Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-g7vj-c29h-3h5m
  • Packagist/fof/oauth
FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider 13 hours ago
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-v65j-hff3-753c
  • Packagist/starcitizenwiki/embedvideo
Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled 14 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-qxg3-46rw-79j8
  • Packagist/code16/sharp
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute 14 hours ago
  • Fix available
  • Severity - 7.3 (High)
GHSA-vj3q-vp3g-j9c8
  • Packagist/code16/sharp
code16/sharp has a stored XSS via data-html-content Sanitizer Bypass 14 hours ago
  • Fix available
  • Severity - 8.7 (High)
GHSA-87mg-5grr-rhwh
  • Packagist/contao/contao
  • Packagist/contao/core-bundle
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module yesterday
  • Fix available
  • Severity - 3.1 (Low)
GHSA-36h5-qg4p-q2qf
  • Packagist/zbateson/mail-mime-parser
zbateson/mail-mime-parser has CRLF header injection via attachment filename yesterday
  • Fix available
  • Severity - 7.2 (High)
GHSA-f6v3-2qmr-vfjx
  • Packagist/zbateson/mail-mime-parser
zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME yesterday
  • Fix available
  • Severity - 7.5 (High)
GHSA-rw77-vq4g-x3hp
  • Packagist/phpmyfaq/phpmyfaq
  • Packagist/thorsten/phpmyfaq
phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion yesterday
  • Fix available
  • Severity - 8.5 (High)
GHSA-8gpw-xvpf-hvx5
  • Packagist/phpmyfaq/phpmyfaq
  • Packagist/thorsten/phpmyfaq
phpMyFAQ's two-factor authentication login bypasses the password factor yesterday
  • Fix available
  • Severity - 8.1 (High)
GHSA-pgwp-vc7q-cvj3
  • Packagist/phpmyfaq/phpmyfaq
  • Packagist/thorsten/phpmyfaq
phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission yesterday
  • Fix available
  • Severity - 8.2 (High)
GHSA-396x-xmvh-p563
  • Packagist/snipe/snipe-it
Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API yesterday
  • Fix available
  • Severity - 8.7 (High)
GHSA-p9h3-gvpq-5539
  • Packagist/snipe/snipe-it
Snipe-IT: Stored XSS via Custom Field name in asset-list column headers yesterday
  • Fix available
  • Severity - 8.1 (High)
GHSA-hxcx-9h4f-42xx
  • Packagist/snipe/snipe-it
Snipe-IT: 2FA bypass via the API token flow yesterday
  • Fix available
  • Severity - 8.6 (High)
GHSA-4f5f-j737-pm58
  • Packagist/redaxo/source
REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration yesterday
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-9rg8-2wvr-fgjh
  • Packagist/verbb/formie
Formie: Missing authorization on sent notification resend modal exposes submission PII 2 days ago
  • Fix available
  • Severity - 7.7 (High)
GHSA-584p-f93j-wpgc
  • Packagist/verbb/formie
Formie: Unauthenticated users can overwrite incomplete submissions via submit action 2 days ago
  • Fix available
  • Severity - 8.2 (High)