{"advisories":{"codeigniter4\/framework":[{"advisoryId":"PKSA-kcc6-gffv-vchj","packageName":"codeigniter4\/framework","remoteId":"GHSA-7wmf-pw8j-mc78","title":"CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()","link":"https:\/\/github.com\/advisories\/GHSA-7wmf-pw8j-mc78","cve":"CVE-2026-63220","affectedVersions":"\u003C4.7.4","source":"GitHub","reportedAt":"2026-08-07 18:21:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7wmf-pw8j-mc78"}]},{"advisoryId":"PKSA-t8h5-ngj8-z43w","packageName":"codeigniter4\/framework","remoteId":"GHSA-c9w5-rwh3-7pm9","title":"CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions","link":"https:\/\/github.com\/advisories\/GHSA-c9w5-rwh3-7pm9","cve":"CVE-2026-63221","affectedVersions":"\u003E=4.3.0,\u003C4.7.4","source":"GitHub","reportedAt":"2026-08-07 18:22:59","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-c9w5-rwh3-7pm9"}]},{"advisoryId":"PKSA-ykyc-889h-7jxf","packageName":"codeigniter4\/framework","remoteId":"GHSA-hhmc-q9hp-r662","title":"CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames","link":"https:\/\/github.com\/advisories\/GHSA-hhmc-q9hp-r662","cve":"CVE-2026-63222","affectedVersions":"\u003C4.7.4","source":"GitHub","reportedAt":"2026-08-07 18:23:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hhmc-q9hp-r662"}]},{"advisoryId":"PKSA-kcm9-w3rf-jxsk","packageName":"codeigniter4\/framework","remoteId":"GHSA-mmj4-63m4-r6h5","title":"CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules","link":"https:\/\/github.com\/advisories\/GHSA-mmj4-63m4-r6h5","cve":"CVE-2026-63223","affectedVersions":"\u003C4.7.4","source":"GitHub","reportedAt":"2026-08-07 18:24:21","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-mmj4-63m4-r6h5"}]}],"craftcms\/cms":[{"advisoryId":"PKSA-gh5w-x99g-b53n","packageName":"craftcms\/cms","remoteId":"GHSA-xxpx-f366-4xpq","title":"Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures\/move-element","link":"https:\/\/github.com\/advisories\/GHSA-xxpx-f366-4xpq","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:43:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xxpx-f366-4xpq"}]},{"advisoryId":"PKSA-jk69-ryht-534b","packageName":"craftcms\/cms","remoteId":"GHSA-wg23-69c2-gjc8","title":"Craft CMS: Passkey login accepts replayed WebAuthn assertions","link":"https:\/\/github.com\/advisories\/GHSA-wg23-69c2-gjc8","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.5","source":"GitHub","reportedAt":"2026-08-07 14:57:29","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-wg23-69c2-gjc8"}]},{"advisoryId":"PKSA-4q3g-gxhk-813s","packageName":"craftcms\/cms","remoteId":"GHSA-596p-6jv8-775v","title":"Craft CMS: Authenticated leak of secret environment variables","link":"https:\/\/github.com\/advisories\/GHSA-596p-6jv8-775v","cve":null,"affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:53:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-596p-6jv8-775v"}]},{"advisoryId":"PKSA-19kf-75v5-vy76","packageName":"craftcms\/cms","remoteId":"GHSA-957r-qf9p-67xw","title":"Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts","link":"https:\/\/github.com\/advisories\/GHSA-957r-qf9p-67xw","cve":null,"affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:54:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-957r-qf9p-67xw"}]},{"advisoryId":"PKSA-1412-5vdy-cd6w","packageName":"craftcms\/cms","remoteId":"GHSA-rvmm-v933-jgxq","title":"Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics","link":"https:\/\/github.com\/advisories\/GHSA-rvmm-v933-jgxq","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.3|\u003E=4.0.0-RC1,\u003C4.18.1","source":"GitHub","reportedAt":"2026-08-06 21:42:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rvmm-v933-jgxq"}]},{"advisoryId":"PKSA-x767-zzvx-956t","packageName":"craftcms\/cms","remoteId":"GHSA-2rp4-x2j7-qmcc","title":"Craft CMS: Stored XSS in the control panel via unescaped draft name","link":"https:\/\/github.com\/advisories\/GHSA-2rp4-x2j7-qmcc","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.8","source":"GitHub","reportedAt":"2026-08-06 21:33:15","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2rp4-x2j7-qmcc"}]},{"advisoryId":"PKSA-82nd-44zr-vpmz","packageName":"craftcms\/cms","remoteId":"GHSA-7hxc-f267-h5q7","title":"Craft CMS: Incorrect path validation could potentially lead to path traversal","link":"https:\/\/github.com\/advisories\/GHSA-7hxc-f267-h5q7","cve":null,"affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 21:36:11","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7hxc-f267-h5q7"}]},{"advisoryId":"PKSA-d48x-nyby-nphv","packageName":"craftcms\/cms","remoteId":"GHSA-f5wm-88jv-g5hx","title":"Craft CMS: Authenticated RCE through Twig sandbox escape","link":"https:\/\/github.com\/advisories\/GHSA-f5wm-88jv-g5hx","cve":null,"affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.3|\u003E=5.0.0-RC1,\u003C5.10.7","source":"GitHub","reportedAt":"2026-08-06 21:02:28","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-f5wm-88jv-g5hx"}]},{"advisoryId":"PKSA-s5dz-k87m-97ms","packageName":"craftcms\/cms","remoteId":"GHSA-p8x7-9vfw-p7vc","title":"Craft CMS: Arbitrary user password reset leading to administrator account takeover","link":"https:\/\/github.com\/advisories\/GHSA-p8x7-9vfw-p7vc","cve":null,"affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.8","source":"GitHub","reportedAt":"2026-08-06 21:04:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-p8x7-9vfw-p7vc"}]},{"advisoryId":"PKSA-x2qp-qkxh-fw67","packageName":"craftcms\/cms","remoteId":"GHSA-9p7c-v5x3-rfx8","title":"Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets","link":"https:\/\/github.com\/advisories\/GHSA-9p7c-v5x3-rfx8","cve":"CVE-2026-14793","affectedVersions":"\u003E=5.0.0-RC1,\u003C5.10.3|\u003E=4.0.0-RC1,\u003C4.18.1","source":"GitHub","reportedAt":"2026-08-06 20:55:48","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9p7c-v5x3-rfx8"}]},{"advisoryId":"PKSA-4tjq-33kk-ghq8","packageName":"craftcms\/cms","remoteId":"GHSA-265m-7826-wjqm","title":"Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass","link":"https:\/\/github.com\/advisories\/GHSA-265m-7826-wjqm","cve":null,"affectedVersions":"\u003E=4.0.0-RC1,\u003C4.18.2|\u003E=5.0.0-RC1,\u003C5.10.6","source":"GitHub","reportedAt":"2026-08-06 20:45:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-265m-7826-wjqm"}]},{"advisoryId":"PKSA-5x6f-x35f-73db","packageName":"craftcms\/cms","remoteId":"GHSA-c43v-4cr8-6mvp","title":"Craft CMS has authenticated path traversal in `assets\/icon`, allowing local `.svg` file read","link":"https:\/\/github.com\/advisories\/GHSA-c43v-4cr8-6mvp","cve":"CVE-2026-56394","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.12|\u003E=4.0.0-RC1,\u003C=4.17.6","source":"GitHub","reportedAt":"2026-07-09 13:44:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-c43v-4cr8-6mvp"}]},{"advisoryId":"PKSA-r87g-h2pd-9vq1","packageName":"craftcms\/cms","remoteId":"GHSA-86vw-x4ww-x467","title":"Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview","link":"https:\/\/github.com\/advisories\/GHSA-86vw-x4ww-x467","cve":"CVE-2026-56382","affectedVersions":"\u003E=5.5.0,\u003C=5.9.13","source":"GitHub","reportedAt":"2026-07-09 13:44:12","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-86vw-x4ww-x467"}]},{"advisoryId":"PKSA-pqnm-5q4k-cx7j","packageName":"craftcms\/cms","remoteId":"GHSA-x76w-8c62-48mg","title":"Craft CMS: Authenticated \u0022assets\/preview-thumb\u0022 discloses signed fallback transform preview link to CP users without asset-view permission","link":"https:\/\/github.com\/advisories\/GHSA-x76w-8c62-48mg","cve":"CVE-2026-56384","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.9.13|\u003E=4.0.0-RC1,\u003C=4.17.7","source":"GitHub","reportedAt":"2026-07-06 20:28:07","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-x76w-8c62-48mg"}]},{"advisoryId":"PKSA-hq3k-cthz-b9zn","packageName":"craftcms\/cms","remoteId":"GHSA-44px-qjjc-xrhq","title":"Craft CMS: Authorized asset \u0022preview file\u0022 requests bypass allows users without asset access to retrieve private preview metadata","link":"https:\/\/github.com\/advisories\/GHSA-44px-qjjc-xrhq","cve":"CVE-2026-56385","affectedVersions":"\u003E=4.0.0-RC1,\u003C=4.17.7|\u003E=5.0.0-RC1,\u003C=5.9.13","source":"GitHub","reportedAt":"2026-03-26 17:12:21","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-44px-qjjc-xrhq"}]},{"advisoryId":"PKSA-sc5m-6n1y-h7vz","packageName":"craftcms\/cms","remoteId":"GHSA-g3hp-vvqf-8vw6","title":"Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page","link":"https:\/\/github.com\/advisories\/GHSA-g3hp-vvqf-8vw6","cve":"CVE-2026-56381","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.8.21","source":"GitHub","reportedAt":"2026-03-11 14:56:59","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-g3hp-vvqf-8vw6"}]},{"advisoryId":"PKSA-skz7-x8dk-h7t1","packageName":"craftcms\/cms","remoteId":"GHSA-4mgv-366x-qxvx","title":"Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options","link":"https:\/\/github.com\/advisories\/GHSA-4mgv-366x-qxvx","cve":"CVE-2026-56393","affectedVersions":"\u003E=4.0.0-RC1,\u003C4.17.0-beta.1|\u003E=5.0.0-RC1,\u003C5.9.0-beta.1","source":"GitHub","reportedAt":"2026-03-03 20:58:07","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-4mgv-366x-qxvx"}]},{"advisoryId":"PKSA-cf9h-wtzj-5nwd","packageName":"craftcms\/cms","remoteId":"GHSA-6j87-m5qx-9fqp","title":"Craft CMS has Stored XSS in Table Field in its \u0022Row Heading\u0022 Column Type","link":"https:\/\/github.com\/advisories\/GHSA-6j87-m5qx-9fqp","cve":"CVE-2026-56383","affectedVersions":"\u003E=5.0.0-RC1,\u003C=5.8.22|\u003E=4.5.0-beta.1,\u003C=4.16.18","source":"GitHub","reportedAt":"2026-02-25 19:11:31","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-6j87-m5qx-9fqp"}]}],"api-platform\/core":[{"advisoryId":"PKSA-8kfs-m8zw-ggzs","packageName":"api-platform\/core","remoteId":"GHSA-9rjg-x2p2-h68h","title":"API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)","link":"https:\/\/github.com\/advisories\/GHSA-9rjg-x2p2-h68h","cve":"CVE-2026-54164","affectedVersions":"\u003E=4.3.0,\u003C4.3.12|\u003E=4.2.0,\u003C4.2.26|\u003C4.1.30","source":"GitHub","reportedAt":"2026-08-07 16:54:42","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9rjg-x2p2-h68h"}]}],"smarty\/smarty":[{"advisoryId":"PKSA-7cg9-1cz1-3qff","packageName":"smarty\/smarty","remoteId":"GHSA-rjhh-76wf-8xmw","title":"Smarty Security stream restriction bypass through stream: resource","link":"https:\/\/github.com\/advisories\/GHSA-rjhh-76wf-8xmw","cve":"CVE-2026-62996","affectedVersions":"\u003E=5.0.0,\u003C5.8.4","source":"GitHub","reportedAt":"2026-08-07 15:10:51","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-rjhh-76wf-8xmw"}]},{"advisoryId":"PKSA-zw1q-6h4d-mf1m","packageName":"smarty\/smarty","remoteId":"GHSA-f6wf-28g6-769x","title":"Smarty: Symlink path traversal out of trusted directories","link":"https:\/\/github.com\/advisories\/GHSA-f6wf-28g6-769x","cve":"CVE-2026-62992","affectedVersions":"\u003C4.5.7|\u003E=5.0.0,\u003C5.8.2","source":"GitHub","reportedAt":"2026-08-07 15:02:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f6wf-28g6-769x"}]}],"league\/commonmark":[{"advisoryId":"PKSA-cqd6-fg4n-nxpf","packageName":"league\/commonmark","remoteId":"GHSA-mh25-x5hq-wrqp","title":"league\/commonmark: Denial of service via colliding heading slugs","link":"https:\/\/github.com\/advisories\/GHSA-mh25-x5hq-wrqp","cve":null,"affectedVersions":"\u003E=2.0.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:41:45","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mh25-x5hq-wrqp"}]},{"advisoryId":"PKSA-1q6p-sqkj-8mmj","packageName":"league\/commonmark","remoteId":"GHSA-jfm3-95jq-q3rf","title":"league\/commonmark:  Denial of service via duplicate footnote definitions","link":"https:\/\/github.com\/advisories\/GHSA-jfm3-95jq-q3rf","cve":null,"affectedVersions":"\u003E=1.5.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:40:53","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-jfm3-95jq-q3rf"}]},{"advisoryId":"PKSA-5mzr-szzf-z6cn","packageName":"league\/commonmark","remoteId":"GHSA-mj63-m3rc-8ppr","title":"league\/commonmark: Denial of service via deeply nested XML output","link":"https:\/\/github.com\/advisories\/GHSA-mj63-m3rc-8ppr","cve":null,"affectedVersions":"\u003E=2.0.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:42:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mj63-m3rc-8ppr"}]},{"advisoryId":"PKSA-scnn-p8mm-jbft","packageName":"league\/commonmark","remoteId":"GHSA-29pj-957v-52mc","title":"league\/commonmark: AttributesExtension href\/src unsafe-link filter bypass via embedded control bytes","link":"https:\/\/github.com\/advisories\/GHSA-29pj-957v-52mc","cve":"CVE-2026-71478","affectedVersions":"\u003E=1.5.0,\u003C=2.8.3","source":"GitHub","reportedAt":"2026-08-06 20:30:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-29pj-957v-52mc"}]},{"advisoryId":"PKSA-t21r-vtr5-3mdz","packageName":"league\/commonmark","remoteId":"GHSA-2q4p-g7hv-5rgv","title":"league\/commonmark: Quadratic-time denial of service when parsing crafted Markdown","link":"https:\/\/github.com\/advisories\/GHSA-2q4p-g7hv-5rgv","cve":"CVE-2026-71488","affectedVersions":"\u003E=0.6.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:37:20","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-2q4p-g7hv-5rgv"}]},{"advisoryId":"PKSA-mc58-w91n-f5gv","packageName":"league\/commonmark","remoteId":"GHSA-g2gp-3wwq-f4ph","title":"league\/commonmark: Denial of service via adjacent inline attribute blocks","link":"https:\/\/github.com\/advisories\/GHSA-g2gp-3wwq-f4ph","cve":null,"affectedVersions":"\u003E=1.5.0,\u003C2.9.0","source":"GitHub","reportedAt":"2026-08-06 20:39:52","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-g2gp-3wwq-f4ph"}]}],"statamic\/cms":[{"advisoryId":"PKSA-yprw-4kcc-73cg","packageName":"statamic\/cms","remoteId":"GHSA-qh8c-7588-qfrv","title":"Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries","link":"https:\/\/github.com\/advisories\/GHSA-qh8c-7588-qfrv","cve":"CVE-2026-64662","affectedVersions":"\u003E=6.0.0,\u003C6.24.0|\u003C5.74.1","source":"GitHub","reportedAt":"2026-08-06 19:30:39","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qh8c-7588-qfrv"}]},{"advisoryId":"PKSA-htv4-42tq-8d9c","packageName":"statamic\/cms","remoteId":"GHSA-qhr7-v3xp-vw9m","title":"Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types","link":"https:\/\/github.com\/advisories\/GHSA-qhr7-v3xp-vw9m","cve":"CVE-2026-71434","affectedVersions":"\u003E=6.0.0,\u003C6.24.2|\u003C5.74.3","source":"GitHub","reportedAt":"2026-08-06 19:35:00","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-qhr7-v3xp-vw9m"}]},{"advisoryId":"PKSA-h7t4-kgpy-prgj","packageName":"statamic\/cms","remoteId":"GHSA-vx89-p3j7-8xqc","title":"Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template","link":"https:\/\/github.com\/advisories\/GHSA-vx89-p3j7-8xqc","cve":"CVE-2026-71435","affectedVersions":"\u003E=6.0.0,\u003C6.24.2|\u003C5.74.3","source":"GitHub","reportedAt":"2026-08-06 19:37:58","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-vx89-p3j7-8xqc"}]},{"advisoryId":"PKSA-691k-v8bf-zdg7","packageName":"statamic\/cms","remoteId":"GHSA-225x-3jhx-wh4q","title":"Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence","link":"https:\/\/github.com\/advisories\/GHSA-225x-3jhx-wh4q","cve":"CVE-2026-64664","affectedVersions":"\u003E=6.0.0,\u003C6.24.0|\u003C5.74.1","source":"GitHub","reportedAt":"2026-08-06 19:22:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-225x-3jhx-wh4q"}]},{"advisoryId":"PKSA-vbqf-w9v5-8bfs","packageName":"statamic\/cms","remoteId":"GHSA-93qh-5269-9wcf","title":"Statamic: Account takeover via OAuth email matching without email-verification check","link":"https:\/\/github.com\/advisories\/GHSA-93qh-5269-9wcf","cve":"CVE-2026-64665","affectedVersions":"\u003E=6.0.0,\u003C6.24.0|\u003C5.74.1","source":"GitHub","reportedAt":"2026-08-06 19:25:05","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-93qh-5269-9wcf"}]},{"advisoryId":"PKSA-p8hp-2yrt-f2d6","packageName":"statamic\/cms","remoteId":"GHSA-j2vp-f2pv-5rj4","title":"Statamic: Unsafe method invocation via Antlers template resolution allows data destruction","link":"https:\/\/github.com\/advisories\/GHSA-j2vp-f2pv-5rj4","cve":"CVE-2026-64663","affectedVersions":"\u003E=6.0.0,\u003C6.24.0|\u003C5.74.1","source":"GitHub","reportedAt":"2026-08-06 19:28:08","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-j2vp-f2pv-5rj4"}]}],"squizlabs\/php_codesniffer":[{"advisoryId":"PKSA-rdkp-vv9z-mjkg","packageName":"squizlabs\/php_codesniffer","remoteId":"squizlabs\/php_codesniffer\/CVE-2026-67434.yaml","title":"OS Command injection","link":"https:\/\/github.com\/PHPCSStandards\/PHP_CodeSniffer\/security\/advisories\/GHSA-hmqg-cxww-wqhq","cve":"CVE-2026-67434","affectedVersions":"\u003C3.13.6|\u003E=4.0.0,\u003C4.0.2","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-05 23:53:11","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-hmqg-cxww-wqhq"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"squizlabs\/php_codesniffer\/CVE-2026-67434.yaml"}]}],"guzzlehttp\/guzzle":[{"advisoryId":"PKSA-cnw1-2ytm-cgr8","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-f7vp-7xgx-4w4r","title":"Guzzle: Noncanonical cookie domain keeps subdomain scope","link":"https:\/\/github.com\/advisories\/GHSA-f7vp-7xgx-4w4r","cve":"CVE-2026-69245","affectedVersions":"\u003E=8.0.0,\u003C8.0.1|\u003C7.15.2","source":"GitHub","reportedAt":"2026-08-03 21:05:26","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f7vp-7xgx-4w4r"}]},{"advisoryId":"PKSA-gcrk-3vtt-1r14","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-v5mv-p594-2x33","title":"Guzzle: Noncanonical host can bypass host-based checks","link":"https:\/\/github.com\/advisories\/GHSA-v5mv-p594-2x33","cve":"CVE-2026-69246","affectedVersions":"\u003E=8.0.0,\u003C8.0.1|\u003C7.15.2","source":"GitHub","reportedAt":"2026-08-03 21:07:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-v5mv-p594-2x33"}]},{"advisoryId":"PKSA-bbs6-q5q9-f3t4","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-f283-ghqc-fg79","title":"Guzzle: Unbounded response cookies risk denial of service","link":"https:\/\/github.com\/advisories\/GHSA-f283-ghqc-fg79","cve":"CVE-2026-67353","affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:27:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-f283-ghqc-fg79"}]},{"advisoryId":"PKSA-qxvb-2bpp-dnk6","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-wm3w-8rrp-j577","title":"Guzzle: Host-only cookie scope is not preserved","link":"https:\/\/github.com\/advisories\/GHSA-wm3w-8rrp-j577","cve":"CVE-2026-67355","affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:27:49","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-wm3w-8rrp-j577"}]},{"advisoryId":"PKSA-fy2t-3c5f-827y","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-h95v-h523-3mw8","title":"Guzzle: URI fragments disclosed in redirect Referer headers","link":"https:\/\/github.com\/advisories\/GHSA-h95v-h523-3mw8","cve":"CVE-2026-67354","affectedVersions":"\u003C7.15.1","source":"GitHub","reportedAt":"2026-07-20 23:28:36","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-h95v-h523-3mw8"}]},{"advisoryId":"PKSA-pwsk-hy21-4gby","packageName":"guzzlehttp\/guzzle","remoteId":"GHSA-94pj-82f3-465w","title":"Guzzle: Proxy-Authorization headers can be sent to origin servers","link":"https:\/\/github.com\/advisories\/GHSA-94pj-82f3-465w","cve":"CVE-2026-67339","affectedVersions":"\u003C7.14.2","source":"GitHub","reportedAt":"2026-07-20 21:46:02","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-94pj-82f3-465w"}]}],"wp-coding-standards\/wpcs":[{"advisoryId":"PKSA-mh9b-91zm-m1gy","packageName":"wp-coding-standards\/wpcs","remoteId":"wp-coding-standards\/wpcs\/CVE-2026-45293.yaml","title":"Arbitrary code execution","link":"https:\/\/github.com\/WordPress\/WordPress-Coding-Standards\/security\/advisories\/GHSA-3pwp-g2mj-5p3v","cve":"CVE-2026-45293","affectedVersions":"\u003E=0.14.1,\u003C3.4.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-07-27 11:42:13","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3pwp-g2mj-5p3v"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"wp-coding-standards\/wpcs\/CVE-2026-45293.yaml"}]}],"contao\/contao":[{"advisoryId":"PKSA-8pr1-zw9p-tzyx","packageName":"contao\/contao","remoteId":"contao\/contao\/CVE-2026-55824.yaml","title":"Credentials disclosure in the crawler","link":"https:\/\/contao.org\/en\/security-advisories\/credentials-disclosure-in-the-crawler","cve":"CVE-2026-55824","affectedVersions":"\u003E=4.13.0,\u003C5.3.47|\u003E=5.4.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/CVE-2026-55824.yaml"},{"name":"GitHub","remoteId":"GHSA-3mr9-p497-58f6"}]},{"advisoryId":"PKSA-311q-qrt9-s2k4","packageName":"contao\/contao","remoteId":"contao\/contao\/CVE-2026-55825.yaml","title":"Path traversal in the jobs module","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-jobs-module","cve":"CVE-2026-55825","affectedVersions":"\u003E=5.7.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/contao\/CVE-2026-55825.yaml"},{"name":"GitHub","remoteId":"GHSA-grm4-wm43-9jh5"}]}],"contao\/core-bundle":[{"advisoryId":"PKSA-f8tt-pn3h-s2tw","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/CVE-2026-55824.yaml","title":"Credentials disclosure in the crawler","link":"https:\/\/contao.org\/en\/security-advisories\/credentials-disclosure-in-the-crawler","cve":"CVE-2026-55824","affectedVersions":"\u003E=4.13.0,\u003C5.3.47|\u003E=5.4.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/CVE-2026-55824.yaml"},{"name":"GitHub","remoteId":"GHSA-3mr9-p497-58f6"}]},{"advisoryId":"PKSA-4ps2-832y-6pns","packageName":"contao\/core-bundle","remoteId":"contao\/core-bundle\/CVE-2026-55825.yaml","title":"Path traversal in the jobs module","link":"https:\/\/contao.org\/en\/security-advisories\/path-traversal-in-the-jobs-module","cve":"CVE-2026-55825","affectedVersions":"\u003E=5.7.0,\u003C5.7.7","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-15 15:39:06","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"contao\/core-bundle\/CVE-2026-55825.yaml"},{"name":"GitHub","remoteId":"GHSA-grm4-wm43-9jh5"}]}],"simplesamlphp\/saml2":[{"advisoryId":"PKSA-yk3g-3g3t-ts6q","packageName":"simplesamlphp\/saml2","remoteId":"GHSA-6929-8p9f-26jx","title":"SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass","link":"https:\/\/github.com\/advisories\/GHSA-6929-8p9f-26jx","cve":"CVE-2026-49283","affectedVersions":"\u003C4.19.3|\u003E=4.20.0,\u003C4.20.2|\u003E=5.0.0,\u003C5.0.6|\u003E=6.0.0,\u003C6.2.1","source":"GitHub","reportedAt":"2026-07-02 20:25:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6929-8p9f-26jx"}]},{"advisoryId":"PKSA-1fc7-xrz7-vw78","packageName":"simplesamlphp\/saml2","remoteId":"GHSA-5cjr-mxj5-wmrx","title":"SimpleSAMLphp has Possible DoS via XPath Transform","link":"https:\/\/github.com\/advisories\/GHSA-5cjr-mxj5-wmrx","cve":"CVE-2026-49289","affectedVersions":"\u003C=4.19.2|\u003E=4.20.0,\u003C=4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:27:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5cjr-mxj5-wmrx"}]}],"simplesamlphp\/saml2-legacy":[{"advisoryId":"PKSA-4y26-97zb-p98g","packageName":"simplesamlphp\/saml2-legacy","remoteId":"GHSA-6929-8p9f-26jx","title":"SimpleSAMLphp HTTP-Artifact TLS validator confusion allows cross-IdP authentication bypass","link":"https:\/\/github.com\/advisories\/GHSA-6929-8p9f-26jx","cve":"CVE-2026-49283","affectedVersions":"\u003C4.19.3|\u003E=4.20.0,\u003C4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:25:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-6929-8p9f-26jx"}]},{"advisoryId":"PKSA-11bv-m3wk-h9sn","packageName":"simplesamlphp\/saml2-legacy","remoteId":"GHSA-5cjr-mxj5-wmrx","title":"SimpleSAMLphp has Possible DoS via XPath Transform","link":"https:\/\/github.com\/advisories\/GHSA-5cjr-mxj5-wmrx","cve":"CVE-2026-49289","affectedVersions":"\u003C=4.19.2|\u003E=4.20.0,\u003C=4.20.2","source":"GitHub","reportedAt":"2026-07-02 20:27:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5cjr-mxj5-wmrx"}]}],"silverstripe\/cms":[{"advisoryId":"PKSA-pjvm-vnw2-n3m2","packageName":"silverstripe\/cms","remoteId":"silverstripe\/cms\/CVE-2026-54717.yaml","title":"CVE-2026-54717 - XSS in breadcrumbs in page list view","link":"https:\/\/www.silverstripe.org\/download\/security-releases\/cve-2026-54717","cve":"CVE-2026-54717","affectedVersions":"\u003C6.2.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-24 02:39:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-w3cp-g2pf-65wh"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"silverstripe\/cms\/CVE-2026-54717.yaml"}]}]}}