Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

10 advisories

Loading
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
Laravel Backpack CRUD: Stored XSS in the color column — the `@if($column['escaped'])` branches are inverted Moderate
CVE-2026-54181 was published for backpack/crud (Composer) Aug 20, 2026
therawdev Credited to therawdev and tabacitu tabacitu tabacitu
tabacitu Credited to tabacitu
pxpm Credited to pxpm and tabacitu tabacitu tabacitu
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check Moderate
CVE-2026-54176 was published for backpack/crud (Composer) Aug 20, 2026
pxpm Credited to pxpm and tabacitu tabacitu tabacitu
Laravel Backpack CRUD: Unverified password change in MyAccountController via mass assignment High
CVE-2026-54175 was published for backpack/crud (Composer) Aug 20, 2026
therawdev Credited to therawdev and tabacitu tabacitu tabacitu
backpack/crud is vulnerable to Cross-Site Scripting (XSS) Moderate
CVE-2022-31114 was published for backpack/crud (Composer) Jun 3, 2026
tabacitu Credited to tabacitu and pxpm pxpm pxpm
ProTip! Advisories are also available from the GraphQL API