[go: up one dir, main page]

Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-v5mv-p594-2x33
  • Packagist/guzzlehttp/guzzle
Guzzle: Noncanonical host can bypass host-based checks 14 hours ago
  • Fix available
  • Severity - 7.2 (High)
GHSA-f7vp-7xgx-4w4r
  • Packagist/guzzlehttp/guzzle
Guzzle: Noncanonical cookie domain keeps subdomain scope 14 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-jhh7-832h-f8hv
  • Packagist/wp-graphql/wp-graphql
WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design) 3 days ago
  • No fix available
  • Severity - 6.9 (Medium)
GHSA-98pp-vccm-qm25
  • Packagist/redaxo/source
Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers 3 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-x83g-979r-f5fh
  • Packagist/sylius/mollie-plugin
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII 3 days ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-rc52-c4hv-w89p
  • Packagist/sylius/mollie-plugin
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook 3 days ago
  • Fix available
  • Severity - 7.5 (High)
DRUPAL-CONTRIB-2026-091
  • Packagist:https://packages.drupal.org/8/drupal/disable_login
See record for full details 5 days ago
  • No fix available
DRUPAL-CONTRIB-2026-090
  • Packagist:https://packages.drupal.org/8/drupal/tca
See record for full details 5 days ago
  • Fix available
GHSA-996f-334j-67g7
  • Packagist/alextselegidis/easyappointments
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS 5 days ago
  • No fix available
  • Severity - 2.6 (Low)
GHSA-8hm4-r66f-29wr
  • Packagist/alextselegidis/easyappointments
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync 5 days ago
  • No fix available
  • Severity - 3.1 (Low)
GHSA-xgr6-pqjv-3pf8
  • Packagist/alextselegidis/easyappointments
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page 5 days ago
  • No fix available
  • Severity - 6.9 (Medium)
GHSA-w8xc-8g92-v77h
  • Packagist/alextselegidis/easyappointments
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass 5 days ago
  • Fix available
  • Severity - 3.3 (Low)
GHSA-pm5p-7w5h-jm5q
  • Packagist/alextselegidis/easyappointments
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network 5 days ago
  • No fix available
  • Severity - 2.7 (Low)
GHSA-4vmm-5qvc-w5p7
  • Packagist/alextselegidis/easyappointments
Easy!Appointments Vulnerable to Appointments Takeover via Excessive Data Exposure 5 days ago
  • No fix available
  • Severity - 7.1 (High)
GHSA-3735-5339-xfwx
  • Packagist/poweradmin/poweradmin
Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction. 6 days ago
  • Fix available
  • Severity - 9.6 (Critical)
GHSA-8r6w-3qq5-4p4r
  • Go/github.com/pterodactyl/wings
  • Packagist/pterodactyl/panel
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions 6 days ago
  • Fix available
  • Severity - 8.1 (High)