Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,236 advisories

Loading
Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration Moderate
GHSA-cvpc-hccg-wmw4 was published for verbb/formie (Composer) Jul 17, 2026
chaitanyagarware Credited to chaitanyagarware
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise Critical
CVE-2026-55579 was published for pheditor/pheditor (Composer) Jul 16, 2026
sondt99 Credited to sondt99
sondt99 Credited to sondt99
Pheditor has an authenticated terminal command whitelist bypass High
CVE-2026-54540 was published for pheditor/pheditor (Composer) Jul 16, 2026
shanjijian Credited to shanjijian
adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files Moderate
GHSA-xg43-5579-qw6v was published for adawolfa/isdoc (Composer) Jul 15, 2026
MantisBT: Stored XSS in print_all_bug_page_word.php High
CVE-2026-62944 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
dracosectech-code Credited to dracosectech-code and dregad dregad dregad
MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs Moderate
CVE-2026-52883 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
byteoverride Credited to byteoverride and dregad dregad dregad
MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters Moderate
CVE-2026-52882 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
dregad Credited to dregad
MantisBT: Reflected XSS in admin/install.php via unescaped printf Critical
CVE-2026-52881 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
McCaulay Credited to McCaulay and dregad dregad dregad
MantisBT: Reflected XSS in admin/install.php Critical
CVE-2026-52847 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
McCaulay Credited to McCaulay and dregad dregad dregad
Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail Moderate
CVE-2026-50552 was published for phanan/koel (Composer) Jul 15, 2026
Yunkaiwjs Credited to Yunkaiwjs
Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths High
CVE-2026-54491 was published for phanan/koel (Composer) Jul 15, 2026
kiffa-australis256 Credited to kiffa-australis256
Koel has SSRF through Authenticated Subsonic podcast feed URLs Moderate
GHSA-8q6q-m837-fv64 was published for phanan/koel (Composer) Jul 15, 2026
DavidCarliez Credited to DavidCarliez
Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations High
CVE-2026-54493 was published for phanan/koel (Composer) Jul 15, 2026
dennyabrahamsinaga Credited to dennyabrahamsinaga
Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation Moderate
CVE-2026-54492 was published for phanan/koel (Composer) Jul 15, 2026
dennyabrahamsinaga Credited to dennyabrahamsinaga
MantisBT: REST API unauthorized Issue status change Moderate
CVE-2026-49280 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
dregad Credited to dregad and mamdouhmahfouz mamdouhmahfouz mamdouhmahfouz
MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php High
CVE-2026-49273 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
McCaulay Credited to McCaulay and dregad dregad dregad
MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator Critical
CVE-2026-47156 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
McCaulay Credited to McCaulay, dregad, tyage, voraci0us, chndlrx, and bharatdevasani dregad dregad
tyage tyage voraci0us voraci0us chndlrx chndlrx bharatdevasani bharatdevasani
MantisBT: SQL Injection via history_order Configuration Value High
CVE-2026-47142 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
McCaulay Credited to McCaulay and dregad dregad dregad
FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE Critical
GHSA-hgjx-r89m-m7v4 was published for facturascripts/facturascripts (Composer) Jul 14, 2026
aslein1413-sys Credited to aslein1413-sys
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField High
CVE-2026-54087 was published for easycorp/easyadmin-bundle (Composer) Jul 14, 2026
Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter Moderate
CVE-2026-50157 was published for auth0/symfony (Composer) Jul 14, 2026
ProTip! Advisories are also available from the GraphQL API