VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3812 CVEsRSS

GHSA-j8pm-gj4c-rq4xHigh· 7.5
3w ago

league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters

league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters

▾ Twilightleague · league/commonmarkvia GHSA
GHSA-f8fg-pg57-v4j8High· 7.2
3w ago

league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed

league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed

▾ Twilightleague · league/commonmarkvia GHSA
GHSA-jjv6-8j6v-6j52High· 7.5
3w ago

league/commonmark: Denial of service in the SmartPunct and Attributes extensions

league/commonmark: Denial of service in the SmartPunct and Attributes extensions

▾ Twilightleague · league/commonmarkvia GHSA
GHSA-8rr7-cvq3-gmfhHigh· 7.5
3w ago

league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension

league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension

▾ Twilightleague · league/commonmarkvia GHSA
CVE-2026-58191Medium· 6.5PoC
3w ago

Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes

Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes

▾ Twilightappium · @appium/base-driverEPSS 0.56%via GHSA
GHSA-2rx9-3g3h-c2jvHigh· 7.1
3w ago

pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project

pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project

▾ Twilightpnpm · pnpmvia GHSA
GHSA-vx52-2968-3vc6High· 7.4
3w ago

pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml

pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml

▾ Twilightpnpm · pnpmvia GHSA
GHSA-3f6p-5ww8-9rcrHigh
3w ago

MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials

MySQL2: Auth Plugin Downgrade to mysql_clear_password Leaks Plaintext Credentials

▾ Twilightmysql2 · mysql2via GHSA
GHSA-gqvg-gmmx-x4hmHigh· 8.8
3w ago

MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact

MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact

▾ Twilightmlflow · mlflowvia GHSA
CVE-2026-75592Medium
4w ago

Kirby is an open-source content management system

Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler used incomplete filesystem containment checks in src/Filesystem/Dir.php and src/Filesystem/F.php through Ki…

▾ Sunlitgetkirby · getkirby/cmsEPSS 0.68%via NVD
CVE-2026-82395Medium
4w ago

Sulu is an open-source PHP content management system based on the Symfony framework

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the media move endpoint derives its permission check from the client-supplied collection value instead of the media …

▾ Sunlitsulu · sulu/suluEPSS 0.43%via NVD
CVE-2026-82394Medium
4w ago

Sulu is an open-source PHP content management system based on the Symfony framework

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, the preview-link endpoint and src/Sulu/Bundle/PreviewBundle/Application/Manager/PreviewLinkManager.php do not enforc…

▾ Sunlitsulu · sulu/suluEPSS 0.58%via NVD
CVE-2026-82396Medium· 5.4
4w ago

Sulu is an open-source PHP content management system based on the Symfony framework

Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /media/{id}/download/{slug} route and it…

▾ Sunlitsulu · sulu/suluEPSS 0.30%via NVD
CVE-2026-82393High· 7.5
4w ago

pnpm is a package manager

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for…

▾ Twilightpnpm · pnpmEPSS 0.63%via NVD
CVE-2026-82392High· 7.1
4w ago

pnpm is a package manager

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builde…

▾ Twilightpnpm · pnpmEPSS 0.61%via NVD
CVE-2026-81890Medium· 5.4
4w ago

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in php/elFinderConnector.class.php, so validateCsrfToken(…

▾ Sunlitstudio-42 · studio-42/elfinderEPSS 0.18%via NVD
CVE-2026-81891High· 8.1
4w ago

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeType…

▾ TwilightStudio-42 · Studio-42/elFinderEPSS 0.90%via NVD
CVE-2026-82398Medium· 5.3
4w ago

pypdf is a free and open-source pure-python PDF library

pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, an attacker can craft a PDF that causes long runtimes when the pypdf/_utils.py function read_until_whitespace reads a stream containing a long run of bytes without…

▾ Sunlitpypdf · pypdfEPSS 0.52%via NVD
CVE-2026-82397High· 7.5
4w ago

Tornado is a Python web framework and asynchronous networking library

Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_num_fields. Reques…

▾ Twilighttornado · tornadoEPSS 0.63%via NVD
CVE-2026-81887Medium
4w ago

Livewire is a full-stack framework for Laravel

Livewire is a full-stack framework for Laravel. From 3.0.0-beta.1 until 3.8.3 and 4.3.4, the dot-notated query-string parser in js/plugins/history/index.js, including fromQueryString() and insertDotNotatedValueIntoData(), accepts the __p…

▾ Sunlitlivewire · livewire/livewireEPSS 0.68%via NVD
CVE-2026-81892High· 8.1
4w ago

EasyAdmin is a fast and modern admin generator for Symfony applications

EasyAdmin is a fast and modern admin generator for Symfony applications. From 4.0.0 until 4.29.16 and 5.5.1, EasyAdmin serves all backend requests through a single dashboard route and, for custom actions (Action::linkToRoute() and MenuIt…

▾ Twilighteasycorp · easycorp/easyadmin-bundleEPSS 0.45%via NVD
CVE-2026-62993Medium· 8.6
4w ago

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic

Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to 4.5.7 and 5.8.2, depending on the release line, Smarty's {fetch} handling in libs/plugins/function.fetch.php and…

▾ Sunlitsmarty · smarty/smartyEPSS 0.57%via NVD
CVE-2026-75594High
4w ago

Kirby is an open-source content management system

Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php allowed Kirby\Cms\Media::thumb() to append a path-bearing filename to a validated pare…

▾ Twilightgetkirby · getkirby/cmsEPSS 0.76%via NVD
CVE-2026-71415High
4w ago

Kirby is an open-source content management system

Kirby is an open-source content management system. From 5.0.0 until 5.5.2, Kirby's REST API chunk upload handler in src/Api/Upload.php did not run the relevant upload authorization preflight in Kirby\Api\Upload::process() before Kirby\Ap…

▾ Twilightgetkirby · getkirby/cmsEPSS 0.43%via NVD
CVE-2026-81889High· 8.6
4w ago

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable becau…

▾ Twilightstudio-42 · studio-42/elfinderEPSS 0.55%via NVD
CVE-2026-81888Medium· 5.4
4w ago

@hono/oauth-providers is Authentication middleware for Hono

@hono/oauth-providers is Authentication middleware for Hono. Prior to version 0.8.6, the built-in social login providers accept an OAuth callback even when the `state` value is absent on both sides, so the anti-CSRF check passes for a ca…

▾ Sunlithono · @hono/oauth-providersEPSS 0.19%via NVD
CVE-2026-15305Medium
4w ago

TYPO3 CMS - Unrestricted File Upload in Form Framework

TYPO3 CMS - Unrestricted File Upload in Form Framework

▾ Sunlittypo3 · typo3/cms-formEPSS 0.25%via GHSA
CVE-2026-54179Medium· 4.4
4w ago

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels

backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. From 6.0.0 until 6.8.14 and 7.0.37, the src/app/Library/Uploaders/Si…

▾ Sunlitbackpack · backpack/crudEPSS 0.26%via NVD
CVE-2026-53508Medium
4w ago

oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs

oasdiff is a command-line and Go package that compares and detects breaking changes in OpenAPI specs. From version 1.13.2 through version 1.18.0, oasdiff did not enforce --allow-external-refs=false (library: openapi3.Loader.IsExternalRef…

▾ Sunlitoasdiff · github.com/oasdiff/oasdiffEPSS 0.50%via NVD
CVE-2026-53552Critical· 9.6
4w ago

Goploy is an open-source automation deployment system

Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Project.Edit in cmd/server/api/project/handler.go accept a project or project-file row id fro…

▾ Midnightzhenorzz · github.com/zhenorzz/goployEPSS 0.35%via NVD
CVEs tagged “ghsa” — page 26 · VulnSea