Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-96h3-5x6v-m776
  • Packagist/composer/composer
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path 3 hours ago
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-97jj-33gv-5xf9
  • Packagist/league/commonmark
league/commonmark: DisallowedRawHtml bypassed when a disallowed tag name ends the raw-HTML literal 2 days ago
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-3q6v-r5mr-hxv8
  • Packagist/league/commonmark
league/commonmark: Quadratic-time denial of service in the GitHub Flavored Markdown Table extension block-start scan 2 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-jh5r-qr3c-85q8
  • Packagist/laravel/framework
Laravel: XSS in Debug Page Information 3 days ago
  • Fix available
  • Severity - 3.1 (Low)
GHSA-cxf4-7mrp-vvpr
  • Packagist/league/flysystem
Flysystem: WhitespacePathNormalizer's control-character (CorruptedPathDetected) check is bypassed by malformed UTF-8 in the path, affecting every adapter 3 days ago
  • Fix available
  • Severity - 3.5 (Low)
GHSA-r6hr-vr92-vv28
  • Packagist/phpcsstandards/phpcsutils
PHPCSUtils: Remote code execution via eval() in AbstractArrayDeclarationSniff::getActualArrayKey() 3 days ago
  • Fix available
  • Severity - 8.6 (High)
GHSA-g7vj-c29h-3h5m
  • Packagist/fof/oauth
FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider 25 Sep
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-v65j-hff3-753c
  • Packagist/starcitizenwiki/embedvideo
Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled 25 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-qxg3-46rw-79j8
  • Packagist/code16/sharp
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute 25 Sep
  • Fix available
  • Severity - 7.3 (High)
GHSA-vj3q-vp3g-j9c8
  • Packagist/code16/sharp
code16/sharp has a stored XSS via data-html-content Sanitizer Bypass 25 Sep
  • Fix available
  • Severity - 8.7 (High)
GHSA-87mg-5grr-rhwh
  • Packagist/contao/contao
  • Packagist/contao/core-bundle
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module 24 Sep
  • Fix available
  • Severity - 3.1 (Low)
GHSA-36h5-qg4p-q2qf
  • Packagist/zbateson/mail-mime-parser
zbateson/mail-mime-parser has CRLF header injection via attachment filename 24 Sep
  • Fix available
  • Severity - 7.2 (High)
GHSA-f6v3-2qmr-vfjx
  • Packagist/zbateson/mail-mime-parser
zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME 24 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-rw77-vq4g-x3hp
  • Packagist/phpmyfaq/phpmyfaq
  • Packagist/thorsten/phpmyfaq
phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion 24 Sep
  • Fix available
  • Severity - 8.5 (High)
GHSA-8gpw-xvpf-hvx5
  • Packagist/phpmyfaq/phpmyfaq
  • Packagist/thorsten/phpmyfaq
phpMyFAQ's two-factor authentication login bypasses the password factor 24 Sep
  • Fix available
  • Severity - 8.1 (High)
GHSA-pgwp-vc7q-cvj3
  • Packagist/phpmyfaq/phpmyfaq
  • Packagist/thorsten/phpmyfaq
phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission 24 Sep
  • Fix available
  • Severity - 8.2 (High)