Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,562 advisories

Loading
alham-rizvi Credited to alham-rizvi
Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection Low
CVE-2026-72701 was published for getgrav/grav (Composer) Sep 17, 2026
alham-rizvi Credited to alham-rizvi
Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match Low
CVE-2026-72702 was published for getgrav/grav (Composer) Sep 17, 2026
alham-rizvi Credited to alham-rizvi
Chamilo LMS CStudio upload flow allows unauthenticated remote code execution Critical
CVE-2026-45140 was published for chamilo/chamilo-lms (Composer) Sep 17, 2026
h4knet Credited to h4knet
Grav: Stored XSS via Markdown audio/video media <source> URL Moderate
CVE-2026-75831 was published for getgrav/grav (Composer) Sep 17, 2026
alimony Credited to alimony
Grav: Stored XSS via quoted-attribute bypass in detectXss Moderate
CVE-2026-72832 was published for getgrav/grav (Composer) Sep 17, 2026
koyokr Credited to koyokr
Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images High
CVE-2026-69089 was published for getgrav/grav (Composer) Sep 17, 2026
nihaddhuseynli Credited to nihaddhuseynli
adamyordan Credited to adamyordan
Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation High
CVE-2026-65608 was published for getgrav/grav (Composer) Sep 17, 2026
haftoe Credited to haftoe
Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer Moderate
CVE-2026-61449 was published for getgrav/grav (Composer) Sep 17, 2026
iliaal Credited to iliaal
Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav Moderate
CVE-2026-58657 was published for getgrav/grav (Composer) Sep 16, 2026
DavidCarliez Credited to DavidCarliez
Grav: XSS Blueprint Validation Bypass via Twig String Concatenation Moderate
CVE-2026-61453 was published for getgrav/grav (Composer) Sep 16, 2026
alienkeric Credited to alienkeric and gemstone-source gemstone-source gemstone-source
Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip() Moderate
CVE-2026-59193 was published for getgrav/grav (Composer) Sep 16, 2026
Scriptmagum Credited to Scriptmagum
October CMS: Incomplete Scheme Validation in Image Resizer Low
GHSA-2xmm-m4wv-3fjh was published for october/october (Composer) Sep 14, 2026
0xGenesi Credited to 0xGenesi
October CMS: PHP Object Injection via Backend Widget Session Storage Low
CVE-2026-49400 was published for october/system (Composer) Sep 14, 2026
EndlssNightmare Credited to EndlssNightmare
October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls Low
CVE-2026-46696 was published for october/system (Composer) Sep 14, 2026
r00tn0b0dy Credited to r00tn0b0dy
Shopper: Missing authorization on product removal actions in CollectionProducts component High
CVE-2026-56825 was published for shopper/framework (Composer) Sep 11, 2026
therawdev Credited to therawdev
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph) Moderate
CVE-2026-56830 was published for shopper/framework (Composer) Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component High
CVE-2026-56829 was published for shopper/framework (Composer) Sep 11, 2026
therawdev Credited to therawdev
Shopper: privilege escalation via improper Livewire admin component authorization High
CVE-2026-56828 was published for shopper/framework (Composer) Sep 11, 2026
therawdev Credited to therawdev
Shopping privilege escalation through missing authorization in Settings components Moderate
CVE-2026-56826 was published for shopper/framework (Composer) Sep 11, 2026
baradika Credited to baradika
Shopper: Negative discount values accepted and propagated through order calculation pipeline Moderate
CVE-2026-56831 was published for shopper/framework (Composer) Sep 11, 2026
Fr6ey Credited to Fr6ey
Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration High
CVE-2026-55416 was published for pimcore/pimcore (Composer) Sep 10, 2026
EclipsSec Credited to EclipsSec
ProTip! Advisories are also available from the GraphQL API