Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5,913 advisories

Loading
Froxlor's API Authentication bypasses 2FA Authentication High
GHSA-f9rx-7wf7-jr36 was published for froxlor/froxlor (Composer) Jun 3, 2026
hett-patell Credited to hett-patell and SKaif009 SKaif009 SKaif009
Froxlor: BIND Zone File Injection via TXT Record Content High
CVE-2026-41234 was published for froxlor/froxlor (Composer) Jun 3, 2026
hett-patell Credited to hett-patell and SKaif009 SKaif009 SKaif009
backpack/crud is vulnerable to Cross-Site Scripting (XSS) Moderate
CVE-2022-31114 was published for backpack/crud (Composer) Jun 3, 2026
tabacitu Credited to tabacitu
formie's unauthenticated front-end submission editing can overwrite existing submissions High
CVE-2026-47266 was published for verbb/formie (Composer) May 29, 2026
Admidio: Any logged-in user can delete inventory fields via `mode=field_delete` — incomplete fix of #2024 Moderate
CVE-2026-47233 was published for admidio/admidio (Composer) May 29, 2026
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
Admidio writes session IDs and auto-login cookie values to application logs Moderate
CVE-2026-47234 was published for admidio/admidio (Composer) May 29, 2026
0x2face Credited to 0x2face, spect3r1, 0xreizouko, ADHAM-KHAIRY, BabaYaga0x01, and 0xheg3zy spect3r1 spect3r1
0xreizouko 0xreizouko ADHAM-KHAIRY ADHAM-KHAIRY BabaYaga0x01 BabaYaga0x01 0xheg3zy 0xheg3zy
Admidio PKCS#12 private key export action lacks CSRF protection Moderate
CVE-2026-47232 was published for admidio/admidio (Composer) May 29, 2026
0x2face Credited to 0x2face, ADHAM-KHAIRY, 0xreizouko, spect3r1, agn4by, BabaYaga0x01, and 0xheg3zy ADHAM-KHAIRY ADHAM-KHAIRY
0xreizouko 0xreizouko spect3r1 spect3r1 agn4by agn4by BabaYaga0x01 BabaYaga0x01 0xheg3zy 0xheg3zy
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
Admidio: IDOR in documents-files.php allows cross-folder file rename and description changes by unauthorized uploaders Moderate
CVE-2026-47230 was published for admidio/admidio (Composer) May 29, 2026
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
Admidio: CSRF in SSO client `enable` action toggles SAML/OIDC clients without token validation Moderate
CVE-2026-47229 was published for admidio/admidio (Composer) May 29, 2026
offset Credited to offset
Admidio's CSRF in registration `send_login` mode resets arbitrary user passwords Moderate
CVE-2026-47228 was published for admidio/admidio (Composer) May 29, 2026
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
VishaaLlKumaaRr Credited to VishaaLlKumaaRr
Symfony: Twilio SMS Notifier allows unauthenticated webhook injection due to missing X-Twilio-Signature verification Moderate
CVE-2026-47212 was published for symfony/symfony (Composer) May 29, 2026
nicolas-grekas Credited to nicolas-grekas
Koel Vulnerable to SSRF via Podcast Episode Enclosure URLs High
CVE-2026-47260 was published for phanan/koel (Composer) May 29, 2026
EndlssNightmare Credited to EndlssNightmare
ezsystems/ezpublish-legacy has a SQL injection in dfscleanup High
CVE-2026-38739 was published for ezsystems/ezpublish-legacy (Composer) May 29, 2026
Goaterino Credited to Goaterino
Froxlor has an incomplete fix for CVE-2026-30932 Moderate
CVE-2026-41237 was published for froxlor/froxlor (Composer) May 29, 2026
Froxlor has privilege escalation in SSH key synchronization via symlinked `authorized_keys` path High
CVE-2026-41236 was published for froxlor/froxlor (Composer) May 29, 2026
larlarua Credited to larlarua
Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement High
CVE-2026-41235 was published for froxlor/froxlor (Composer) May 29, 2026
larlarua Credited to larlarua
Pimcore Platform - SQL Injection in DataObject composite index handling during class definition import/save High
CVE-2026-5394 was published for pimcore/pimcore (Composer) May 28, 2026
researchatfluidattacks Credited to researchatfluidattacks
nicolas-grekas Credited to nicolas-grekas
Symfony's JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS Low
CVE-2026-45756 was published for symfony/json-path (Composer) May 28, 2026
alexandre-daubois Credited to alexandre-daubois and unknownhad unknownhad unknownhad
Symfony's Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event Injection Moderate
CVE-2026-45755 was published for symfony/mailtrap-mailer (Composer) May 28, 2026
alexandre-daubois Credited to alexandre-daubois and unknownhad unknownhad unknownhad
Symfony's Mailjet Mailer Webhook Parser Never Verifies the Configured Secret — Unauthenticated Webhook Event Injection Moderate
CVE-2026-45754 was published for symfony/lox24-notifier (Composer) May 28, 2026
alexandre-daubois Credited to alexandre-daubois, nicolas-grekas, and unknownhad nicolas-grekas nicolas-grekas
unknownhad unknownhad
nicolas-grekas Credited to nicolas-grekas
ProTip! Advisories are also available from the GraphQL API