Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,269 advisories

Loading
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS Low
CVE-2026-52838 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync Low
CVE-2026-52841 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
Dredsen Credited to Dredsen
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page Moderate
CVE-2026-52837 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
peoplstar Credited to peoplstar
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass Low
CVE-2026-52839 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network Low
CVE-2026-52840 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
Dredsen Credited to Dredsen
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure High
CVE-2026-55651 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
0xmupa Credited to 0xmupa
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction. Critical
CVE-2026-54588 was published for poweradmin/poweradmin (Composer) Jul 28, 2026
mike197312 Credited to mike197312
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions High
CVE-2026-54593 was published for github.com/pterodactyl/wings (Composer) Jul 28, 2026
TrixterTheTux Credited to TrixterTheTux
0x7d8 Credited to 0x7d8
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability High
CVE-2026-45293 was published for wp-coding-standards/wpcs (Composer) Jul 28, 2026
FORIMOC Credited to FORIMOC and rodrigoprimo rodrigoprimo rodrigoprimo
Poweradmin: OIDC `sub` collation bypass in Poweradmin leading to account takeover High
GHSA-cmwh-g2h8-c222 was published for poweradmin/poweradmin (Composer) Jul 24, 2026
William957-web Credited to William957-web
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own High
GHSA-rm67-g9ch-vxff was published for poweradmin/poweradmin (Composer) Jul 24, 2026
SaifSalah Credited to SaifSalah
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account High
GHSA-h4hf-v6w5-897x was published for poweradmin/poweradmin (Composer) Jul 24, 2026
SaifSalah Credited to SaifSalah
Pheditor: Authentication Bypass in Forced Password-Change Flow via Unverified Current Password Critical
GHSA-f25v-x6vr-962g was published for pheditor/pheditor (Composer) Jul 24, 2026
sermikr0 Credited to sermikr0
anir0y Credited to anir0y, manus-use, sermikr0, adamyordan, Pig-Tail, tonghuaroot, and alimony manus-use manus-use
sermikr0 sermikr0 adamyordan adamyordan Pig-Tail Pig-Tail tonghuaroot tonghuaroot alimony alimony
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion High
CVE-2026-59933 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion High
CVE-2026-59932 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist High
CVE-2026-59931 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
longcalif Credited to longcalif and sondt99 sondt99 sondt99
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem Moderate
CVE-2026-59943 was published for dompdf/dompdf (Composer) Jul 22, 2026
w4tchd0ge Credited to w4tchd0ge
Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps Moderate
CVE-2026-59942 was published for dompdf/dompdf (Composer) Jul 22, 2026
far00t01 Credited to far00t01
Dompdf: Uncontrolled resource consumption based on declared BMP dimensions Moderate
CVE-2026-59941 was published for dompdf/dompdf (Composer) Jul 22, 2026
riodrwn Credited to riodrwn
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI Moderate
CVE-2026-56722 was published for dompdf/dompdf (Composer) Jul 22, 2026
Dompdf: File existence oracle via font-face stylesheet declaration Low
CVE-2026-55555 was published for dompdf/dompdf (Composer) Jul 22, 2026
g4nkd Credited to g4nkd
Dompdf: Chroot Validation Bypass Low
CVE-2026-55554 was published for dompdf/dompdf (Composer) Jul 22, 2026
vxhex Credited to vxhex and snoopysecurity snoopysecurity snoopysecurity
guzzlehttp/psr7: Host Confusion via Weak URI Host Validation Moderate
CVE-2026-59882 was published for guzzlehttp/psr7 (Composer) Jul 21, 2026
GrahamCampbell Credited to GrahamCampbell
ProTip! Advisories are also available from the GraphQL API