Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7 advisories

Loading
Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata Moderate
CVE-2026-54256 was published for winter/wn-backend-module (Composer) Aug 20, 2026
r00tn0b0dy Credited to r00tn0b0dy and baradika baradika baradika
Filament has inconsistent scope enforcement for its AttachAction and AssociateAction Select fields Moderate
CVE-2026-48067 was published for filament/actions (Composer) Jun 11, 2026
baradika Credited to baradika and danharrin danharrin danharrin
Sylius: IDOR on Shop Payment Request API endpoints Moderate
CVE-2026-53639 was published for sylius/sylius (Composer) Jul 9, 2026
baradika Credited to baradika
Sharp Missing Authorization Check in Quick Creation Command Endpoints Moderate
CVE-2026-53634 was published for code16/sharp (Composer) Jul 8, 2026
baradika Credited to baradika
shopper/framework: Race condition on Discount.usage_limit allows silent over-redemption Moderate
CVE-2026-47741 was published for shopper/cart (Composer) May 18, 2026
baradika Credited to baradika
Shopper: Missing per-action authorization on PaymentMethods, Currencies and Carriers admin tables Moderate
CVE-2026-47745 was published for shopper/framework (Composer) Jun 5, 2026
baradika Credited to baradika
Shopper: Missing authorization on Product admin Livewire sub-form components Moderate
CVE-2026-47742 was published for shopper/framework (Composer) Jun 5, 2026
baradika Credited to baradika
ProTip! Advisories are also available from the GraphQL API