GitHub Security Advisories
Open-source package ecosystem coverage across npm / PyPI / Maven / Go / RubyGems and more.
1,893 advisories tracked · showing 100
- May 22, 2026GHSA-97r5-pg8x-p63pMediumCVE-2026-46715
Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance
- May 22, 2026GHSA-7m8f-hgjq-8gc9HighCVSS 7.5Disclosed before NVD
aiosend: Deserialization of request body before signature verification (Pre-auth DoS) in webhook handler
- May 22, 2026GHSA-q8mj-m7cp-5q26MediumCVSS 5.3CVE-2026-8723
qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/undefined entries in comma-format arrays when encodeValuesOnly is set
- May 22, 2026GHSA-qqqm-5547-774xCriticalDisclosed before NVD
FileBrowser Quantum: Path traversal in public share PATCH allows file ops outside shared directory
- May 22, 2026GHSA-jwvv-qr7q-cv8jCriticalCVSS 9.8CVE-2026-46670
YesWiki: Unauthenticated SQL Injection
- May 22, 2026GHSA-6gxq-f64p-5w6fMediumCVSS 5.7CVE-2026-47166
ImageMagick: Heap Buffer Over-Read in distributed pixel cache server
- May 22, 2026GHSA-2rgj-gx5x-f62wMediumCVSS 4.1CVE-2026-47165
ImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication model
- May 22, 2026GHSA-4g75-9r48-jf92MediumCVSS 4.1CVE-2026-46693
ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking
- May 22, 2026GHSA-p93h-f2jc-477jMediumCVSS 4.1CVE-2026-46692
ImageMagick: Heap Buffer Over-Write in distributed pixel cache server
- May 22, 2026GHSA-jrc7-p252-6hpqMediumCVSS 4.3CVE-2026-7615
The Widget Context plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
- May 22, 2026GHSA-273r-585g-q7wvMediumCVSS 4.3CVE-2026-7636
The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is...
- May 22, 2026GHSA-x4qq-w73c-72mvMediumCVSS 5.4CVE-2026-8381
A broken access control vulnerability exists in the TeamViewer DEX Platform (On‑Premises) prior...
- May 22, 2026GHSA-hvqp-vjwf-27jgHighCVSS 7.5CVE-2026-8679
The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in...
- May 22, 2026GHSA-pq4x-338r-cq3hMediumCVSS 5.4CVE-2026-7798
The FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads,...
- May 22, 2026GHSA-x7jf-v64x-878jMediumCVSS 5.3CVE-2026-8684
The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all...
- May 22, 2026GHSA-92j9-vfpr-4xhfMediumCVSS 4.3CVE-2026-8692
The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for...
- May 22, 2026GHSA-hg7j-7v3f-fjq2HighCVSS 7.5CVE-2026-9011
The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to...
- May 22, 2026GHSA-jvg6-x4cw-2wj7HighCVSS 8.8CVE-2026-9018
The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable...
- May 22, 2026GHSA-222q-9hw5-chw9HighCVSS 7.5CVE-2026-4834
The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter...
- May 22, 2026GHSA-gcf2-x38g-f7w4MediumCVSS 5.7CVE-2026-44409
There is an an information disclosure vulnerability in ZTE MU5250. Due to improper configuration...
- May 22, 2026GHSA-jjqp-72fq-xmqpMediumCVSS 4.3CVE-2026-2518
The FastX theme for WordPress is vulnerable to unauthorized limited plugin installation and...
- May 22, 2026GHSA-hx3j-p7vv-7jq2MediumCVSS 4.3CVE-2026-7249
The Location Weather plugin for WordPress is vulnerable to unauthorized modification of data due...
- May 22, 2026GHSA-38r3-cgcv-g3qpMediumCVE-2026-9053
Mothra would respect a default value given by a website for HTML file upload forms. An attacker...
- May 22, 2026GHSA-m4c4-9rgw-f76cMediumCVSS 6.4CVE-2026-7509
The KIA Subtitle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
- May 22, 2026GHSA-ggv5-f87x-rf79CriticalCVE-2026-9054
An attacker sending tcp, il, rudp, rudp, or gre packets with a length less than the header size...
- May 22, 2026GHSA-v8xg-3gv8-m4wcMediumCVSS 4.3CVE-2026-4070
The Alfie – Feed Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
- May 22, 2026GHSA-jf98-h9cw-4365MediumCVSS 6.1CVE-2026-6864
The CBX 5 Star Rating & Review plugin for WordPress is vulnerable to Reflected Cross-Site...
- May 22, 2026GHSA-p9mp-xq3w-289vMediumCVSS 6.1CVE-2026-3481
The WP Blockade plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ...
- May 22, 2026GHSA-fvgm-jgwh-qwx7CriticalCVSS 10.0CVE-2026-34910
A malicious actor with access to the network could exploit an Improper Input Validation...
- May 22, 2026GHSA-gfqf-9c7q-2qmrunknownCVE-2026-9264
A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows...
- May 22, 2026GHSA-m2r4-jq7j-hchxHighCVSS 7.7CVE-2026-34911
A malicious actor with access to the network and low privileges could exploit a Path Traversal...
- May 22, 2026GHSA-p8c5-xwrc-584fCriticalCVSS 10.0CVE-2026-34908
A malicious actor with access to the network could exploit an Improper Access Control...
- May 22, 2026GHSA-95fp-244g-g3vrCriticalCVSS 10.0CVE-2026-34909
A malicious actor with access to the network could exploit a Path Traversal vulnerability found...
- May 22, 2026GHSA-3ggx-cv4j-6p7jCriticalCVSS 9.1CVE-2026-33000
A malicious actor with access to the network and high privileges could exploit an Improper Input...
- May 22, 2026GHSA-752x-23hp-jmv6LowCVE-2026-8411
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete...
- May 22, 2026GHSA-98qf-jvwj-2r5fLowCVE-2026-8414
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete...
- May 22, 2026GHSA-f73j-pm2c-rxvrMediumCVE-2026-8245
Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML...
- May 22, 2026GHSA-xj25-753j-wgp9LowCVE-2026-8415
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete...
- May 22, 2026GHSA-8c7c-h7px-267gMediumCVE-2026-8337
Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would...
- May 22, 2026GHSA-rv3q-xmfw-mcjvLowCVE-2026-8412
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete...
- May 22, 2026GHSA-5j68-3wmc-p4rcunknownCVE-2026-5297
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- May 22, 2026GHSA-56c9-xq5g-xrf9LowCVE-2026-8409
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete...
- May 22, 2026GHSA-v7c7-658v-hh7vLowCVE-2026-8410
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete...
- May 22, 2026GHSA-6qjh-p324-694fLowCVE-2026-8434
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete...
- May 22, 2026GHSA-qj94-6rx6-27frLowCVE-2026-8416
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete...
- May 22, 2026GHSA-mpq2-mv8p-9wm6LowCVE-2026-8413
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete...
- May 22, 2026GHSA-44q4-354f-c826LowCVE-2026-8435
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete...
- May 22, 2026GHSA-67hj-8239-cmf5LowCVE-2026-8427
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete...
- May 22, 2026GHSA-97jw-gr4m-c5v8LowCVE-2026-8432
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete...
- May 22, 2026GHSA-6fxm-r8p3-mx5cLowCVE-2026-8433
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete...
- May 22, 2026GHSA-p8p9-5953-h9jwLowCVE-2026-7886
Concrete CMS 9.5.0 and below is vulnerable to IDOR in AddMessage/UpdateMessage via attachments[]...
- May 22, 2026GHSA-66rg-92q4-6m8qLowCVE-2026-7882
Concrete CMS 9.5.0 and below is vulnerable to unauthorized file deletion due to an Inverted CSRF...
- May 22, 2026GHSA-58c8-vvqw-cm7mMediumCVE-2026-8236
Concrete CMS 9.5.0 and below is vulnerable to IDOR combined with a missing authentication gate....
- May 22, 2026GHSA-wmw3-3fv3-h54wMediumCVE-2026-8327
Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and...
- May 22, 2026GHSA-fqg3-8w8r-8g94MediumCVE-2026-7879
In Concrete CMS 9.5.0 and below, the submit_password() method in concrete/controllers...
- May 22, 2026GHSA-xpgc-7vc2-8725MediumCVE-2026-8237
Concrete CMS 9.5.0 and below is vulnerable to IDOR. The `/ccm/frontend/conversations...
- May 22, 2026GHSA-chfm-cm6h-q5x7MediumCVE-2026-7881
Concrete CMS 9.5.0 and below is subject to Insecure Direct Object Reference (IDOR) in the Express...
- May 22, 2026GHSA-pcrh-gj77-j4mwLowCVE-2026-8139
Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via external-link page cvName because...
- May 22, 2026GHSA-f54h-78c9-c24hLowCVE-2026-7887
For Concrete CMS 9.5.0 and below, OAuth 2.0 Authorization-Code Handler Bypasses Account Status. A...
- May 22, 2026GHSA-qf4r-cjjc-2864CriticalCVSS 9.8CVE-2026-6960
The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
- May 22, 2026GHSA-qv3x-mffx-9gw8MediumCVE-2026-8238
Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/message_page...
- May 22, 2026GHSA-gjwq-9v8p-47w7LowCVE-2026-7890
In Concrete CMS 9.5.0 and below, the RSS Displayer block accepts a feed URL from any page editor...
- May 22, 2026GHSA-2xp7-rpvc-pjwcMediumCVE-2026-8239
Concrete CMS 9.5.0 and below is vulnerable to IDOR. The '/ccm/frontend/conversations/get_rating'...
- May 22, 2026GHSA-vpgr-cwfx-pwfwMediumCVE-2026-8240
Concrete CMS 9.5.0 and below is vulnerable to unauthenticated page metadata disclosure across...
- May 22, 2026GHSA-q6w2-7g3j-5vg3MediumCVE-2026-4093
In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter...
- May 22, 2026GHSA-w38v-4c3f-mg76MediumCVE-2026-4929
Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper...
- May 22, 2026GHSA-vxwv-pg73-pf78MediumCVSS 5.4CVE-2026-22678
Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template...
- May 22, 2026GHSA-37jv-v9vv-wxwvunknownCVE-2026-5091
Catalyst::Plugin::Authentication versions through 0.10024 for Perl is susceptible to timing...
- May 21, 2026GHSA-j3vx-cx2r-pvg8HighCVSS 7.6CVE-2026-46701
Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret
- May 21, 2026GHSA-f396-4rp4-7v2jCriticalCVSS 9.6CVE-2026-46703
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
- May 21, 2026GHSA-g6ww-w5j2-r7x3CriticalCVSS 10.0CVE-2026-46695
BoxLite: Permission Bypass Allows Modification of Read-Only Files
- May 21, 2026GHSA-qv2q-c278-pch5LowCVSS 3.7Disclosed before NVD
ImageMagick: Information Disclosure in PasskeyEncipherImage via AES-CTR nonce reuse
- May 21, 2026GHSA-vf33-6r7x-66xxLowCVSS 3.3Disclosed before NVD
ImageMagick: Division by Zero in binomial kernel
- May 21, 2026GHSA-jqq5-8px3-9m6mMediumCVSS 6.2Disclosed before NVD
ImageMagick: Heap Buffer Over-Write in json and yaml encoder of a single byte due to incorrect fix
- May 21, 2026GHSA-x7j8-49r8-mr43HighCVE-2026-46681
@nevware21/ts-utils: Prototype Pollution in objDeepCopy/objCopyProps via for...in without hasOwnProperty
- May 21, 2026GHSA-fqw6-gf59-qr4wHighCVE-2026-46680
containerd user ID handling bypass allows runAsNonRoot evasion
- May 21, 2026GHSA-4f8r-922h-2vgvHighCVSS 7.5CVE-2026-46679
js-libp2p: Memory DoS via subscription flood of unique topics
- May 21, 2026GHSA-cqp8-fcvh-x7r3MediumCVSS 6.8CVE-2026-46678
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
- May 21, 2026GHSA-4j5m-wc25-pvh7MediumCVSS 4.4CVE-2026-46671
Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory
- May 21, 2026GHSA-54mc-gghv-4cfjMediumCVSS 4.3CVE-2026-46645
SQLAdmin: Authorization Bypass on `ajax_lookup`
- May 21, 2026GHSA-45vw-wh46-2vx8HighCVE-2026-46640
Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
- May 21, 2026GHSA-mm6w-gr99-p3jjHighCVE-2026-46639
Twig: Sandbox property and method bypass via object-destructuring assignment
- May 21, 2026GHSA-x2fp-hj8c-mmxhMediumCVE-2026-8204
Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend...
- May 21, 2026GHSA-g7xp-jf3x-wcx4HighCVE-2026-8350
Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment...
- May 21, 2026GHSA-9v2g-37mp-qpxfHighCVE-2026-8203
Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not...
- May 21, 2026GHSA-46xh-7854-f568MediumCVE-2026-8205
Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since...
- May 21, 2026GHSA-jr5g-qv3g-rxxxHighCVE-2026-8417
Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to ...
- May 21, 2026GHSA-prxr-vjgc-2cq9HighCVE-2026-8428
Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token-...
- May 21, 2026GHSA-4c8m-6fwx-m7xqHighCVE-2026-8421
Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of...
- May 21, 2026GHSA-5rj5-gfmr-hrc3HighCVE-2026-8426
Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to ...
- May 21, 2026GHSA-wpfp-gwwc-vwq6HighCVSS 8.8CVE-2026-47102
LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update...
- May 21, 2026GHSA-645j-cm4x-3xvwCriticalCVE-2026-8134
Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the...
- May 21, 2026GHSA-r42c-3rr2-jrfpHighCVE-2026-8140
Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to ...
- May 21, 2026GHSA-4g7q-44qp-cc5cMediumCVE-2026-6826
Concrete CMS 9.5.0 and below is vulnerable to unauthenticated file usage disclosure via missing...
- May 21, 2026GHSA-h72c-xx3w-w8h7HighCVE-2026-8197
Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name. The OAuth...
- May 21, 2026GHSA-pv2v-6w2v-97x6HighCVE-2026-8135
Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure...
- May 21, 2026GHSA-mh3x-vcwp-x5rhMediumCVSS 4.3CVE-2026-4843
The GSheet For Woo Importer plugin for WordPress is vulnerable to unauthorized loss of data due...
- May 21, 2026GHSA-qrc4-49gv-mv9mHighCVSS 8.8CVE-2026-47101
LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to...
- May 21, 2026GHSA-55r7-xx3w-x2wfHighCVSS 8.8CVE-2026-47114
IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote...
- May 21, 2026GHSA-wm67-cj4w-p69mHighCVSS 7.5CVE-2026-46473
Authen::TOTP versions before 0.1.1 for Perl generate secrets using rand. Secrets were generated...