Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-mmj4-63m4-r6h5
  • Packagist/codeigniter4/framework
CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules yesterday
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-hhmc-q9hp-r662
  • Packagist/codeigniter4/framework
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames yesterday
  • Fix available
  • Severity - 7.5 (High)
GHSA-c9w5-rwh3-7pm9
  • Packagist/codeigniter4/framework
CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions yesterday
  • Fix available
  • Severity - 9.4 (Critical)
GHSA-7wmf-pw8j-mc78
  • Packagist/codeigniter4/framework
CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure() yesterday
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-9rjg-x2p2-h68h
  • Packagist/api-platform/core
API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion) yesterday
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-rjhh-76wf-8xmw
  • Packagist/smarty/smarty
Smarty Security stream restriction bypass through stream: resource yesterday
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-f6wf-28g6-769x
  • Packagist/smarty/smarty
Smarty: Symlink path traversal out of trusted directories yesterday
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-wg23-69c2-gjc8
  • Packagist/craftcms/cms
Craft CMS: Passkey login accepts replayed WebAuthn assertions yesterday
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-957r-qf9p-67xw
  • Packagist/craftcms/cms
Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts 2 days ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-596p-6jv8-775v
  • Packagist/craftcms/cms
Craft CMS: Authenticated leak of secret environment variables 2 days ago
  • Fix available
  • Severity - 5.1 (Medium)
GHSA-xxpx-f366-4xpq
  • Packagist/craftcms/cms
Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element 2 days ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-rvmm-v933-jgxq
  • Packagist/craftcms/cms
Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics 2 days ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-7hxc-f267-h5q7
  • Packagist/craftcms/cms
Craft CMS: Incorrect path validation could potentially lead to path traversal 2 days ago
  • Fix available
  • Severity - 2.1 (Low)
GHSA-2rp4-x2j7-qmcc
  • Packagist/craftcms/cms
Craft CMS: Stored XSS in the control panel via unescaped draft name 2 days ago
  • Fix available
  • Severity - 5.1 (Medium)
GHSA-hmqg-cxww-wqhq
  • Packagist/squizlabs/php_codesniffer
PHP_CodeSniffer gitblame report command injection via crafted filename 2 days ago
  • Fix available
  • Severity - 7.3 (High)
GHSA-p8x7-9vfw-p7vc
  • Packagist/craftcms/cms
Craft CMS: Arbitrary user password reset leading to administrator account takeover 2 days ago
  • Fix available