Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

292 advisories

Loading
Kimai: Login CSRF in the Timesheet Stop and Restart API Endpoints Allows Unauthorized State Changes Moderate
CVE-2026-52823 was published for kimai/kimai (Composer) Jul 14, 2026
Mitchell45 Credited to Mitchell45
Kimai: Login CSRF in Default Team Creation Endpoints Allows Unauthorized Team and Permission Structure Changes Moderate
CVE-2026-49992 was published for kimai/kimai (Composer) Jul 13, 2026
Mitchell45 Credited to Mitchell45
YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserialize Critical
CVE-2026-52777 was published for yeswiki/yeswiki (Composer) Jul 9, 2026
fg0x0 Credited to fg0x0
Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET Requests Moderate
CVE-2026-53760 was published for admidio/admidio (Composer) Jul 9, 2026
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
symfony/ux-live-component: CSRF Protection Bypass — Accept Header is CORS-Safelisted Low
CVE-2026-49215 was published for symfony/ux-live-component (Composer) Jun 19, 2026
Kocal Credited to Kocal
Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module Moderate
CVE-2026-55745 was published for cotonti/cotonti (Composer) Jun 18, 2026
Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module High
CVE-2026-55744 was published for cotonti/cotonti (Composer) Jun 18, 2026
Cotonti: Cross-Site Request Forgery in the administration rights handler Critical
CVE-2026-55742 was published for cotonti/cotonti (Composer) Jun 18, 2026
Admidio PKCS#12 private key export action lacks CSRF protection Moderate
CVE-2026-47232 was published for admidio/admidio (Composer) May 29, 2026
0x2face Credited to 0x2face, ADHAM-KHAIRY, 0xreizouko, spect3r1, agn4by, BabaYaga0x01, Elkhatebx22, 00xCanelo, and 0xheg3zy ADHAM-KHAIRY ADHAM-KHAIRY
0xreizouko 0xreizouko spect3r1 spect3r1 agn4by agn4by BabaYaga0x01 BabaYaga0x01 Elkhatebx22 Elkhatebx22 00xCanelo 00xCanelo 0xheg3zy 0xheg3zy
Admidio: CSRF in SSO client `enable` action toggles SAML/OIDC clients without token validation Moderate
CVE-2026-47229 was published for admidio/admidio (Composer) May 29, 2026
offset Credited to offset
Admidio's CSRF in registration `send_login` mode resets arbitrary user passwords Moderate
CVE-2026-47228 was published for admidio/admidio (Composer) May 29, 2026
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
Concrete CMS is vulnerable to CSRF via Backend\File::approveVersion Low
CVE-2026-8340 was published for concrete5/concrete5 (Composer) May 26, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache Low
CVE-2026-8412 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete Low
CVE-2026-8410 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete Low
CVE-2026-8409 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan() Low
CVE-2026-8433 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete Low
CVE-2026-8411 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate Low
CVE-2026-8414 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design Low
CVE-2026-8413 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple() Low
CVE-2026-8434 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star() Low
CVE-2026-8432 was published for concrete5/concrete5 (Composer) May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion() Low
CVE-2026-8435 was published for concrete5/concrete5 (Composer) May 22, 2026
ProTip! Advisories are also available from the GraphQL API