{"advisories":{"paymenter\/paymenter":[{"advisoryId":"PKSA-6cm2-46tz-5tjg","packageName":"paymenter\/paymenter","remoteId":"GHSA-5gmm-hjfj-8ff7","title":"Paymenter has a credit-refund double-spend race condition in service downgrade (doUpgrade)","link":"https:\/\/github.com\/advisories\/GHSA-5gmm-hjfj-8ff7","cve":"CVE-2026-71537","affectedVersions":"\u003C=1.5.6","source":"GitHub","reportedAt":"2026-09-18 17:58:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5gmm-hjfj-8ff7"}]}],"mediawiki\/semantic-media-wiki":[{"advisoryId":"PKSA-stqx-crkb-215f","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-7xv3-gf2g-498h","title":"Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS","link":"https:\/\/github.com\/advisories\/GHSA-7xv3-gf2g-498h","cve":"CVE-2026-77607","affectedVersions":"\u003C=7.1.0","source":"GitHub","reportedAt":"2026-09-18 16:50:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7xv3-gf2g-498h"}]},{"advisoryId":"PKSA-k3v8-z9j2-2f38","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-hw3m-8j5x-94ff","title":"Semantic MediaWiki has an open redirect in Special:URIResolver","link":"https:\/\/github.com\/advisories\/GHSA-hw3m-8j5x-94ff","cve":"CVE-2026-77609","affectedVersions":"\u003C=7.1.0","source":"GitHub","reportedAt":"2026-09-18 16:51:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hw3m-8j5x-94ff"}]},{"advisoryId":"PKSA-5kcn-7vbr-1pdw","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-q5fm-9mx6-44f4","title":"Semantic MediaWiki has a query debug output XSS (`DebugFormatter`)","link":"https:\/\/github.com\/advisories\/GHSA-q5fm-9mx6-44f4","cve":"CVE-2026-77610","affectedVersions":"\u003C=7.1.0","source":"GitHub","reportedAt":"2026-09-18 16:53:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q5fm-9mx6-44f4"}]},{"advisoryId":"PKSA-yxd8-n1ty-bgkg","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-cx86-7xwp-w9wf","title":"Semantic MediaWiki affected by reflected XSS in `Special:Ask` via a forged cursor pagination token","link":"https:\/\/github.com\/advisories\/GHSA-cx86-7xwp-w9wf","cve":"CVE-2026-77616","affectedVersions":"\u003E=7.0.0,\u003C=7.1.0","source":"GitHub","reportedAt":"2026-09-18 16:58:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cx86-7xwp-w9wf"}]},{"advisoryId":"PKSA-rt5h-3dwq-vdnx","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-9rcc-pmj8-ffhr","title":"Semantic MediaWiki\u0027s Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)","link":"https:\/\/github.com\/advisories\/GHSA-9rcc-pmj8-ffhr","cve":null,"affectedVersions":"\u003E=4.2.0,\u003C=7.2.0","source":"GitHub","reportedAt":"2026-09-18 16:59:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9rcc-pmj8-ffhr"}]},{"advisoryId":"PKSA-8k3f-637m-ptt7","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-jr78-w6w5-m8f8","title":"Semantic MediaWiki\u0027a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks","link":"https:\/\/github.com\/advisories\/GHSA-jr78-w6w5-m8f8","cve":null,"affectedVersions":"\u003E=3.0.0,\u003C=7.2.1","source":"GitHub","reportedAt":"2026-09-18 16:59:31","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jr78-w6w5-m8f8"}]},{"advisoryId":"PKSA-6xyn-p8dg-1kgj","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-3jp5-3h47-28qf","title":"Semantic MediaWiki has reflected XSS in Special:Ask plain table headers","link":"https:\/\/github.com\/advisories\/GHSA-3jp5-3h47-28qf","cve":"CVE-2026-77606","affectedVersions":"\u003C=7.1.0","source":"GitHub","reportedAt":"2026-09-18 16:40:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3jp5-3h47-28qf"}]},{"advisoryId":"PKSA-2trz-n7bz-xg2h","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-59xw-qv23-j3rc","title":"Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters)","link":"https:\/\/github.com\/advisories\/GHSA-59xw-qv23-j3rc","cve":"CVE-2026-77608","affectedVersions":"\u003C=7.1.0","source":"GitHub","reportedAt":"2026-09-18 16:42:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-59xw-qv23-j3rc"}]},{"advisoryId":"PKSA-q8ty-xz99-jhhj","packageName":"mediawiki\/semantic-media-wiki","remoteId":"GHSA-hg8h-557g-q8pp","title":"Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes","link":"https:\/\/github.com\/advisories\/GHSA-hg8h-557g-q8pp","cve":"CVE-2025-61682","affectedVersions":"\u003E=3.1.0,\u003C7.0.0","source":"GitHub","reportedAt":"2026-09-18 16:07:29","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hg8h-557g-q8pp"}]}],"getgrav\/grav":[{"advisoryId":"PKSA-nc3c-xf26-g5gp","packageName":"getgrav\/grav","remoteId":"GHSA-f8wv-xp27-6gq7","title":"Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file write","link":"https:\/\/github.com\/advisories\/GHSA-f8wv-xp27-6gq7","cve":"CVE-2026-75827","affectedVersions":"\u003C=2.0.14","source":"GitHub","reportedAt":"2026-09-17 20:44:16","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-f8wv-xp27-6gq7"}]},{"advisoryId":"PKSA-ht1d-wm6t-8sdj","packageName":"getgrav\/grav","remoteId":"GHSA-q2j8-x8hf-63ch","title":"Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate","link":"https:\/\/github.com\/advisories\/GHSA-q2j8-x8hf-63ch","cve":"CVE-2026-75834","affectedVersions":"\u003C2.0.14","source":"GitHub","reportedAt":"2026-09-17 20:44:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q2j8-x8hf-63ch"}]},{"advisoryId":"PKSA-t3gq-ss3y-p7b7","packageName":"getgrav\/grav","remoteId":"GHSA-4v9q-p283-qc2m","title":"Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)","link":"https:\/\/github.com\/advisories\/GHSA-4v9q-p283-qc2m","cve":"CVE-2026-74907","affectedVersions":"\u003C=2.0.14","source":"GitHub","reportedAt":"2026-09-17 20:43:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4v9q-p283-qc2m"}]},{"advisoryId":"PKSA-dzhx-7r7k-p6cx","packageName":"getgrav\/grav","remoteId":"GHSA-xhfv-7758-r9hx","title":"Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin","link":"https:\/\/github.com\/advisories\/GHSA-xhfv-7758-r9hx","cve":"CVE-2026-75837","affectedVersions":"\u003C2.0.14","source":"GitHub","reportedAt":"2026-09-17 20:45:15","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xhfv-7758-r9hx"}]},{"advisoryId":"PKSA-tr1n-vmpf-rmt6","packageName":"getgrav\/grav","remoteId":"GHSA-vfmf-q6x9-cw96","title":"Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS","link":"https:\/\/github.com\/advisories\/GHSA-vfmf-q6x9-cw96","cve":"CVE-2026-75828","affectedVersions":"\u003C=2.0.14","source":"GitHub","reportedAt":"2026-09-17 20:43:43","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-vfmf-q6x9-cw96"}]},{"advisoryId":"PKSA-b2c2-gv41-gcc7","packageName":"getgrav\/grav","remoteId":"GHSA-r94f-hx44-8jqf","title":"Grav CMS vulnerable to remote code execution via .zip file upload","link":"https:\/\/github.com\/advisories\/GHSA-r94f-hx44-8jqf","cve":"CVE-2026-72819","affectedVersions":"\u003C2.0.13","source":"GitHub","reportedAt":"2026-09-17 20:45:57","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r94f-hx44-8jqf"}]},{"advisoryId":"PKSA-275t-x9d8-k5s3","packageName":"getgrav\/grav","remoteId":"GHSA-jq29-c7v8-rg55","title":"Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion","link":"https:\/\/github.com\/advisories\/GHSA-jq29-c7v8-rg55","cve":"CVE-2026-72695","affectedVersions":"\u003C=2.0.15","source":"GitHub","reportedAt":"2026-09-17 20:34:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jq29-c7v8-rg55"}]},{"advisoryId":"PKSA-ms14-tz6x-6sqm","packageName":"getgrav\/grav","remoteId":"GHSA-9ccq-2jfg-qw33","title":"Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match","link":"https:\/\/github.com\/advisories\/GHSA-9ccq-2jfg-qw33","cve":"CVE-2026-72702","affectedVersions":"\u003C=2.0.15","source":"GitHub","reportedAt":"2026-09-17 20:24:38","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-9ccq-2jfg-qw33"}]},{"advisoryId":"PKSA-xzd7-91fp-yh97","packageName":"getgrav\/grav","remoteId":"GHSA-38p6-h87p-r4cg","title":"Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection","link":"https:\/\/github.com\/advisories\/GHSA-38p6-h87p-r4cg","cve":"CVE-2026-72701","affectedVersions":"\u003C=2.0.15","source":"GitHub","reportedAt":"2026-09-17 20:25:05","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-38p6-h87p-r4cg"}]},{"advisoryId":"PKSA-wz98-fgrh-3wq2","packageName":"getgrav\/grav","remoteId":"GHSA-p597-crqc-m349","title":"Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths","link":"https:\/\/github.com\/advisories\/GHSA-p597-crqc-m349","cve":"CVE-2026-72698","affectedVersions":"\u003C2.0.16","source":"GitHub","reportedAt":"2026-09-17 20:25:42","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-p597-crqc-m349"}]},{"advisoryId":"PKSA-rk3g-1sfp-78gs","packageName":"getgrav\/grav","remoteId":"GHSA-xjw5-q542-3vmr","title":"Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled","link":"https:\/\/github.com\/advisories\/GHSA-xjw5-q542-3vmr","cve":"CVE-2026-76846","affectedVersions":"\u003C=2.0.15","source":"GitHub","reportedAt":"2026-09-17 20:27:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xjw5-q542-3vmr"}]},{"advisoryId":"PKSA-f7gk-wxm8-5j49","packageName":"getgrav\/grav","remoteId":"GHSA-3jhr-mxmx-38cx","title":"Grav: UserInterface offsetget\/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()","link":"https:\/\/github.com\/advisories\/GHSA-3jhr-mxmx-38cx","cve":"CVE-2026-76839","affectedVersions":"\u003C=2.0.15","source":"GitHub","reportedAt":"2026-09-17 20:27:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3jhr-mxmx-38cx"}]},{"advisoryId":"PKSA-9871-4yy4-mgt8","packageName":"getgrav\/grav","remoteId":"GHSA-47ch-6w46-6xm7","title":"Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content","link":"https:\/\/github.com\/advisories\/GHSA-47ch-6w46-6xm7","cve":"CVE-2026-72697","affectedVersions":"\u003C=2.0.15","source":"GitHub","reportedAt":"2026-09-17 20:27:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-47ch-6w46-6xm7"}]},{"advisoryId":"PKSA-12j4-4z12-p48k","packageName":"getgrav\/grav","remoteId":"GHSA-6qw9-4vv5-jr97","title":"Grav: Stored XSS via Markdown audio\/video media \u003Csource\u003E URL","link":"https:\/\/github.com\/advisories\/GHSA-6qw9-4vv5-jr97","cve":"CVE-2026-75831","affectedVersions":"\u003C=2.0.14","source":"GitHub","reportedAt":"2026-09-17 17:31:41","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6qw9-4vv5-jr97"}]},{"advisoryId":"PKSA-rstv-2c4g-sjjn","packageName":"getgrav\/grav","remoteId":"GHSA-269c-h76q-8cxw","title":"Grav: Stored XSS via quoted-attribute bypass in detectXss","link":"https:\/\/github.com\/advisories\/GHSA-269c-h76q-8cxw","cve":"CVE-2026-72832","affectedVersions":"\u003E=1.5.2,\u003C=2.0.12","source":"GitHub","reportedAt":"2026-09-17 17:28:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-269c-h76q-8cxw"}]},{"advisoryId":"PKSA-7hs4-c5nt-m1jh","packageName":"getgrav\/grav","remoteId":"GHSA-c4wf-2xxc-68qm","title":"Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation","link":"https:\/\/github.com\/advisories\/GHSA-c4wf-2xxc-68qm","cve":"CVE-2026-65608","affectedVersions":"\u003E=1.7.0,\u003C2.0.9","source":"GitHub","reportedAt":"2026-09-17 17:15:33","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c4wf-2xxc-68qm"}]},{"advisoryId":"PKSA-pr7b-2t3z-v8y8","packageName":"getgrav\/grav","remoteId":"GHSA-7pgq-cr25-xvc8","title":"Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure","link":"https:\/\/github.com\/advisories\/GHSA-7pgq-cr25-xvc8","cve":"CVE-2026-69088","affectedVersions":"\u003E=2.0.7,\u003C=2.0.10","source":"GitHub","reportedAt":"2026-09-17 17:16:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7pgq-cr25-xvc8"}]},{"advisoryId":"PKSA-89qq-5khy-n4c4","packageName":"getgrav\/grav","remoteId":"GHSA-w3f4-8pj2-599w","title":"Grav: Path Traversal in ImageMedium::watermark() \u2014 arbitrary file disclosure via publicly-cached images","link":"https:\/\/github.com\/advisories\/GHSA-w3f4-8pj2-599w","cve":"CVE-2026-69089","affectedVersions":"=2.0.10","source":"GitHub","reportedAt":"2026-09-17 17:16:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w3f4-8pj2-599w"}]},{"advisoryId":"PKSA-wwkm-grbv-93ck","packageName":"getgrav\/grav","remoteId":"GHSA-37f3-6p89-6qr9","title":"Grav: Authenticated ReDoS via regex_replace in Twig Sandbox","link":"https:\/\/github.com\/advisories\/GHSA-37f3-6p89-6qr9","cve":"CVE-2026-62672","affectedVersions":"\u003C2.0.4","source":"GitHub","reportedAt":"2026-09-02 14:50:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-37f3-6p89-6qr9"}]},{"advisoryId":"PKSA-yvdd-fpv6-9ncp","packageName":"getgrav\/grav","remoteId":"GHSA-8h9x-89f2-m7x3","title":"Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver\/Installer","link":"https:\/\/github.com\/advisories\/GHSA-8h9x-89f2-m7x3","cve":"CVE-2026-61449","affectedVersions":"=2.0.1","source":"GitHub","reportedAt":"2026-09-17 14:53:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8h9x-89f2-m7x3"}]},{"advisoryId":"PKSA-4j1y-b223-8d57","packageName":"getgrav\/grav","remoteId":"GHSA-2vcx-h8p2-9pg9","title":"Grav CMS \u2014 Improper Handling of Highly Compressed Data in Installer::unZip()","link":"https:\/\/github.com\/advisories\/GHSA-2vcx-h8p2-9pg9","cve":"CVE-2026-59193","affectedVersions":"\u003E=1.0.0,\u003C2.0.0","source":"GitHub","reportedAt":"2026-09-16 22:12:10","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2vcx-h8p2-9pg9"}]},{"advisoryId":"PKSA-y2jw-px84-6zx6","packageName":"getgrav\/grav","remoteId":"GHSA-2c4f-86xc-cr74","title":"Grav: XSS Blueprint Validation Bypass via Twig String Concatenation","link":"https:\/\/github.com\/advisories\/GHSA-2c4f-86xc-cr74","cve":"CVE-2026-61453","affectedVersions":"=2.0.0","source":"GitHub","reportedAt":"2026-09-16 22:13:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2c4f-86xc-cr74"}]},{"advisoryId":"PKSA-fkd8-syrt-878t","packageName":"getgrav\/grav","remoteId":"GHSA-ffmg-hfvg-jhg9","title":"Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav","link":"https:\/\/github.com\/advisories\/GHSA-ffmg-hfvg-jhg9","cve":"CVE-2026-58657","affectedVersions":"=2.0.0-rc.9","source":"GitHub","reportedAt":"2026-09-16 22:14:53","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-ffmg-hfvg-jhg9"}]}],"chamilo\/chamilo-lms":[{"advisoryId":"PKSA-m8ms-hgzz-8ddw","packageName":"chamilo\/chamilo-lms","remoteId":"GHSA-g4c3-4g96-6g4m","title":"Chamilo LMS CStudio upload flow allows unauthenticated remote code execution","link":"https:\/\/github.com\/advisories\/GHSA-g4c3-4g96-6g4m","cve":"CVE-2026-45140","affectedVersions":"\u003C=2.0.0","source":"GitHub","reportedAt":"2026-09-17 20:23:39","composerRepository":null,"severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-g4c3-4g96-6g4m"}]}],"cakephp\/database":[{"advisoryId":"PKSA-ny8z-1rqf-8z42","packageName":"cakephp\/database","remoteId":"GHSA-vjqc-q4mp-2rvf","title":"CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection","link":"https:\/\/github.com\/advisories\/GHSA-vjqc-q4mp-2rvf","cve":"CVE-2026-79752","affectedVersions":"\u003E=5.3.0,\u003C5.3.7|\u003E=5.2.0,\u003C5.2.14|\u003E=5.0.0,\u003C5.1.9|\u003E=4.6.0,\u003C4.6.5|\u003C4.5.12","source":"GitHub","reportedAt":"2026-09-17 20:28:14","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-vjqc-q4mp-2rvf"}]}],"cakephp\/cakephp":[{"advisoryId":"PKSA-vxgj-bmcq-9b6x","packageName":"cakephp\/cakephp","remoteId":"GHSA-vjqc-q4mp-2rvf","title":"CakePHP: Multiple methods in FunctionsBuilder vulnerable to SQL injection","link":"https:\/\/github.com\/advisories\/GHSA-vjqc-q4mp-2rvf","cve":"CVE-2026-79752","affectedVersions":"\u003E=5.3.0,\u003C5.3.7|\u003E=5.2.0,\u003C5.2.14|\u003E=5.0.0,\u003C5.1.9|\u003E=4.6.0,\u003C4.6.5|\u003C4.5.12","source":"GitHub","reportedAt":"2026-09-17 20:28:14","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-vjqc-q4mp-2rvf"}]}],"october\/october":[{"advisoryId":"PKSA-dqgv-qnp4-9j5k","packageName":"october\/october","remoteId":"GHSA-2xmm-m4wv-3fjh","title":"October CMS: Incomplete Scheme Validation in Image Resizer","link":"https:\/\/github.com\/advisories\/GHSA-2xmm-m4wv-3fjh","cve":null,"affectedVersions":"\u003E=4.3.0,\u003C4.3.4","source":"GitHub","reportedAt":"2026-09-14 17:15:44","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-2xmm-m4wv-3fjh"}]}],"october\/system":[{"advisoryId":"PKSA-syjw-hb9p-2d5m","packageName":"october\/system","remoteId":"GHSA-2ff2-mx52-q8wp","title":"October CMS: PHP Object Injection via Backend Widget Session Storage","link":"https:\/\/github.com\/advisories\/GHSA-2ff2-mx52-q8wp","cve":"CVE-2026-49400","affectedVersions":"\u003E=4.0.0,\u003C4.2.23|\u003C3.7.17","source":"GitHub","reportedAt":"2026-09-14 17:08:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-2ff2-mx52-q8wp"}]},{"advisoryId":"PKSA-m19v-7rfv-5pmv","packageName":"october\/system","remoteId":"GHSA-xv9m-fm3w-8w5x","title":"October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls","link":"https:\/\/github.com\/advisories\/GHSA-xv9m-fm3w-8w5x","cve":"CVE-2026-46696","affectedVersions":"\u003E=4.0.0,\u003C4.2.23|\u003C3.7.17","source":"GitHub","reportedAt":"2026-09-14 16:02:35","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xv9m-fm3w-8w5x"}]}],"react\/http":[{"advisoryId":"PKSA-7xc4-r5ry-fg9s","packageName":"react\/http","remoteId":"react\/http\/CVE-2026-84997.yaml","title":"A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU","link":"https:\/\/github.com\/reactphp\/http\/security\/advisories\/GHSA-x424-64qh-5j54","cve":"CVE-2026-84997","affectedVersions":"\u003E=0.6.0,\u003C1.11.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-09-09 09:11:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-x424-64qh-5j54"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"react\/http\/CVE-2026-84997.yaml"}]}]}}