Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

235 advisories

Loading
Contao: Path traversal in the images controller Moderate
CVE-2026-107844 was published for contao/core-bundle (Composer) Oct 9, 2026
HDWSec Credited to HDWSec
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path Moderate
CVE-2026-59944 was published for composer/composer (Composer) Oct 2, 2026
DavidCarliez Credited to DavidCarliez, manus-use, and arpitjain099 manus-use manus-use
arpitjain099 arpitjain099
alham-rizvi Credited to alham-rizvi
Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion High
CVE-2026-72695 was published for getgrav/grav (Composer) Sep 17, 2026
ka3n1x Credited to ka3n1x
alham-rizvi Credited to alham-rizvi
Chamilo LMS CStudio upload flow allows unauthenticated remote code execution Critical
CVE-2026-45140 was published for chamilo/chamilo-lms (Composer) Sep 17, 2026
h4knet Credited to h4knet
Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images High
CVE-2026-69089 was published for getgrav/grav (Composer) Sep 17, 2026
nihaddhuseynli Credited to nihaddhuseynli
Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path High
CVE-2026-84374 was published for maatwebsite/excel (Composer) Sep 8, 2026
seck19 Credited to seck19
Kirby: Access to image files outside of the site root via path traversal in the media handling Moderate
CVE-2026-75592 was published for getkirby/cms (Composer) Sep 2, 2026
0x1saac Credited to 0x1saac
Pig-Tail Credited to Pig-Tail
Snipe-IT has a path traversal vulnerability via CSV import `image` field Low
CVE-2026-55469 was published for snipe/snipe-it (Composer) Aug 28, 2026
Vasco0x4 Credited to Vasco0x4
phpMyFAQ has Potential Authenticated Path Traversal in PDF Export Moderate
GHSA-88g4-74f3-63x9 was published for phpmyfaq/phpmyfaq (Composer) Aug 25, 2026
DomainXTech Credited to DomainXTech
Duplicate Advisory: Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion High
GHSA-896w-cw95-xq7w was published for getgrav/grav (Composer) Aug 25, 2026 • withdrawn
Winter: Local File Inclusion through =include directives in JavaScript asset compilation Moderate
GHSA-2223-f22x-24cq was published for winter/wn-system-module (Composer) Aug 20, 2026
elmahy111 Credited to elmahy111
Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets Moderate
CVE-2026-63179 was published for winter/wn-backend-module (Composer) Aug 20, 2026
hypnguyen1209 Credited to hypnguyen1209
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall High
CVE-2026-55224 was published for mineadmin/mineadmin (Composer) Aug 18, 2026
tikket1 Credited to tikket1
Duplicate Advisory: Craft CMS: Incorrect path validation could potentially lead to path traversal Moderate
GHSA-9w6w-8x3c-hfqp was published for craftcms/cms (Composer) Aug 11, 2026 • withdrawn
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames High
CVE-2026-63222 was published for codeigniter4/framework (Composer) Aug 7, 2026
gr8man Credited to gr8man
Smarty Security stream restriction bypass through stream: resource Moderate
CVE-2026-62996 was published for smarty/smarty (Composer) Aug 7, 2026
Faze-up Credited to Faze-up
Smarty: Symlink path traversal out of trusted directories Moderate
CVE-2026-62992 was published for smarty/smarty (Composer) Aug 7, 2026
Craft CMS: Incorrect path validation could potentially lead to path traversal Low
CVE-2026-72783 was published for craftcms/cms (Composer) Aug 6, 2026
Contao: Possible path traversal in job download URIs Low
CVE-2026-55825 was published for contao/contao (Composer) Aug 6, 2026
0x1saac Credited to 0x1saac
ProTip! Advisories are also available from the GraphQL API