqh-95g6-7jpj","cve":"CVE-2026-54736","affectedVersions":"\u003C=5.14.0","source":"GitHub","reportedAt":"2026-08-28 16:01:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8jqh-95g6-7jpj"}]},{"advisoryId":"PKSA-5stm-rfkw-zjbb","packageName":"phalcon\/cphalcon","remoteId":"GHSA-x7rj-f32v-7jjg","title":"Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS","link":"https:\/\/github.com\/advisories\/GHSA-x7rj-f32v-7jjg","cve":"CVE-2026-57584","affectedVersions":"\u003C=5.14.2","source":"GitHub","reportedAt":"2026-08-28 16:06:31","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-x7rj-f32v-7jjg"}]}],"typo3\/cms-core":[{"advisoryId":"PKSA-hf64-fs5s-6k3h","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-19418.yaml","title":"TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-core-sa-2026-021","cve":"CVE-2026-19418","affectedVersions":"\u003E=13.0.0,\u003C13.4.34|\u003E=14.0.0,\u003C14.3.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-11 09:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-68jx-f42c-7599"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-19418.yaml"}]}],"easycorp\/easyadmin-bundle":[{"advisoryId":"PKSA-7ck7-y4vp-mmcz","packageName":"easycorp\/easyadmin-bundle","remoteId":"easycorp\/easyadmin-bundle\/CVE-2026-81892.yaml","title":"Custom action dispatcher bypasses access_control on other routes","link":"https:\/\/github.com\/EasyCorp\/EasyAdminBundle\/security\/advisories\/GHSA-g2fm-8hr4-j82h","cve":"CVE-2026-81892","affectedVersions":"\u003E=4.0.0,\u003C4.29.16|\u003E=5.0.0,\u003C5.5.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-11 06:38:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"easycorp\/easyadmin-bundle\/CVE-2026-81892.yaml"},{"name":"GitHub","remoteId":"GHSA-g2fm-8hr4-j82h"}]}],"craftcms\/cms":[{"advisoryId":"PKSA-gh5w-x99g-b53n","packageName":"craftcms\/cms","remoteId":"GHSA-xxpx-f366-4xpq","title":"Craft CMS: Authorization bypass: view-only Categories user can modify category structure via structures\/move-element","link":"https:\/\/github.com\/advisories\/GHSA-xxpx-f366-4xpq","cve":"CVE-2026-72785","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:43:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xxpx-f366-4xpq"}]},{"advisoryId":"PKSA-4q3g-gxhk-813s","packageName":"craftcms\/cms","remoteId":"GHSA-596p-6jv8-775v","title":"Craft CMS: Authenticated leak of secret environment variables","link":"https:\/\/github.com\/advisories\/GHSA-596p-6jv8-775v","cve":"CVE-2026-72782","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:53:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-596p-6jv8-775v"}]},{"advisoryId":"PKSA-19kf-75v5-vy76","packageName":"craftcms\/cms","remoteId":"GHSA-957r-qf9p-67xw","title":"Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts","link":"https:\/\/github.com\/advisories\/GHSA-957r-qf9p-67xw","cve":"CVE-2026-72779","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:54:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-957r-qf9p-67xw"}]},{"advisoryId":"PKSA-1412-5vdy-cd6w","packageName":"craftcms\/cms","remoteId":"GHSA-rvmm-v933-jgxq","title":"Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics","link":"https:\/\/github.com\/advisories\/GHSA-rvmm-v933-jgxq","cve":"CVE-2026-14794","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.3|\u003E=4.0.0-RC1,\u003C4.18.1","source":"GitHub","reportedAt":"2026-08-06 21:42:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rvmm-v933-jgxq"}]},{"advisoryId":"PKSA-82nd-44zr-vpmz","packageName":"craftcms\/cms","remoteId":"GHSA-7hxc-f267-h5q7","title":"Craft CMS: Incorrect path validation could potentially lead to path traversal","link":"https:\/\/github.com\/advisories\/GHSA-7hxc-f267-h5q7","cve":"CVE-2026-72783","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:36:11","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7hxc-f267-h5q7"}]},{"advisoryId":"PKSA-d48x-nyby-nphv","packageName":"craftcms\/cms","remoteId":"GHSA-f5wm-88jv-g5hx","title":"Craft CMS: Authenticated RCE through Twig sandbox escape","link":"https:\/\/github.com\/advisories\/GHSA-f5wm-88jv-g5hx","cve":"CVE-2026-72781","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.3|\u003E=5.0.0-RC1,\u003C5.10.7","source":"GitHub","reportedAt":"2026-08-06 21:02:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f5wm-88jv-g5hx"}]},{"advisoryId":"PKSA-4tjq-33kk-ghq8","packageName":"craftcms\/cms","remoteId":"GHSA-265m-7826-wjqm","title":"Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass","link":"https:\/\/github.com\/advisories\/GHSA-265m-7826-wjqm","cve":"CVE-2026-72778","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 20:45:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-265m-7826-wjqm"}]},{"advisoryId":"PKSA-24yr-dkzm-n9v5","packageName":"craftcms\/cms","remoteId":"GHSA-vg3j-hpm9-8v5v","title":"Craft CMS has a potential information disclosure vulnerability in preview tokens","link":"https:\/\/github.com\/advisories\/GHSA-vg3j-hpm9-8v5v","cve":"CVE-2026-29113","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.9.7|\u003E=4.0.0-RC1,\u003C4.17.3","source":"GitHub","reportedAt":"2026-03-10 18:22:02","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-vg3j-hpm9-8v5v"}]}],"typo3\/cms-form":[{"advisoryId":"PKSA-d4vj-m6hn-xm1j","packageName":"typo3\/cms-form","remoteId":"typo3\/cms-form\/CVE-2026-15305.yaml","title":"TYPO3-CORE-SA-2026-020: TYPO3 CMS - Unrestricted File Upload in Form Framework","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-core-sa-2026-020","cve":"CVE-2026-15305","affectedVersions":"\u003E=14.2.0,\u003C14.3.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-14 12:08:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mfqj-cqv3-h7xw"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-form\/CVE-2026-15305.yaml"}]}],"silverstripe\/versioned":[{"advisoryId":"PKSA-nksq-cxj8-zb32","packageName":"silverstripe\/versioned","remoteId":"silverstripe\/versioned\/CVE-2026-55779.yaml","title":"CVE-2026-55779 - XSS in archive admin restore","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-55779","cve":"CVE-2026-55779","affectedVersions":"\u003C3.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 02:53:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m4g4-86qc-v8w7"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/versioned\/CVE-2026-55779.yaml"}]}],"wwbn\/avideo":[{"advisoryId":"PKSA-mpqq-rw7h-r6qr","packageName":"wwbn\/avideo","remoteId":"GHSA-h39h-7cvg-q7j6","title":"AVideo has Authenticated Server-Side Request Forgery via downloadURL in aVideoEncoder.json.php","link":"https:\/\/github.com\/advisories\/GHSA-h39h-7cvg-q7j6","cve":"CVE-2026-27732","affectedVersions":"\u003C=21.0","source":"GitHub","reportedAt":"2026-02-25 18:57:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h39h-7cvg-q7j6"}]}]}}