Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

98 advisories

Loading
Contao: Path traversal in the images controller Moderate
CVE-2026-107844 was published for contao/core-bundle (Composer) Oct 9, 2026
HDWSec Credited to HDWSec
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path Moderate
CVE-2026-59944 was published for composer/composer (Composer) Oct 2, 2026
DavidCarliez Credited to DavidCarliez, manus-use, and arpitjain099 manus-use manus-use
arpitjain099 arpitjain099
Kirby: Access to image files outside of the site root via path traversal in the media handling Moderate
CVE-2026-75592 was published for getkirby/cms (Composer) Sep 2, 2026
0x1saac Credited to 0x1saac
phpMyFAQ has Potential Authenticated Path Traversal in PDF Export Moderate
GHSA-88g4-74f3-63x9 was published for phpmyfaq/phpmyfaq (Composer) Aug 25, 2026
DomainXTech Credited to DomainXTech
Winter: Local File Inclusion through =include directives in JavaScript asset compilation Moderate
GHSA-2223-f22x-24cq was published for winter/wn-system-module (Composer) Aug 20, 2026
elmahy111 Credited to elmahy111
Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets Moderate
CVE-2026-63179 was published for winter/wn-backend-module (Composer) Aug 20, 2026
hypnguyen1209 Credited to hypnguyen1209
Duplicate Advisory: Craft CMS: Incorrect path validation could potentially lead to path traversal Moderate
GHSA-9w6w-8x3c-hfqp was published for craftcms/cms (Composer) Aug 11, 2026 • withdrawn
Smarty Security stream restriction bypass through stream: resource Moderate
CVE-2026-62996 was published for smarty/smarty (Composer) Aug 7, 2026
Faze-up Credited to Faze-up
Smarty: Symlink path traversal out of trusted directories Moderate
CVE-2026-62992 was published for smarty/smarty (Composer) Aug 7, 2026
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI Moderate
CVE-2026-56722 was published for dompdf/dompdf (Composer) Jul 22, 2026
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files Moderate
CVE-2026-59946 was published for composer/composer (Composer) Jul 20, 2026
iliaal Credited to iliaal
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components Moderate
GHSA-2wwr-9x6f-88gp was published for easycorp/easyadmin-bundle (Composer) Jul 1, 2026
CakePHP: View::element() is missing a path containment check Moderate
CVE-2026-48820 was published for cakephp/cakephp (Composer) Jun 26, 2026
zxcvbbq Credited to zxcvbbq, get-wright, markstory, and dereuromark get-wright get-wright
markstory markstory dereuromark dereuromark
Microweber vulnerable to Path Traversal Moderate
CVE-2026-12198 was published for microweber/microweber (Composer) Jun 15, 2026
AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php` Moderate
CVE-2026-46337 was published for WWBN/AVideo (Composer) May 19, 2026
pr3ungdt Credited to pr3ungdt
TYPO3 ke_search path traversal due to lack of normalization on config directory from file indexer Moderate
CVE-2026-46724 was published for tpwd/ke_search (Composer) May 19, 2026
eliashaeussler Credited to eliashaeussler
AVideo: Authenticated Arbitrary File Read in view/update.php Moderate
CVE-2026-45731 was published for WWBN/AVideo (Composer) May 18, 2026
pr3ungdt Credited to pr3ungdt
Kimai has an arbitrary file read in its invoice PDF renderer (admin) Moderate
CVE-2026-44298 was published for kimai/kimai (Composer) May 8, 2026
melnicek Credited to melnicek
Flight has path traversal in `make:controller` CLI that creates arbitrary directories outside project root Moderate
CVE-2026-42549 was published for flightphp/core (Composer) May 6, 2026
Rootingg Credited to Rootingg
phpMyFAQ: Path Traversal in Client::deleteClientFolder enables arbitrary directory deletion by non-super-admin admins Moderate
CVE-2026-45008 was published for phpmyfaq/phpmyfaq (Composer) May 6, 2026
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
Admidio has Path Traversal via Unvalidated `name` Parameter in Document Add Mode that Enables Arbitrary Server File Read Moderate
CVE-2026-41656 was published for admidio/admidio (Composer) Apr 29, 2026
offset Credited to offset
Admidio has Path Traversal in ECard Preview that Allows Reading Arbitrary Server Files Including Database Credentials Moderate
CVE-2026-41655 was published for admidio/admidio (Composer) Apr 29, 2026
offset Credited to offset
Cockpit is vulnerable to directory traversal Moderate
CVE-2026-38993 was published for cockpit-hq/cockpit (Composer) Apr 29, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577) Moderate
CVE-2026-41887 was published for flarum/core (Composer) Apr 22, 2026
LiamSnow Credited to LiamSnow and imorland imorland imorland
October CMS has Safe Mode Bypass via CSS Preprocessor Compilers Moderate
CVE-2026-26067 was published for october/system (Composer) Apr 21, 2026
Neosprings Credited to Neosprings and daftspunk daftspunk daftspunk
ProTip! Advisories are also available from the GraphQL API