Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5,855 advisories

Loading
Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation High
CVE-2026-46640 was published for twig/twig (Composer) May 21, 2026
Twig: Sandbox property and method bypass via object-destructuring assignment High
CVE-2026-46639 was published for twig/twig (Composer) May 21, 2026
Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411) Moderate
CVE-2026-46638 was published for twig/twig (Composer) May 21, 2026
Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']` Low
CVE-2026-46637 was published for twig/cssinliner-extra (Composer) May 21, 2026
Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects) Low
CVE-2026-46635 was published for twig/twig (Composer) May 21, 2026
Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name Moderate
CVE-2026-46634 was published for twig/twig (Composer) May 21, 2026
Twig: PHP code injection via `{% use %}` template name Critical
CVE-2026-46633 was published for twig/twig (Composer) May 21, 2026
twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled arguments Low
CVE-2026-46629 was published for twig/intl-extra (Composer) May 21, 2026
Twig: The `spaceless` filter implicitly marks its output as safe Low
CVE-2026-46628 was published for twig/twig (Composer) May 21, 2026
phpMyFAQ: Stored XSS via Utils::parseUrl() in comment rendering High
CVE-2026-46367 was published for phpMyFAQ (Composer) May 15, 2026
phpMyFAQ: Missing Authorization on Tag Deletion Allows Any Authenticated User to Delete Tags Moderate
CVE-2026-46365 was published for phpMyFAQ/phpMyFAQ (Composer) May 15, 2026
phpMyFAQ: Stored XSS in FAQ Question/Answer via Encode-Decode Bypass of removeAttributes() Sanitization Moderate
CVE-2026-46363 was published for phpMyFAQ/phpMyFAQ (Composer) May 15, 2026
phpMyFAQ: SVG Sanitizer Entity Decoding Depth Limit Bypass Leading to Stored XSS Moderate
CVE-2026-46360 was published for phpMyFAQ/phpMyFAQ (Composer) May 15, 2026
phpMyFAQ: Path traversal in Client::deleteClientFolder enables arbitrary directory deletion by non-super-admin admins Moderate
CVE-2026-45008 was published for phpMyFAQ/phpMyFAQ (Composer) May 15, 2026
phpMyFAQ: Ordinary Authenticated User Can Access Admin-Only API Endpoints Due to Insufficient Authorization Check Moderate
CVE-2026-45009 was published for phpMyFAQ/phpMyFAQ (Composer) May 15, 2026
Cockpit CMS: Stored cross-site scripting vulnerability in the Set field type's Display template option Moderate
CVE-2026-23695 was published for cockpit-hq/cockpit (Composer) May 15, 2026
Snappy: Binary path is never shell-escaped due to an inverted is_executable check High
CVE-2026-46643 was published for KnpLabs/knp-snappy (Composer) May 21, 2026
Snappy : SSRF and local file read via the xsl-style-sheet option Moderate
CVE-2026-46683 was published for knplabs/knp-snappy (Composer) May 21, 2026
hjson stack exhaustion vulnerability High
CVE-2023-34620 was published for github.com/hjson/hjson-go/v4 (Composer) Jun 14, 2023
achibear Credited to achibear
phpMyFAQ: Missing Password Reset Token Allows Account Takeover via Username/Email Enumeration High
GHSA-w9xh-5f39-vq89 was published for phpmyfaq/phpmyfaq (Composer) May 20, 2026
cyberHunter127 Credited to cyberHunter127
phpMyFAQ: Default Empty API Token Authentication Bypass High
GHSA-gp95-j463-vv28 was published for phpmyfaq/phpmyfaq (Composer) May 20, 2026
guayu-kakeru Credited to guayu-kakeru
phpMyFAQ: IDOR Account Takeover High
GHSA-xvp4-phqj-cjr3 was published for phpmyfaq/phpmyfaq (Composer) May 20, 2026
cyberHunter127 Credited to cyberHunter127
phpMyFAQ: Unauthenticated Password Reset Endpoint Allows User Enumeration and Forced Password Change Without Token Validation High
GHSA-9qv9-8xv6-5p35 was published for phpmyfaq/phpmyfaq (Composer) May 20, 2026
kitu232 Credited to kitu232
FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service Moderate
CVE-2026-45802 was published for setasign/fpdi (Composer) May 19, 2026
esnard Credited to esnard
AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php` Moderate
CVE-2026-46337 was published for WWBN/AVideo (Composer) May 19, 2026
pr3ungdt Credited to pr3ungdt
ProTip! Advisories are also available from the GraphQL API