Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

344 advisories

Loading
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin Moderate
CVE-2026-70599 was published for electron (npm) Aug 5, 2026
offset Credited to offset
offset Credited to offset
OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output Moderate
CVE-2026-67439 was published for github.com/OliveTin/OliveTin (Go) Jul 30, 2026
offset Credited to offset
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution High
GHSA-qw6m-8fw2-2v64 was published for @budibase/server (npm) Jul 24, 2026
offset Credited to offset
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users Moderate
CVE-2026-73304 was published for @budibase/server (npm) Jul 24, 2026
offset Credited to offset
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce High
CVE-2026-55575 was published for liquidjs (npm) Jul 24, 2026
offset Credited to offset
offset Credited to offset
offset Credited to offset
offset Credited to offset
FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn` Critical
CVE-2026-45262 was published for facturascripts/facturascripts (Composer) Jul 14, 2026
offset Credited to offset
Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypass Moderate
CVE-2026-52820 was published for kimai/kimai (Composer) Jul 13, 2026
offset Credited to offset
offset Credited to offset
YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html')) Moderate
CVE-2026-52772 was published for yeswiki/yeswiki (Composer) Jul 9, 2026
offset Credited to offset
Froxlor customer can create MySQL databases on disallowed servers via Mysqls.add API Moderate
GHSA-q4rm-m6xh-5pv7 was published for froxlor/froxlor (Composer) Jul 2, 2026
offset Credited to offset
offset Credited to offset
offset Credited to offset
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources Moderate
CVE-2026-49288 was published for statamic/cms (Composer) Jun 26, 2026
offset Credited to offset, Eszh, and geo-chen Eszh Eszh
geo-chen geo-chen
Fleet DM Vulnerable to Cross-Team Policy Data Exposure via Global Policy Read Endpoint Moderate
CVE-2026-41262 was published for github.com/fleetdm/fleet/v4 (Go) Jun 26, 2026
offset Credited to offset
OliveTin: ValidateArgumentType API Endpoint's Missing Authentication Allows Action and Argument Enumeration Low
CVE-2026-48709 was published for github.com/OliveTin/OliveTin (Go) Jun 24, 2026
offset Credited to offset
@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields Moderate
CVE-2026-50179 was published for @actual-app/web (npm) Jun 22, 2026
offset Credited to offset and MatissJanis MatissJanis MatissJanis
Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override High
CVE-2026-54351 was published for @budibase/server (npm) Jun 22, 2026
offset Credited to offset
offset Credited to offset and MatissJanis MatissJanis MatissJanis
@actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper Moderate
CVE-2026-46672 was published for @actual-app/cli (npm) Jun 22, 2026
offset Credited to offset and MatissJanis MatissJanis MatissJanis
ProTip! Advisories are also available from the GraphQL API