{"advisories":{"phpoffice\/phpspreadsheet":[{"advisoryId":"PKSA-m9cr-9614-rsf7","packageName":"phpoffice\/phpspreadsheet","remoteId":"GHSA-2mrg-gjxq-2gvr","title":"PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion","link":"https:\/\/github.com\/advisories\/GHSA-2mrg-gjxq-2gvr","cve":"CVE-2026-59932","affectedVersions":"\u003C=1.30.5|\u003E=2.0.0,\u003C=2.1.17|\u003E=2.2.0,\u003C=2.4.6|\u003E=3.3.0,\u003C=3.10.6|\u003E=4.0.0,\u003C=5.8.0","source":"GitHub","reportedAt":"2026-07-23 15:00:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2mrg-gjxq-2gvr"}]},{"advisoryId":"PKSA-r22k-87hv-mfk4","packageName":"phpoffice\/phpspreadsheet","remoteId":"GHSA-xh5m-36r6-47m3","title":"PHPSpreadsheet: XLS\/OLE sector-chain self-loop causes memory exhaustion","link":"https:\/\/github.com\/advisories\/GHSA-xh5m-36r6-47m3","cve":"CVE-2026-59933","affectedVersions":"\u003C=1.30.5|\u003E=2.0.0,\u003C=2.1.17|\u003E=2.2.0,\u003C=2.4.6|\u003E=3.3.0,\u003C=3.10.6|\u003E=4.0.0,\u003C=5.8.0","source":"GitHub","reportedAt":"2026-07-23 15:01:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xh5m-36r6-47m3"}]},{"advisoryId":"PKSA-dqzt-yst9-1w9y","packageName":"phpoffice\/phpspreadsheet","remoteId":"GHSA-6hq5-7373-42rg","title":"PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist","link":"https:\/\/github.com\/advisories\/GHSA-6hq5-7373-42rg","cve":"CVE-2026-59931","affectedVersions":"\u003C=1.30.5|\u003E=2.0.0,\u003C=2.1.17|\u003E=2.2.0,\u003C=2.4.6|\u003E=3.3.0,\u003C=3.10.6|\u003E=4.0.0,\u003C=5.8.0","source":"GitHub","reportedAt":"2026-07-23 14:55:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6hq5-7373-42rg"}]}],"dompdf\/dompdf":[{"advisoryId":"PKSA-gh7h-hhy4-byg7","packageName":"dompdf\/dompdf","remoteId":"GHSA-8hg6-c449-896m","title":"Dompdf: Uncontrolled resource consumption based on declared BMP dimensions","link":"https:\/\/github.com\/advisories\/GHSA-8hg6-c449-896m","cve":"CVE-2026-59941","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 22:50:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8hg6-c449-896m"}]},{"advisoryId":"PKSA-6r8f-nxsb-67bq","packageName":"dompdf\/dompdf","remoteId":"GHSA-f5gf-2cj8-52g2","title":"Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps","link":"https:\/\/github.com\/advisories\/GHSA-f5gf-2cj8-52g2","cve":"CVE-2026-59942","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 22:51:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f5gf-2cj8-52g2"}]},{"advisoryId":"PKSA-cv56-2228-pzr6","packageName":"dompdf\/dompdf","remoteId":"GHSA-j8qw-6jw8-r297","title":"Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem","link":"https:\/\/github.com\/advisories\/GHSA-j8qw-6jw8-r297","cve":"CVE-2026-59943","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 22:52:44","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j8qw-6jw8-r297"}]},{"advisoryId":"PKSA-mwt3-h9tv-kx78","packageName":"dompdf\/dompdf","remoteId":"GHSA-cx96-42px-69fm","title":"Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI","link":"https:\/\/github.com\/advisories\/GHSA-cx96-42px-69fm","cve":"CVE-2026-56722","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 21:30:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cx96-42px-69fm"}]},{"advisoryId":"PKSA-mckv-s5hg-868k","packageName":"dompdf\/dompdf","remoteId":"GHSA-wvh6-f5jh-8gw4","title":"Dompdf: Chroot Validation Bypass","link":"https:\/\/github.com\/advisories\/GHSA-wvh6-f5jh-8gw4","cve":"CVE-2026-55554","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 21:06:48","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-wvh6-f5jh-8gw4"}]},{"advisoryId":"PKSA-hp6n-n4kz-21wk","packageName":"dompdf\/dompdf","remoteId":"GHSA-7x2p-4jvh-6384","title":"Dompdf: File existence oracle via font-face stylesheet declaration","link":"https:\/\/github.com\/advisories\/GHSA-7x2p-4jvh-6384","cve":"CVE-2026-55555","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 21:07:07","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7x2p-4jvh-6384"}]}],"guzzlehttp\/psr7":[{"advisoryId":"PKSA-vznr-tgp9-fd7d","packageName":"guzzlehttp\/psr7","remoteId":"GHSA-c2w2-prh8-qm98","title":"guzzlehttp\/psr7: Host Confusion via Weak URI Host Validation","link":"https:\/\/github.com\/advisories\/GHSA-c2w2-prh8-qm98","cve":"CVE-2026-59882","affectedVersions":"\u003C2.12.3","source":"GitHub","reportedAt":"2026-07-21 18:35:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c2w2-prh8-qm98"}]}],"guzzlehttp\/guzzle":[{"advisoryId":"PKSA-bbs6-q5q9-f3t4","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-f283-ghqc-fg79","title":"Guzzle: Unbounded response cookies risk denial of service","link":"https:\/\/github.com\/advisories\/GHSA-f283-ghqc-fg79","cve":null,"affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:27:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f283-ghqc-fg79"}]},{"advisoryId":"PKSA-qxvb-2bpp-dnk6","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-wm3w-8rrp-j577","title":"Guzzle: Host-only cookie scope is not preserved","link":"https:\/\/github.com\/advisories\/GHSA-wm3w-8rrp-j577","cve":null,"affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:27:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wm3w-8rrp-j577"}]},{"advisoryId":"PKSA-fy2t-3c5f-827y","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-h95v-h523-3mw8","title":"Guzzle: URI fragments disclosed in redirect Referer headers","link":"https:\/\/github.com\/advisories\/GHSA-h95v-h523-3mw8","cve":null,"affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:28:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h95v-h523-3mw8"}]},{"advisoryId":"PKSA-bcdd-5xc7-gwfb","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-g446-98w2-8p5w","title":"Guzzle: Cookie Disclosure and Injection via IP-Address Domains","link":"https:\/\/github.com\/advisories\/GHSA-g446-98w2-8p5w","cve":"CVE-2026-59883","affectedVersions":"\u003C7.12.3","source":"GitHub","reportedAt":"2026-07-20 22:00:09","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g446-98w2-8p5w"}]},{"advisoryId":"PKSA-pwsk-hy21-4gby","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-94pj-82f3-465w","title":"Guzzle: Proxy-Authorization headers can be sent to origin servers","link":"https:\/\/github.com\/advisories\/GHSA-94pj-82f3-465w","cve":null,"affectedVersions":"\u003C7.14.2","source":"GitHub","reportedAt":"2026-07-20 21:46:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-94pj-82f3-465w"}]}],"composer\/composer":[{"advisoryId":"PKSA-4pm6-g63v-5rkr","packageName":"composer\/composer","remoteId":"GHSA-g6xq-892h-64w3","title":"Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)","link":"https:\/\/github.com\/advisories\/GHSA-g6xq-892h-64w3","cve":"CVE-2026-59947","affectedVersions":"\u003E=1.0.0,\u003C2.2.29|\u003E=2.3.0,\u003C2.10.2","source":"GitHub","reportedAt":"2026-07-20 21:55:05","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g6xq-892h-64w3"}]},{"advisoryId":"PKSA-q3ht-3g42-rg8f","packageName":"composer\/composer","remoteId":"GHSA-gjfg-22fp-rrxx","title":"Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files","link":"https:\/\/github.com\/advisories\/GHSA-gjfg-22fp-rrxx","cve":"CVE-2026-59946","affectedVersions":"\u003E=1.0.0,\u003C2.2.29|\u003E=2.3.0,\u003C2.10.2","source":"GitHub","reportedAt":"2026-07-20 21:57:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gjfg-22fp-rrxx"}]},{"advisoryId":"PKSA-zcdk-qnhk-hq2g","packageName":"composer\/composer","remoteId":"GHSA-499r-g7pc-vmp9","title":"Composer: Arbitrary file write outside vendor via malicious transitive package name","link":"https:\/\/github.com\/advisories\/GHSA-499r-g7pc-vmp9","cve":"CVE-2026-59948","affectedVersions":"\u003E=1.0.0,\u003C2.2.29|\u003E=2.3.0,\u003C2.10.2","source":"GitHub","reportedAt":"2026-07-20 19:15:29","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-499r-g7pc-vmp9"}]}],"verbb\/formie":[{"advisoryId":"PKSA-xm2v-2qmq-bmd3","packageName":"verbb\/formie","remoteId":"GHSA-cvpc-hccg-wmw4","title":"Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration","link":"https:\/\/github.com\/advisories\/GHSA-cvpc-hccg-wmw4","cve":null,"affectedVersions":"\u003C3.1.28","source":"GitHub","reportedAt":"2026-07-17 19:05:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cvpc-hccg-wmw4"}]}],"pheditor\/pheditor":[{"advisoryId":"PKSA-c2s6-j4sd-8g42","packageName":"pheditor\/pheditor","remoteId":"GHSA-wg4w-wr5q-6vjc","title":"Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection","link":"https:\/\/github.com\/advisories\/GHSA-wg4w-wr5q-6vjc","cve":"CVE-2026-55578","affectedVersions":"\u003E=2.0.1,\u003C2.0.6","source":"GitHub","reportedAt":"2026-07-16 20:10:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wg4w-wr5q-6vjc"}]},{"advisoryId":"PKSA-fw3p-jbcz-gm98","packageName":"pheditor\/pheditor","remoteId":"GHSA-p4h7-p9rj-2pq2","title":"Pheditor: Hardcoded default password \u0027admin\u0027 with no forced change enables full application compromise","link":"https:\/\/github.com\/advisories\/GHSA-p4h7-p9rj-2pq2","cve":"CVE-2026-55579","affectedVersions":"\u003E=2.0.1,\u003C2.0.6","source":"GitHub","reportedAt":"2026-07-16 20:11:23","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-p4h7-p9rj-2pq2"}]},{"advisoryId":"PKSA-35mf-8p9f-f31c","packageName":"pheditor\/pheditor","remoteId":"GHSA-9643-6xjp-vx57","title":"Pheditor has an authenticated terminal command whitelist bypass","link":"https:\/\/github.com\/advisories\/GHSA-9643-6xjp-vx57","cve":"CVE-2026-54540","affectedVersions":"\u003C=2.0.4","source":"GitHub","reportedAt":"2026-07-16 20:01:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9643-6xjp-vx57"}]}],"typo3\/cms-fluid":[{"advisoryId":"PKSA-gq2f-sdxt-2mmr","packageName":"typo3\/cms-fluid","remoteId":"GHSA-22q7-cg4r-p9mx","title":"TYPO3 Cross-Site Scripting in Fluid ViewHelpers","link":"https:\/\/github.com\/advisories\/GHSA-22q7-cg4r-p9mx","cve":null,"affectedVersions":"\u003E=9.0.0,\u003C9.5.4|\u003E=8.0.0,\u003C8.7.23","source":"GitHub","reportedAt":"2024-05-30 15:46:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-22q7-cg4r-p9mx"}]}],"adawolfa\/isdoc":[{"advisoryId":"PKSA-zwm1-4dcx-xx1p","packageName":"adawolfa\/isdoc","remoteId":"GHSA-xg43-5579-qw6v","title":"adawolfa\/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files","link":"https:\/\/github.com\/advisories\/GHSA-xg43-5579-qw6v","cve":null,"affectedVersions":"\u003C1.4.0|\u003E=1.4.0,\u003C1.4.3|\u003E=1.5.0,\u003C1.5.1|\u003E=1.6.0,\u003C1.6.1","source":"GitHub","reportedAt":"2026-07-15 23:30:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xg43-5579-qw6v"}]}],"mantisbt\/mantisbt":[{"advisoryId":"PKSA-xw73-w41z-8sfx","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-4vpf-w7qv-5h3q","title":"MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs","link":"https:\/\/github.com\/advisories\/GHSA-4vpf-w7qv-5h3q","cve":"CVE-2026-52883","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 18:52:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4vpf-w7qv-5h3q"}]},{"advisoryId":"PKSA-vymf-gj2q-2bk6","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-h2wf-967x-gxvw","title":"MantisBT: Stored XSS in print_all_bug_page_word.php","link":"https:\/\/github.com\/advisories\/GHSA-h2wf-967x-gxvw","cve":"CVE-2026-62944","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 18:56:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h2wf-967x-gxvw"}]},{"advisoryId":"PKSA-2zcr-93ry-6511","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-3v2j-6fw9-f57c","title":"MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters","link":"https:\/\/github.com\/advisories\/GHSA-3v2j-6fw9-f57c","cve":"CVE-2026-52882","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 18:41:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3v2j-6fw9-f57c"}]},{"advisoryId":"PKSA-23vf-p9ny-hdcn","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-vcrw-4xvv-jh49","title":"MantisBT: Reflected XSS in admin\/install.php via unescaped printf ","link":"https:\/\/github.com\/advisories\/GHSA-vcrw-4xvv-jh49","cve":"CVE-2026-52881","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 18:34:36","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-vcrw-4xvv-jh49"}]},{"advisoryId":"PKSA-cgcp-ngm1-hmmf","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-77x8-3v3h-hrhv","title":"MantisBT: Reflected XSS in admin\/install.php","link":"https:\/\/github.com\/advisories\/GHSA-77x8-3v3h-hrhv","cve":"CVE-2026-52847","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 18:25:36","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-77x8-3v3h-hrhv"}]},{"advisoryId":"PKSA-6qcn-z5zm-cd63","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-m7ph-9558-mrx3","title":"MantisBT: REST API unauthorized Issue status change","link":"https:\/\/github.com\/advisories\/GHSA-m7ph-9558-mrx3","cve":"CVE-2026-49280","affectedVersions":"\u003E=2.8.0,\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 17:02:12","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m7ph-9558-mrx3"}]},{"advisoryId":"PKSA-5jjt-2py9-5v67","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-v84x-qvhg-f36r","title":"MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php","link":"https:\/\/github.com\/advisories\/GHSA-v84x-qvhg-f36r","cve":"CVE-2026-49273","affectedVersions":"\u003E=1.3.0,\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 16:52:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v84x-qvhg-f36r"}]},{"advisoryId":"PKSA-vcbb-b851-hxr5","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-c2xg-qjqw-2v98","title":"MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator","link":"https:\/\/github.com\/advisories\/GHSA-c2xg-qjqw-2v98","cve":"CVE-2026-47156","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 16:45:22","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-c2xg-qjqw-2v98"}]},{"advisoryId":"PKSA-3d2f-71dg-17ys","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-mw6p-33vw-46cc","title":"MantisBT: SQL Injection via history_order Configuration Value","link":"https:\/\/github.com\/advisories\/GHSA-mw6p-33vw-46cc","cve":"CVE-2026-47142","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 16:38:22","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mw6p-33vw-46cc"}]}],"phanan\/koel":[{"advisoryId":"PKSA-69y7-vwnx-px15","packageName":"phanan\/koel","remoteId":"GHSA-jr4p-4xjh-fwvw","title":"Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail","link":"https:\/\/github.com\/advisories\/GHSA-jr4p-4xjh-fwvw","cve":"CVE-2026-50552","affectedVersions":"\u003C=9.7.0","source":"GitHub","reportedAt":"2026-07-15 18:21:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jr4p-4xjh-fwvw"}]},{"advisoryId":"PKSA-nwpt-px6q-b5bv","packageName":"phanan\/koel","remoteId":"GHSA-rjg7-r26h-cfp2","title":"Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::\/96) or 6to4 (2002::\/16) IPv6-transition wrappers of internal IPv4","link":"https:\/\/github.com\/advisories\/GHSA-rjg7-r26h-cfp2","cve":"CVE-2026-54494","affectedVersions":"\u003C=9.7.0","source":"GitHub","reportedAt":"2026-07-15 18:21:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rjg7-r26h-cfp2"}]},{"advisoryId":"PKSA-1qtf-pcfh-kb47","packageName":"phanan\/koel","remoteId":"GHSA-6qvr-wjmv-v8mm","title":"Koel: Incomplete fix for CVE-2026-47260 \u2014 systemic SSRF in podcast \u0026 radio fetch paths","link":"https:\/\/github.com\/advisories\/GHSA-6qvr-wjmv-v8mm","cve":"CVE-2026-54491","affectedVersions":"\u003C=9.7.0","source":"GitHub","reportedAt":"2026-07-15 17:59:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6qvr-wjmv-v8mm"}]},{"advisoryId":"PKSA-74sr-w83z-r28d","packageName":"phanan\/koel","remoteId":"GHSA-8q6q-m837-fv64","title":" Koel has SSRF through Authenticated Subsonic podcast feed URLs","link":"https:\/\/github.com\/advisories\/GHSA-8q6q-m837-fv64","cve":null,"affectedVersions":"\u003C=9.6.0","source":"GitHub","reportedAt":"2026-07-15 17:31:12","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8q6q-m837-fv64"}]},{"advisoryId":"PKSA-gv41-hnht-9yhw","packageName":"phanan\/koel","remoteId":"GHSA-6p96-cfg5-4vhp","title":"Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations","link":"https:\/\/github.com\/advisories\/GHSA-6p96-cfg5-4vhp","cve":"CVE-2026-54493","affectedVersions":"\u003C=9.6.0","source":"GitHub","reportedAt":"2026-07-15 17:13:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6p96-cfg5-4vhp"}]},{"advisoryId":"PKSA-drvx-ht86-w4b7","packageName":"phanan\/koel","remoteId":"GHSA-w79m-f3jx-779v","title":"Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation","link":"https:\/\/github.com\/advisories\/GHSA-w79m-f3jx-779v","cve":"CVE-2026-54492","affectedVersions":"\u003C=9.6.0","source":"GitHub","reportedAt":"2026-07-15 17:07:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w79m-f3jx-779v"}]}],"typo3\/cms-form":[{"advisoryId":"PKSA-d4vj-m6hn-xm1j","packageName":"typo3\/cms-form","remoteId":"typo3\/cms-form\/CVE-2026-15305.yaml","title":"TYPO3-CORE-SA-2026-020: TYPO3 CMS - Unrestricted File Upload in Form Framework","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-core-sa-2026-020","cve":"CVE-2026-15305","affectedVersions":"\u003E=14.2.0,\u003C14.3.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-14 12:08:47","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-form\/CVE-2026-15305.yaml"}]}],"facturascripts\/facturascripts":[{"advisoryId":"PKSA-ckhc-1b7w-fbqb","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-hgjx-r89m-m7v4","title":"FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() \u2014 arbitrary file write outside MyFiles\/ leading to   RCE","link":"https:\/\/github.com\/advisories\/GHSA-hgjx-r89m-m7v4","cve":null,"affectedVersions":"\u003E=2025,\u003C=2026.2","source":"GitHub","reportedAt":"2026-07-14 20:52:00","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-hgjx-r89m-m7v4"}]},{"advisoryId":"PKSA-tj9x-5rgg-xzgk","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-3x7p-v8hj-xh5m","title":"FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`","link":"https:\/\/github.com\/advisories\/GHSA-3x7p-v8hj-xh5m","cve":"CVE-2026-45710","affectedVersions":"\u003C=2026.1","source":"GitHub","reportedAt":"2026-07-14 17:30:26","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-3x7p-v8hj-xh5m"}]},{"advisoryId":"PKSA-582m-pjr9-1vy2","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-5qmh-x653-g8qj","title":"FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`","link":"https:\/\/github.com\/advisories\/GHSA-5qmh-x653-g8qj","cve":"CVE-2026-45262","affectedVersions":"\u003C=2026.1","source":"GitHub","reportedAt":"2026-07-14 17:11:06","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-5qmh-x653-g8qj"}]},{"advisoryId":"PKSA-cphp-d9mj-j5ny","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-cv65-7cg8-r623","title":"FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents","link":"https:\/\/github.com\/advisories\/GHSA-cv65-7cg8-r623","cve":"CVE-2026-45693","affectedVersions":"\u003C=2026.2","source":"GitHub","reportedAt":"2026-07-14 17:12:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-cv65-7cg8-r623"}]},{"advisoryId":"PKSA-9nsq-164p-6ppm","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-2p5x-4jr6-x5jg","title":"FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export","link":"https:\/\/github.com\/advisories\/GHSA-2p5x-4jr6-x5jg","cve":"CVE-2026-45263","affectedVersions":"\u003C=2026.1","source":"GitHub","reportedAt":"2026-07-14 17:18:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2p5x-4jr6-x5jg"}]},{"advisoryId":"PKSA-dn8k-128k-8cz7","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-c67f-gmxw-mj93","title":"FacturaScripts: Account takeover of any 2FA-enabled user","link":"https:\/\/github.com\/advisories\/GHSA-c67f-gmxw-mj93","cve":"CVE-2026-47677","affectedVersions":"\u003C=2026.2","source":"GitHub","reportedAt":"2026-07-13 23:35:48","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-c67f-gmxw-mj93"}]}],"auth0\/symfony":[{"advisoryId":"PKSA-nrzm-zxwz-yhq9","packageName":"auth0\/symfony","remoteId":"GHSA-ffq7-hh2j-r24p","title":"Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter","link":"https:\/\/github.com\/advisories\/GHSA-ffq7-hh2j-r24p","cve":"CVE-2026-50157","affectedVersions":"\u003E=5.0.0-BETA0,\u003C=5.8.0","source":"GitHub","reportedAt":"2026-07-14 19:31:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-ffq7-hh2j-r24p"}]}],"concrete5\/concrete5":[{"advisoryId":"PKSA-93vh-t1hn-q1kn","packageName":"concrete5\/concrete5","remoteId":"GHSA-52pr-7vmf-2w7x","title":"Concrete CMS is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File\/Set components","link":"https:\/\/github.com\/advisories\/GHSA-52pr-7vmf-2w7x","cve":"CVE-2026-7888","affectedVersions":"\u003C9.5.2","source":"GitHub","reportedAt":"2026-06-03 21:30:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-52pr-7vmf-2w7x"}]}],"contao\/contao":[{"advisoryId":"PKSA-55tn-sgd6-9twh","packageName":"contao\/contao","remoteId":"contao\/contao\/CVE-2026-57232.yaml","title":"Server-side request forgery (SSRF) via unvalidated RSS feed URLs","link":"https:\/\/contao.org\/en\/security-advisories\/server-side-request-forgery-via-unvalidated-rss-feed-urls","cve":"CVE-2026-57232","affectedVersions":"\u003E=5.3.35,\u003C5.3.48|\u003E=5.4.0,\u003C5.7.9","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-13 09:10:22","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/CVE-2026-57232.yaml"}]},{"advisoryId":"PKSA-8pr1-zw9p-tzyx","packageName":"contao\/contao","remoteId":"contao\/contao\/CVE-2026-55824.yaml","title":"Credentials disclosure in the crawler","link":"https:\/\/contao.org\/en\/security-advisories\/credentials-disclosure-in-the-crawler","cve":"CVE-2026-55824","affectedVersions":"\u003E=4.13.0,\u003C5.3.47|\u003E=5.4.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/CVE-2026-55824.yaml"}]},{"advisoryId":"PKSA-311q-qrt9-s2k4","packageName":"contao\/contao","remoteId":"contao\/contao\/CVE-2026-55825.yaml","title":"Path traversal in the jobs module","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-jobs-module","cve":"CVE-2026-55825","affectedVersions":"\u003E=5.7.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/CVE-2026-55825.yaml"}]}],"contao\/core-bundle":[{"advisoryId":"PKSA-yx24-z15d-x2k7","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/CVE-2026-57232.yaml","title":"Server-side request forgery (SSRF) via unvalidated RSS feed URLs","link":"https:\/\/contao.org\/en\/security-advisories\/server-side-request-forgery-via-unvalidated-rss-feed-urls","cve":"CVE-2026-57232","affectedVersions":"\u003E=5.3.35,\u003C5.3.48|\u003E=5.4.0,\u003C5.7.9","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-13 09:10:22","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/CVE-2026-57232.yaml"}]},{"advisoryId":"PKSA-f8tt-pn3h-s2tw","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/CVE-2026-55824.yaml","title":"Credentials disclosure in the crawler","link":"https:\/\/contao.org\/en\/security-advisories\/credentials-disclosure-in-the-crawler","cve":"CVE-2026-55824","affectedVersions":"\u003E=4.13.0,\u003C5.3.47|\u003E=5.4.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/CVE-2026-55824.yaml"}]},{"advisoryId":"PKSA-4ps2-832y-6pns","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/CVE-2026-55825.yaml","title":"Path traversal in the jobs module","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-jobs-module","cve":"CVE-2026-55825","affectedVersions":"\u003E=5.7.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/CVE-2026-55825.yaml"}]}],"kimai\/kimai":[{"advisoryId":"PKSA-kznk-ncz5-wyws","packageName":"kimai\/kimai","remoteId":"GHSA-v8hx-4vx8-wc96","title":"Kimai: Pre-2FA KIMAI_SESSION\u00a0cookie grants full authenticated REST API access, bypassing TOTP","link":"https:\/\/github.com\/advisories\/GHSA-v8hx-4vx8-wc96","cve":"CVE-2026-52827","affectedVersions":"\u003C2.59.0","source":"GitHub","reportedAt":"2026-07-14 00:33:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v8hx-4vx8-wc96"}]},{"advisoryId":"PKSA-2sk3-y15b-6c7y","packageName":"kimai\/kimai","remoteId":"GHSA-rw46-qg69-vg6h","title":"Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access","link":"https:\/\/github.com\/advisories\/GHSA-rw46-qg69-vg6h","cve":"CVE-2026-52828","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-14 00:34:03","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rw46-qg69-vg6h"}]},{"advisoryId":"PKSA-r2bg-9v9s-cjfy","packageName":"kimai\/kimai","remoteId":"GHSA-3q6q-26vg-v97x","title":"Kimai: Improper Authorization Through Activity Creation with Preset Project Allows Creation Under Unauthorized Projects","link":"https:\/\/github.com\/advisories\/GHSA-3q6q-26vg-v97x","cve":"CVE-2026-52821","affectedVersions":"\u003C=2.56.0","source":"GitHub","reportedAt":"2026-07-14 00:03:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3q6q-26vg-v97x"}]},{"advisoryId":"PKSA-8c2d-bzrd-yygj","packageName":"kimai\/kimai","remoteId":"GHSA-c6w6-57jj-62vh","title":"Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access Revocation","link":"https:\/\/github.com\/advisories\/GHSA-c6w6-57jj-62vh","cve":"CVE-2026-52822","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-14 00:04:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c6w6-57jj-62vh"}]},{"advisoryId":"PKSA-st54-1y6x-76ks","packageName":"kimai\/kimai","remoteId":"GHSA-r8vr-m544-qh4h","title":"Kimai: Login CSRF in the Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes","link":"https:\/\/github.com\/advisories\/GHSA-r8vr-m544-qh4h","cve":"CVE-2026-52823","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-14 00:05:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r8vr-m544-qh4h"}]},{"advisoryId":"PKSA-rg27-2yxz-ng1q","packageName":"kimai\/kimai","remoteId":"GHSA-jr9p-4h4j-6c58","title":"Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover","link":"https:\/\/github.com\/advisories\/GHSA-jr9p-4h4j-6c58","cve":"CVE-2026-52824","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-14 00:07:59","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-jr9p-4h4j-6c58"}]},{"advisoryId":"PKSA-v6y1-r12h-qsx3","packageName":"kimai\/kimai","remoteId":"GHSA-xv4r-4885-gwpg","title":"Kimai has Improper Authorization in Team Member and Team Activity Assignment APIs Which Allows Expansion of Team Scope Beyond Authorized Visibility","link":"https:\/\/github.com\/advisories\/GHSA-xv4r-4885-gwpg","cve":"CVE-2026-52825","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-14 00:09:03","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xv4r-4885-gwpg"}]},{"advisoryId":"PKSA-zsy3-64rr-9k1n","packageName":"kimai\/kimai","remoteId":"GHSA-2xgg-2x8h-8xw4","title":"Kimai: Improper Authorization in Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate Manipulation","link":"https:\/\/github.com\/advisories\/GHSA-2xgg-2x8h-8xw4","cve":"CVE-2026-52826","affectedVersions":"\u003C=2.56.0","source":"GitHub","reportedAt":"2026-07-14 00:09:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2xgg-2x8h-8xw4"}]},{"advisoryId":"PKSA-35k6-pfzb-3chy","packageName":"kimai\/kimai","remoteId":"GHSA-pgcc-vfmc-7cw5","title":" Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes","link":"https:\/\/github.com\/advisories\/GHSA-pgcc-vfmc-7cw5","cve":"CVE-2026-49992","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-13 23:55:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pgcc-vfmc-7cw5"}]},{"advisoryId":"PKSA-mhmq-vzyg-sjjv","packageName":"kimai\/kimai","remoteId":"GHSA-4m8q-55qv-9pwp","title":"Kimai: Teamlead authorization bypass in GET \/api\/timesheets allows reading other users\u0027 timesheet records without being teamlead of the target","link":"https:\/\/github.com\/advisories\/GHSA-4m8q-55qv-9pwp","cve":"CVE-2026-52819","affectedVersions":"\u003C=2.56.0","source":"GitHub","reportedAt":"2026-07-13 23:55:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4m8q-55qv-9pwp"}]},{"advisoryId":"PKSA-q7f8-m7q7-t9t8","packageName":"kimai\/kimai","remoteId":"GHSA-vrr2-g9gh-c3jc","title":"Kimai: Timesheet PATCH\/POST allows assigning to project outside user\u0027s team via query_builder OR-bypass","link":"https:\/\/github.com\/advisories\/GHSA-vrr2-g9gh-c3jc","cve":"CVE-2026-52820","affectedVersions":"\u003C=2.56.0","source":"GitHub","reportedAt":"2026-07-13 23:55:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vrr2-g9gh-c3jc"}]},{"advisoryId":"PKSA-j8yw-pd54-qb9k","packageName":"kimai\/kimai","remoteId":"GHSA-pj8j-p4g4-4vw8","title":"Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs","link":"https:\/\/github.com\/advisories\/GHSA-pj8j-p4g4-4vw8","cve":"CVE-2026-49865","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-10 16:04:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pj8j-p4g4-4vw8"}]}],"nukeviet\/nukeviet":[{"advisoryId":"PKSA-npyr-6yvm-53qx","packageName":"nukeviet\/nukeviet","remoteId":"GHSA-465g-4q99-5x86","title":"NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module","link":"https:\/\/github.com\/advisories\/GHSA-465g-4q99-5x86","cve":"CVE-2026-54064","affectedVersions":"\u003C4.6.00","source":"GitHub","reportedAt":"2026-07-13 17:54:08","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-465g-4q99-5x86"}]},{"advisoryId":"PKSA-dsc1-qrmn-vnq5","packageName":"nukeviet\/nukeviet","remoteId":"GHSA-c9xg-64p9-f2jj","title":"NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function","link":"https:\/\/github.com\/advisories\/GHSA-c9xg-64p9-f2jj","cve":"CVE-2026-54065","affectedVersions":"\u003C4.6.00","source":"GitHub","reportedAt":"2026-07-13 17:55:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c9xg-64p9-f2jj"}]},{"advisoryId":"PKSA-x92d-g786-69f4","packageName":"nukeviet\/nukeviet","remoteId":"GHSA-4chg-4752-w88r","title":"NukeViet: Pre-authentication SSRF via X-Forwarded-Host","link":"https:\/\/github.com\/advisories\/GHSA-4chg-4752-w88r","cve":"CVE-2026-55372","affectedVersions":"\u003C4.6.00","source":"GitHub","reportedAt":"2026-07-13 17:58:44","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4chg-4752-w88r"}]},{"advisoryId":"PKSA-zhpy-zkp7-5p69","packageName":"nukeviet\/nukeviet","remoteId":"GHSA-mxpf-qgg6-v3ff","title":"NukeViet: Unauthenticated Reflected XSS in Comment Module","link":"https:\/\/github.com\/advisories\/GHSA-mxpf-qgg6-v3ff","cve":"CVE-2026-48118","affectedVersions":"\u003C4.5.09","source":"GitHub","reportedAt":"2026-07-13 17:21:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mxpf-qgg6-v3ff"}]},{"advisoryId":"PKSA-qw3x-tkjj-83zs","packageName":"nukeviet\/nukeviet","remoteId":"GHSA-w2w5-w2pw-r929","title":"NukeViet: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)","link":"https:\/\/github.com\/advisories\/GHSA-w2w5-w2pw-r929","cve":"CVE-2026-49259","affectedVersions":"\u003C4.5.09","source":"GitHub","reportedAt":"2026-07-13 17:22:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w2w5-w2pw-r929"}]}],"prestashop\/ps_facetedsearch":[{"advisoryId":"PKSA-36b6-kgzr-fpm3","packageName":"prestashop\/ps_facetedsearch","remoteId":"GHSA-m5f5-28qr-9g9r","title":"prestashop\/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE","link":"https:\/\/github.com\/advisories\/GHSA-m5f5-28qr-9g9r","cve":"CVE-2026-54159","affectedVersions":"\u003E=3.0.0,\u003C4.0.4","source":"GitHub","reportedAt":"2026-07-10 20:36:56","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-m5f5-28qr-9g9r"}]}],"notrinos\/notrinos-erp":[{"advisoryId":"PKSA-6c2y-dycw-7c38","packageName":"notrinos\/notrinos-erp","remoteId":"GHSA-qv4m-m73m-8hj7","title":"NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee \u0022Documents\u0022 (doc_file)","link":"https:\/\/github.com\/advisories\/GHSA-qv4m-m73m-8hj7","cve":null,"affectedVersions":"\u003C=1.0.0","source":"GitHub","reportedAt":"2026-07-10 19:34:03","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qv4m-m73m-8hj7"}]}],"api-platform\/core":[{"advisoryId":"PKSA-3ncz-km6v-5vjr","packageName":"api-platform\/core","remoteId":"GHSA-pjhx-3c3w-9v23","title":"API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate","link":"https:\/\/github.com\/advisories\/GHSA-pjhx-3c3w-9v23","cve":"CVE-2026-49858","affectedVersions":"\u003E=4.3.0,\u003C4.3.8|\u003E=4.2.0,\u003C4.2.25|\u003E=2.6.0,\u003C4.1.29","source":"GitHub","reportedAt":"2026-07-10 14:32:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pjhx-3c3w-9v23"}]}],"api-platform\/json-api":[{"advisoryId":"PKSA-scrq-f2mk-7bhq","packageName":"api-platform\/json-api","remoteId":"GHSA-pjhx-3c3w-9v23","title":"API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate","link":"https:\/\/github.com\/advisories\/GHSA-pjhx-3c3w-9v23","cve":"CVE-2026-49858","affectedVersions":"\u003E=4.3.0,\u003C4.3.8|\u003E=4.2.0,\u003C4.2.25|\u003E=4.0.0,\u003C4.1.29","source":"GitHub","reportedAt":"2026-07-10 14:32:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pjhx-3c3w-9v23"}]}],"api-platform\/hal":[{"advisoryId":"PKSA-9wr7-4vnk-wwmr","packageName":"api-platform\/hal","remoteId":"GHSA-pjhx-3c3w-9v23","title":"API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate","link":"https:\/\/github.com\/advisories\/GHSA-pjhx-3c3w-9v23","cve":"CVE-2026-49858","affectedVersions":"\u003E=4.3.0,\u003C4.3.8|\u003E=4.2.0,\u003C4.2.25|\u003E=4.0.0,\u003C4.1.29","source":"GitHub","reportedAt":"2026-07-10 14:32:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pjhx-3c3w-9v23"}]}],"tinymce\/tinymce":[{"advisoryId":"PKSA-2v47-9p8y-4qt3","packageName":"tinymce\/tinymce","remoteId":"GHSA-v98h-vmpc-fpqv","title":"TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments","link":"https:\/\/github.com\/advisories\/GHSA-v98h-vmpc-fpqv","cve":"CVE-2026-47762","affectedVersions":"\u003C=5.10.9|\u003E=8.0.0,\u003C8.5.1|\u003E=6.0.0,\u003C7.9.3","source":"GitHub","reportedAt":"2026-06-05 20:29:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v98h-vmpc-fpqv"}]}],"easycorp\/easyadmin-bundle":[{"advisoryId":"PKSA-8yhb-cz5n-f41h","packageName":"easycorp\/easyadmin-bundle","remoteId":"easycorp\/easyadmin-bundle\/GHSA-8559-gwj3-q37r.yaml","title":"Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField","link":"https:\/\/github.com\/EasyCorp\/EasyAdminBundle\/security\/advisories\/GHSA-8559-gwj3-q37r","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-04 06:43:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"easycorp\/easyadmin-bundle\/GHSA-8559-gwj3-q37r.yaml"},{"name":"GitHub","remoteId":"GHSA-8559-gwj3-q37r"}]}],"pimcore\/pimcore":[{"advisoryId":"PKSA-vd5r-2gyh-m6cc","packageName":"pimcore\/pimcore","remoteId":"GHSA-jwcc-gv4m-93x6","title":"Pimcore has a CustomReports Share Bypass","link":"https:\/\/github.com\/advisories\/GHSA-jwcc-gv4m-93x6","cve":"CVE-2026-45704","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.2|\u003C=11.5.16|\u003E=12.0.0-RC1,\u003C=12.3.5","source":"GitHub","reportedAt":"2026-05-27 22:34:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jwcc-gv4m-93x6"}]},{"advisoryId":"PKSA-v5bg-33q7-q8zj","packageName":"pimcore\/pimcore","remoteId":"GHSA-332x-r494-54fq","title":"Pimcore has a WordExport Authorization Bypass for Unauthorized Document Export","link":"https:\/\/github.com\/advisories\/GHSA-332x-r494-54fq","cve":"CVE-2026-45703","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.3|\u003C=11.5.16|\u003E=12.0.0-RC1,\u003C=12.3.6","source":"GitHub","reportedAt":"2026-05-27 22:27:18","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-332x-r494-54fq"}]},{"advisoryId":"PKSA-y4yc-6g1b-qfqz","packageName":"pimcore\/pimcore","remoteId":"GHSA-wc7j-g8wx-m2qx","title":"Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling","link":"https:\/\/github.com\/advisories\/GHSA-wc7j-g8wx-m2qx","cve":"CVE-2026-45260","affectedVersions":"\u003C=11.5.16|\u003E=2026.1.0,\u003C2026.1.3|\u003E=12.0.0-RC1,\u003C=12.3.6","source":"GitHub","reportedAt":"2026-05-27 17:17:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wc7j-g8wx-m2qx"}]},{"advisoryId":"PKSA-882j-k212-wjbf","packageName":"pimcore\/pimcore","remoteId":"GHSA-36fc-7wjg-mfvj","title":"Pimcore has Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction","link":"https:\/\/github.com\/advisories\/GHSA-36fc-7wjg-mfvj","cve":"CVE-2026-45162","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.3|\u003C=11.5.16|\u003E=12.0.0-RC1,\u003C=12.3.6","source":"GitHub","reportedAt":"2026-05-27 16:57:04","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-36fc-7wjg-mfvj"}]},{"advisoryId":"PKSA-kp19-xmdp-rvyj","packageName":"pimcore\/pimcore","remoteId":"GHSA-3234-gxc3-pq6f","title":"Pimcore Vulnerable to SQL Injection in Custom Reports Column Configuration","link":"https:\/\/github.com\/advisories\/GHSA-3234-gxc3-pq6f","cve":"CVE-2026-44739","affectedVersions":"\u003E=12.0.0-RC1,\u003C=12.3.5|\u003C=11.5.16|\u003E=2026.1.0,\u003C2026.1.2","source":"GitHub","reportedAt":"2026-05-27 00:35:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3234-gxc3-pq6f"}]},{"advisoryId":"PKSA-vp19-ydt7-tws9","packageName":"pimcore\/pimcore","remoteId":"GHSA-r2f4-ff2p-xc64","title":"Pimcore Platform - SQL Injection in DataObject composite index handling during class definition import\/save","link":"https:\/\/github.com\/advisories\/GHSA-r2f4-ff2p-xc64","cve":"CVE-2026-5394","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.3|\u003C=11.5.16|\u003E=12.0.0-RC1,\u003C=12.3.6","source":"GitHub","reportedAt":"2026-05-28 20:47:10","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r2f4-ff2p-xc64"}]}],"pimcore\/admin-ui-classic-bundle":[{"advisoryId":"PKSA-v29g-sqpm-mznn","packageName":"pimcore\/admin-ui-classic-bundle","remoteId":"GHSA-h4ph-crvj-9h92","title":"Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter","link":"https:\/\/github.com\/advisories\/GHSA-h4ph-crvj-9h92","cve":"CVE-2026-44741","affectedVersions":"\u003C1.7.18|\u003E=2.0.0-RC1,\u003C=2.3.5","source":"GitHub","reportedAt":"2026-05-27 00:35:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h4ph-crvj-9h92"}]}]}}