Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-4x9g-vw65-vvf9
  • Packagist/getgrav/grav
Grav: Unauthenticated denial of service via unbounded image derivative dimensions yesterday
  • Fix available
  • Severity - 8.7 (High)
GHSA-2mhj-fhvg-v428
  • Packagist/pimcore/pimcore
Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name 2 days ago
  • Fix available
  • Severity - 8.5 (High)
DRUPAL-CONTRIB-2026-099
  • Packagist:https://packages.drupal.org/8/drupal/quicktabs
See record for full details 3 days ago
  • Fix available
DRUPAL-CONTRIB-2026-098
  • Packagist:https://packages.drupal.org/8/drupal/externalauth
See record for full details 3 days ago
  • Fix available
DRUPAL-CONTRIB-2026-097
  • Packagist:https://packages.drupal.org/8/drupal/entity_share_websub
See record for full details 3 days ago
  • Fix available
DRUPAL-CONTRIB-2026-096
  • Packagist:https://packages.drupal.org/8/drupal/diff
See record for full details 3 days ago
  • Fix available
DRUPAL-CONTRIB-2026-095
  • Packagist:https://packages.drupal.org/8/drupal/commerce_paypal
See record for full details 3 days ago
  • Fix available
GHSA-6pvm-2vjj-rx4w
  • Packagist/thorsten/phpmyfaq
phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration 3 days ago
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-jmqm-f8q4-v7wx
  • Packagist/librenms/librenms
LibreNMS: Reflected XSS via Proxmox instance/vmid GET parameters injected into document.title JavaScript assignment 3 days ago
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-j5jq-cr68-v2xx
  • Packagist/winter/wn-backend-module
Winter: Authenticated backend users can bypass Users controller permission checks 3 days ago
  • Fix available
  • Severity - 7.1 (High)
GHSA-5c4f-9pq9-6c77
  • Packagist/winter/wn-cms-module
Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads 3 days ago
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-m7jc-g4rc-jmvh
  • Packagist/winter/wn-backend-module
Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax 3 days ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-vgp4-2fc4-qff2
  • Packagist/winter/wn-backend-module
Winter: Stored XSS through Editor Settings custom styles 3 days ago
  • Fix available
  • Severity - 8.1 (High)
GHSA-v7cf-8gh9-gxmj
  • Packagist/winter/wn-backend-module
Winter: Stored XSS through Brand Settings custom styles 3 days ago
  • Fix available
  • Severity - 8.1 (High)
GHSA-mmj4-63m4-r6h5
  • Packagist/codeigniter4/framework
CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules 07 Aug
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-hhmc-q9hp-r662
  • Packagist/codeigniter4/framework
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames 07 Aug
  • Fix available
  • Severity - 7.5 (High)