{"advisories":{"october\/october":[{"advisoryId":"PKSA-dqgv-qnp4-9j5k","packageName":"october\/october","remoteId":"GHSA-2xmm-m4wv-3fjh","title":"October CMS: Incomplete Scheme Validation in Image Resizer","link":"https:\/\/github.com\/advisories\/GHSA-2xmm-m4wv-3fjh","cve":null,"affectedVersions":"\u003E=4.3.0,\u003C4.3.4","source":"GitHub","reportedAt":"2026-09-14 17:15:44","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-2xmm-m4wv-3fjh"}]}],"october\/system":[{"advisoryId":"PKSA-syjw-hb9p-2d5m","packageName":"october\/system","remoteId":"GHSA-2ff2-mx52-q8wp","title":"October CMS: PHP Object Injection via Backend Widget Session Storage","link":"https:\/\/github.com\/advisories\/GHSA-2ff2-mx52-q8wp","cve":"CVE-2026-49400","affectedVersions":"\u003E=4.0.0,\u003C4.2.23|\u003C3.7.17","source":"GitHub","reportedAt":"2026-09-14 17:08:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-2ff2-mx52-q8wp"}]},{"advisoryId":"PKSA-m19v-7rfv-5pmv","packageName":"october\/system","remoteId":"GHSA-xv9m-fm3w-8w5x","title":"October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls","link":"https:\/\/github.com\/advisories\/GHSA-xv9m-fm3w-8w5x","cve":"CVE-2026-46696","affectedVersions":"\u003E=4.0.0,\u003C4.2.23|\u003C3.7.17","source":"GitHub","reportedAt":"2026-09-14 16:02:35","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xv9m-fm3w-8w5x"}]}],"shopper\/framework":[{"advisoryId":"PKSA-xbk1-5yr7-c54k","packageName":"shopper\/framework","remoteId":"GHSA-99h5-jhh7-v3r3","title":"Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)","link":"https:\/\/github.com\/advisories\/GHSA-99h5-jhh7-v3r3","cve":"CVE-2026-56830","affectedVersions":"\u003C2.9.2","source":"GitHub","reportedAt":"2026-09-11 21:30:14","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-99h5-jhh7-v3r3"}]},{"advisoryId":"PKSA-b41c-cwpv-9733","packageName":"shopper\/framework","remoteId":"GHSA-2cg9-97gq-9mqp","title":"Shopper: Missing authorization on product removal actions in CollectionProducts component","link":"https:\/\/github.com\/advisories\/GHSA-2cg9-97gq-9mqp","cve":"CVE-2026-56825","affectedVersions":"\u003C2.9.2","source":"GitHub","reportedAt":"2026-09-11 21:31:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2cg9-97gq-9mqp"}]},{"advisoryId":"PKSA-j6gh-mr7c-jrwc","packageName":"shopper\/framework","remoteId":"GHSA-5vf4-452p-jjhf","title":"Shopper: Negative discount values accepted and propagated through order calculation pipeline","link":"https:\/\/github.com\/advisories\/GHSA-5vf4-452p-jjhf","cve":"CVE-2026-56831","affectedVersions":"\u003C2.9.0","source":"GitHub","reportedAt":"2026-09-11 21:28:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5vf4-452p-jjhf"}]},{"advisoryId":"PKSA-kzx5-8h8q-mx1w","packageName":"shopper\/framework","remoteId":"GHSA-f7h9-qv4x-9x57","title":"Shopping privilege escalation through missing authorization in Settings components","link":"https:\/\/github.com\/advisories\/GHSA-f7h9-qv4x-9x57","cve":"CVE-2026-56826","affectedVersions":"\u003E=2.0.0,\u003C2.9.2","source":"GitHub","reportedAt":"2026-09-11 21:28:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f7h9-qv4x-9x57"}]},{"advisoryId":"PKSA-5w3n-c3b1-mxqj","packageName":"shopper\/framework","remoteId":"GHSA-j328-xmgp-j4q3","title":"Shopper: privilege escalation via improper Livewire admin component authorization","link":"https:\/\/github.com\/advisories\/GHSA-j328-xmgp-j4q3","cve":"CVE-2026-56828","affectedVersions":"\u003E=2.8.0,\u003C2.9.2","source":"GitHub","reportedAt":"2026-09-11 21:28:54","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j328-xmgp-j4q3"}]},{"advisoryId":"PKSA-d6w1-f12g-cj15","packageName":"shopper\/framework","remoteId":"GHSA-g3f9-g5vj-p62f","title":"Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component","link":"https:\/\/github.com\/advisories\/GHSA-g3f9-g5vj-p62f","cve":"CVE-2026-56829","affectedVersions":"\u003C2.9.2","source":"GitHub","reportedAt":"2026-09-11 21:29:20","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g3f9-g5vj-p62f"}]},{"advisoryId":"PKSA-wj51-ggrn-qn6q","packageName":"shopper\/framework","remoteId":"GHSA-243p-f3cv-c5wh","title":"Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes\/tags and mass-toggle visibility of brands\/categories\/suppliers","link":"https:\/\/github.com\/advisories\/GHSA-243p-f3cv-c5wh","cve":"CVE-2026-56827","affectedVersions":"\u003C2.9.2","source":"GitHub","reportedAt":"2026-09-11 20:47:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-243p-f3cv-c5wh"}]}],"pimcore\/pimcore":[{"advisoryId":"PKSA-pmf2-z78s-582m","packageName":"pimcore\/pimcore","remoteId":"GHSA-23rh-xw42-fq82","title":"Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration","link":"https:\/\/github.com\/advisories\/GHSA-23rh-xw42-fq82","cve":"CVE-2026-55416","affectedVersions":"\u003C11.5.18|\u003E=12.0.0-RC1,\u003C=12.3.9|\u003E=2026.1.0,\u003C=2026.1.5","source":"GitHub","reportedAt":"2026-09-10 19:25:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-23rh-xw42-fq82"}]},{"advisoryId":"PKSA-kkjc-bw16-f3kq","packageName":"pimcore\/pimcore","remoteId":"GHSA-w23p-wrp7-ch38","title":"Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502)","link":"https:\/\/github.com\/advisories\/GHSA-w23p-wrp7-ch38","cve":"CVE-2026-55220","affectedVersions":"\u003C=12.3.9|\u003E=2026.1.0,\u003C=2026.1.5","source":"GitHub","reportedAt":"2026-08-28 19:13:25","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-w23p-wrp7-ch38"}]},{"advisoryId":"PKSA-vgg9-cbdg-s4xt","packageName":"pimcore\/pimcore","remoteId":"GHSA-9x44-4gxf-8c25","title":"Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name","link":"https:\/\/github.com\/advisories\/GHSA-9x44-4gxf-8c25","cve":"CVE-2026-55634","affectedVersions":"\u003E=2026.1.0,\u003C=2026.1.5|\u003C=12.3.9","source":"GitHub","reportedAt":"2026-08-28 19:17:42","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-9x44-4gxf-8c25"}]},{"advisoryId":"PKSA-fpxc-s2d8-24zv","packageName":"pimcore\/pimcore","remoteId":"GHSA-2mhj-fhvg-v428","title":"Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name","link":"https:\/\/github.com\/advisories\/GHSA-2mhj-fhvg-v428","cve":"CVE-2026-55072","affectedVersions":"\u003C12.3.9|\u003E=2026.1.0,\u003C=2026.1.4","source":"GitHub","reportedAt":"2026-08-13 13:44:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2mhj-fhvg-v428"}]},{"advisoryId":"PKSA-6dhb-gq75-qpgr","packageName":"pimcore\/pimcore","remoteId":"GHSA-7p36-fq2r-4h7r","title":"Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed","link":"https:\/\/github.com\/advisories\/GHSA-7p36-fq2r-4h7r","cve":"CVE-2026-11407","affectedVersions":"\u003C=11.5.14.1|\u003E=12.0.0-RC1,\u003C=12.3.8","source":"GitHub","reportedAt":"2026-06-17 21:34:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7p36-fq2r-4h7r"}]},{"advisoryId":"PKSA-vd5r-2gyh-m6cc","packageName":"pimcore\/pimcore","remoteId":"GHSA-jwcc-gv4m-93x6","title":"Pimcore has a CustomReports Share Bypass","link":"https:\/\/github.com\/advisories\/GHSA-jwcc-gv4m-93x6","cve":"CVE-2026-45704","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.2|\u003C=11.5.16|\u003E=12.0.0-RC1,\u003C=12.3.5","source":"GitHub","reportedAt":"2026-05-27 22:34:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jwcc-gv4m-93x6"}]},{"advisoryId":"PKSA-v5bg-33q7-q8zj","packageName":"pimcore\/pimcore","remoteId":"GHSA-332x-r494-54fq","title":"Pimcore has a WordExport Authorization Bypass for Unauthorized Document Export","link":"https:\/\/github.com\/advisories\/GHSA-332x-r494-54fq","cve":"CVE-2026-45703","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.3|\u003C=11.5.16|\u003E=12.0.0-RC1,\u003C=12.3.6","source":"GitHub","reportedAt":"2026-05-27 22:27:18","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-332x-r494-54fq"}]},{"advisoryId":"PKSA-y4yc-6g1b-qfqz","packageName":"pimcore\/pimcore","remoteId":"GHSA-wc7j-g8wx-m2qx","title":"Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling","link":"https:\/\/github.com\/advisories\/GHSA-wc7j-g8wx-m2qx","cve":"CVE-2026-45260","affectedVersions":"\u003C=11.5.16|\u003E=2026.1.0,\u003C2026.1.3|\u003E=12.0.0-RC1,\u003C=12.3.6","source":"GitHub","reportedAt":"2026-05-27 17:17:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wc7j-g8wx-m2qx"}]},{"advisoryId":"PKSA-882j-k212-wjbf","packageName":"pimcore\/pimcore","remoteId":"GHSA-36fc-7wjg-mfvj","title":"Pimcore has Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction","link":"https:\/\/github.com\/advisories\/GHSA-36fc-7wjg-mfvj","cve":"CVE-2026-45162","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.3|\u003C=11.5.16|\u003E=12.0.0-RC1,\u003C=12.3.6","source":"GitHub","reportedAt":"2026-05-27 16:57:04","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-36fc-7wjg-mfvj"}]},{"advisoryId":"PKSA-kp19-xmdp-rvyj","packageName":"pimcore\/pimcore","remoteId":"GHSA-3234-gxc3-pq6f","title":"Pimcore Vulnerable to SQL Injection in Custom Reports Column Configuration","link":"https:\/\/github.com\/advisories\/GHSA-3234-gxc3-pq6f","cve":"CVE-2026-44739","affectedVersions":"\u003E=12.0.0-RC1,\u003C=12.3.5|\u003C=11.5.16|\u003E=2026.1.0,\u003C2026.1.2","source":"GitHub","reportedAt":"2026-05-27 00:35:01","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3234-gxc3-pq6f"}]},{"advisoryId":"PKSA-vp19-ydt7-tws9","packageName":"pimcore\/pimcore","remoteId":"GHSA-r2f4-ff2p-xc64","title":"Pimcore Platform - SQL Injection in DataObject composite index handling during class definition import\/save","link":"https:\/\/github.com\/advisories\/GHSA-r2f4-ff2p-xc64","cve":"CVE-2026-5394","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.3|\u003C=11.5.16|\u003E=12.0.0-RC1,\u003C=12.3.6","source":"GitHub","reportedAt":"2026-05-28 20:47:10","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-r2f4-ff2p-xc64"}]}],"react\/http":[{"advisoryId":"PKSA-2zvc-7x4m-kphn","packageName":"react\/http","remoteId":"react\/http\/GHSA-g4f2-2pf3-2pwj.yaml","title":"Unbounded HTTP Client Response Header Buffering Leads to Memory Exhaustion DoS in react\/http","link":"https:\/\/github.com\/reactphp\/http\/security\/advisories\/GHSA-g4f2-2pf3-2pwj","cve":null,"affectedVersions":"\u003E=1.0.0,\u003C1.11.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-09-09 09:11:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"react\/http\/GHSA-g4f2-2pf3-2pwj.yaml"}]},{"advisoryId":"PKSA-7xc4-r5ry-fg9s","packageName":"react\/http","remoteId":"react\/http\/CVE-2026-84997.yaml","title":"A malformed HTTP chunked body can lead to a denial-of-service and peg the CPU","link":"https:\/\/github.com\/reactphp\/http\/security\/advisories\/GHSA-x424-64qh-5j54","cve":"CVE-2026-84997","affectedVersions":"\u003E=0.6.0,\u003C1.11.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-09-09 09:11:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"react\/http\/CVE-2026-84997.yaml"}]}],"phpseclib":[{"advisoryId":"PKSA-8ydg-yj6h-v5y7","packageName":"phpseclib","remoteId":"GHSA-q97c-8qh3-fpc6","title":"phpseclib \u2014 non-constant-time X25519 scalar multiplication permits full private-key recovery","link":"https:\/\/github.com\/advisories\/GHSA-q97c-8qh3-fpc6","cve":"CVE-2026-84308","affectedVersions":"\u003E=4.0.0,\u003C4.0.1|\u003C3.0.57","source":"GitHub","reportedAt":"2026-09-08 21:24:29","composerRepository":null,"severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-q97c-8qh3-fpc6"}]}],"composer\/composer":[{"advisoryId":"PKSA-ym19-cy3j-z6df","packageName":"composer\/composer","remoteId":"GHSA-rvx4-ffvw-m9q3","title":"Composer arbitrary command execution via a malicious package\u0027s Perforce source URL","link":"https:\/\/github.com\/advisories\/GHSA-rvx4-ffvw-m9q3","cve":"CVE-2026-84361","affectedVersions":"\u003E=1.0,\u003C2.2.30|\u003E=2.3.0,\u003C2.10.3","source":"GitHub","reportedAt":"2026-09-08 21:25:41","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-rvx4-ffvw-m9q3"}]},{"advisoryId":"PKSA-4pm6-g63v-5rkr","packageName":"composer\/composer","remoteId":"GHSA-g6xq-892h-64w3","title":"Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)","link":"https:\/\/github.com\/advisories\/GHSA-g6xq-892h-64w3","cve":"CVE-2026-59947","affectedVersions":"\u003E=1.0.0,\u003C2.2.29|\u003E=2.3.0,\u003C2.10.2","source":"GitHub","reportedAt":"2026-07-20 21:55:05","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g6xq-892h-64w3"}]},{"advisoryId":"PKSA-q3ht-3g42-rg8f","packageName":"composer\/composer","remoteId":"GHSA-gjfg-22fp-rrxx","title":"Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files","link":"https:\/\/github.com\/advisories\/GHSA-gjfg-22fp-rrxx","cve":"CVE-2026-59946","affectedVersions":"\u003E=1.0.0,\u003C2.2.29|\u003E=2.3.0,\u003C2.10.2","source":"GitHub","reportedAt":"2026-07-20 21:57:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gjfg-22fp-rrxx"}]},{"advisoryId":"PKSA-zcdk-qnhk-hq2g","packageName":"composer\/composer","remoteId":"GHSA-499r-g7pc-vmp9","title":"Composer: Arbitrary file write outside vendor via malicious transitive package name","link":"https:\/\/github.com\/advisories\/GHSA-499r-g7pc-vmp9","cve":"CVE-2026-59948","affectedVersions":"\u003E=1.0.0,\u003C2.2.29|\u003E=2.3.0,\u003C2.10.2","source":"GitHub","reportedAt":"2026-07-20 19:15:29","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-499r-g7pc-vmp9"}]}],"mongodb\/mongodb":[{"advisoryId":"PKSA-61k5-cqr9-b8b4","packageName":"mongodb\/mongodb","remoteId":"GHSA-65fr-j4p9-vc33","title":"mongodb: Reject \u0022.\u0022 and NUL bytes in database and collection names","link":"https:\/\/github.com\/advisories\/GHSA-65fr-j4p9-vc33","cve":"CVE-2026-81525","affectedVersions":"\u003E=2.0.0,\u003C2.4.1|\u003C1.21.4","source":"GitHub","reportedAt":"2026-09-08 21:27:42","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-65fr-j4p9-vc33"}]}],"cakephp\/cakephp":[{"advisoryId":"PKSA-rdvp-7sns-1dvh","packageName":"cakephp\/cakephp","remoteId":"GHSA-2qh5-382h-3jpc","title":"CakePHP: SmtpTransport vulnerable to CRLF header injection","link":"https:\/\/github.com\/advisories\/GHSA-2qh5-382h-3jpc","cve":"CVE-2026-77634","affectedVersions":"\u003E=5.3.0,\u003C5.3.7|\u003E=5.2.0,\u003C5.2.14|\u003E=5.0.0,\u003C5.1.8|\u003E=4.6.0,\u003C4.6.5|\u003E=4.5.0,\u003C4.5.12","source":"GitHub","reportedAt":"2026-09-08 20:56:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2qh5-382h-3jpc"}]},{"advisoryId":"PKSA-d2h7-11vv-v66p","packageName":"cakephp\/cakephp","remoteId":"GHSA-fxf7-vhh8-7vpq","title":"CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver","link":"https:\/\/github.com\/advisories\/GHSA-fxf7-vhh8-7vpq","cve":"CVE-2026-77635","affectedVersions":"\u003E=5.1.0,\u003C5.1.10|\u003E=5.2.0,\u003C5.2.15|\u003E=5.3.0,\u003C5.3.7","source":"GitHub","reportedAt":"2026-09-08 20:56:41","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-fxf7-vhh8-7vpq"}]}],"cakephp\/database":[{"advisoryId":"PKSA-xyyq-wf7k-89mv","packageName":"cakephp\/database","remoteId":"GHSA-fxf7-vhh8-7vpq","title":"CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver","link":"https:\/\/github.com\/advisories\/GHSA-fxf7-vhh8-7vpq","cve":"CVE-2026-77635","affectedVersions":"\u003E=5.1.0,\u003C5.1.10|\u003E=5.2.0,\u003C5.2.15|\u003E=5.3.0,\u003C5.3.7","source":"GitHub","reportedAt":"2026-09-08 20:56:41","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-fxf7-vhh8-7vpq"}]}],"predis\/predis":[{"advisoryId":"PKSA-z888-whwt-brbj","packageName":"predis\/predis","remoteId":"GHSA-w6f5-v2h6-g786","title":"Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections","link":"https:\/\/github.com\/advisories\/GHSA-w6f5-v2h6-g786","cve":"CVE-2026-84372","affectedVersions":"\u003E=3.0.0-RC1,\u003C3.3.0","source":"GitHub","reportedAt":"2026-09-08 20:57:50","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-w6f5-v2h6-g786"}]}],"maatwebsite\/excel":[{"advisoryId":"PKSA-xgss-dh88-nswy","packageName":"maatwebsite\/excel","remoteId":"GHSA-c7r6-vx3h-w5g2","title":"Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path","link":"https:\/\/github.com\/advisories\/GHSA-c7r6-vx3h-w5g2","cve":"CVE-2026-84374","affectedVersions":"\u003E=3.1.8,\u003C3.1.70","source":"GitHub","reportedAt":"2026-09-08 20:40:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c7r6-vx3h-w5g2"}]}],"typo3\/cms-lowlevel":[{"advisoryId":"PKSA-t4m5-b2kz-hh4n","packageName":"typo3\/cms-lowlevel","remoteId":"typo3\/cms-lowlevel\/CVE-2026-85400.yaml","title":"TYPO3-CORE-SA-2026-023: Missing Authorization in lowlevel commands","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-core-sa-2026-023","cve":"CVE-2026-85400","affectedVersions":"\u003E=14.2.0,\u003C14.3.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-09-08 09:01:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-lowlevel\/CVE-2026-85400.yaml"}]}],"typo3\/cms-backend":[{"advisoryId":"PKSA-745m-816f-bzfy","packageName":"typo3\/cms-backend","remoteId":"typo3\/cms-backend\/CVE-2026-77132.yaml","title":"TYPO3-CORE-SA-2026-022: Information Disclosure via Backend Localization Wizard","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-core-sa-2026-022","cve":"CVE-2026-77132","affectedVersions":"\u003E=10.0.0,\u003C10.4.60|\u003E=11.0.0,\u003C11.5.54|\u003E=12.0.0,\u003C12.4.49|\u003E=13.0.0,\u003C13.4.35|\u003E=14.0.0,\u003C14.3.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-09-08 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-backend\/CVE-2026-77132.yaml"}]},{"advisoryId":"PKSA-nmd9-kc7m-nsvr","packageName":"typo3\/cms-backend","remoteId":"GHSA-68jx-f42c-7599","title":"TYPO3 CMS - Broken Access Control in Backend and Install Tool","link":"https:\/\/github.com\/advisories\/GHSA-68jx-f42c-7599","cve":"CVE-2026-19418","affectedVersions":"\u003E=13.0.0,\u003C13.4.34","source":"GitHub","reportedAt":"2026-09-01 21:31:42","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-68jx-f42c-7599"}]}],"getgrav\/grav":[{"advisoryId":"PKSA-p6yn-thc9-dbs3","packageName":"getgrav\/grav","remoteId":"GHSA-7mgc-c7pq-3rr3","title":"Grav: 2FA Bypass via \u0027login.regenerate2FASecret\u0027 - Secret Rotation During Pending Challenge","link":"https:\/\/github.com\/advisories\/GHSA-7mgc-c7pq-3rr3","cve":"CVE-2026-62669","affectedVersions":"\u003C2.0.4","source":"GitHub","reportedAt":"2026-09-02 22:01:25","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7mgc-c7pq-3rr3"}]},{"advisoryId":"PKSA-sq15-xbtt-m678","packageName":"getgrav\/grav","remoteId":"GHSA-mc5q-6hpj-rp7j","title":"Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)","link":"https:\/\/github.com\/advisories\/GHSA-mc5q-6hpj-rp7j","cve":"CVE-2026-61842","affectedVersions":"\u003C2.0.2","source":"GitHub","reportedAt":"2026-09-02 21:41:12","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mc5q-6hpj-rp7j"}]},{"advisoryId":"PKSA-2vrn-cxz9-yg23","packageName":"getgrav\/grav","remoteId":"GHSA-928x-9mpw-8h56","title":"Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits","link":"https:\/\/github.com\/advisories\/GHSA-928x-9mpw-8h56","cve":"CVE-2026-61690","affectedVersions":"\u003C2.0.1","source":"GitHub","reportedAt":"2026-09-02 21:35:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-928x-9mpw-8h56"}]},{"advisoryId":"PKSA-1q9r-bgms-91mf","packageName":"getgrav\/grav","remoteId":"GHSA-fj2p-qj2f-74v5","title":"Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()","link":"https:\/\/github.com\/advisories\/GHSA-fj2p-qj2f-74v5","cve":"CVE-2026-64850","affectedVersions":"\u003C2.0.7","source":"GitHub","reportedAt":"2026-09-02 14:51:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fj2p-qj2f-74v5"}]},{"advisoryId":"PKSA-rjzr-vkvg-cvmf","packageName":"getgrav\/grav","remoteId":"GHSA-8hgv-xc77-jmcr","title":"Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox\u0027s assets.addJs\/addCss allowlist, escalating to super-admin","link":"https:\/\/github.com\/advisories\/GHSA-8hgv-xc77-jmcr","cve":null,"affectedVersions":"\u003C=2.0.19","source":"GitHub","reportedAt":"2026-08-21 19:14:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8hgv-xc77-jmcr"}]},{"advisoryId":"PKSA-wh99-p4gt-7bkp","packageName":"getgrav\/grav","remoteId":"GHSA-vwg3-w8w3-pc79","title":"Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems","link":"https:\/\/github.com\/advisories\/GHSA-vwg3-w8w3-pc79","cve":"CVE-2026-62673","affectedVersions":"\u003C2.0.4","source":"GitHub","reportedAt":"2026-08-19 19:32:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vwg3-w8w3-pc79"}]},{"advisoryId":"PKSA-pv12-m6cp-m9cd","packageName":"getgrav\/grav","remoteId":"GHSA-4x9g-vw65-vvf9","title":"Grav: Unauthenticated denial of service via unbounded image derivative dimensions","link":"https:\/\/github.com\/advisories\/GHSA-4x9g-vw65-vvf9","cve":"CVE-2026-53653","affectedVersions":"\u003C1.7.53|\u003E=2.0.0-beta.1,\u003C2.0.0-rc.8","source":"GitHub","reportedAt":"2026-08-14 19:23:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4x9g-vw65-vvf9"}]}],"snipe\/snipe-it":[{"advisoryId":"PKSA-g91f-rycz-yjcf","packageName":"snipe\/snipe-it","remoteId":"GHSA-c6w2-j4wq-mvwg","title":"Snipe-IT: Tenant Isolation Bypass in FMCS Floater Mode","link":"https:\/\/github.com\/advisories\/GHSA-c6w2-j4wq-mvwg","cve":"CVE-2026-55643","affectedVersions":"\u003C8.6.3","source":"GitHub","reportedAt":"2026-08-19 19:32:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c6w2-j4wq-mvwg"}]},{"advisoryId":"PKSA-dysn-9smy-t3nb","packageName":"snipe\/snipe-it","remoteId":"GHSA-j5g3-42wp-gqm3","title":"Snipe-IT has an Improper Privilege Management issue","link":"https:\/\/github.com\/advisories\/GHSA-j5g3-42wp-gqm3","cve":"CVE-2026-55843","affectedVersions":"\u003C8.6.0","source":"GitHub","reportedAt":"2026-08-28 22:37:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j5g3-42wp-gqm3"}]},{"advisoryId":"PKSA-4bks-zvdb-53gs","packageName":"snipe\/snipe-it","remoteId":"GHSA-xr9m-gphc-9p63","title":"Snipe-IT has a path traversal vulnerability via CSV import `image` field","link":"https:\/\/github.com\/advisories\/GHSA-xr9m-gphc-9p63","cve":"CVE-2026-55469","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:00:38","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xr9m-gphc-9p63"}]},{"advisoryId":"PKSA-wsms-bsnd-yhwp","packageName":"snipe\/snipe-it","remoteId":"GHSA-8w8c-8mx9-52cw","title":"Snipe-IT\u0027s API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation","link":"https:\/\/github.com\/advisories\/GHSA-8w8c-8mx9-52cw","cve":"CVE-2026-55472","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:01:06","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8w8c-8mx9-52cw"}]},{"advisoryId":"PKSA-b2sw-ngv6-5kt1","packageName":"snipe\/snipe-it","remoteId":"GHSA-c6f4-wj38-m3g3","title":"Snipe-IT vulnerable to directory traversal in displaySig","link":"https:\/\/github.com\/advisories\/GHSA-c6f4-wj38-m3g3","cve":"CVE-2026-55474","affectedVersions":"\u003C8.5.0","source":"GitHub","reportedAt":"2026-08-28 18:01:32","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c6f4-wj38-m3g3"}]},{"advisoryId":"PKSA-spdd-pnpq-79f1","packageName":"snipe\/snipe-it","remoteId":"GHSA-5wx7-xq8j-v4qm","title":"Snipe-IT\u0027s import created_by can be overwritten","link":"https:\/\/github.com\/advisories\/GHSA-5wx7-xq8j-v4qm","cve":"CVE-2026-55475","affectedVersions":"\u003C=8.6.0","source":"GitHub","reportedAt":"2026-08-28 18:01:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5wx7-xq8j-v4qm"}]},{"advisoryId":"PKSA-3ybt-zv27-1tk1","packageName":"snipe\/snipe-it","remoteId":"GHSA-53jc-27pc-x8r8","title":"Snipe-IT Vulnerable to Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter","link":"https:\/\/github.com\/advisories\/GHSA-53jc-27pc-x8r8","cve":"CVE-2026-55476","affectedVersions":"\u003C8.6.0","source":"GitHub","reportedAt":"2026-08-28 18:02:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-53jc-27pc-x8r8"}]},{"advisoryId":"PKSA-3nxv-xvdx-984d","packageName":"snipe\/snipe-it","remoteId":"GHSA-crv3-j83j-f3r6","title":"Snipe-IT has missing object-level authorization in Kits API","link":"https:\/\/github.com\/advisories\/GHSA-crv3-j83j-f3r6","cve":"CVE-2026-55478","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:02:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-crv3-j83j-f3r6"}]},{"advisoryId":"PKSA-j17x-hbvs-1cxn","packageName":"snipe\/snipe-it","remoteId":"GHSA-8frh-vhgh-64cf","title":"Snipe-IT has incorrect permission for legacy license checkin API ","link":"https:\/\/github.com\/advisories\/GHSA-8frh-vhgh-64cf","cve":"CVE-2026-55479","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:02:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8frh-vhgh-64cf"}]},{"advisoryId":"PKSA-78g8-kyjb-j6v1","packageName":"snipe\/snipe-it","remoteId":"GHSA-w7qw-5wfv-gwx9","title":"Snipe-IT has CSS Injection via `header_color` Setting","link":"https:\/\/github.com\/advisories\/GHSA-w7qw-5wfv-gwx9","cve":"CVE-2026-55481","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:04:29","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w7qw-5wfv-gwx9"}]},{"advisoryId":"PKSA-mtr1-kyd4-dpz1","packageName":"snipe\/snipe-it","remoteId":"GHSA-35cr-9hqq-p2mg","title":"Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint","link":"https:\/\/github.com\/advisories\/GHSA-35cr-9hqq-p2mg","cve":"CVE-2026-55515","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:04:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-35cr-9hqq-p2mg"}]},{"advisoryId":"PKSA-9w68-kyxd-kgh7","packageName":"snipe\/snipe-it","remoteId":"GHSA-575r-357h-fhch","title":"Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update","link":"https:\/\/github.com\/advisories\/GHSA-575r-357h-fhch","cve":"CVE-2026-55516","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 18:06:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-575r-357h-fhch"}]},{"advisoryId":"PKSA-3b5d-jjsk-z4w4","packageName":"snipe\/snipe-it","remoteId":"GHSA-wg2f-x2c2-c4rp","title":"Snipe-IT has an Open Redirect After User Edit","link":"https:\/\/github.com\/advisories\/GHSA-wg2f-x2c2-c4rp","cve":"CVE-2026-55461","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:57:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wg2f-x2c2-c4rp"}]},{"advisoryId":"PKSA-2vjy-7jj7-vvq3","packageName":"snipe\/snipe-it","remoteId":"GHSA-fc33-6w3q-538h","title":"Snipe-IT has an authorization bypass on print inventory page","link":"https:\/\/github.com\/advisories\/GHSA-fc33-6w3q-538h","cve":"CVE-2026-55462","affectedVersions":"\u003C=8.6.0","source":"GitHub","reportedAt":"2026-08-28 17:57:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-fc33-6w3q-538h"}]},{"advisoryId":"PKSA-6ddj-s9z1-gtxr","packageName":"snipe\/snipe-it","remoteId":"GHSA-r52f-r9v5-66xr","title":"Snipe-IT vulnerable to stored XSS via Markdown custom field ","link":"https:\/\/github.com\/advisories\/GHSA-r52f-r9v5-66xr","cve":"CVE-2026-55464","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:58:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r52f-r9v5-66xr"}]},{"advisoryId":"PKSA-3mmm-zfys-jjqm","packageName":"snipe\/snipe-it","remoteId":"GHSA-jhph-5q74-pmfx","title":"Snipe-IT vulnerable to stored XSS via inline-served attachment","link":"https:\/\/github.com\/advisories\/GHSA-jhph-5q74-pmfx","cve":"CVE-2026-55466","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:59:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jhph-5q74-pmfx"}]},{"advisoryId":"PKSA-cj32-qmb9-vwgy","packageName":"snipe\/snipe-it","remoteId":"GHSA-whrx-mmgr-gpcf","title":"Snipe-IT has CSV formula injection in Activity Report export","link":"https:\/\/github.com\/advisories\/GHSA-whrx-mmgr-gpcf","cve":"CVE-2026-55452","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:46:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-whrx-mmgr-gpcf"}]},{"advisoryId":"PKSA-n99m-2gcm-8bc6","packageName":"snipe\/snipe-it","remoteId":"GHSA-vgx7-c78r-69w9","title":"Snipe-IT has an authorization bypass on bulk editing users","link":"https:\/\/github.com\/advisories\/GHSA-vgx7-c78r-69w9","cve":"CVE-2026-55460","affectedVersions":"\u003C=8.6.1","source":"GitHub","reportedAt":"2026-08-28 17:48:36","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vgx7-c78r-69w9"}]},{"advisoryId":"PKSA-9n96-zyz7-nxh9","packageName":"snipe\/snipe-it","remoteId":"GHSA-3hgv-jr5j-cg9x","title":"Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover","link":"https:\/\/github.com\/advisories\/GHSA-3hgv-jr5j-cg9x","cve":"CVE-2026-55694","affectedVersions":"\u003C8.6.3","source":"GitHub","reportedAt":"2026-08-19 19:32:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3hgv-jr5j-cg9x"}]},{"advisoryId":"PKSA-2v9y-4jt3-bxpm","packageName":"snipe\/snipe-it","remoteId":"GHSA-r9r3-g9fp-3q4q","title":"Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET","link":"https:\/\/github.com\/advisories\/GHSA-r9r3-g9fp-3q4q","cve":"CVE-2026-55703","affectedVersions":"\u003C8.6.3","source":"GitHub","reportedAt":"2026-08-19 19:32:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r9r3-g9fp-3q4q"}]},{"advisoryId":"PKSA-9ywr-ywdr-gcrt","packageName":"snipe\/snipe-it","remoteId":"GHSA-c8qc-wf67-342w","title":"Snipe-IT: Stored DOM XSS via table selected-count IDs","link":"https:\/\/github.com\/advisories\/GHSA-c8qc-wf67-342w","cve":"CVE-2026-61807","affectedVersions":"\u003C8.6.2","source":"GitHub","reportedAt":"2026-08-19 19:32:32","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c8qc-wf67-342w"}]}],"sulu\/sulu":[{"advisoryId":"PKSA-nbbf-nf63-19vd","packageName":"sulu\/sulu","remoteId":"GHSA-pp4x-ccxq-6r33","title":"Sulu: Stored XSS via media download inline-disposition override","link":"https:\/\/github.com\/advisories\/GHSA-pp4x-ccxq-6r33","cve":"CVE-2026-82396","affectedVersions":"\u003E=3.0.0-alpha1,\u003C3.0.8|\u003C=2.6.24","source":"GitHub","reportedAt":"2026-09-02 15:10:19","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pp4x-ccxq-6r33"}]},{"advisoryId":"PKSA-2gwf-7fts-yzvv","packageName":"sulu\/sulu","remoteId":"GHSA-65cv-w493-7vhq","title":"Sulu: Fix authorization bypass when creating preview links","link":"https:\/\/github.com\/advisories\/GHSA-65cv-w493-7vhq","cve":"CVE-2026-82394","affectedVersions":"\u003E=3.0.0-alpha1,\u003C3.0.8|\u003C=2.6.24","source":"GitHub","reportedAt":"2026-09-02 15:09:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-65cv-w493-7vhq"}]},{"advisoryId":"PKSA-zmfc-sgjt-9gmb","packageName":"sulu\/sulu","remoteId":"GHSA-h6cx-gjxx-v25c","title":"Sulu: Media move\/update authorization bypass (IDOR)","link":"https:\/\/github.com\/advisories\/GHSA-h6cx-gjxx-v25c","cve":"CVE-2026-82395","affectedVersions":"\u003E=3.0.0-alpha1,\u003C3.0.8|\u003C=2.6.24","source":"GitHub","reportedAt":"2026-09-02 14:57:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h6cx-gjxx-v25c"}]}],"getkirby\/cms":[{"advisoryId":"PKSA-cmzk-n5t6-2v3k","packageName":"getkirby\/cms","remoteId":"GHSA-6j4c-mgqr-qv76","title":"Kirby: Access to image files outside of the site root via path traversal in the media handling","link":"https:\/\/github.com\/advisories\/GHSA-6j4c-mgqr-qv76","cve":"CVE-2026-75592","affectedVersions":"\u003E=5.0.0,\u003C5.5.2|\u003C4.9.5","source":"GitHub","reportedAt":"2026-09-02 14:55:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6j4c-mgqr-qv76"}]},{"advisoryId":"PKSA-wq8z-fxnn-1fxz","packageName":"getkirby\/cms","remoteId":"GHSA-rf2p-vh74-7vvh","title":"Kirby: System path exposure from error messages in the REST API","link":"https:\/\/github.com\/advisories\/GHSA-rf2p-vh74-7vvh","cve":"CVE-2026-69127","affectedVersions":"\u003E=5.0.0,\u003C5.5.2|\u003C=4.9.4","source":"GitHub","reportedAt":"2026-09-01 16:37:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rf2p-vh74-7vvh"}]},{"advisoryId":"PKSA-n74d-ghht-18nt","packageName":"getkirby\/cms","remoteId":"GHSA-9vx2-j98c-p72w","title":"Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling","link":"https:\/\/github.com\/advisories\/GHSA-9vx2-j98c-p72w","cve":"CVE-2026-75594","affectedVersions":"\u003E=5.0.0,\u003C5.5.2|\u003C=4.9.4","source":"GitHub","reportedAt":"2026-08-31 22:12:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9vx2-j98c-p72w"}]},{"advisoryId":"PKSA-cxg1-n9gs-z2t6","packageName":"getkirby\/cms","remoteId":"GHSA-67mx-6wf2-92xp","title":"Kirby: File upload permissions are not checked during processing of chunk data","link":"https:\/\/github.com\/advisories\/GHSA-67mx-6wf2-92xp","cve":"CVE-2026-71415","affectedVersions":"\u003E=5.0.0,\u003C5.5.2","source":"GitHub","reportedAt":"2026-08-31 22:14:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-67mx-6wf2-92xp"}]}],"apache\/thrift":[{"advisoryId":"PKSA-t5dt-c9kk-znks","packageName":"apache\/thrift","remoteId":"GHSA-8wv5-x4w7-5gww","title":"Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop","link":"https:\/\/github.com\/advisories\/GHSA-8wv5-x4w7-5gww","cve":"CVE-2026-43871","affectedVersions":"\u003C0.24.0","source":"GitHub","reportedAt":"2026-07-27 12:31:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8wv5-x4w7-5gww"}]}],"studio-42\/elfinder":[{"advisoryId":"PKSA-th2b-2jzf-hmp6","packageName":"studio-42\/elfinder","remoteId":"GHSA-9hjf-w35w-6vx2","title":"elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections","link":"https:\/\/github.com\/advisories\/GHSA-9hjf-w35w-6vx2","cve":"CVE-2026-81890","affectedVersions":"\u003C2.1.70","source":"GitHub","reportedAt":"2026-09-02 14:37:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9hjf-w35w-6vx2"}]},{"advisoryId":"PKSA-71vn-d2sp-v1x4","packageName":"studio-42\/elfinder","remoteId":"GHSA-gxmj-r5rf-ggwq","title":"elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)","link":"https:\/\/github.com\/advisories\/GHSA-gxmj-r5rf-ggwq","cve":"CVE-2026-81891","affectedVersions":"\u003C2.1.70","source":"GitHub","reportedAt":"2026-09-02 14:37:54","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gxmj-r5rf-ggwq"}]},{"advisoryId":"PKSA-r7xr-47v5-58tx","packageName":"studio-42\/elfinder","remoteId":"GHSA-8x3q-jpjh-qh5c","title":"elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback","link":"https:\/\/github.com\/advisories\/GHSA-8x3q-jpjh-qh5c","cve":"CVE-2026-81889","affectedVersions":"\u003C=2.1.69","source":"GitHub","reportedAt":"2026-08-31 20:28:06","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8x3q-jpjh-qh5c"}]}],"livewire\/livewire":[{"advisoryId":"PKSA-bgw4-5zmg-2njg","packageName":"livewire\/livewire","remoteId":"GHSA-g3hc-697w-wm82","title":"Livewire DOM-based cross-site scripting during client-side state handling","link":"https:\/\/github.com\/advisories\/GHSA-g3hc-697w-wm82","cve":"CVE-2026-81887","affectedVersions":"\u003E=4.0.0-beta.1,\u003C=4.3.3|\u003E=3.0.0-beta.1,\u003C=3.8.2","source":"GitHub","reportedAt":"2026-09-02 14:38:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g3hc-697w-wm82"}]}],"filament\/filament":[{"advisoryId":"PKSA-wst7-5d23-qy5j","packageName":"filament\/filament","remoteId":"GHSA-52xp-w8hr-xv3c","title":"Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled","link":"https:\/\/github.com\/advisories\/GHSA-52xp-w8hr-xv3c","cve":"CVE-2026-77567","affectedVersions":"\u003E=5.0.0,\u003C5.7.0|\u003E=4.0.0,\u003C4.12.0","source":"GitHub","reportedAt":"2026-09-01 21:28:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-52xp-w8hr-xv3c"}]},{"advisoryId":"PKSA-r2v2-7j3d-th1m","packageName":"filament\/filament","remoteId":"GHSA-xwpv-pqxp-5v36","title":"Filament: Password validity disclosure for accounts denied panel access on login page","link":"https:\/\/github.com\/advisories\/GHSA-xwpv-pqxp-5v36","cve":"CVE-2026-84307","affectedVersions":"\u003E=5.0.0,\u003C5.7.5|\u003E=4.0.0,\u003C4.12.5","source":"GitHub","reportedAt":"2026-09-01 21:29:00","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xwpv-pqxp-5v36"}]},{"advisoryId":"PKSA-fwm5-nrzy-yd41","packageName":"filament\/filament","remoteId":"GHSA-r3j6-gpjw-qfjr","title":"Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used","link":"https:\/\/github.com\/advisories\/GHSA-r3j6-gpjw-qfjr","cve":"CVE-2026-84306","affectedVersions":"\u003E=5.0.0,\u003C5.7.6|\u003E=4.0.0,\u003C4.12.6","source":"GitHub","reportedAt":"2026-09-01 21:29:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r3j6-gpjw-qfjr"}]}],"league\/commonmark":[{"advisoryId":"PKSA-nv44-1b4d-6gjg","packageName":"league\/commonmark","remoteId":"GHSA-jjv6-8j6v-6j52","title":"league\/commonmark: Denial of service in the SmartPunct and Attributes extensions","link":"https:\/\/github.com\/advisories\/GHSA-jjv6-8j6v-6j52","cve":null,"affectedVersions":"\u003E=1.5.0,\u003C2.9.1","source":"GitHub","reportedAt":"2026-09-01 20:21:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jjv6-8j6v-6j52"}]},{"advisoryId":"PKSA-zyf5-hrxv-hrd7","packageName":"league\/commonmark","remoteId":"GHSA-8rr7-cvq3-gmfh","title":"league\/commonmark: Denial of service via distinctly-named attributes in the Attributes extension","link":"https:\/\/github.com\/advisories\/GHSA-8rr7-cvq3-gmfh","cve":null,"affectedVersions":"\u003E=1.5.0,\u003C2.10.0","source":"GitHub","reportedAt":"2026-09-01 20:28:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8rr7-cvq3-gmfh"}]},{"advisoryId":"PKSA-kr3s-894t-g5w2","packageName":"league\/commonmark","remoteId":"GHSA-f8fg-pg57-v4j8","title":"league\/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed","link":"https:\/\/github.com\/advisories\/GHSA-f8fg-pg57-v4j8","cve":null,"affectedVersions":"\u003E=2.7.0,\u003C2.9.1","source":"GitHub","reportedAt":"2026-09-01 20:18:29","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f8fg-pg57-v4j8"}]},{"advisoryId":"PKSA-9q1p-3s19-bp1q","packageName":"league\/commonmark","remoteId":"GHSA-j8pm-gj4c-rq4x","title":"league\/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters","link":"https:\/\/github.com\/advisories\/GHSA-j8pm-gj4c-rq4x","cve":null,"affectedVersions":"\u003E=0.6.0,\u003C2.9.1","source":"GitHub","reportedAt":"2026-09-01 20:17:59","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j8pm-gj4c-rq4x"}]},{"advisoryId":"PKSA-cqd6-fg4n-nxpf","packageName":"league\/commonmark","remoteId":"GHSA-mh25-x5hq-wrqp","title":"league\/commonmark: Denial of service via colliding heading slugs","link":"https:\/\/github.com\/advisories\/GHSA-mh25-x5hq-wrqp","cve":null,"affectedVersions":"\u003E=2.0.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:41:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mh25-x5hq-wrqp"}]},{"advisoryId":"PKSA-1q6p-sqkj-8mmj","packageName":"league\/commonmark","remoteId":"GHSA-jfm3-95jq-q3rf","title":"league\/commonmark:  Denial of service via duplicate footnote definitions","link":"https:\/\/github.com\/advisories\/GHSA-jfm3-95jq-q3rf","cve":null,"affectedVersions":"\u003E=1.5.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:40:53","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jfm3-95jq-q3rf"}]},{"advisoryId":"PKSA-5mzr-szzf-z6cn","packageName":"league\/commonmark","remoteId":"GHSA-mj63-m3rc-8ppr","title":"league\/commonmark: Denial of service via deeply nested XML output","link":"https:\/\/github.com\/advisories\/GHSA-mj63-m3rc-8ppr","cve":null,"affectedVersions":"\u003E=2.0.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:42:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mj63-m3rc-8ppr"}]},{"advisoryId":"PKSA-scnn-p8mm-jbft","packageName":"league\/commonmark","remoteId":"GHSA-29pj-957v-52mc","title":"league\/commonmark: AttributesExtension href\/src unsafe-link filter bypass via embedded control bytes","link":"https:\/\/github.com\/advisories\/GHSA-29pj-957v-52mc","cve":"CVE-2026-71478","affectedVersions":"\u003E=1.5.0,\u003C=2.8.3","source":"GitHub","reportedAt":"2026-08-06 20:30:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-29pj-957v-52mc"}]},{"advisoryId":"PKSA-t21r-vtr5-3mdz","packageName":"league\/commonmark","remoteId":"GHSA-2q4p-g7hv-5rgv","title":"league\/commonmark: Quadratic-time denial of service when parsing crafted Markdown","link":"https:\/\/github.com\/advisories\/GHSA-2q4p-g7hv-5rgv","cve":"CVE-2026-71488","affectedVersions":"\u003E=0.6.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:37:20","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2q4p-g7hv-5rgv"}]},{"advisoryId":"PKSA-mc58-w91n-f5gv","packageName":"league\/commonmark","remoteId":"GHSA-g2gp-3wwq-f4ph","title":"league\/commonmark: Denial of service via adjacent inline attribute blocks","link":"https:\/\/github.com\/advisories\/GHSA-g2gp-3wwq-f4ph","cve":null,"affectedVersions":"\u003E=1.5.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:39:52","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g2gp-3wwq-f4ph"}]}],"statamic\/cms":[{"advisoryId":"PKSA-rsd9-mj5m-pj4f","packageName":"statamic\/cms","remoteId":"GHSA-jppw-r5j3-xf7x","title":"Statamic CMS exposes two-factor recovery codes through dynamic Antlers rendering","link":"https:\/\/github.com\/advisories\/GHSA-jppw-r5j3-xf7x","cve":"CVE-2026-71293","affectedVersions":"\u003E=6.0.0-alpha.1,\u003C=6.30.0","source":"GitHub","reportedAt":"2026-08-05 15:32:21","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jppw-r5j3-xf7x"}]},{"advisoryId":"PKSA-yprw-4kcc-73cg","packageName":"statamic\/cms","remoteId":"GHSA-qh8c-7588-qfrv","title":"Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries","link":"https:\/\/github.com\/advisories\/GHSA-qh8c-7588-qfrv","cve":"CVE-2026-64662","affectedVersions":"\u003E=6.0.0,\u003C6.24.0|\u003C5.74.1","source":"GitHub","reportedAt":"2026-08-06 19:30:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qh8c-7588-qfrv"}]},{"advisoryId":"PKSA-htv4-42tq-8d9c","packageName":"statamic\/cms","remoteId":"GHSA-qhr7-v3xp-vw9m","title":"Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types","link":"https:\/\/github.com\/advisories\/GHSA-qhr7-v3xp-vw9m","cve":"CVE-2026-71434","affectedVersions":"\u003E=6.0.0,\u003C6.24.2|\u003C5.74.3","source":"GitHub","reportedAt":"2026-08-06 19:35:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qhr7-v3xp-vw9m"}]},{"advisoryId":"PKSA-h7t4-kgpy-prgj","packageName":"statamic\/cms","remoteId":"GHSA-vx89-p3j7-8xqc","title":"Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template","link":"https:\/\/github.com\/advisories\/GHSA-vx89-p3j7-8xqc","cve":"CVE-2026-71435","affectedVersions":"\u003E=6.0.0,\u003C6.24.2|\u003C5.74.3","source":"GitHub","reportedAt":"2026-08-06 19:37:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vx89-p3j7-8xqc"}]},{"advisoryId":"PKSA-691k-v8bf-zdg7","packageName":"statamic\/cms","remoteId":"GHSA-225x-3jhx-wh4q","title":"Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence","link":"https:\/\/github.com\/advisories\/GHSA-225x-3jhx-wh4q","cve":"CVE-2026-64664","affectedVersions":"\u003E=6.0.0,\u003C6.24.0|\u003C5.74.1","source":"GitHub","reportedAt":"2026-08-06 19:22:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-225x-3jhx-wh4q"}]},{"advisoryId":"PKSA-vbqf-w9v5-8bfs","packageName":"statamic\/cms","remoteId":"GHSA-93qh-5269-9wcf","title":"Statamic: Account takeover via OAuth email matching without email-verification check","link":"https:\/\/github.com\/advisories\/GHSA-93qh-5269-9wcf","cve":"CVE-2026-64665","affectedVersions":"\u003E=6.0.0,\u003C6.24.0|\u003C5.74.1","source":"GitHub","reportedAt":"2026-08-06 19:25:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-93qh-5269-9wcf"}]},{"advisoryId":"PKSA-p8hp-2yrt-f2d6","packageName":"statamic\/cms","remoteId":"GHSA-j2vp-f2pv-5rj4","title":"Statamic: Unsafe method invocation via Antlers template resolution allows data destruction","link":"https:\/\/github.com\/advisories\/GHSA-j2vp-f2pv-5rj4","cve":"CVE-2026-64663","affectedVersions":"\u003E=6.0.0,\u003C6.24.0|\u003C5.74.1","source":"GitHub","reportedAt":"2026-08-06 19:28:08","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j2vp-f2pv-5rj4"}]}],"smarty\/smarty":[{"advisoryId":"PKSA-mz8k-7h5s-m8kh","packageName":"smarty\/smarty","remoteId":"GHSA-cq55-c7wv-pxmq","title":"Smarty: SSRF via redirect bypass of trusted_uri using {fetch}","link":"https:\/\/github.com\/advisories\/GHSA-cq55-c7wv-pxmq","cve":"CVE-2026-62993","affectedVersions":"\u003C4.5.7|\u003E=5.0.0,\u003C5.8.2","source":"GitHub","reportedAt":"2026-09-01 16:38:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cq55-c7wv-pxmq"}]},{"advisoryId":"PKSA-7cg9-1cz1-3qff","packageName":"smarty\/smarty","remoteId":"GHSA-rjhh-76wf-8xmw","title":"Smarty Security stream restriction bypass through stream: resource","link":"https:\/\/github.com\/advisories\/GHSA-rjhh-76wf-8xmw","cve":"CVE-2026-62996","affectedVersions":"\u003E=5.0.0,\u003C5.8.4","source":"GitHub","reportedAt":"2026-08-07 15:10:51","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rjhh-76wf-8xmw"}]},{"advisoryId":"PKSA-zw1q-6h4d-mf1m","packageName":"smarty\/smarty","remoteId":"GHSA-f6wf-28g6-769x","title":"Smarty: Symlink path traversal out of trusted directories","link":"https:\/\/github.com\/advisories\/GHSA-f6wf-28g6-769x","cve":"CVE-2026-62992","affectedVersions":"\u003C4.5.7|\u003E=5.0.0,\u003C5.8.2","source":"GitHub","reportedAt":"2026-08-07 15:02:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f6wf-28g6-769x"}]}],"privatebin\/privatebin":[{"advisoryId":"PKSA-ysv6-x4qh-fd9v","packageName":"privatebin\/privatebin","remoteId":"GHSA-f2xf-7x3g-4272","title":"PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction","link":"https:\/\/github.com\/advisories\/GHSA-f2xf-7x3g-4272","cve":"CVE-2026-55696","affectedVersions":"\u003C=2.0.4","source":"GitHub","reportedAt":"2026-08-28 20:22:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f2xf-7x3g-4272"}]},{"advisoryId":"PKSA-t55m-4nf3-277t","packageName":"privatebin\/privatebin","remoteId":"GHSA-xrjc-c68j-hp7w","title":"PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI","link":"https:\/\/github.com\/advisories\/GHSA-xrjc-c68j-hp7w","cve":"CVE-2026-55891","affectedVersions":"\u003C=2.0.4","source":"GitHub","reportedAt":"2026-08-28 20:25:34","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-xrjc-c68j-hp7w"}]}],"pimcore\/studio-backend-bundle":[{"advisoryId":"PKSA-spw3-r32w-35m6","packageName":"pimcore\/studio-backend-bundle","remoteId":"GHSA-h854-c3m3-mh5v","title":"Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass","link":"https:\/\/github.com\/advisories\/GHSA-h854-c3m3-mh5v","cve":"CVE-2026-55207","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.6|\u003C2025.4.6","source":"GitHub","reportedAt":"2026-08-28 19:04:16","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h854-c3m3-mh5v"}]},{"advisoryId":"PKSA-pq1q-v29r-6xp5","packageName":"pimcore\/studio-backend-bundle","remoteId":"GHSA-79cw-hfcc-7mw9","title":"Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes","link":"https:\/\/github.com\/advisories\/GHSA-79cw-hfcc-7mw9","cve":"CVE-2026-55208","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.6|\u003C2025.4.6","source":"GitHub","reportedAt":"2026-08-28 19:04:54","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-79cw-hfcc-7mw9"}]},{"advisoryId":"PKSA-89fg-v2s3-x29j","packageName":"pimcore\/studio-backend-bundle","remoteId":"GHSA-f97c-ph8j-8vff","title":"Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation","link":"https:\/\/github.com\/advisories\/GHSA-f97c-ph8j-8vff","cve":"CVE-2026-55212","affectedVersions":"\u003E=2026.1.0,\u003C2026.1.6|\u003C2025.4.6","source":"GitHub","reportedAt":"2026-08-28 19:05:25","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f97c-ph8j-8vff"}]}],"phpsysinfo\/phpsysinfo":[{"advisoryId":"PKSA-m4bq-bq4t-zzsh","packageName":"phpsysinfo\/phpsysinfo","remoteId":"GHSA-786w-p5pm-cvgh","title":"phpSysInfo has an IP allowlist (PSI_ALLOWED) bypass via spoofed X-Forwarded-For \/ Client-IP headers","link":"https:\/\/github.com\/advisories\/GHSA-786w-p5pm-cvgh","cve":"CVE-2026-55584","affectedVersions":"\u003C=3.4.5","source":"GitHub","reportedAt":"2026-08-28 18:30:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-786w-p5pm-cvgh"}]}],"phalcon\/cphalcon":[{"advisoryId":"PKSA-65xj-m5g6-56k1","packageName":"phalcon\/cphalcon","remoteId":"GHSA-8jqh-95g6-7jpj","title":"Phalcon: Non-constant-time HMAC verification in `Encryption\\Crypt::decrypt` (timing side-channel)","link":"https:\/\/github.com\/advisories\/GHSA-8jqh-95g6-7jpj","cve":"CVE-2026-54736","affectedVersions":"\u003C=5.14.0","source":"GitHub","reportedAt":"2026-08-28 16:01:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8jqh-95g6-7jpj"}]},{"advisoryId":"PKSA-5stm-rfkw-zjbb","packageName":"phalcon\/cphalcon","remoteId":"GHSA-x7rj-f32v-7jjg","title":"Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS","link":"https:\/\/github.com\/advisories\/GHSA-x7rj-f32v-7jjg","cve":"CVE-2026-57584","affectedVersions":"\u003C=5.14.2","source":"GitHub","reportedAt":"2026-08-28 16:06:31","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-x7rj-f32v-7jjg"}]},{"advisoryId":"PKSA-n2s8-x5tr-m78t","packageName":"phalcon\/cphalcon","remoteId":"GHSA-hrwp-4hh9-c8r8","title":"Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)","link":"https:\/\/github.com\/advisories\/GHSA-hrwp-4hh9-c8r8","cve":"CVE-2026-59989","affectedVersions":"\u003C=5.15.0","source":"GitHub","reportedAt":"2026-08-21 20:55:56","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-hrwp-4hh9-c8r8"}]}],"cakephp\/queue":[{"advisoryId":"PKSA-tgsp-smx2-wtkc","packageName":"cakephp\/queue","remoteId":"GHSA-r5pm-vrc5-3m73","title":"cakephp\/queue\u0027s Incomplete Comparison in getUniqueId vulnerable to collisions","link":"https:\/\/github.com\/advisories\/GHSA-r5pm-vrc5-3m73","cve":"CVE-2026-54713","affectedVersions":"\u003E=0.1.10,\u003C2.3.1","source":"GitHub","reportedAt":"2026-08-27 17:03:56","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-r5pm-vrc5-3m73"}]}],"grumpydictator\/firefly-iii":[{"advisoryId":"PKSA-1kzk-15h2-h7dj","packageName":"grumpydictator\/firefly-iii","remoteId":"GHSA-9mmg-q95p-gp67","title":"Project Firefly III has incorrect access control in the webhook management component","link":"https:\/\/github.com\/advisories\/GHSA-9mmg-q95p-gp67","cve":"CVE-2026-50886","affectedVersions":"\u003C=6.5.9","source":"GitHub","reportedAt":"2026-06-15 21:30:41","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-9mmg-q95p-gp67"}]}],"shlinkio\/shlink":[{"advisoryId":"PKSA-wdxh-t7c7-2k2p","packageName":"shlinkio\/shlink","remoteId":"GHSA-p85r-x2wj-mxqj","title":"shlink has a Server-Side Request Forgery issue","link":"https:\/\/github.com\/advisories\/GHSA-p85r-x2wj-mxqj","cve":"CVE-2026-50887","affectedVersions":"\u003C=5.0.1","source":"GitHub","reportedAt":"2026-06-15 21:30:41","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-p85r-x2wj-mxqj"}]}],"koillection\/koillection":[{"advisoryId":"PKSA-r52z-frv4-qfxy","packageName":"koillection\/koillection","remoteId":"GHSA-gmxh-hjfv-qc2w","title":"Koillection has an authenticated Server-Side Request Forgery issue","link":"https:\/\/github.com\/advisories\/GHSA-gmxh-hjfv-qc2w","cve":"CVE-2026-50888","affectedVersions":"\u003C1.8.4","source":"GitHub","reportedAt":"2026-06-15 21:30:41","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-gmxh-hjfv-qc2w"}]}],"devcode-it\/openstamanager":[{"advisoryId":"PKSA-nvw4-h4ry-dgt3","packageName":"devcode-it\/openstamanager","remoteId":"GHSA-crx4-7mmq-j74j","title":"OpenSTAManager has HTML Injection in modules\/utenti\/edit.php","link":"https:\/\/github.com\/advisories\/GHSA-crx4-7mmq-j74j","cve":"CVE-2026-44701","affectedVersions":"\u003C=2.10.1","source":"GitHub","reportedAt":"2026-08-26 18:12:25","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-crx4-7mmq-j74j"}]}],"librenms\/librenms":[{"advisoryId":"PKSA-pcg8-3qh7-w8k9","packageName":"librenms\/librenms","remoteId":"GHSA-7w8c-qgxg-m7jx","title":"LibreNMS \u2014 Stored XSS via SNMP\/Syslog Data in Legacy Templates","link":"https:\/\/github.com\/advisories\/GHSA-7w8c-qgxg-m7jx","cve":null,"affectedVersions":"\u003C26.5.0","source":"GitHub","reportedAt":"2026-08-26 18:05:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7w8c-qgxg-m7jx"}]},{"advisoryId":"PKSA-m3bp-hsvq-mjs5","packageName":"librenms\/librenms","remoteId":"GHSA-jf24-8g2h-2wg7","title":"LibreNMS Vulnerable to Remote Code Execution via AboutController","link":"https:\/\/github.com\/advisories\/GHSA-jf24-8g2h-2wg7","cve":null,"affectedVersions":"\u003C26.5.0","source":"GitHub","reportedAt":"2026-08-18 21:17:11","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jf24-8g2h-2wg7"}]},{"advisoryId":"PKSA-jmpz-3j3j-881p","packageName":"librenms\/librenms","remoteId":"GHSA-7cj5-v4pp-v632","title":"LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users","link":"https:\/\/github.com\/advisories\/GHSA-7cj5-v4pp-v632","cve":null,"affectedVersions":"\u003C26.7.0","source":"GitHub","reportedAt":"2026-08-18 21:17:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7cj5-v4pp-v632"}]},{"advisoryId":"PKSA-9d1b-7dzj-kkfs","packageName":"librenms\/librenms","remoteId":"GHSA-7gww-x7fh-jf9j","title":"LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page","link":"https:\/\/github.com\/advisories\/GHSA-7gww-x7fh-jf9j","cve":null,"affectedVersions":"\u003C26.7.0","source":"GitHub","reportedAt":"2026-08-18 21:17:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7gww-x7fh-jf9j"}]},{"advisoryId":"PKSA-8dtq-rfyc-264h","packageName":"librenms\/librenms","remoteId":"GHSA-c9fv-cgmm-2wg7","title":"LibreNMS Vulnerable to Remote Code Execution by Signal Alert Transportation module","link":"https:\/\/github.com\/advisories\/GHSA-c9fv-cgmm-2wg7","cve":"CVE-2026-55182","affectedVersions":"\u003E=21.6.0,\u003C26.5.0","source":"GitHub","reportedAt":"2026-08-18 17:59:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c9fv-cgmm-2wg7"}]},{"advisoryId":"PKSA-63gx-s9j2-62yc","packageName":"librenms\/librenms","remoteId":"GHSA-jmqm-f8q4-v7wx","title":"LibreNMS: Reflected XSS via Proxmox instance\/vmid GET parameters injected into document.title JavaScript assignment","link":"https:\/\/github.com\/advisories\/GHSA-jmqm-f8q4-v7wx","cve":"CVE-2026-45694","affectedVersions":"\u003C=26.4.0","source":"GitHub","reportedAt":"2026-08-12 15:16:22","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jmqm-f8q4-v7wx"}]}],"cakephp\/debug_kit":[{"advisoryId":"PKSA-8d84-6pxy-6g1s","packageName":"cakephp\/debug_kit","remoteId":"GHSA-p46m-g734-vpc4","title":"cakephp\/debug_kit: MailPreview contains unsafe reflection","link":"https:\/\/github.com\/advisories\/GHSA-p46m-g734-vpc4","cve":"CVE-2026-54614","affectedVersions":"\u003E=5.0.0,\u003C5.2.4|\u003C4.10.3","source":"GitHub","reportedAt":"2026-08-26 15:31:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-p46m-g734-vpc4"}]}],"microweber\/microweber":[{"advisoryId":"PKSA-y3dv-vpbg-vs2t","packageName":"microweber\/microweber","remoteId":"GHSA-vv4x-qcpq-wgrg","title":"Microweber vulnerable to Path Traversal","link":"https:\/\/github.com\/advisories\/GHSA-vv4x-qcpq-wgrg","cve":"CVE-2026-12198","affectedVersions":"\u003C=2.0.20","source":"GitHub","reportedAt":"2026-06-15 00:31:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vv4x-qcpq-wgrg"}]}],"intelliants\/subrion":[{"advisoryId":"PKSA-9dbm-kft4-ck43","packageName":"intelliants\/subrion","remoteId":"GHSA-wrcg-234w-hfhq","title":"Subrion CMS vulnerable to Cross-site Scripting","link":"https:\/\/github.com\/advisories\/GHSA-wrcg-234w-hfhq","cve":"CVE-2026-12202","affectedVersions":"\u003C=4.0.3","source":"GitHub","reportedAt":"2026-06-15 03:30:32","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-wrcg-234w-hfhq"}]}],"phpmyfaq\/phpmyfaq":[{"advisoryId":"PKSA-g5hk-s1sp-5tnd","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-mf8r-wm2w-f8c5","title":"phpMyFAQ public FAQ APIs expose inactive FAQ content","link":"https:\/\/github.com\/advisories\/GHSA-mf8r-wm2w-f8c5","cve":null,"affectedVersions":"\u003E=4.1.0,\u003C=4.1.4","source":"GitHub","reportedAt":"2026-08-25 17:30:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mf8r-wm2w-f8c5"}]},{"advisoryId":"PKSA-p7rj-kmfh-92s9","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-pg62-f8g4-4wqh","title":"phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold","link":"https:\/\/github.com\/advisories\/GHSA-pg62-f8g4-4wqh","cve":null,"affectedVersions":"\u003C=4.1.4","source":"GitHub","reportedAt":"2026-08-25 17:32:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pg62-f8g4-4wqh"}]},{"advisoryId":"PKSA-wjc4-72dv-h8tm","packageName":"phpmyfaq\/phpmyfaq","remoteId":"GHSA-88g4-74f3-63x9","title":"phpMyFAQ has Potential Authenticated Path Traversal in PDF Export","link":"https:\/\/github.com\/advisories\/GHSA-88g4-74f3-63x9","cve":null,"affectedVersions":"\u003E=4.0.0-alpha,\u003C=4.1.4","source":"GitHub","reportedAt":"2026-08-25 17:28:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-88g4-74f3-63x9"}]}],"thorsten\/phpmyfaq":[{"advisoryId":"PKSA-5ym8-q7sn-cqmx","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-mf8r-wm2w-f8c5","title":"phpMyFAQ public FAQ APIs expose inactive FAQ content","link":"https:\/\/github.com\/advisories\/GHSA-mf8r-wm2w-f8c5","cve":null,"affectedVersions":"\u003E=4.1.0,\u003C=4.1.4","source":"GitHub","reportedAt":"2026-08-25 17:30:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mf8r-wm2w-f8c5"}]},{"advisoryId":"PKSA-hycs-5t33-gw1y","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-pg62-f8g4-4wqh","title":"phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold","link":"https:\/\/github.com\/advisories\/GHSA-pg62-f8g4-4wqh","cve":null,"affectedVersions":"\u003C=4.1.4","source":"GitHub","reportedAt":"2026-08-25 17:32:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pg62-f8g4-4wqh"}]},{"advisoryId":"PKSA-wqvs-f8jk-pt53","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-88g4-74f3-63x9","title":"phpMyFAQ has Potential Authenticated Path Traversal in PDF Export","link":"https:\/\/github.com\/advisories\/GHSA-88g4-74f3-63x9","cve":null,"affectedVersions":"\u003E=4.0.0-alpha,\u003C=4.1.4","source":"GitHub","reportedAt":"2026-08-25 17:28:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-88g4-74f3-63x9"}]},{"advisoryId":"PKSA-cz4f-38kk-4ywj","packageName":"thorsten\/phpmyfaq","remoteId":"GHSA-6pvm-2vjj-rx4w","title":"phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration","link":"https:\/\/github.com\/advisories\/GHSA-6pvm-2vjj-rx4w","cve":"CVE-2026-47132","affectedVersions":"\u003C4.2.0-alpha","source":"GitHub","reportedAt":"2026-08-12 15:17:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-6pvm-2vjj-rx4w"}]}],"in2code\/powermail":[{"advisoryId":"PKSA-dhfp-j236-nf9h","packageName":"in2code\/powermail","remoteId":"in2code\/powermail\/CVE-2026-77136.yaml","title":"TYPO3-EXT-SA-2026-022: Server-Side Template Injection in extension \u0022powermail\u0022 (powermail)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-022","cve":"CVE-2026-77136","affectedVersions":"\u003E=13.0.0,\u003C13.2.1|\u003E=11.0.0,\u003C12.6.1|\u003C10.9.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"in2code\/powermail\/CVE-2026-77136.yaml"}]}],"in2code\/femanager":[{"advisoryId":"PKSA-d8yc-sp4m-wsqx","packageName":"in2code\/femanager","remoteId":"in2code\/femanager\/CVE-2026-77146.yaml","title":"TYPO3-EXT-SA-2026-024: Broken Access Control in extension \u0022femanager\u0022 (femanager)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-024","cve":"CVE-2026-77146","affectedVersions":"\u003E=8.0.0,\u003C8.4.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"in2code\/femanager\/CVE-2026-77146.yaml"}]},{"advisoryId":"PKSA-ys21-4vkn-ktz8","packageName":"in2code\/femanager","remoteId":"in2code\/femanager\/CVE-2026-77133.yaml","title":"TYPO3-EXT-SA-2026-024: Broken Access Control in extension \u0022femanager\u0022 (femanager)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-024","cve":"CVE-2026-77133","affectedVersions":"\u003E=13.0.0,\u003C13.3.5|\u003E=8.0.0,\u003C8.4.2|\u003E=7.0.0,\u003C7.5.5|\u003C6.4.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"in2code\/femanager\/CVE-2026-77133.yaml"}]},{"advisoryId":"PKSA-8rwj-778x-wr3q","packageName":"in2code\/femanager","remoteId":"in2code\/femanager\/CVE-2026-77135.yaml","title":"TYPO3-EXT-SA-2026-024: Information Disclosure in extension \u0022femanager\u0022 (femanager)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-024","cve":"CVE-2026-77135","affectedVersions":"\u003E=13.0.0,\u003C13.3.5|\u003E=8.0.0,\u003C8.4.2|\u003E=7.0.0,\u003C7.5.5|\u003C6.4.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"in2code\/femanager\/CVE-2026-77135.yaml"}]},{"advisoryId":"PKSA-2nc4-qstv-j2k4","packageName":"in2code\/femanager","remoteId":"in2code\/femanager\/CVE-2026-77134.yaml","title":"TYPO3-EXT-SA-2026-024: Broken Access Control in extension \u0022femanager\u0022 (femanager)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-024","cve":"CVE-2026-77134","affectedVersions":"\u003E=13.0.0,\u003C13.3.5|\u003E=8.0.0,\u003C8.4.2|\u003E=7.0.0,\u003C7.5.5|\u003C6.4.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"in2code\/femanager\/CVE-2026-77134.yaml"}]}],"jweiland\/yellowpages2":[{"advisoryId":"PKSA-18gt-2dzk-y4sf","packageName":"jweiland\/yellowpages2","remoteId":"jweiland\/yellowpages2\/CVE-2026-77142.yaml","title":"TYPO3-EXT-SA-2026-020: Broken Access Control in extension \u0022Industry Directory\u0022 (yellowpages2)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-020","cve":"CVE-2026-77142","affectedVersions":"\u003C6.1.6|\u003E=7.0.0,\u003C7.0.3|\u003E=8.0.0,\u003C8.1.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/yellowpages2\/CVE-2026-77142.yaml"}]}],"jweiland\/pforum":[{"advisoryId":"PKSA-j6mc-zgry-j2jj","packageName":"jweiland\/pforum","remoteId":"jweiland\/pforum\/CVE-2026-77143.yaml","title":"TYPO3-EXT-SA-2026-021: Broken Access Control in extension \u0022Forum\u0022 (pforum)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-021","cve":"CVE-2026-77143","affectedVersions":"\u003C4.0.4|\u003E=5.0.0,\u003C5.0.1|\u003E=6.0.0,\u003C6.2.4","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/pforum\/CVE-2026-77143.yaml"}]}],"jweiland\/events2":[{"advisoryId":"PKSA-j7f2-fsqf-djzr","packageName":"jweiland\/events2","remoteId":"jweiland\/events2\/CVE-2026-77145.yaml","title":"TYPO3-EXT-SA-2026-026: Broken Access Control in extension \u0022Events 2\u0022 (events2)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-026","cve":"CVE-2026-77145","affectedVersions":"\u003C8.6.3|\u003E=9.0.0,\u003C9.4.2|\u003E=10.0.0,\u003C10.2.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/events2\/CVE-2026-77145.yaml"}]},{"advisoryId":"PKSA-yh4t-fxmy-jygr","packageName":"jweiland\/events2","remoteId":"jweiland\/events2\/CVE-2026-77144.yaml","title":"TYPO3-EXT-SA-2026-026: Broken Access Control in extension \u0022Events 2\u0022 (events2)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-026","cve":"CVE-2026-77144","affectedVersions":"\u003C8.6.3|\u003E=9.0.0,\u003C9.4.2|\u003E=10.0.0,\u003C10.2.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/events2\/CVE-2026-77144.yaml"}]}],"jweiland\/clubdirectory":[{"advisoryId":"PKSA-zj12-wn7w-mydt","packageName":"jweiland\/clubdirectory","remoteId":"jweiland\/clubdirectory\/CVE-2026-77141.yaml","title":"TYPO3-EXT-SA-2026-019: Broken Access Control in extension \u0022Club Directory\u0022 (clubdirectory)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-019","cve":"CVE-2026-77141","affectedVersions":"\u003C6.0.2|\u003E=7.0.0,\u003C7.0.2|\u003E=8.0.0,\u003C8.1.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/clubdirectory\/CVE-2026-77141.yaml"}]}],"jweiland\/telephonedirectory":[{"advisoryId":"PKSA-kq76-qzx4-zwwk","packageName":"jweiland\/telephonedirectory","remoteId":"jweiland\/telephonedirectory\/CVE-2026-77140.yaml","title":"TYPO3-EXT-SA-2026-018: Broken Access Control in extension \u0022Telephone Directory\u0022 (telephonedirectory)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-018","cve":"CVE-2026-77140","affectedVersions":"\u003C4.1.1|\u003E=5.0.0,\u003C5.0.1|\u003E=6.0.0,\u003C6.2.0","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"jweiland\/telephonedirectory\/CVE-2026-77140.yaml"}]}],"frappant\/frp-form-answers":[{"advisoryId":"PKSA-67bk-g8n5-47sq","packageName":"frappant\/frp-form-answers","remoteId":"frappant\/frp-form-answers\/CVE-2026-77137.yaml","title":"TYPO3-EXT-SA-2026-027: SQL Injection in extension \u0022Forms Export\u0022 (frp_form_answers)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-027","cve":"CVE-2026-77137","affectedVersions":"\u003E=7.0.0,\u003C7.1.1|\u003E=6.0.0,\u003C6.1.3|\u003C5.0.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"frappant\/frp-form-answers\/CVE-2026-77137.yaml"}]}],"derhansen\/sf_event_mgt":[{"advisoryId":"PKSA-zn9v-7dk7-9n62","packageName":"derhansen\/sf_event_mgt","remoteId":"derhansen\/sf_event_mgt\/CVE-2026-77128.yaml","title":"TYPO3-EXT-SA-2026-023: Broken Access Control in extension \u0022Event management and registration\u0022 (sf_event_mgt)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-023","cve":"CVE-2026-77128","affectedVersions":"\u003E=9.0.0,\u003C9.0.3|\u003E=8.0.0,\u003C8.6.2|\u003E=7.0.0,\u003C7.9.3|\u003E=6.0.0,\u003C6.7.2|\u003C5.9.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"derhansen\/sf_event_mgt\/CVE-2026-77128.yaml"}]},{"advisoryId":"PKSA-xn4n-zch1-3zsy","packageName":"derhansen\/sf_event_mgt","remoteId":"derhansen\/sf_event_mgt\/CVE-2026-77129.yaml","title":"TYPO3-EXT-SA-2026-023: Server-Side Template Injection in extension \u0022Event management and registration\u0022 (sf_event_mgt)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-023","cve":"CVE-2026-77129","affectedVersions":"\u003E=9.0.0,\u003C9.0.3|\u003E=8.0.0,\u003C8.6.2|\u003E=7.0.0,\u003C7.9.3|\u003E=6.0.0,\u003C6.7.2|\u003C5.9.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"derhansen\/sf_event_mgt\/CVE-2026-77129.yaml"}]}],"apache-solr-for-typo3\/solr":[{"advisoryId":"PKSA-f58b-fgg4-r9xs","packageName":"apache-solr-for-typo3\/solr","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56093.yaml","title":"TYPO3-EXT-SA-2026-025: Broken Access Control in extension \u0022Apache Solr for TYPO3 - Enterprise Search\u0022 (solr)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-025","cve":"CVE-2026-56093","affectedVersions":"\u003E=13.0.0,\u003C13.1.4|\u003E=12.0.0,\u003C12.1.4|\u003C11.6.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56093.yaml"}]},{"advisoryId":"PKSA-h6s2-79xk-1xwg","packageName":"apache-solr-for-typo3\/solr","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56092.yaml","title":"TYPO3-EXT-SA-2026-025: Broken Access Control in extension \u0022Apache Solr for TYPO3 - Enterprise Search\u0022 (solr)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-025","cve":"CVE-2026-56092","affectedVersions":"\u003E=13.0.0,\u003C13.1.4|\u003E=12.0.0,\u003C12.1.4|\u003C11.6.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56092.yaml"}]},{"advisoryId":"PKSA-nmhg-n7vm-6z1n","packageName":"apache-solr-for-typo3\/solr","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56095.yaml","title":"TYPO3-EXT-SA-2026-025: Insecure Deserialization in extension \u0022Apache Solr for TYPO3 - Enterprise Search\u0022 (solr)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-025","cve":"CVE-2026-56095","affectedVersions":"\u003E=13.0.0,\u003C13.1.4|\u003E=12.0.0,\u003C12.1.4|\u003C11.6.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56095.yaml"}]},{"advisoryId":"PKSA-218x-ph2q-d2nf","packageName":"apache-solr-for-typo3\/solr","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56096.yaml","title":"TYPO3-EXT-SA-2026-025: Information Disclosure in extension \u0022Apache Solr for TYPO3 - Enterprise Search\u0022 (solr)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-025","cve":"CVE-2026-56096","affectedVersions":"\u003E=13.0.0,\u003C13.1.4|\u003E=12.0.0,\u003C12.1.4|\u003C11.6.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56096.yaml"}]},{"advisoryId":"PKSA-xyyb-y2c3-k558","packageName":"apache-solr-for-typo3\/solr","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56094.yaml","title":"TYPO3-EXT-SA-2026-025: Information Disclosure in extension \u0022Apache Solr for TYPO3 - Enterprise Search\u0022 (solr)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-025","cve":"CVE-2026-56094","affectedVersions":"\u003E=13.0.0,\u003C13.1.4|\u003E=12.0.0,\u003C12.1.4|\u003C11.6.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"apache-solr-for-typo3\/solr\/CVE-2026-56094.yaml"}]}],"mask\/mask":[{"advisoryId":"PKSA-vwmg-xq1p-q4cz","packageName":"mask\/mask","remoteId":"mask\/mask\/CVE-2026-77139.yaml","title":"TYPO3-EXT-SA-2026-017: Path Traversal in extension \u0022Mask\u0022 (mask)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-017","cve":"CVE-2026-77139","affectedVersions":"\u003E=9.0.0,\u003C9.0.11|\u003C8.3.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"mask\/mask\/CVE-2026-77139.yaml"}]}],"syssy\/syssy-typo3-extension":[{"advisoryId":"PKSA-p17b-6gjj-m8kp","packageName":"syssy\/syssy-typo3-extension","remoteId":"syssy\/syssy-typo3-extension\/CVE-2026-77131.yaml","title":"TYPO3-EXT-SA-2026-015: Cleartext Transmission of Sensitive Information in extension \u0022SYSSY - TYPO3 Monitoring \u0026 Security Checks\u0022 (syssy)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-015","cve":"CVE-2026-77131","affectedVersions":"\u003C3.0.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"syssy\/syssy-typo3-extension\/CVE-2026-77131.yaml"}]},{"advisoryId":"PKSA-xf71-q2f9-j6qg","packageName":"syssy\/syssy-typo3-extension","remoteId":"syssy\/syssy-typo3-extension\/CVE-2026-77130.yaml","title":"TYPO3-EXT-SA-2026-015: Insufficient Session Expiration in extension \u0022SYSSY - TYPO3 Monitoring \u0026 Security Checks\u0022 (syssy)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-015","cve":"CVE-2026-77130","affectedVersions":"\u003C3.0.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"syssy\/syssy-typo3-extension\/CVE-2026-77130.yaml"}]}],"codingms\/modules":[{"advisoryId":"PKSA-8bb5-r84n-24n7","packageName":"codingms\/modules","remoteId":"codingms\/modules\/CVE-2026-77127.yaml","title":"TYPO3-EXT-SA-2026-016: Information Disclosure in extension \u0022Modules\u0022 (modules)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-016","cve":"CVE-2026-77127","affectedVersions":"\u003E=8.0.0,\u003C8.1.4|\u003C7.10.4","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 09:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"codingms\/modules\/CVE-2026-77127.yaml"}]}],"lochmueller\/html5videoplayer-powermail":[{"advisoryId":"PKSA-6xxy-q4qw-wtq1","packageName":"lochmueller\/html5videoplayer-powermail","remoteId":"lochmueller\/html5videoplayer-powermail\/CVE-2026-77138.yaml","title":"TYPO3-EXT-SA-2026-014: Remote Code Execution in extension \u0022HTML5 Video Player vs. Powermail\u0022 (html5videoplayer_powermail)","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-ext-sa-2026-014","cve":"CVE-2026-77138","affectedVersions":"\u003C=0.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-01-01 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"lochmueller\/html5videoplayer-powermail\/CVE-2026-77138.yaml"}]}],"contao-components\/colorbox":[{"advisoryId":"PKSA-vz5f-wd4z-2kf4","packageName":"contao-components\/colorbox","remoteId":"contao-components\/colorbox\/2026-08-25.yaml","title":"Cross-site scripting in the Colorbox caption (see GHSA-rr85-7j77-pppg)","link":"https:\/\/github.com\/contao-components\/colorbox\/security\/advisories\/GHSA-rr85-7j77-pppg","cve":null,"affectedVersions":"\u003E=1.0.0,\u003C1.6.4.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao-components\/colorbox\/2026-08-25.yaml"}]}],"contao\/comments-bundle":[{"advisoryId":"PKSA-xbg5-kkqv-jb9y","packageName":"contao\/comments-bundle","remoteId":"contao\/comments-bundle\/2026-08-25.yaml","title":"Cross-site scripting in the comments bundle (see GHSA-628f-v4f6-p37r)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-scripting-in-the-comments-bundle","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/comments-bundle\/2026-08-25.yaml"}]}],"contao\/contao":[{"advisoryId":"PKSA-6gsv-pjvq-z35p","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-5.yaml","title":"Improper access control in the preview links module (see GHSA-q6wp-fr43-gm9v)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-preview-links-module","cve":null,"affectedVersions":"\u003E=5.7.1,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-5.yaml"}]},{"advisoryId":"PKSA-rfnv-mh54-2pc9","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-2.yaml","title":"Improper access control in the CSV import wizard (see GHSA-23w9-4pg3-xwm3)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-csv-import-wizard","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-2.yaml"}]},{"advisoryId":"PKSA-2s8k-hn9c-bkvy","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-6.yaml","title":"Path traversal in the images controller (see GHSA-mrvp-7wmx-5m4h)","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-images-controller","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-6.yaml"}]},{"advisoryId":"PKSA-vy31-xjc7-3g2h","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-9.yaml","title":"Exposure of sensitive information through a stale search index (see GHSA-x2rp-9qf7-2fmq)","link":"https:\/\/contao.org\/en\/security-advisories\/exposure-of-sensitive-information-through-a-stale-search-index","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-9.yaml"}]},{"advisoryId":"PKSA-8zc2-xpjt-dfrb","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-7.yaml","title":"Cross-site request forgery in custom backend actions (see GHSA-9ff2-p842-45wq)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-request-forgery-in-custom-backend-actions","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-7.yaml"}]},{"advisoryId":"PKSA-3fqv-nq39-s3wg","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-10.yaml","title":"Cross-site scripting in the comments bundle (see GHSA-628f-v4f6-p37r)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-scripting-in-the-comments-bundle","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-10.yaml"}]},{"advisoryId":"PKSA-nqyj-w4wy-fs47","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-3.yaml","title":"Non-admin users can self-grant permissions that implicitly make them administrators (see GHSA-r9qp-pqx5-8369)","link":"https:\/\/contao.org\/en\/security-advisories\/non-admin-users-can-self-grant-permissions-that-implicitly-make-them-administrators","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-3.yaml"}]},{"advisoryId":"PKSA-ws7m-s1y9-vkw6","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-11.yaml","title":"Improper access control in the newsletter module (see GHSA-3r9g-pfhv-3228)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-newsletter-module","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-11.yaml"}]},{"advisoryId":"PKSA-dtqn-wjcr-pw7c","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-8.yaml","title":"Unrestricted activation email resending (see GHSA-mfxh-vp55-7gc6)","link":"https:\/\/contao.org\/en\/security-advisories\/unrestricted-activation-email-resending","cve":null,"affectedVersions":"\u003E=4.1.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-8.yaml"}]},{"advisoryId":"PKSA-ncw3-bhm6-s2mg","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-4.yaml","title":"Cross-site scripting in the frontend search results (see GHSA-h57j-5f5m-789v)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-scripting-in-the-frontend-search-results","cve":null,"affectedVersions":"\u003E=4.9.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-4.yaml"}]},{"advisoryId":"PKSA-vtsh-c9df-2j1j","packageName":"contao\/contao","remoteId":"contao\/contao\/2026-08-25-1.yaml","title":"Improper access control in the table access voter (see GHSA-5974-gfqc-wrcm)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-table-access-voter","cve":null,"affectedVersions":"\u003E=5.7.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/2026-08-25-1.yaml"}]},{"advisoryId":"PKSA-55tn-sgd6-9twh","packageName":"contao\/contao","remoteId":"contao\/contao\/CVE-2026-57232.yaml","title":"Server-side request forgery (SSRF) via unvalidated RSS feed URLs","link":"https:\/\/contao.org\/en\/security-advisories\/server-side-request-forgery-via-unvalidated-rss-feed-urls","cve":"CVE-2026-57232","affectedVersions":"\u003E=5.3.35,\u003C5.3.48|\u003E=5.4.0,\u003C5.7.9","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-13 09:10:22","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/CVE-2026-57232.yaml"}]},{"advisoryId":"PKSA-8pr1-zw9p-tzyx","packageName":"contao\/contao","remoteId":"contao\/contao\/CVE-2026-55824.yaml","title":"Credentials disclosure in the crawler","link":"https:\/\/contao.org\/en\/security-advisories\/credentials-disclosure-in-the-crawler","cve":"CVE-2026-55824","affectedVersions":"\u003E=4.13.0,\u003C5.3.47|\u003E=5.4.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/CVE-2026-55824.yaml"},{"name":"GitHub","remoteId":"GHSA-3mr9-p497-58f6"}]},{"advisoryId":"PKSA-311q-qrt9-s2k4","packageName":"contao\/contao","remoteId":"contao\/contao\/CVE-2026-55825.yaml","title":"Path traversal in the jobs module","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-jobs-module","cve":"CVE-2026-55825","affectedVersions":"\u003E=5.7.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/CVE-2026-55825.yaml"},{"name":"GitHub","remoteId":"GHSA-grm4-wm43-9jh5"}]}],"contao\/core-bundle":[{"advisoryId":"PKSA-yksm-8fg2-dsvs","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-5.yaml","title":"Improper access control in the preview links module (see GHSA-q6wp-fr43-gm9v)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-preview-links-module","cve":null,"affectedVersions":"\u003E=5.7.1,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-5.yaml"}]},{"advisoryId":"PKSA-t5k3-41dk-f7y5","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-2.yaml","title":"Improper access control in the CSV import wizard (see GHSA-23w9-4pg3-xwm3)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-csv-import-wizard","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-2.yaml"}]},{"advisoryId":"PKSA-zm5t-426r-gfpx","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-6.yaml","title":"Path traversal in the images controller (see GHSA-mrvp-7wmx-5m4h)","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-images-controller","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-6.yaml"}]},{"advisoryId":"PKSA-cvfh-n5dv-w5t9","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-9.yaml","title":"Exposure of sensitive information through a stale search index (see GHSA-x2rp-9qf7-2fmq)","link":"https:\/\/contao.org\/en\/security-advisories\/exposure-of-sensitive-information-through-a-stale-search-index","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-9.yaml"}]},{"advisoryId":"PKSA-4788-1fwx-c4gc","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-7.yaml","title":"Cross-site request forgery in custom backend actions (see GHSA-9ff2-p842-45wq)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-request-forgery-in-custom-backend-actions","cve":null,"affectedVersions":"\u003E=4.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-7.yaml"}]},{"advisoryId":"PKSA-335s-36s8-mdj4","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-3.yaml","title":"Non-admin users can self-grant permissions that implicitly make them administrators (see GHSA-r9qp-pqx5-8369)","link":"https:\/\/contao.org\/en\/security-advisories\/non-admin-users-can-self-grant-permissions-that-implicitly-make-them-administrators","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-3.yaml"}]},{"advisoryId":"PKSA-wrr4-414y-fqmj","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-8.yaml","title":"Unrestricted activation email resending (see GHSA-mfxh-vp55-7gc6)","link":"https:\/\/contao.org\/en\/security-advisories\/unrestricted-activation-email-resending","cve":null,"affectedVersions":"\u003E=4.1.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-8.yaml"}]},{"advisoryId":"PKSA-snk8-7c3n-1x4z","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-4.yaml","title":"Cross-site scripting in the frontend search results (see GHSA-h57j-5f5m-789v)","link":"https:\/\/contao.org\/en\/security-advisories\/cross-site-scripting-in-the-frontend-search-results","cve":null,"affectedVersions":"\u003E=4.9.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-4.yaml"}]},{"advisoryId":"PKSA-xtw6-fy62-6vn3","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/2026-08-25-1.yaml","title":"Improper access control in the table access voter (see GHSA-5974-gfqc-wrcm)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-table-access-voter","cve":null,"affectedVersions":"\u003E=5.7.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/2026-08-25-1.yaml"}]},{"advisoryId":"PKSA-yx24-z15d-x2k7","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/CVE-2026-57232.yaml","title":"Server-side request forgery (SSRF) via unvalidated RSS feed URLs","link":"https:\/\/contao.org\/en\/security-advisories\/server-side-request-forgery-via-unvalidated-rss-feed-urls","cve":"CVE-2026-57232","affectedVersions":"\u003E=5.3.35,\u003C5.3.48|\u003E=5.4.0,\u003C5.7.9","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-13 09:10:22","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/CVE-2026-57232.yaml"}]},{"advisoryId":"PKSA-f8tt-pn3h-s2tw","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/CVE-2026-55824.yaml","title":"Credentials disclosure in the crawler","link":"https:\/\/contao.org\/en\/security-advisories\/credentials-disclosure-in-the-crawler","cve":"CVE-2026-55824","affectedVersions":"\u003E=4.13.0,\u003C5.3.47|\u003E=5.4.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/CVE-2026-55824.yaml"},{"name":"GitHub","remoteId":"GHSA-3mr9-p497-58f6"}]},{"advisoryId":"PKSA-4ps2-832y-6pns","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/CVE-2026-55825.yaml","title":"Path traversal in the jobs module","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-jobs-module","cve":"CVE-2026-55825","affectedVersions":"\u003E=5.7.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/CVE-2026-55825.yaml"},{"name":"GitHub","remoteId":"GHSA-grm4-wm43-9jh5"}]}],"contao\/newsletter-bundle":[{"advisoryId":"PKSA-r5wh-6cgq-ck8m","packageName":"contao\/newsletter-bundle","remoteId":"contao\/newsletter-bundle\/2026-08-25.yaml","title":"Improper access control in the newsletter module (see GHSA-3r9g-pfhv-3228)","link":"https:\/\/contao.org\/en\/security-advisories\/improper-access-control-in-the-newsletter-module","cve":null,"affectedVersions":"\u003E=5.0.0,\u003C5.3.50|\u003E=5.4.0,\u003C5.7.12","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-25 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/newsletter-bundle\/2026-08-25.yaml"}]}],"yourls\/yourls":[{"advisoryId":"PKSA-v9p2-y9c7-y991","packageName":"yourls\/yourls","remoteId":"GHSA-5h77-88j3-r659","title":"YOURLS has stored XSS in referrer statistics chart via crafted Referer header","link":"https:\/\/github.com\/advisories\/GHSA-5h77-88j3-r659","cve":"CVE-2026-63135","affectedVersions":"\u003E=1.5.1,\u003C=1.10.3","source":"GitHub","reportedAt":"2026-08-21 20:57:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5h77-88j3-r659"}]}],"backpack\/crud":[{"advisoryId":"PKSA-1hj4-7f8v-mbzt","packageName":"backpack\/crud","remoteId":"GHSA-42vx-43vc-x6pr","title":"Laravel Backpack CRUD: HasMany\/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelation","link":"https:\/\/github.com\/advisories\/GHSA-42vx-43vc-x6pr","cve":"CVE-2026-57570","affectedVersions":"\u003E=6.0.0,\u003C6.8.15|\u003E=7.0.0,\u003C7.0.47","source":"GitHub","reportedAt":"2026-08-20 18:42:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-42vx-43vc-x6pr"}]},{"advisoryId":"PKSA-x88v-wcq5-j3kt","packageName":"backpack\/crud","remoteId":"GHSA-xpv2-hrfc-hw62","title":"Laravel Backpack CRUD: Unverified password change in MyAccountController via mass assignment","link":"https:\/\/github.com\/advisories\/GHSA-xpv2-hrfc-hw62","cve":"CVE-2026-54175","affectedVersions":"\u003E=7.0.0-alpha.1,\u003C7.0.34|\u003C6.8.11","source":"GitHub","reportedAt":"2026-08-20 18:38:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xpv2-hrfc-hw62"}]},{"advisoryId":"PKSA-wb9h-r8p2-f7xj","packageName":"backpack\/crud","remoteId":"GHSA-9fw9-8c49-qch8","title":"Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check","link":"https:\/\/github.com\/advisories\/GHSA-9fw9-8c49-qch8","cve":"CVE-2026-54176","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9fw9-8c49-qch8"}]},{"advisoryId":"PKSA-4pjj-nc36-rj91","packageName":"backpack\/crud","remoteId":"GHSA-8q2w-pv9p-mjvc","title":"Laravel Backpack CRUD: HasUploadFields keeps the attacker-supplied file extension \u2014 public-disk uploads of `shell.php` reach the webserver","link":"https:\/\/github.com\/advisories\/GHSA-8q2w-pv9p-mjvc","cve":"CVE-2026-54177","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8q2w-pv9p-mjvc"}]},{"advisoryId":"PKSA-kbc2-vykn-d61h","packageName":"backpack\/crud","remoteId":"GHSA-8xjm-wqrp-2f25","title":"Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_\u003Cattr\u003E[] in HasUploadFields::uploadMultipleFilesToDisk","link":"https:\/\/github.com\/advisories\/GHSA-8xjm-wqrp-2f25","cve":"CVE-2026-54178","affectedVersions":"\u003E=7.0.0,\u003C7.0.35|\u003E=6.0.0,\u003C6.8.12|\u003E=5.0.0,\u003C6.0.0","source":"GitHub","reportedAt":"2026-08-20 18:38:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8xjm-wqrp-2f25"}]},{"advisoryId":"PKSA-gr8y-xsj7-jw48","packageName":"backpack\/crud","remoteId":"GHSA-8hw4-7qjr-3wxg","title":"Laravel Backpack CRUD: SingleBase64Image accepts any base64 payload behind a `data:image` prefix \u2014 SVG-with-script lands on the public disk","link":"https:\/\/github.com\/advisories\/GHSA-8hw4-7qjr-3wxg","cve":"CVE-2026-54179","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8hw4-7qjr-3wxg"}]},{"advisoryId":"PKSA-s7xs-gg49-zwxc","packageName":"backpack\/crud","remoteId":"GHSA-vgmv-8xjc-6rch","title":"Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)","link":"https:\/\/github.com\/advisories\/GHSA-vgmv-8xjc-6rch","cve":"CVE-2026-54180","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vgmv-8xjc-6rch"}]},{"advisoryId":"PKSA-5phc-pmxf-y81y","packageName":"backpack\/crud","remoteId":"GHSA-mmg4-322v-6jvc","title":"Laravel Backpack CRUD: Stored XSS in the color column \u2014 the `@if($column[\u0027escaped\u0027])` branches are inverted","link":"https:\/\/github.com\/advisories\/GHSA-mmg4-322v-6jvc","cve":"CVE-2026-54181","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mmg4-322v-6jvc"}]},{"advisoryId":"PKSA-qrrt-7bj6-f81q","packageName":"backpack\/crud","remoteId":"GHSA-mrc5-3mm3-45c5","title":"Laravel Backpack CRUD: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)","link":"https:\/\/github.com\/advisories\/GHSA-mrc5-3mm3-45c5","cve":"CVE-2026-54182","affectedVersions":"\u003E=7.0.0,\u003C7.0.36|\u003E=6.0.0,\u003C6.8.13|\u003E=5.0.0,\u003C5.6.2|\u003E=4.1.0,\u003C4.1.72","source":"GitHub","reportedAt":"2026-08-20 18:38:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mrc5-3mm3-45c5"}]}],"winter\/wn-system-module":[{"advisoryId":"PKSA-xv7p-39zk-tqqd","packageName":"winter\/wn-system-module","remoteId":"GHSA-2223-f22x-24cq","title":"Winter: Local File Inclusion through =include directives in JavaScript asset compilation","link":"https:\/\/github.com\/advisories\/GHSA-2223-f22x-24cq","cve":null,"affectedVersions":"\u003C1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2223-f22x-24cq"}]},{"advisoryId":"PKSA-wtw3-z7vh-tcrk","packageName":"winter\/wn-system-module","remoteId":"GHSA-8cfw-pcwh-v63w","title":"Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)","link":"https:\/\/github.com\/advisories\/GHSA-8cfw-pcwh-v63w","cve":null,"affectedVersions":"\u003E=1.2.7,\u003C1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8cfw-pcwh-v63w"}]}],"winter\/wn-backend-module":[{"advisoryId":"PKSA-54hz-1x12-hy82","packageName":"winter\/wn-backend-module","remoteId":"GHSA-58fp-mcx6-7qf9","title":"Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets","link":"https:\/\/github.com\/advisories\/GHSA-58fp-mcx6-7qf9","cve":"CVE-2026-63179","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-20 18:43:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-58fp-mcx6-7qf9"}]},{"advisoryId":"PKSA-b1tx-fpj9-bp5n","packageName":"winter\/wn-backend-module","remoteId":"GHSA-7mpf-4465-7fc2","title":"Winter: Stored XSS through Backend List widget image columns","link":"https:\/\/github.com\/advisories\/GHSA-7mpf-4465-7fc2","cve":null,"affectedVersions":"\u003E=1.1.0,\u003C1.2.14","source":"GitHub","reportedAt":"2026-08-20 18:44:41","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7mpf-4465-7fc2"}]},{"advisoryId":"PKSA-g4kv-c5yp-h2rm","packageName":"winter\/wn-backend-module","remoteId":"GHSA-mpmw-f6h6-3g26","title":"Winter: My Account preview exposes another backend user\u0027s profile by record ID","link":"https:\/\/github.com\/advisories\/GHSA-mpmw-f6h6-3g26","cve":null,"affectedVersions":"=1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mpmw-f6h6-3g26"}]},{"advisoryId":"PKSA-kk7w-bn2w-32z8","packageName":"winter\/wn-backend-module","remoteId":"GHSA-fm29-4mq3-phg6","title":"Winter: ImportExportController AJAX handlers bypass granular import\/export permission gate","link":"https:\/\/github.com\/advisories\/GHSA-fm29-4mq3-phg6","cve":null,"affectedVersions":"\u003C=1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fm29-4mq3-phg6"}]},{"advisoryId":"PKSA-qr5m-g14w-86df","packageName":"winter\/wn-backend-module","remoteId":"GHSA-5cwr-5jxg-pcf6","title":"Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles","link":"https:\/\/github.com\/advisories\/GHSA-5cwr-5jxg-pcf6","cve":null,"affectedVersions":"\u003C=1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5cwr-5jxg-pcf6"}]},{"advisoryId":"PKSA-r35b-91gt-bn2p","packageName":"winter\/wn-backend-module","remoteId":"GHSA-p2ch-c2c3-4xm5","title":"Winter: CSRF through AJAX handler names reachable as backend page actions","link":"https:\/\/github.com\/advisories\/GHSA-p2ch-c2c3-4xm5","cve":null,"affectedVersions":"\u003E=1.0.319,\u003C1.2.14","source":"GitHub","reportedAt":"2026-08-20 18:44:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-p2ch-c2c3-4xm5"}]},{"advisoryId":"PKSA-5ts5-4cbq-8ssk","packageName":"winter\/wn-backend-module","remoteId":"GHSA-hq84-x37p-j6q5","title":"Winter: Reflected XSS through the search query parameter in the backend Table widget","link":"https:\/\/github.com\/advisories\/GHSA-hq84-x37p-j6q5","cve":null,"affectedVersions":"\u003E=1.0.420,\u003C=1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:45:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hq84-x37p-j6q5"}]},{"advisoryId":"PKSA-dbvq-twhc-nj83","packageName":"winter\/wn-backend-module","remoteId":"GHSA-3277-h8g9-qj5f","title":"Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata","link":"https:\/\/github.com\/advisories\/GHSA-3277-h8g9-qj5f","cve":"CVE-2026-54256","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-20 18:39:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3277-h8g9-qj5f"}]},{"advisoryId":"PKSA-kh9g-dm85-trgm","packageName":"winter\/wn-backend-module","remoteId":"GHSA-j5jq-cr68-v2xx","title":"Winter: Authenticated backend users can bypass Users controller permission checks","link":"https:\/\/github.com\/advisories\/GHSA-j5jq-cr68-v2xx","cve":"CVE-2026-35445","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-12 15:15:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j5jq-cr68-v2xx"}]},{"advisoryId":"PKSA-8fbj-xdrm-f43z","packageName":"winter\/wn-backend-module","remoteId":"GHSA-v7cf-8gh9-gxmj","title":"Winter: Stored XSS through Brand Settings custom styles","link":"https:\/\/github.com\/advisories\/GHSA-v7cf-8gh9-gxmj","cve":"CVE-2026-32257","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-12 14:40:21","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v7cf-8gh9-gxmj"}]},{"advisoryId":"PKSA-g651-qxh9-xb57","packageName":"winter\/wn-backend-module","remoteId":"GHSA-vgp4-2fc4-qff2","title":"Winter: Stored XSS through Editor Settings custom styles","link":"https:\/\/github.com\/advisories\/GHSA-vgp4-2fc4-qff2","cve":"CVE-2026-32258","affectedVersions":"\u003E=1.2.10,\u003C1.2.13","source":"GitHub","reportedAt":"2026-08-12 14:40:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vgp4-2fc4-qff2"}]},{"advisoryId":"PKSA-rw8y-31yz-4tck","packageName":"winter\/wn-backend-module","remoteId":"GHSA-m7jc-g4rc-jmvh","title":"Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax","link":"https:\/\/github.com\/advisories\/GHSA-m7jc-g4rc-jmvh","cve":"CVE-2026-32593","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-12 14:41:13","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m7jc-g4rc-jmvh"}]}],"mineadmin\/mineadmin":[{"advisoryId":"PKSA-56hm-hvjp-d16p","packageName":"mineadmin\/mineadmin","remoteId":"GHSA-59xm-4m8c-g3xj","title":"MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install\/Uninstall","link":"https:\/\/github.com\/advisories\/GHSA-59xm-4m8c-g3xj","cve":"CVE-2026-55224","affectedVersions":"\u003C3.2.0-alpha.2","source":"GitHub","reportedAt":"2026-08-18 20:40:37","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-59xm-4m8c-g3xj"}]}],"froxlor\/froxlor":[{"advisoryId":"PKSA-nrnn-2mjw-x29c","packageName":"froxlor\/froxlor","remoteId":"GHSA-43gm-9rr3-cx7g","title":"Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover","link":"https:\/\/github.com\/advisories\/GHSA-43gm-9rr3-cx7g","cve":"CVE-2026-54347","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2026-08-18 20:47:53","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-43gm-9rr3-cx7g"}]},{"advisoryId":"PKSA-tbmy-ntqq-5hz6","packageName":"froxlor\/froxlor","remoteId":"GHSA-w27m-rmmf-g5w4","title":"Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration","link":"https:\/\/github.com\/advisories\/GHSA-w27m-rmmf-g5w4","cve":"CVE-2026-54348","affectedVersions":"\u003C2.3.8","source":"GitHub","reportedAt":"2026-08-18 20:47:59","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w27m-rmmf-g5w4"}]},{"advisoryId":"PKSA-prvy-3kk5-2fyv","packageName":"froxlor\/froxlor","remoteId":"GHSA-5rw4-4665-cvwf","title":"Froxlor DomainZones.add allows DNS zone-file RR injection via record\/type fields","link":"https:\/\/github.com\/advisories\/GHSA-5rw4-4665-cvwf","cve":"CVE-2026-54543","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2026-08-18 20:48:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5rw4-4665-cvwf"}]},{"advisoryId":"PKSA-2y9n-tpcf-96wh","packageName":"froxlor\/froxlor","remoteId":"GHSA-xpr4-8vp6-c87j","title":"Froxlor has CSRF Vulnerability in AJAX Endpoint \u2014 Missing Cross-Site Request Forgery Protection","link":"https:\/\/github.com\/advisories\/GHSA-xpr4-8vp6-c87j","cve":"CVE-2026-55593","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2026-08-18 20:48:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xpr4-8vp6-c87j"}]},{"advisoryId":"PKSA-bk7h-s9s3-p5rt","packageName":"froxlor\/froxlor","remoteId":"GHSA-7788-ghfq-c6mh","title":"Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints","link":"https:\/\/github.com\/advisories\/GHSA-7788-ghfq-c6mh","cve":"CVE-2026-62988","affectedVersions":"\u003C2.3.8","source":"GitHub","reportedAt":"2026-08-18 20:48:35","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-7788-ghfq-c6mh"}]}],"paragonie\/sodium_compat":[{"advisoryId":"PKSA-32g2-byr9-drtw","packageName":"paragonie\/sodium_compat","remoteId":"paragonie\/sodium_compat\/2026-08-18.yaml","title":"Incorrect Ed25519 public key validation","link":"https:\/\/github.com\/paragonie\/sodium_compat\/pull\/206","cve":null,"affectedVersions":"\u003E=2,\u003C2.5.1|\u003C1.24.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-18 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"paragonie\/sodium_compat\/2026-08-18.yaml"}]}],"mcp\/sdk":[{"advisoryId":"PKSA-p9gd-j6gr-6f9t","packageName":"mcp\/sdk","remoteId":"mcp\/sdk\/CVE-2026-53965.yaml","title":"Client HttpTransport SSE buffer grows unbounded when server withholds the event delimiter","link":"https:\/\/github.com\/modelcontextprotocol\/php-sdk\/security\/advisories\/GHSA-7m52-jw36-44r3","cve":"CVE-2026-53965","affectedVersions":"\u003E=0.5.0,\u003C0.7.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-14 06:19:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7m52-jw36-44r3"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"mcp\/sdk\/CVE-2026-53965.yaml"}]}],"plank\/laravel-mediable":[{"advisoryId":"PKSA-7xqc-8t8n-q551","packageName":"plank\/laravel-mediable","remoteId":"GHSA-xv8g-76mx-2rxc","title":"Laravel-Mediable: path traversal vulnerability in the File::sanitizePath()","link":"https:\/\/github.com\/advisories\/GHSA-xv8g-76mx-2rxc","cve":"CVE-2026-49970","affectedVersions":"\u003C7.0.0","source":"GitHub","reportedAt":"2026-07-13 21:31:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xv8g-76mx-2rxc"}]}],"typo3\/cms-core":[{"advisoryId":"PKSA-hf64-fs5s-6k3h","packageName":"typo3\/cms-core","remoteId":"typo3\/cms-core\/CVE-2026-19418.yaml","title":"TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-core-sa-2026-021","cve":"CVE-2026-19418","affectedVersions":"\u003E=13.0.0,\u003C13.4.34|\u003E=14.0.0,\u003C14.3.6","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-11 09:00:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-68jx-f42c-7599"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-core\/CVE-2026-19418.yaml"}]}],"concrete5\/concrete5":[{"advisoryId":"PKSA-bm9s-qzpp-vx3v","packageName":"concrete5\/concrete5","remoteId":"GHSA-g82f-9pw7-773w","title":"Concrete CMS: PHP Object Injection via\u00a0unserialize()\u00a0calls","link":"https:\/\/github.com\/advisories\/GHSA-g82f-9pw7-773w","cve":"CVE-2026-10721","affectedVersions":"\u003C9.5.2","source":"GitHub","reportedAt":"2026-06-10 09:31:57","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g82f-9pw7-773w"}]},{"advisoryId":"PKSA-93vh-t1hn-q1kn","packageName":"concrete5\/concrete5","remoteId":"GHSA-52pr-7vmf-2w7x","title":"Concrete CMS is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File\/Set components","link":"https:\/\/github.com\/advisories\/GHSA-52pr-7vmf-2w7x","cve":"CVE-2026-7888","affectedVersions":"\u003C9.5.2","source":"GitHub","reportedAt":"2026-06-03 21:30:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-52pr-7vmf-2w7x"}]}],"buddypress\/buddypress":[{"advisoryId":"PKSA-16rx-1nsm-bg1c","packageName":"buddypress\/buddypress","remoteId":"GHSA-wmjr-58rf-xgrc","title":"BuddyPress: Any authenticated attacker can enumerate another user\u0027s complete friend list via IDOR","link":"https:\/\/github.com\/advisories\/GHSA-wmjr-58rf-xgrc","cve":"CVE-2026-53675","affectedVersions":"\u003C=14.4.0","source":"GitHub","reportedAt":"2026-06-10 00:31:53","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wmjr-58rf-xgrc"}]},{"advisoryId":"PKSA-dkkm-zjdb-8pmc","packageName":"buddypress\/buddypress","remoteId":"GHSA-j3j5-5m8v-7gvc","title":"BuddyPress: Authenticated attackers can access arbitrary private message threads via user_id request parameter","link":"https:\/\/github.com\/advisories\/GHSA-j3j5-5m8v-7gvc","cve":"CVE-2026-53673","affectedVersions":"\u003C14.5.0","source":"GitHub","reportedAt":"2026-06-10 00:31:53","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-j3j5-5m8v-7gvc"}]}],"winter\/wn-cms-module":[{"advisoryId":"PKSA-m75m-ptnr-6hhr","packageName":"winter\/wn-cms-module","remoteId":"GHSA-5c4f-9pq9-6c77","title":"Winter: Broken access control in `Cms\\Controllers\\Index` allows cross-template actions and unauthorized asset uploads","link":"https:\/\/github.com\/advisories\/GHSA-5c4f-9pq9-6c77","cve":"CVE-2026-32639","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-12 15:14:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5c4f-9pq9-6c77"}]}],"easycorp\/easyadmin-bundle":[{"advisoryId":"PKSA-7ck7-y4vp-mmcz","packageName":"easycorp\/easyadmin-bundle","remoteId":"easycorp\/easyadmin-bundle\/CVE-2026-81892.yaml","title":"Custom action dispatcher bypasses access_control on other routes","link":"https:\/\/github.com\/EasyCorp\/EasyAdminBundle\/security\/advisories\/GHSA-g2fm-8hr4-j82h","cve":"CVE-2026-81892","affectedVersions":"\u003E=4.0.0,\u003C4.29.16|\u003E=5.0.0,\u003C5.5.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-11 06:38:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"easycorp\/easyadmin-bundle\/CVE-2026-81892.yaml"},{"name":"GitHub","remoteId":"GHSA-g2fm-8hr4-j82h"}]},{"advisoryId":"PKSA-8yhb-cz5n-f41h","packageName":"easycorp\/easyadmin-bundle","remoteId":"easycorp\/easyadmin-bundle\/CVE-2026-54087.yaml","title":"Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField","link":"https:\/\/github.com\/EasyCorp\/EasyAdminBundle\/security\/advisories\/GHSA-8559-gwj3-q37r","cve":"CVE-2026-54087","affectedVersions":"\u003E=5.0.0,\u003C5.0.13","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-04 06:43:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"easycorp\/easyadmin-bundle\/CVE-2026-54087.yaml"},{"name":"GitHub","remoteId":"GHSA-8559-gwj3-q37r"}]}],"phpcsstandards\/phpcsutils":[{"advisoryId":"PKSA-kh6k-gs3g-dgr6","packageName":"phpcsstandards\/phpcsutils","remoteId":"phpcsstandards\/phpcsutils\/CVE-2026-65954.yaml","title":"Arbitrary code execution","link":"https:\/\/github.com\/PHPCSStandards\/PHPCSUtils\/security\/advisories\/GHSA-r6hr-vr92-vv28","cve":"CVE-2026-65954","affectedVersions":"\u003E=1.0.0-alpha1,\u003C1.2.3","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-27 09:13:28","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"phpcsstandards\/phpcsutils\/CVE-2026-65954.yaml"}]}],"codeigniter4\/framework":[{"advisoryId":"PKSA-kcc6-gffv-vchj","packageName":"codeigniter4\/framework","remoteId":"GHSA-7wmf-pw8j-mc78","title":"CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()","link":"https:\/\/github.com\/advisories\/GHSA-7wmf-pw8j-mc78","cve":"CVE-2026-63220","affectedVersions":"\u003C4.7.4","source":"GitHub","reportedAt":"2026-08-07 18:21:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7wmf-pw8j-mc78"}]},{"advisoryId":"PKSA-t8h5-ngj8-z43w","packageName":"codeigniter4\/framework","remoteId":"GHSA-c9w5-rwh3-7pm9","title":"CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions","link":"https:\/\/github.com\/advisories\/GHSA-c9w5-rwh3-7pm9","cve":"CVE-2026-63221","affectedVersions":"\u003E=4.3.0,\u003C4.7.4","source":"GitHub","reportedAt":"2026-08-07 18:22:59","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-c9w5-rwh3-7pm9"}]},{"advisoryId":"PKSA-ykyc-889h-7jxf","packageName":"codeigniter4\/framework","remoteId":"GHSA-hhmc-q9hp-r662","title":"CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames","link":"https:\/\/github.com\/advisories\/GHSA-hhmc-q9hp-r662","cve":"CVE-2026-63222","affectedVersions":"\u003C4.7.4","source":"GitHub","reportedAt":"2026-08-07 18:23:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hhmc-q9hp-r662"}]},{"advisoryId":"PKSA-kcm9-w3rf-jxsk","packageName":"codeigniter4\/framework","remoteId":"GHSA-mmj4-63m4-r6h5","title":"CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules","link":"https:\/\/github.com\/advisories\/GHSA-mmj4-63m4-r6h5","cve":"CVE-2026-63223","affectedVersions":"\u003C4.7.4","source":"GitHub","reportedAt":"2026-08-07 18:24:21","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-mmj4-63m4-r6h5"}]}],"craftcms\/cms":[{"advisoryId":"PKSA-gh5w-x99g-b53n","packageName":"craftcms\/cms","remoteId":"GHSA-xxpx-f366-4xpq","title":"Craft CMS: Authorization bypass: view-only Categories user can modify category structure via structures\/move-element","link":"https:\/\/github.com\/advisories\/GHSA-xxpx-f366-4xpq","cve":"CVE-2026-72785","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:43:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xxpx-f366-4xpq"}]},{"advisoryId":"PKSA-jk69-ryht-534b","packageName":"craftcms\/cms","remoteId":"GHSA-wg23-69c2-gjc8","title":"Craft CMS: Passkey login accepts replayed WebAuthn assertions","link":"https:\/\/github.com\/advisories\/GHSA-wg23-69c2-gjc8","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.5","source":"GitHub","reportedAt":"2026-08-07 14:57:29","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-wg23-69c2-gjc8"}]},{"advisoryId":"PKSA-4q3g-gxhk-813s","packageName":"craftcms\/cms","remoteId":"GHSA-596p-6jv8-775v","title":"Craft CMS: Authenticated leak of secret environment variables","link":"https:\/\/github.com\/advisories\/GHSA-596p-6jv8-775v","cve":"CVE-2026-72782","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:53:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-596p-6jv8-775v"}]},{"advisoryId":"PKSA-19kf-75v5-vy76","packageName":"craftcms\/cms","remoteId":"GHSA-957r-qf9p-67xw","title":"Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts","link":"https:\/\/github.com\/advisories\/GHSA-957r-qf9p-67xw","cve":"CVE-2026-72779","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:54:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-957r-qf9p-67xw"}]},{"advisoryId":"PKSA-1412-5vdy-cd6w","packageName":"craftcms\/cms","remoteId":"GHSA-rvmm-v933-jgxq","title":"Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics","link":"https:\/\/github.com\/advisories\/GHSA-rvmm-v933-jgxq","cve":"CVE-2026-14794","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.3|\u003E=4.0.0-RC1,\u003C4.18.1","source":"GitHub","reportedAt":"2026-08-06 21:42:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rvmm-v933-jgxq"}]},{"advisoryId":"PKSA-x767-zzvx-956t","packageName":"craftcms\/cms","remoteId":"GHSA-2rp4-x2j7-qmcc","title":"Craft CMS: Stored XSS in the control panel via unescaped draft name","link":"https:\/\/github.com\/advisories\/GHSA-2rp4-x2j7-qmcc","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.8","source":"GitHub","reportedAt":"2026-08-06 21:33:15","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2rp4-x2j7-qmcc"}]},{"advisoryId":"PKSA-82nd-44zr-vpmz","packageName":"craftcms\/cms","remoteId":"GHSA-7hxc-f267-h5q7","title":"Craft CMS: Incorrect path validation could potentially lead to path traversal","link":"https:\/\/github.com\/advisories\/GHSA-7hxc-f267-h5q7","cve":"CVE-2026-72783","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:36:11","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7hxc-f267-h5q7"}]},{"advisoryId":"PKSA-d48x-nyby-nphv","packageName":"craftcms\/cms","remoteId":"GHSA-f5wm-88jv-g5hx","title":"Craft CMS: Authenticated RCE through Twig sandbox escape","link":"https:\/\/github.com\/advisories\/GHSA-f5wm-88jv-g5hx","cve":"CVE-2026-72781","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.3|\u003E=5.0.0-RC1,\u003C5.10.7","source":"GitHub","reportedAt":"2026-08-06 21:02:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f5wm-88jv-g5hx"}]},{"advisoryId":"PKSA-s5dz-k87m-97ms","packageName":"craftcms\/cms","remoteId":"GHSA-p8x7-9vfw-p7vc","title":"Craft CMS: Arbitrary user password reset leading to administrator account takeover","link":"https:\/\/github.com\/advisories\/GHSA-p8x7-9vfw-p7vc","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.8","source":"GitHub","reportedAt":"2026-08-06 21:04:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-p8x7-9vfw-p7vc"}]},{"advisoryId":"PKSA-x2qp-qkxh-fw67","packageName":"craftcms\/cms","remoteId":"GHSA-9p7c-v5x3-rfx8","title":"Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets","link":"https:\/\/github.com\/advisories\/GHSA-9p7c-v5x3-rfx8","cve":"CVE-2026-14793","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.3|\u003E=4.0.0-RC1,\u003C4.18.1","source":"GitHub","reportedAt":"2026-08-06 20:55:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9p7c-v5x3-rfx8"}]},{"advisoryId":"PKSA-4tjq-33kk-ghq8","packageName":"craftcms\/cms","remoteId":"GHSA-265m-7826-wjqm","title":"Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass","link":"https:\/\/github.com\/advisories\/GHSA-265m-7826-wjqm","cve":"CVE-2026-72778","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 20:45:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-265m-7826-wjqm"}]},{"advisoryId":"PKSA-5x6f-x35f-73db","packageName":"craftcms\/cms","remoteId":"GHSA-c43v-4cr8-6mvp","title":"Craft CMS has authenticated path traversal in `assets\/icon`, allowing local `.svg` file read","link":"https:\/\/github.com\/advisories\/GHSA-c43v-4cr8-6mvp","cve":"CVE-2026-56394","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.12|\u003E=4.0.0-RC1,\u003C=4.17.6","source":"GitHub","reportedAt":"2026-07-09 13:44:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-c43v-4cr8-6mvp"}]},{"advisoryId":"PKSA-r87g-h2pd-9vq1","packageName":"craftcms\/cms","remoteId":"GHSA-86vw-x4ww-x467","title":"Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview","link":"https:\/\/github.com\/advisories\/GHSA-86vw-x4ww-x467","cve":"CVE-2026-56382","affectedVersions":"\u003E=5.5.0,\u003C=5.9.13","source":"GitHub","reportedAt":"2026-07-09 13:44:12","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-86vw-x4ww-x467"}]},{"advisoryId":"PKSA-pqnm-5q4k-cx7j","packageName":"craftcms\/cms","remoteId":"GHSA-x76w-8c62-48mg","title":"Craft CMS: Authenticated \u0022assets\/preview-thumb\u0022 discloses signed fallback transform preview link to CP users without asset-view permission","link":"https:\/\/github.com\/advisories\/GHSA-x76w-8c62-48mg","cve":"CVE-2026-56384","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.13|\u003E=4.0.0-RC1,\u003C=4.17.7","source":"GitHub","reportedAt":"2026-07-06 20:28:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x76w-8c62-48mg"}]},{"advisoryId":"PKSA-hq3k-cthz-b9zn","packageName":"craftcms\/cms","remoteId":"GHSA-44px-qjjc-xrhq","title":"Craft CMS: Authorized asset \u0022preview file\u0022 requests bypass allows users without asset access to retrieve private preview metadata","link":"https:\/\/github.com\/advisories\/GHSA-44px-qjjc-xrhq","cve":"CVE-2026-56385","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.17.7|\u003E=5.0.0-RC1,\u003C=5.9.13","source":"GitHub","reportedAt":"2026-03-26 17:12:21","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-44px-qjjc-xrhq"}]},{"advisoryId":"PKSA-sc5m-6n1y-h7vz","packageName":"craftcms\/cms","remoteId":"GHSA-g3hp-vvqf-8vw6","title":"Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page","link":"https:\/\/github.com\/advisories\/GHSA-g3hp-vvqf-8vw6","cve":"CVE-2026-56381","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.8.21","source":"GitHub","reportedAt":"2026-03-11 14:56:59","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-g3hp-vvqf-8vw6"}]},{"advisoryId":"PKSA-24yr-dkzm-n9v5","packageName":"craftcms\/cms","remoteId":"GHSA-vg3j-hpm9-8v5v","title":"Craft CMS has a potential information disclosure vulnerability in preview tokens","link":"https:\/\/github.com\/advisories\/GHSA-vg3j-hpm9-8v5v","cve":"CVE-2026-29113","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.9.7|\u003E=4.0.0-RC1,\u003C4.17.3","source":"GitHub","reportedAt":"2026-03-10 18:22:02","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-vg3j-hpm9-8v5v"}]},{"advisoryId":"PKSA-skz7-x8dk-h7t1","packageName":"craftcms\/cms","remoteId":"GHSA-4mgv-366x-qxvx","title":"Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options","link":"https:\/\/github.com\/advisories\/GHSA-4mgv-366x-qxvx","cve":"CVE-2026-56393","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.0-beta.1|\u003E=5.0.0-RC1,\u003C5.9.0-beta.1","source":"GitHub","reportedAt":"2026-03-03 20:58:07","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-4mgv-366x-qxvx"}]},{"advisoryId":"PKSA-cf9h-wtzj-5nwd","packageName":"craftcms\/cms","remoteId":"GHSA-6j87-m5qx-9fqp","title":"Craft CMS has Stored XSS in Table Field in its \u0022Row Heading\u0022 Column Type","link":"https:\/\/github.com\/advisories\/GHSA-6j87-m5qx-9fqp","cve":"CVE-2026-56383","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.8.22|\u003E=4.5.0-beta.1,\u003C=4.16.18","source":"GitHub","reportedAt":"2026-02-25 19:11:31","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-6j87-m5qx-9fqp"}]}],"api-platform\/core":[{"advisoryId":"PKSA-8kfs-m8zw-ggzs","packageName":"api-platform\/core","remoteId":"GHSA-9rjg-x2p2-h68h","title":"API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)","link":"https:\/\/github.com\/advisories\/GHSA-9rjg-x2p2-h68h","cve":"CVE-2026-54164","affectedVersions":"\u003E=4.3.0,\u003C4.3.12|\u003E=4.2.0,\u003C4.2.26|\u003C4.1.30","source":"GitHub","reportedAt":"2026-08-07 16:54:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9rjg-x2p2-h68h"}]},{"advisoryId":"PKSA-3ncz-km6v-5vjr","packageName":"api-platform\/core","remoteId":"GHSA-pjhx-3c3w-9v23","title":"API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate","link":"https:\/\/github.com\/advisories\/GHSA-pjhx-3c3w-9v23","cve":"CVE-2026-49858","affectedVersions":"\u003E=4.3.0,\u003C4.3.8|\u003E=4.2.0,\u003C4.2.25|\u003E=2.6.0,\u003C4.1.29","source":"GitHub","reportedAt":"2026-07-10 14:32:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pjhx-3c3w-9v23"}]}],"squizlabs\/php_codesniffer":[{"advisoryId":"PKSA-rdkp-vv9z-mjkg","packageName":"squizlabs\/php_codesniffer","remoteId":"squizlabs\/php_codesniffer\/CVE-2026-67434.yaml","title":"OS Command injection","link":"https:\/\/github.com\/PHPCSStandards\/PHP_CodeSniffer\/security\/advisories\/GHSA-hmqg-cxww-wqhq","cve":"CVE-2026-67434","affectedVersions":"\u003C3.13.6|\u003E=4.0.0,\u003C4.0.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-05 23:53:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hmqg-cxww-wqhq"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"squizlabs\/php_codesniffer\/CVE-2026-67434.yaml"}]}],"guzzlehttp\/guzzle":[{"advisoryId":"PKSA-cnw1-2ytm-cgr8","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-f7vp-7xgx-4w4r","title":"Guzzle: Noncanonical cookie domain keeps subdomain scope","link":"https:\/\/github.com\/advisories\/GHSA-f7vp-7xgx-4w4r","cve":"CVE-2026-69245","affectedVersions":"\u003E=8.0.0,\u003C8.0.1|\u003C7.15.2","source":"GitHub","reportedAt":"2026-08-03 21:05:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f7vp-7xgx-4w4r"}]},{"advisoryId":"PKSA-gcrk-3vtt-1r14","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-v5mv-p594-2x33","title":"Guzzle: Noncanonical host can bypass host-based checks","link":"https:\/\/github.com\/advisories\/GHSA-v5mv-p594-2x33","cve":"CVE-2026-69246","affectedVersions":"\u003E=8.0.0,\u003C8.0.1|\u003C7.15.2","source":"GitHub","reportedAt":"2026-08-03 21:07:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v5mv-p594-2x33"}]},{"advisoryId":"PKSA-bbs6-q5q9-f3t4","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-f283-ghqc-fg79","title":"Guzzle: Unbounded response cookies risk denial of service","link":"https:\/\/github.com\/advisories\/GHSA-f283-ghqc-fg79","cve":"CVE-2026-67353","affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:27:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f283-ghqc-fg79"}]},{"advisoryId":"PKSA-qxvb-2bpp-dnk6","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-wm3w-8rrp-j577","title":"Guzzle: Host-only cookie scope is not preserved","link":"https:\/\/github.com\/advisories\/GHSA-wm3w-8rrp-j577","cve":"CVE-2026-67355","affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:27:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wm3w-8rrp-j577"}]},{"advisoryId":"PKSA-fy2t-3c5f-827y","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-h95v-h523-3mw8","title":"Guzzle: URI fragments disclosed in redirect Referer headers","link":"https:\/\/github.com\/advisories\/GHSA-h95v-h523-3mw8","cve":"CVE-2026-67354","affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:28:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h95v-h523-3mw8"}]},{"advisoryId":"PKSA-bcdd-5xc7-gwfb","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-g446-98w2-8p5w","title":"Guzzle: Cookie Disclosure and Injection via IP-Address Domains","link":"https:\/\/github.com\/advisories\/GHSA-g446-98w2-8p5w","cve":"CVE-2026-59883","affectedVersions":"\u003C7.12.3","source":"GitHub","reportedAt":"2026-07-20 22:00:09","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-g446-98w2-8p5w"}]},{"advisoryId":"PKSA-pwsk-hy21-4gby","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-94pj-82f3-465w","title":"Guzzle: Proxy-Authorization headers can be sent to origin servers","link":"https:\/\/github.com\/advisories\/GHSA-94pj-82f3-465w","cve":"CVE-2026-67339","affectedVersions":"\u003C7.14.2","source":"GitHub","reportedAt":"2026-07-20 21:46:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-94pj-82f3-465w"}]}],"wp-graphql\/wp-graphql":[{"advisoryId":"PKSA-2dkq-4nxk-nkts","packageName":"wp-graphql\/wp-graphql","remoteId":"GHSA-jhh7-832h-f8hv","title":"WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)","link":"https:\/\/github.com\/advisories\/GHSA-jhh7-832h-f8hv","cve":"CVE-2026-54768","affectedVersions":"\u003C=2.6.0","source":"GitHub","reportedAt":"2026-07-31 22:24:29","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jhh7-832h-f8hv"}]}],"redaxo\/source":[{"advisoryId":"PKSA-h751-bdn3-ptsn","packageName":"redaxo\/source","remoteId":"GHSA-98pp-vccm-qm25","title":"Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers","link":"https:\/\/github.com\/advisories\/GHSA-98pp-vccm-qm25","cve":"CVE-2026-53599","affectedVersions":"\u003E=5.18.2,\u003C5.21.1","source":"GitHub","reportedAt":"2026-07-31 19:43:51","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-98pp-vccm-qm25"}]}],"limesurvey\/limesurvey":[{"advisoryId":"PKSA-bgzx-wwbd-v2zr","packageName":"limesurvey\/limesurvey","remoteId":"GHSA-5c37-5j7w-8mh8","title":"LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it.","link":"https:\/\/github.com\/advisories\/GHSA-5c37-5j7w-8mh8","cve":"CVE-2026-50635","affectedVersions":"\u003C=7.0.0-beta1","source":"GitHub","reportedAt":"2026-06-09 18:31:04","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5c37-5j7w-8mh8"}]},{"advisoryId":"PKSA-jm8r-vn8x-qc36","packageName":"limesurvey\/limesurvey","remoteId":"GHSA-pr6f-87hf-hx24","title":"LimeSurvey has a SQL Injection issue","link":"https:\/\/github.com\/advisories\/GHSA-pr6f-87hf-hx24","cve":"CVE-2026-50636","affectedVersions":"\u003C=7.0.0-beta1","source":"GitHub","reportedAt":"2026-06-09 18:31:04","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-pr6f-87hf-hx24"}]}],"sylius\/mollie-plugin":[{"advisoryId":"PKSA-b8jy-36rm-9gkc","packageName":"sylius\/mollie-plugin","remoteId":"GHSA-rc52-c4hv-w89p","title":"Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook","link":"https:\/\/github.com\/advisories\/GHSA-rc52-c4hv-w89p","cve":"CVE-2026-68500","affectedVersions":"\u003E=3.3.0,\u003C3.3.1|\u003E=3.0.0,\u003C3.2.4|\u003C2.2.8","source":"GitHub","reportedAt":"2026-07-31 16:52:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-rc52-c4hv-w89p"}]},{"advisoryId":"PKSA-jv9x-q24z-dm7x","packageName":"sylius\/mollie-plugin","remoteId":"GHSA-x83g-979r-f5fh","title":"Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII","link":"https:\/\/github.com\/advisories\/GHSA-x83g-979r-f5fh","cve":"CVE-2026-68501","affectedVersions":"\u003E=3.3.0,\u003C3.3.1|\u003E=3.0.0,\u003C3.2.4|\u003C2.2.8","source":"GitHub","reportedAt":"2026-07-31 16:52:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x83g-979r-f5fh"}]}],"oxid-esales\/oxideshop-metapackage-ce":[{"advisoryId":"PKSA-8whs-nq1s-2hbz","packageName":"oxid-esales\/oxideshop-metapackage-ce","remoteId":"GHSA-qqcr-9jfc-35c4","title":"OXID eShop May Display User Information","link":"https:\/\/github.com\/advisories\/GHSA-qqcr-9jfc-35c4","cve":"CVE-2024-56526","affectedVersions":"\u003E=6.0.0,\u003C6.5.5","source":"GitHub","reportedAt":"2025-05-13 18:30:52","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qqcr-9jfc-35c4"}]}],"oxid-esales\/smarty-component":[{"advisoryId":"PKSA-jkjj-3f6r-p397","packageName":"oxid-esales\/smarty-component","remoteId":"GHSA-qqcr-9jfc-35c4","title":"OXID eShop May Display User Information","link":"https:\/\/github.com\/advisories\/GHSA-qqcr-9jfc-35c4","cve":"CVE-2024-56526","affectedVersions":"\u003C1.0.1","source":"GitHub","reportedAt":"2025-05-13 18:30:52","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qqcr-9jfc-35c4"}]}],"alextselegidis\/easyappointments":[{"advisoryId":"PKSA-qjn8-scvh-tqz1","packageName":"alextselegidis\/easyappointments","remoteId":"GHSA-996f-334j-67g7","title":"Easy!Appointments disable_booking_message rendered as raw HTML on public booking page \u2014 Stored XSS","link":"https:\/\/github.com\/advisories\/GHSA-996f-334j-67g7","cve":"CVE-2026-52838","affectedVersions":"\u003C=1.5.2","source":"GitHub","reportedAt":"2026-07-29 16:30:09","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-996f-334j-67g7"}]},{"advisoryId":"PKSA-hmm5-v3nr-ydfq","packageName":"alextselegidis\/easyappointments","remoteId":"GHSA-4vmm-5qvc-w5p7","title":"Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure","link":"https:\/\/github.com\/advisories\/GHSA-4vmm-5qvc-w5p7","cve":"CVE-2026-55651","affectedVersions":"=1.5.2","source":"GitHub","reportedAt":"2026-07-29 16:22:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4vmm-5qvc-w5p7"}]},{"advisoryId":"PKSA-qvhv-yhm7-8xkk","packageName":"alextselegidis\/easyappointments","remoteId":"GHSA-pm5p-7w5h-jm5q","title":"Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment\u0027s internal network","link":"https:\/\/github.com\/advisories\/GHSA-pm5p-7w5h-jm5q","cve":"CVE-2026-52840","affectedVersions":"\u003C=1.5.2","source":"GitHub","reportedAt":"2026-07-29 16:24:27","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-pm5p-7w5h-jm5q"}]},{"advisoryId":"PKSA-9k3m-y8wr-wv52","packageName":"alextselegidis\/easyappointments","remoteId":"GHSA-w8xc-8g92-v77h","title":"Easy!Appointments appointments\/store and appointments\/update allow cross-provider appointment injection \u2014 Authorization Bypass","link":"https:\/\/github.com\/advisories\/GHSA-w8xc-8g92-v77h","cve":"CVE-2026-52839","affectedVersions":"\u003C=1.5.2","source":"GitHub","reportedAt":"2026-07-29 16:26:25","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-w8xc-8g92-v77h"}]},{"advisoryId":"PKSA-nm1q-gc5c-m98k","packageName":"alextselegidis\/easyappointments","remoteId":"GHSA-xgr6-pqjv-3pf8","title":"Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page","link":"https:\/\/github.com\/advisories\/GHSA-xgr6-pqjv-3pf8","cve":"CVE-2026-52837","affectedVersions":"\u003C=1.5.2","source":"GitHub","reportedAt":"2026-07-29 16:28:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xgr6-pqjv-3pf8"}]},{"advisoryId":"PKSA-4qd5-bb9g-9x8d","packageName":"alextselegidis\/easyappointments","remoteId":"GHSA-8hm4-r66f-29wr","title":"Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider\u0027s Google sync","link":"https:\/\/github.com\/advisories\/GHSA-8hm4-r66f-29wr","cve":"CVE-2026-52841","affectedVersions":"\u003C=1.5.2","source":"GitHub","reportedAt":"2026-07-29 16:29:26","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-8hm4-r66f-29wr"}]}],"poweradmin\/poweradmin":[{"advisoryId":"PKSA-z39g-ypf1-66p7","packageName":"poweradmin\/poweradmin","remoteId":"GHSA-3735-5339-xfwx","title":"Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS\/SLO URL, and Logout Redirect Construction.","link":"https:\/\/github.com\/advisories\/GHSA-3735-5339-xfwx","cve":"CVE-2026-54588","affectedVersions":"\u003E=4.3.0,\u003C4.3.3|\u003C4.2.4","source":"GitHub","reportedAt":"2026-07-28 16:40:05","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-3735-5339-xfwx"}]},{"advisoryId":"PKSA-wfnt-jmc8-c3b3","packageName":"poweradmin\/poweradmin","remoteId":"GHSA-h4hf-v6w5-897x","title":"Poweradmin: API user-update endpoint leads to a non-admin reset any user\u0027s password and take over the superuser account","link":"https:\/\/github.com\/advisories\/GHSA-h4hf-v6w5-897x","cve":null,"affectedVersions":"\u003E=4.3.0,\u003C4.3.4|\u003E=4.0.0,\u003C4.2.5","source":"GitHub","reportedAt":"2026-07-24 21:54:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h4hf-v6w5-897x"}]},{"advisoryId":"PKSA-ybnj-2pv1-jwh7","packageName":"poweradmin\/poweradmin","remoteId":"GHSA-rm67-g9ch-vxff","title":"Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own","link":"https:\/\/github.com\/advisories\/GHSA-rm67-g9ch-vxff","cve":null,"affectedVersions":"\u003E=4.3.0,\u003C4.3.4|\u003E=4.0.0,\u003C4.2.5|\u003E=3.0.0,\u003C3.9.11","source":"GitHub","reportedAt":"2026-07-24 21:55:15","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-rm67-g9ch-vxff"}]},{"advisoryId":"PKSA-zmp4-g5nd-b65p","packageName":"poweradmin\/poweradmin","remoteId":"GHSA-cmwh-g2h8-c222","title":"Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover","link":"https:\/\/github.com\/advisories\/GHSA-cmwh-g2h8-c222","cve":null,"affectedVersions":"\u003E=4.3.0,\u003C4.3.4|\u003E=4.1.0,\u003C4.2.5","source":"GitHub","reportedAt":"2026-07-24 21:56:02","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-cmwh-g2h8-c222"}]}],"pterodactyl\/panel":[{"advisoryId":"PKSA-hhbv-vvdq-cchz","packageName":"pterodactyl\/panel","remoteId":"GHSA-8r6w-3qq5-4p4r","title":"Pterodactyl\u0027s improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions","link":"https:\/\/github.com\/advisories\/GHSA-8r6w-3qq5-4p4r","cve":"CVE-2026-54593","affectedVersions":"\u003C1.12.3","source":"GitHub","reportedAt":"2026-07-28 15:43:25","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8r6w-3qq5-4p4r"}]},{"advisoryId":"PKSA-dkjc-6qnp-q5rq","packageName":"pterodactyl\/panel","remoteId":"GHSA-xvc3-826v-xf47","title":"Pterodactyl\u0027s shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)","link":"https:\/\/github.com\/advisories\/GHSA-xvc3-826v-xf47","cve":"CVE-2026-61609","affectedVersions":"\u003E=1.7.0,\u003C=1.12.4","source":"GitHub","reportedAt":"2026-07-28 14:57:59","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xvc3-826v-xf47"}]}],"wp-coding-standards\/wpcs":[{"advisoryId":"PKSA-mh9b-91zm-m1gy","packageName":"wp-coding-standards\/wpcs","remoteId":"wp-coding-standards\/wpcs\/CVE-2026-45293.yaml","title":"Arbitrary code execution","link":"https:\/\/github.com\/WordPress\/WordPress-Coding-Standards\/security\/advisories\/GHSA-3pwp-g2mj-5p3v","cve":"CVE-2026-45293","affectedVersions":"\u003E=0.14.1,\u003C3.4.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-27 11:42:13","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3pwp-g2mj-5p3v"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"wp-coding-standards\/wpcs\/CVE-2026-45293.yaml"}]}],"pheditor\/pheditor":[{"advisoryId":"PKSA-jw7m-7sxt-c8zt","packageName":"pheditor\/pheditor","remoteId":"GHSA-f25v-x6vr-962g","title":"Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password","link":"https:\/\/github.com\/advisories\/GHSA-f25v-x6vr-962g","cve":null,"affectedVersions":"\u003C2.0.8","source":"GitHub","reportedAt":"2026-07-24 21:54:24","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-f25v-x6vr-962g"}]},{"advisoryId":"PKSA-2169-f5hg-9g35","packageName":"pheditor\/pheditor","remoteId":"GHSA-g3hq-hphg-8fhh","title":"Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE \u2014 surviving vector after the metacharacter-sanitization fixes","link":"https:\/\/github.com\/advisories\/GHSA-g3hq-hphg-8fhh","cve":null,"affectedVersions":"\u003C=2.0.6","source":"GitHub","reportedAt":"2026-07-24 21:45:40","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g3hq-hphg-8fhh"}]},{"advisoryId":"PKSA-c2s6-j4sd-8g42","packageName":"pheditor\/pheditor","remoteId":"GHSA-wg4w-wr5q-6vjc","title":"Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection","link":"https:\/\/github.com\/advisories\/GHSA-wg4w-wr5q-6vjc","cve":"CVE-2026-55578","affectedVersions":"\u003E=2.0.1,\u003C2.0.6","source":"GitHub","reportedAt":"2026-07-16 20:10:47","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wg4w-wr5q-6vjc"}]},{"advisoryId":"PKSA-fw3p-jbcz-gm98","packageName":"pheditor\/pheditor","remoteId":"GHSA-p4h7-p9rj-2pq2","title":"Pheditor: Hardcoded default password \u0027admin\u0027 with no forced change enables full application compromise","link":"https:\/\/github.com\/advisories\/GHSA-p4h7-p9rj-2pq2","cve":"CVE-2026-55579","affectedVersions":"\u003E=2.0.1,\u003C2.0.6","source":"GitHub","reportedAt":"2026-07-16 20:11:23","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-p4h7-p9rj-2pq2"}]},{"advisoryId":"PKSA-35mf-8p9f-f31c","packageName":"pheditor\/pheditor","remoteId":"GHSA-9643-6xjp-vx57","title":"Pheditor has an authenticated terminal command whitelist bypass","link":"https:\/\/github.com\/advisories\/GHSA-9643-6xjp-vx57","cve":"CVE-2026-54540","affectedVersions":"\u003C=2.0.4","source":"GitHub","reportedAt":"2026-07-16 20:01:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-9643-6xjp-vx57"}]}],"phpoffice\/phpspreadsheet":[{"advisoryId":"PKSA-m9cr-9614-rsf7","packageName":"phpoffice\/phpspreadsheet","remoteId":"GHSA-2mrg-gjxq-2gvr","title":"PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion","link":"https:\/\/github.com\/advisories\/GHSA-2mrg-gjxq-2gvr","cve":"CVE-2026-59932","affectedVersions":"\u003C=1.30.5|\u003E=2.0.0,\u003C=2.1.17|\u003E=2.2.0,\u003C=2.4.6|\u003E=3.3.0,\u003C=3.10.6|\u003E=4.0.0,\u003C=5.8.0","source":"GitHub","reportedAt":"2026-07-23 15:00:17","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2mrg-gjxq-2gvr"}]},{"advisoryId":"PKSA-r22k-87hv-mfk4","packageName":"phpoffice\/phpspreadsheet","remoteId":"GHSA-xh5m-36r6-47m3","title":"PHPSpreadsheet: XLS\/OLE sector-chain self-loop causes memory exhaustion","link":"https:\/\/github.com\/advisories\/GHSA-xh5m-36r6-47m3","cve":"CVE-2026-59933","affectedVersions":"\u003C=1.30.5|\u003E=2.0.0,\u003C=2.1.17|\u003E=2.2.0,\u003C=2.4.6|\u003E=3.3.0,\u003C=3.10.6|\u003E=4.0.0,\u003C=5.8.0","source":"GitHub","reportedAt":"2026-07-23 15:01:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xh5m-36r6-47m3"}]},{"advisoryId":"PKSA-dqzt-yst9-1w9y","packageName":"phpoffice\/phpspreadsheet","remoteId":"GHSA-6hq5-7373-42rg","title":"PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist","link":"https:\/\/github.com\/advisories\/GHSA-6hq5-7373-42rg","cve":"CVE-2026-59931","affectedVersions":"\u003C=1.30.5|\u003E=2.0.0,\u003C=2.1.17|\u003E=2.2.0,\u003C=2.4.6|\u003E=3.3.0,\u003C=3.10.6|\u003E=4.0.0,\u003C=5.8.0","source":"GitHub","reportedAt":"2026-07-23 14:55:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6hq5-7373-42rg"}]}],"dompdf\/dompdf":[{"advisoryId":"PKSA-gh7h-hhy4-byg7","packageName":"dompdf\/dompdf","remoteId":"GHSA-8hg6-c449-896m","title":"Dompdf: Uncontrolled resource consumption based on declared BMP dimensions","link":"https:\/\/github.com\/advisories\/GHSA-8hg6-c449-896m","cve":"CVE-2026-59941","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 22:50:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8hg6-c449-896m"}]},{"advisoryId":"PKSA-6r8f-nxsb-67bq","packageName":"dompdf\/dompdf","remoteId":"GHSA-f5gf-2cj8-52g2","title":"Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps","link":"https:\/\/github.com\/advisories\/GHSA-f5gf-2cj8-52g2","cve":"CVE-2026-59942","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 22:51:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f5gf-2cj8-52g2"}]},{"advisoryId":"PKSA-cv56-2228-pzr6","packageName":"dompdf\/dompdf","remoteId":"GHSA-j8qw-6jw8-r297","title":"Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem","link":"https:\/\/github.com\/advisories\/GHSA-j8qw-6jw8-r297","cve":"CVE-2026-59943","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 22:52:44","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j8qw-6jw8-r297"}]},{"advisoryId":"PKSA-mwt3-h9tv-kx78","packageName":"dompdf\/dompdf","remoteId":"GHSA-cx96-42px-69fm","title":"Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI","link":"https:\/\/github.com\/advisories\/GHSA-cx96-42px-69fm","cve":"CVE-2026-56722","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 21:30:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cx96-42px-69fm"}]},{"advisoryId":"PKSA-mckv-s5hg-868k","packageName":"dompdf\/dompdf","remoteId":"GHSA-wvh6-f5jh-8gw4","title":"Dompdf: Chroot Validation Bypass","link":"https:\/\/github.com\/advisories\/GHSA-wvh6-f5jh-8gw4","cve":"CVE-2026-55554","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 21:06:48","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-wvh6-f5jh-8gw4"}]},{"advisoryId":"PKSA-hp6n-n4kz-21wk","packageName":"dompdf\/dompdf","remoteId":"GHSA-7x2p-4jvh-6384","title":"Dompdf: File existence oracle via font-face stylesheet declaration","link":"https:\/\/github.com\/advisories\/GHSA-7x2p-4jvh-6384","cve":"CVE-2026-55555","affectedVersions":"\u003C3.1.6","source":"GitHub","reportedAt":"2026-07-22 21:07:07","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7x2p-4jvh-6384"}]}],"guzzlehttp\/psr7":[{"advisoryId":"PKSA-vznr-tgp9-fd7d","packageName":"guzzlehttp\/psr7","remoteId":"GHSA-c2w2-prh8-qm98","title":"guzzlehttp\/psr7: Host Confusion via Weak URI Host Validation","link":"https:\/\/github.com\/advisories\/GHSA-c2w2-prh8-qm98","cve":"CVE-2026-59882","affectedVersions":"\u003C2.12.3","source":"GitHub","reportedAt":"2026-07-21 18:35:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c2w2-prh8-qm98"}]}],"verbb\/formie":[{"advisoryId":"PKSA-xm2v-2qmq-bmd3","packageName":"verbb\/formie","remoteId":"GHSA-cvpc-hccg-wmw4","title":"Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration","link":"https:\/\/github.com\/advisories\/GHSA-cvpc-hccg-wmw4","cve":null,"affectedVersions":"\u003C3.1.28","source":"GitHub","reportedAt":"2026-07-17 19:05:57","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-cvpc-hccg-wmw4"}]}],"typo3\/cms-fluid":[{"advisoryId":"PKSA-gq2f-sdxt-2mmr","packageName":"typo3\/cms-fluid","remoteId":"GHSA-22q7-cg4r-p9mx","title":"TYPO3 Cross-Site Scripting in Fluid ViewHelpers","link":"https:\/\/github.com\/advisories\/GHSA-22q7-cg4r-p9mx","cve":null,"affectedVersions":"\u003E=9.0.0,\u003C9.5.4|\u003E=8.0.0,\u003C8.7.23","source":"GitHub","reportedAt":"2024-05-30 15:46:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-22q7-cg4r-p9mx"}]}],"adawolfa\/isdoc":[{"advisoryId":"PKSA-zwm1-4dcx-xx1p","packageName":"adawolfa\/isdoc","remoteId":"GHSA-xg43-5579-qw6v","title":"adawolfa\/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files","link":"https:\/\/github.com\/advisories\/GHSA-xg43-5579-qw6v","cve":null,"affectedVersions":"\u003C1.4.0|\u003E=1.4.0,\u003C1.4.3|\u003E=1.5.0,\u003C1.5.1|\u003E=1.6.0,\u003C1.6.1","source":"GitHub","reportedAt":"2026-07-15 23:30:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xg43-5579-qw6v"}]}],"mantisbt\/mantisbt":[{"advisoryId":"PKSA-xw73-w41z-8sfx","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-4vpf-w7qv-5h3q","title":"MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs","link":"https:\/\/github.com\/advisories\/GHSA-4vpf-w7qv-5h3q","cve":"CVE-2026-52883","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 18:52:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4vpf-w7qv-5h3q"}]},{"advisoryId":"PKSA-vymf-gj2q-2bk6","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-h2wf-967x-gxvw","title":"MantisBT: Stored XSS in print_all_bug_page_word.php","link":"https:\/\/github.com\/advisories\/GHSA-h2wf-967x-gxvw","cve":"CVE-2026-62944","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 18:56:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h2wf-967x-gxvw"}]},{"advisoryId":"PKSA-2zcr-93ry-6511","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-3v2j-6fw9-f57c","title":"MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters","link":"https:\/\/github.com\/advisories\/GHSA-3v2j-6fw9-f57c","cve":"CVE-2026-52882","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 18:41:55","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3v2j-6fw9-f57c"}]},{"advisoryId":"PKSA-23vf-p9ny-hdcn","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-vcrw-4xvv-jh49","title":"MantisBT: Reflected XSS in admin\/install.php via unescaped printf ","link":"https:\/\/github.com\/advisories\/GHSA-vcrw-4xvv-jh49","cve":"CVE-2026-52881","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 18:34:36","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-vcrw-4xvv-jh49"}]},{"advisoryId":"PKSA-cgcp-ngm1-hmmf","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-77x8-3v3h-hrhv","title":"MantisBT: Reflected XSS in admin\/install.php","link":"https:\/\/github.com\/advisories\/GHSA-77x8-3v3h-hrhv","cve":"CVE-2026-52847","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 18:25:36","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-77x8-3v3h-hrhv"}]},{"advisoryId":"PKSA-6qcn-z5zm-cd63","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-m7ph-9558-mrx3","title":"MantisBT: REST API unauthorized Issue status change","link":"https:\/\/github.com\/advisories\/GHSA-m7ph-9558-mrx3","cve":"CVE-2026-49280","affectedVersions":"\u003E=2.8.0,\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 17:02:12","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m7ph-9558-mrx3"}]},{"advisoryId":"PKSA-5jjt-2py9-5v67","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-v84x-qvhg-f36r","title":"MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php","link":"https:\/\/github.com\/advisories\/GHSA-v84x-qvhg-f36r","cve":"CVE-2026-49273","affectedVersions":"\u003E=1.3.0,\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 16:52:24","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v84x-qvhg-f36r"}]},{"advisoryId":"PKSA-vcbb-b851-hxr5","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-c2xg-qjqw-2v98","title":"MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator","link":"https:\/\/github.com\/advisories\/GHSA-c2xg-qjqw-2v98","cve":"CVE-2026-47156","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 16:45:22","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-c2xg-qjqw-2v98"}]},{"advisoryId":"PKSA-3d2f-71dg-17ys","packageName":"mantisbt\/mantisbt","remoteId":"GHSA-mw6p-33vw-46cc","title":"MantisBT: SQL Injection via history_order Configuration Value","link":"https:\/\/github.com\/advisories\/GHSA-mw6p-33vw-46cc","cve":"CVE-2026-47142","affectedVersions":"\u003C=2.28.3","source":"GitHub","reportedAt":"2026-07-15 16:38:22","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mw6p-33vw-46cc"}]}],"phanan\/koel":[{"advisoryId":"PKSA-69y7-vwnx-px15","packageName":"phanan\/koel","remoteId":"GHSA-jr4p-4xjh-fwvw","title":"Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail","link":"https:\/\/github.com\/advisories\/GHSA-jr4p-4xjh-fwvw","cve":"CVE-2026-50552","affectedVersions":"\u003C=9.7.0","source":"GitHub","reportedAt":"2026-07-15 18:21:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jr4p-4xjh-fwvw"}]},{"advisoryId":"PKSA-nwpt-px6q-b5bv","packageName":"phanan\/koel","remoteId":"GHSA-rjg7-r26h-cfp2","title":"Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::\/96) or 6to4 (2002::\/16) IPv6-transition wrappers of internal IPv4","link":"https:\/\/github.com\/advisories\/GHSA-rjg7-r26h-cfp2","cve":"CVE-2026-54494","affectedVersions":"\u003C=9.7.0","source":"GitHub","reportedAt":"2026-07-15 18:21:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rjg7-r26h-cfp2"}]},{"advisoryId":"PKSA-1qtf-pcfh-kb47","packageName":"phanan\/koel","remoteId":"GHSA-6qvr-wjmv-v8mm","title":"Koel: Incomplete fix for CVE-2026-47260 \u2014 systemic SSRF in podcast \u0026 radio fetch paths","link":"https:\/\/github.com\/advisories\/GHSA-6qvr-wjmv-v8mm","cve":"CVE-2026-54491","affectedVersions":"\u003C=9.7.0","source":"GitHub","reportedAt":"2026-07-15 17:59:30","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6qvr-wjmv-v8mm"}]},{"advisoryId":"PKSA-74sr-w83z-r28d","packageName":"phanan\/koel","remoteId":"GHSA-8q6q-m837-fv64","title":" Koel has SSRF through Authenticated Subsonic podcast feed URLs","link":"https:\/\/github.com\/advisories\/GHSA-8q6q-m837-fv64","cve":null,"affectedVersions":"\u003C=9.6.0","source":"GitHub","reportedAt":"2026-07-15 17:31:12","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8q6q-m837-fv64"}]},{"advisoryId":"PKSA-gv41-hnht-9yhw","packageName":"phanan\/koel","remoteId":"GHSA-6p96-cfg5-4vhp","title":"Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations","link":"https:\/\/github.com\/advisories\/GHSA-6p96-cfg5-4vhp","cve":"CVE-2026-54493","affectedVersions":"\u003C=9.6.0","source":"GitHub","reportedAt":"2026-07-15 17:13:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6p96-cfg5-4vhp"}]},{"advisoryId":"PKSA-drvx-ht86-w4b7","packageName":"phanan\/koel","remoteId":"GHSA-w79m-f3jx-779v","title":"Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation","link":"https:\/\/github.com\/advisories\/GHSA-w79m-f3jx-779v","cve":"CVE-2026-54492","affectedVersions":"\u003C=9.6.0","source":"GitHub","reportedAt":"2026-07-15 17:07:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w79m-f3jx-779v"}]}],"typo3\/cms-form":[{"advisoryId":"PKSA-d4vj-m6hn-xm1j","packageName":"typo3\/cms-form","remoteId":"typo3\/cms-form\/CVE-2026-15305.yaml","title":"TYPO3-CORE-SA-2026-020: TYPO3 CMS - Unrestricted File Upload in Form Framework","link":"https:\/\/news.typo3.com\/security\/advisory\/typo3-core-sa-2026-020","cve":"CVE-2026-15305","affectedVersions":"\u003E=14.2.0,\u003C14.3.5","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-14 12:08:47","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mfqj-cqv3-h7xw"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"typo3\/cms-form\/CVE-2026-15305.yaml"}]}],"facturascripts\/facturascripts":[{"advisoryId":"PKSA-ckhc-1b7w-fbqb","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-hgjx-r89m-m7v4","title":"FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() \u2014 arbitrary file write outside MyFiles\/ leading to   RCE","link":"https:\/\/github.com\/advisories\/GHSA-hgjx-r89m-m7v4","cve":null,"affectedVersions":"\u003E=2025,\u003C=2026.2","source":"GitHub","reportedAt":"2026-07-14 20:52:00","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-hgjx-r89m-m7v4"}]},{"advisoryId":"PKSA-tj9x-5rgg-xzgk","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-3x7p-v8hj-xh5m","title":"FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`","link":"https:\/\/github.com\/advisories\/GHSA-3x7p-v8hj-xh5m","cve":"CVE-2026-45710","affectedVersions":"\u003C=2026.1","source":"GitHub","reportedAt":"2026-07-14 17:30:26","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-3x7p-v8hj-xh5m"}]},{"advisoryId":"PKSA-582m-pjr9-1vy2","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-5qmh-x653-g8qj","title":"FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`","link":"https:\/\/github.com\/advisories\/GHSA-5qmh-x653-g8qj","cve":"CVE-2026-45262","affectedVersions":"\u003C=2026.1","source":"GitHub","reportedAt":"2026-07-14 17:11:06","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-5qmh-x653-g8qj"}]},{"advisoryId":"PKSA-cphp-d9mj-j5ny","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-cv65-7cg8-r623","title":"FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents","link":"https:\/\/github.com\/advisories\/GHSA-cv65-7cg8-r623","cve":"CVE-2026-45693","affectedVersions":"\u003C=2026.2","source":"GitHub","reportedAt":"2026-07-14 17:12:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-cv65-7cg8-r623"}]},{"advisoryId":"PKSA-9nsq-164p-6ppm","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-2p5x-4jr6-x5jg","title":"FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export","link":"https:\/\/github.com\/advisories\/GHSA-2p5x-4jr6-x5jg","cve":"CVE-2026-45263","affectedVersions":"\u003C=2026.1","source":"GitHub","reportedAt":"2026-07-14 17:18:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2p5x-4jr6-x5jg"}]},{"advisoryId":"PKSA-dn8k-128k-8cz7","packageName":"facturascripts\/facturascripts","remoteId":"GHSA-c67f-gmxw-mj93","title":"FacturaScripts: Account takeover of any 2FA-enabled user","link":"https:\/\/github.com\/advisories\/GHSA-c67f-gmxw-mj93","cve":"CVE-2026-47677","affectedVersions":"\u003C=2026.2","source":"GitHub","reportedAt":"2026-07-13 23:35:48","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-c67f-gmxw-mj93"}]}],"auth0\/symfony":[{"advisoryId":"PKSA-nrzm-zxwz-yhq9","packageName":"auth0\/symfony","remoteId":"GHSA-ffq7-hh2j-r24p","title":"Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter","link":"https:\/\/github.com\/advisories\/GHSA-ffq7-hh2j-r24p","cve":"CVE-2026-50157","affectedVersions":"\u003E=5.0.0-BETA0,\u003C=5.8.0","source":"GitHub","reportedAt":"2026-07-14 19:31:23","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-ffq7-hh2j-r24p"}]}],"kimai\/kimai":[{"advisoryId":"PKSA-kznk-ncz5-wyws","packageName":"kimai\/kimai","remoteId":"GHSA-v8hx-4vx8-wc96","title":"Kimai: Pre-2FA KIMAI_SESSION\u00a0cookie grants full authenticated REST API access, bypassing TOTP","link":"https:\/\/github.com\/advisories\/GHSA-v8hx-4vx8-wc96","cve":"CVE-2026-52827","affectedVersions":"\u003C2.59.0","source":"GitHub","reportedAt":"2026-07-14 00:33:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v8hx-4vx8-wc96"}]},{"advisoryId":"PKSA-2sk3-y15b-6c7y","packageName":"kimai\/kimai","remoteId":"GHSA-rw46-qg69-vg6h","title":"Kimai: ExportTemplate CRUD Missing Authorization Check Allows Unauthorized TEAMLEAD Access","link":"https:\/\/github.com\/advisories\/GHSA-rw46-qg69-vg6h","cve":"CVE-2026-52828","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-14 00:34:03","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rw46-qg69-vg6h"}]},{"advisoryId":"PKSA-r2bg-9v9s-cjfy","packageName":"kimai\/kimai","remoteId":"GHSA-3q6q-26vg-v97x","title":"Kimai: Improper Authorization Through Activity Creation with Preset Project Allows Creation Under Unauthorized Projects","link":"https:\/\/github.com\/advisories\/GHSA-3q6q-26vg-v97x","cve":"CVE-2026-52821","affectedVersions":"\u003C=2.56.0","source":"GitHub","reportedAt":"2026-07-14 00:03:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3q6q-26vg-v97x"}]},{"advisoryId":"PKSA-8c2d-bzrd-yygj","packageName":"kimai\/kimai","remoteId":"GHSA-c6w6-57jj-62vh","title":"Improper Authorization in Kimai Timesheet Restart and Duplicate Allows New Timesheets After Project Access Revocation","link":"https:\/\/github.com\/advisories\/GHSA-c6w6-57jj-62vh","cve":"CVE-2026-52822","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-14 00:04:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c6w6-57jj-62vh"}]},{"advisoryId":"PKSA-st54-1y6x-76ks","packageName":"kimai\/kimai","remoteId":"GHSA-r8vr-m544-qh4h","title":"Kimai: Login CSRF in the Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes","link":"https:\/\/github.com\/advisories\/GHSA-r8vr-m544-qh4h","cve":"CVE-2026-52823","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-14 00:05:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r8vr-m544-qh4h"}]},{"advisoryId":"PKSA-rg27-2yxz-ng1q","packageName":"kimai\/kimai","remoteId":"GHSA-jr9p-4h4j-6c58","title":"Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover","link":"https:\/\/github.com\/advisories\/GHSA-jr9p-4h4j-6c58","cve":"CVE-2026-52824","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-14 00:07:59","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-jr9p-4h4j-6c58"}]},{"advisoryId":"PKSA-v6y1-r12h-qsx3","packageName":"kimai\/kimai","remoteId":"GHSA-xv4r-4885-gwpg","title":"Kimai has Improper Authorization in Team Member and Team Activity Assignment APIs Which Allows Expansion of Team Scope Beyond Authorized Visibility","link":"https:\/\/github.com\/advisories\/GHSA-xv4r-4885-gwpg","cve":"CVE-2026-52825","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-14 00:09:03","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xv4r-4885-gwpg"}]},{"advisoryId":"PKSA-zsy3-64rr-9k1n","packageName":"kimai\/kimai","remoteId":"GHSA-2xgg-2x8h-8xw4","title":"Kimai: Improper Authorization in Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate Manipulation","link":"https:\/\/github.com\/advisories\/GHSA-2xgg-2x8h-8xw4","cve":"CVE-2026-52826","affectedVersions":"\u003C=2.56.0","source":"GitHub","reportedAt":"2026-07-14 00:09:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2xgg-2x8h-8xw4"}]},{"advisoryId":"PKSA-35k6-pfzb-3chy","packageName":"kimai\/kimai","remoteId":"GHSA-pgcc-vfmc-7cw5","title":" Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes","link":"https:\/\/github.com\/advisories\/GHSA-pgcc-vfmc-7cw5","cve":"CVE-2026-49992","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-13 23:55:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pgcc-vfmc-7cw5"}]},{"advisoryId":"PKSA-mhmq-vzyg-sjjv","packageName":"kimai\/kimai","remoteId":"GHSA-4m8q-55qv-9pwp","title":"Kimai: Teamlead authorization bypass in GET \/api\/timesheets allows reading other users\u0027 timesheet records without being teamlead of the target","link":"https:\/\/github.com\/advisories\/GHSA-4m8q-55qv-9pwp","cve":"CVE-2026-52819","affectedVersions":"\u003C=2.56.0","source":"GitHub","reportedAt":"2026-07-13 23:55:16","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-4m8q-55qv-9pwp"}]},{"advisoryId":"PKSA-q7f8-m7q7-t9t8","packageName":"kimai\/kimai","remoteId":"GHSA-vrr2-g9gh-c3jc","title":"Kimai: Timesheet PATCH\/POST allows assigning to project outside user\u0027s team via query_builder OR-bypass","link":"https:\/\/github.com\/advisories\/GHSA-vrr2-g9gh-c3jc","cve":"CVE-2026-52820","affectedVersions":"\u003C=2.56.0","source":"GitHub","reportedAt":"2026-07-13 23:55:35","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vrr2-g9gh-c3jc"}]},{"advisoryId":"PKSA-j8yw-pd54-qb9k","packageName":"kimai\/kimai","remoteId":"GHSA-pj8j-p4g4-4vw8","title":"Kimai has Server-Side Request Forgery in Invoice PDF Rendering via Markdown Image URLs","link":"https:\/\/github.com\/advisories\/GHSA-pj8j-p4g4-4vw8","cve":"CVE-2026-49865","affectedVersions":"\u003C=2.57.0","source":"GitHub","reportedAt":"2026-07-10 16:04:40","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pj8j-p4g4-4vw8"}]}],"nukeviet\/nukeviet":[{"advisoryId":"PKSA-npyr-6yvm-53qx","packageName":"nukeviet\/nukeviet","remoteId":"GHSA-465g-4q99-5x86","title":"NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module","link":"https:\/\/github.com\/advisories\/GHSA-465g-4q99-5x86","cve":"CVE-2026-54064","affectedVersions":"\u003C4.6.00","source":"GitHub","reportedAt":"2026-07-13 17:54:08","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-465g-4q99-5x86"}]},{"advisoryId":"PKSA-dsc1-qrmn-vnq5","packageName":"nukeviet\/nukeviet","remoteId":"GHSA-c9xg-64p9-f2jj","title":"NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function","link":"https:\/\/github.com\/advisories\/GHSA-c9xg-64p9-f2jj","cve":"CVE-2026-54065","affectedVersions":"\u003C4.6.00","source":"GitHub","reportedAt":"2026-07-13 17:55:48","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c9xg-64p9-f2jj"}]},{"advisoryId":"PKSA-x92d-g786-69f4","packageName":"nukeviet\/nukeviet","remoteId":"GHSA-4chg-4752-w88r","title":"NukeViet: Pre-authentication SSRF via X-Forwarded-Host","link":"https:\/\/github.com\/advisories\/GHSA-4chg-4752-w88r","cve":"CVE-2026-55372","affectedVersions":"\u003C4.6.00","source":"GitHub","reportedAt":"2026-07-13 17:58:44","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-4chg-4752-w88r"}]},{"advisoryId":"PKSA-zhpy-zkp7-5p69","packageName":"nukeviet\/nukeviet","remoteId":"GHSA-mxpf-qgg6-v3ff","title":"NukeViet: Unauthenticated Reflected XSS in Comment Module","link":"https:\/\/github.com\/advisories\/GHSA-mxpf-qgg6-v3ff","cve":"CVE-2026-48118","affectedVersions":"\u003C4.5.09","source":"GitHub","reportedAt":"2026-07-13 17:21:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mxpf-qgg6-v3ff"}]},{"advisoryId":"PKSA-qw3x-tkjj-83zs","packageName":"nukeviet\/nukeviet","remoteId":"GHSA-w2w5-w2pw-r929","title":"NukeViet: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)","link":"https:\/\/github.com\/advisories\/GHSA-w2w5-w2pw-r929","cve":"CVE-2026-49259","affectedVersions":"\u003C4.5.09","source":"GitHub","reportedAt":"2026-07-13 17:22:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w2w5-w2pw-r929"}]}],"prestashop\/ps_facetedsearch":[{"advisoryId":"PKSA-36b6-kgzr-fpm3","packageName":"prestashop\/ps_facetedsearch","remoteId":"GHSA-m5f5-28qr-9g9r","title":"prestashop\/ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE","link":"https:\/\/github.com\/advisories\/GHSA-m5f5-28qr-9g9r","cve":"CVE-2026-54159","affectedVersions":"\u003E=3.0.0,\u003C4.0.4","source":"GitHub","reportedAt":"2026-07-10 20:36:56","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-m5f5-28qr-9g9r"}]}],"notrinos\/notrinos-erp":[{"advisoryId":"PKSA-6c2y-dycw-7c38","packageName":"notrinos\/notrinos-erp","remoteId":"GHSA-qv4m-m73m-8hj7","title":"NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee \u0022Documents\u0022 (doc_file)","link":"https:\/\/github.com\/advisories\/GHSA-qv4m-m73m-8hj7","cve":null,"affectedVersions":"\u003C=1.0.0","source":"GitHub","reportedAt":"2026-07-10 19:34:03","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qv4m-m73m-8hj7"}]}],"api-platform\/json-api":[{"advisoryId":"PKSA-scrq-f2mk-7bhq","packageName":"api-platform\/json-api","remoteId":"GHSA-pjhx-3c3w-9v23","title":"API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate","link":"https:\/\/github.com\/advisories\/GHSA-pjhx-3c3w-9v23","cve":"CVE-2026-49858","affectedVersions":"\u003E=4.3.0,\u003C4.3.8|\u003E=4.2.0,\u003C4.2.25|\u003E=4.0.0,\u003C4.1.29","source":"GitHub","reportedAt":"2026-07-10 14:32:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pjhx-3c3w-9v23"}]}],"api-platform\/hal":[{"advisoryId":"PKSA-9wr7-4vnk-wwmr","packageName":"api-platform\/hal","remoteId":"GHSA-pjhx-3c3w-9v23","title":"API Platform Core vulnerable to cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate","link":"https:\/\/github.com\/advisories\/GHSA-pjhx-3c3w-9v23","cve":"CVE-2026-49858","affectedVersions":"\u003E=4.3.0,\u003C4.3.8|\u003E=4.2.0,\u003C4.2.25|\u003E=4.0.0,\u003C4.1.29","source":"GitHub","reportedAt":"2026-07-10 14:32:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-pjhx-3c3w-9v23"}]}],"simplesamlphp\/saml2":[{"advisoryId":"PKSA-yk3g-3g3t-ts6q","packageName":"simplesamlphp\/saml2","remoteId":"GHSA-6929-8p9f-26jx","title":"SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass","link":"https:\/\/github.com\/advisories\/GHSA-6929-8p9f-26jx","cve":"CVE-2026-49283","affectedVersions":"\u003C4.19.3|\u003E=4.20.0,\u003C4.20.2|\u003E=5.0.0,\u003C5.0.6|\u003E=6.0.0,\u003C6.2.1","source":"GitHub","reportedAt":"2026-07-02 20:25:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6929-8p9f-26jx"}]},{"advisoryId":"PKSA-1fc7-xrz7-vw78","packageName":"simplesamlphp\/saml2","remoteId":"GHSA-5cjr-mxj5-wmrx","title":"SimpleSAMLphp has Possible DoS via XPath Transform","link":"https:\/\/github.com\/advisories\/GHSA-5cjr-mxj5-wmrx","cve":"CVE-2026-49289","affectedVersions":"\u003C=4.19.2|\u003E=4.20.0,\u003C=4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:27:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5cjr-mxj5-wmrx"}]}],"simplesamlphp\/saml2-legacy":[{"advisoryId":"PKSA-4y26-97zb-p98g","packageName":"simplesamlphp\/saml2-legacy","remoteId":"GHSA-6929-8p9f-26jx","title":"SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass","link":"https:\/\/github.com\/advisories\/GHSA-6929-8p9f-26jx","cve":"CVE-2026-49283","affectedVersions":"\u003C4.19.3|\u003E=4.20.0,\u003C4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:25:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6929-8p9f-26jx"}]},{"advisoryId":"PKSA-11bv-m3wk-h9sn","packageName":"simplesamlphp\/saml2-legacy","remoteId":"GHSA-5cjr-mxj5-wmrx","title":"SimpleSAMLphp has Possible DoS via XPath Transform","link":"https:\/\/github.com\/advisories\/GHSA-5cjr-mxj5-wmrx","cve":"CVE-2026-49289","affectedVersions":"\u003C=4.19.2|\u003E=4.20.0,\u003C=4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:27:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5cjr-mxj5-wmrx"}]}],"symbiote\/silverstripe-advancedworkflow":[{"advisoryId":"PKSA-x4kf-7gbb-fh93","packageName":"symbiote\/silverstripe-advancedworkflow","remoteId":"symbiote\/silverstripe-advancedworkflow\/CVE-2026-54718.yaml","title":"CVE-2026-54718 - Remote code execution via advanced workflow email template","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-54718","cve":"CVE-2026-54718","affectedVersions":"\u003C6.4.5|\u003E=7.0.0,\u003C7.1.3|\u003E=7.2.0,\u003C7.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 04:12:03","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-39mm-rwm3-29jp"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"symbiote\/silverstripe-advancedworkflow\/CVE-2026-54718.yaml"}]}],"silverstripe\/cms":[{"advisoryId":"PKSA-pjvm-vnw2-n3m2","packageName":"silverstripe\/cms","remoteId":"silverstripe\/cms\/CVE-2026-54717.yaml","title":"CVE-2026-54717 - XSS in breadcrumbs in page list view","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-54717","cve":"CVE-2026-54717","affectedVersions":"\u003C6.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 02:39:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w3cp-g2pf-65wh"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/cms\/CVE-2026-54717.yaml"}]}],"silverstripe\/versioned":[{"advisoryId":"PKSA-nksq-cxj8-zb32","packageName":"silverstripe\/versioned","remoteId":"silverstripe\/versioned\/CVE-2026-55779.yaml","title":"CVE-2026-55779 - XSS in archive admin restore","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-55779","cve":"CVE-2026-55779","affectedVersions":"\u003C3.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 02:53:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-m4g4-86qc-v8w7"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/versioned\/CVE-2026-55779.yaml"}]}],"silverstripe\/framework":[{"advisoryId":"PKSA-x6tz-s6v3-ynk3","packageName":"silverstripe\/framework","remoteId":"silverstripe\/framework\/CVE-2026-54720.yaml","title":"CVE-2026-54720 - XSS attack through media embed","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-54720","cve":"CVE-2026-54720","affectedVersions":"\u003C6.2.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 02:45:19","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-gvrw-qqp5-jgc5"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/framework\/CVE-2026-54720.yaml"}]}],"silverstripe\/userforms":[{"advisoryId":"PKSA-g6zg-78xs-c8r8","packageName":"silverstripe\/userforms","remoteId":"silverstripe\/userforms\/CVE-2026-54721.yaml","title":"CVE-2026-54721 - Remote code execution via userforms email subject","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-54721","cve":"CVE-2026-54721","affectedVersions":"\u003C6.4.9|\u003E=7.0.0,\u003C7.0.7|\u003E=7.1.0,\u003C7.1.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 04:05:09","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g8wr-r2v2-vqc6"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/userforms\/CVE-2026-54721.yaml"}]}],"mtdowling\/jmespath.php":[{"advisoryId":"PKSA-mnyp-475s-ywph","packageName":"mtdowling\/jmespath.php","remoteId":"mtdowling\/jmespath.php\/CVE-2026-54133.yaml","title":"CompilerRuntime code injection via unescaped function names","link":"https:\/\/github.com\/jmespath\/jmespath.php\/security\/advisories\/GHSA-pcw8-m77r-2528","cve":"CVE-2026-54133","affectedVersions":"\u003C2.9.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-11 10:41:50","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-pcw8-m77r-2528"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"mtdowling\/jmespath.php\/CVE-2026-54133.yaml"}]}],"cakephp\/authentication":[{"advisoryId":"PKSA-bz6x-t8z8-r26p","packageName":"cakephp\/authentication","remoteId":"GHSA-hhpq-7wg4-36jm","title":"CakePHP Authentication: Open redirect weakness via backslash bypass","link":"https:\/\/github.com\/advisories\/GHSA-hhpq-7wg4-36jm","cve":"CVE-2026-55590","affectedVersions":"\u003C2.11.1|\u003E=3.0.0,\u003C3.3.6|\u003E=4.0.0,\u003C4.1.1","source":"GitHub","reportedAt":"2026-06-17 18:52:09","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hhpq-7wg4-36jm"}]}],"tinymce\/tinymce":[{"advisoryId":"PKSA-2v47-9p8y-4qt3","packageName":"tinymce\/tinymce","remoteId":"GHSA-v98h-vmpc-fpqv","title":"TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments","link":"https:\/\/github.com\/advisories\/GHSA-v98h-vmpc-fpqv","cve":"CVE-2026-47762","affectedVersions":"\u003C=5.10.9|\u003E=8.0.0,\u003C8.5.1|\u003E=6.0.0,\u003C7.9.3","source":"GitHub","reportedAt":"2026-06-05 20:29:07","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v98h-vmpc-fpqv"}]}],"pimcore\/admin-ui-classic-bundle":[{"advisoryId":"PKSA-v29g-sqpm-mznn","packageName":"pimcore\/admin-ui-classic-bundle","remoteId":"GHSA-h4ph-crvj-9h92","title":"Pimcore Admin Classic Bundle Vulnerable to SQL Injection in Translation Grid Date Filter via Unsanitized Property Parameter","link":"https:\/\/github.com\/advisories\/GHSA-h4ph-crvj-9h92","cve":"CVE-2026-44741","affectedVersions":"\u003C1.7.18|\u003E=2.0.0-RC1,\u003C=2.3.5","source":"GitHub","reportedAt":"2026-05-27 00:35:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h4ph-crvj-9h92"}]}],"wwbn\/avideo":[{"advisoryId":"PKSA-mhr2-p9hx-xy4j","packageName":"wwbn\/avideo","remoteId":"GHSA-wprj-9cvc-5w37","title":"AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records","link":"https:\/\/github.com\/advisories\/GHSA-wprj-9cvc-5w37","cve":"CVE-2026-56341","affectedVersions":"\u003C=26.0","source":"GitHub","reportedAt":"2026-03-29 15:40:52","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-wprj-9cvc-5w37"}]},{"advisoryId":"PKSA-3whn-q4tm-bwhh","packageName":"wwbn\/avideo","remoteId":"GHSA-5x2w-37xf-7962","title":"AVideo has Unauthenticated PGP Message Decryption via Public Endpoint","link":"https:\/\/github.com\/advisories\/GHSA-5x2w-37xf-7962","cve":"CVE-2026-56346","affectedVersions":"\u003C=25.0","source":"GitHub","reportedAt":"2026-03-19 12:46:01","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5x2w-37xf-7962"}]},{"advisoryId":"PKSA-mpqq-rw7h-r6qr","packageName":"wwbn\/avideo","remoteId":"GHSA-h39h-7cvg-q7j6","title":"AVideo has Authenticated Server-Side Request Forgery via downloadURL in aVideoEncoder.json.php","link":"https:\/\/github.com\/advisories\/GHSA-h39h-7cvg-q7j6","cve":"CVE-2026-27732","affectedVersions":"\u003C=21.0","source":"GitHub","reportedAt":"2026-02-25 18:57:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-h39h-7cvg-q7j6"}]}],"oxid-esales\/oxideshop-ce":[{"advisoryId":"PKSA-hjpv-ct4c-8fq5","packageName":"oxid-esales\/oxideshop-ce","remoteId":"GHSA-qqcr-9jfc-35c4","title":"OXID eShop May Display User Information","link":"https:\/\/github.com\/advisories\/GHSA-qqcr-9jfc-35c4","cve":"CVE-2024-56526","affectedVersions":"\u003E=6.0.0,\u003C6.14.4","source":"GitHub","reportedAt":"2025-05-13 18:30:52","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-qqcr-9jfc-35c4"}]}]}}