Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

102 advisories

Loading
alham-rizvi Credited to alham-rizvi
Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion High
CVE-2026-72695 was published for getgrav/grav (Composer) Sep 17, 2026
ka3n1x Credited to ka3n1x
alham-rizvi Credited to alham-rizvi
Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images High
CVE-2026-69089 was published for getgrav/grav (Composer) Sep 17, 2026
nihaddhuseynli Credited to nihaddhuseynli
Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path High
CVE-2026-84374 was published for maatwebsite/excel (Composer) Sep 8, 2026
seck19 Credited to seck19
Pig-Tail Credited to Pig-Tail
Duplicate Advisory: Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion High
GHSA-896w-cw95-xq7w was published for getgrav/grav (Composer) Aug 25, 2026 • withdrawn
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall High
CVE-2026-55224 was published for mineadmin/mineadmin (Composer) Aug 18, 2026
tikket1 Credited to tikket1
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames High
CVE-2026-63222 was published for codeigniter4/framework (Composer) Aug 7, 2026
gr8man Credited to gr8man
Duplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images High
GHSA-mmwh-j75q-gxp8 was published for getgrav/grav (Composer) Aug 3, 2026 • withdrawn
Composer: Arbitrary file write outside vendor via malicious transitive package name High
CVE-2026-59948 was published for composer/composer (Composer) Jul 20, 2026
iliaal Credited to iliaal
FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents High
CVE-2026-45693 was published for facturascripts/facturascripts (Composer) Jul 14, 2026
5kr1pt Credited to 5kr1pt
Laravel-Mediable: path traversal vulnerability in the File::sanitizePath() High
CVE-2026-49970 was published for plank/laravel-mediable (Composer) Jul 13, 2026
0x00-sys Credited to 0x00-sys
NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function High
CVE-2026-54065 was published for nukeviet/nukeviet (Composer) Jul 13, 2026
g03m0n Credited to g03m0n and hoaquynhtim99 hoaquynhtim99 hoaquynhtim99
NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file) High
GHSA-qv4m-m73m-8hj7 was published for notrinos/notrinos-erp (Composer) Jul 10, 2026
Duplicate Advisory: Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read High
GHSA-jcmp-jxh2-4jc3 was published for craftcms/cms (Composer) Jun 21, 2026 • withdrawn
symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest High
CVE-2026-55878 was published for symfony/ux-toolkit (Composer) Jun 19, 2026
Kocal Credited to Kocal and Amoifr Amoifr Amoifr
TYPO3 CMS has Broken Access Control in its Media Module High
CVE-2026-49742 was published for typo3/cms-core (Composer) Jun 12, 2026
Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup High
CVE-2026-44177 was published for getkirby/cms (Composer) May 26, 2026
offset Credited to offset
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion High
CVE-2026-46491 was published for simplesamlphp/simplesamlphp-module-casserver (Composer) May 15, 2026
kamil-sawicki Credited to kamil-sawicki
Grav has Unauthenticated Path Traversal & Arbitrary File Write in its FormFlash component High
CVE-2026-42608 was published for getgrav/grav (Composer) May 5, 2026
sentinal404 Credited to sentinal404
AzuraCast has Path Traversal in `currentDirectory` Parameter that Enables Remote Code Execution via Media Upload High
CVE-2026-42605 was published for azuracast/azuracast (Composer) May 4, 2026
offset Credited to offset
ProTip! Advisories are also available from the GraphQL API