Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,806 advisories

Loading
Vikunja: Permissive Cross-domain Security Policy trusts every localhost origin which should not be trusted High
GHSA-m687-p538-r5hp was published for code.vikunja.io/api (Go) Oct 9, 2026
arthurscchan Credited to arthurscchan and AdamKorcz AdamKorcz AdamKorcz
Vikunja: Write-level project members can delete admin-tier link shares through an unloaded permission check Moderate
GHSA-fmmf-xq98-g327 was published for code.vikunja.io/api (Go) Oct 9, 2026
Vikunja: Webhooks and link shares survive every revocation path, so a removed collaborator keeps a live feed Moderate
GHSA-hjx8-qv73-f7cm was published for code.vikunja.io/api (Go) Oct 9, 2026
euriconicacio Credited to euriconicacio and Tan-JunWei Tan-JunWei Tan-JunWei
Vikunja: Saved filter creation with an empty filter string recalculates task positions across all tenants Moderate
GHSA-fprf-r6rv-xg99 was published for code.vikunja.io/api (Go) Oct 9, 2026
Tan-JunWei Credited to Tan-JunWei
Vikunja: WebSocket authentication ignores server-side session state, so revoked sessions keep receiving live pushes Moderate
GHSA-4hv6-xc92-j86g was published for code.vikunja.io/api (Go) Oct 9, 2026
Tan-JunWei Credited to Tan-JunWei
Nginx UI: Unauthenticated signed-request body staging can exhaust temporary storage High
CVE-2026-107805 was published for github.com/0xJacky/Nginx-UI (Go) Oct 9, 2026
lujiefsi Credited to lujiefsi
Nginx UI: Bundled reverse proxy can bypass IP allowlists and enable shared login lockout Moderate
CVE-2026-107804 was published for github.com/0xJacky/Nginx-UI (Go) Oct 9, 2026
lujiefsi Credited to lujiefsi
Tina: Code injection via unescaped Git branch name in generated client source High
CVE-2026-108259 was published for @tinacms/cli (npm) Oct 9, 2026
canhieu Credited to canhieu
TinaCMS admin preview iframe loads an attacker-controlled origin from the URL fragment Critical
CVE-2026-108261 was published for @tinacms/app (npm) Oct 9, 2026
sondt99 Credited to sondt99
sondt99 Credited to sondt99 and iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team
Shiny for Python has path traversal in bookmark restore Moderate
CVE-2026-108258 was published for shiny (pip) Oct 9, 2026
0xRenSec Credited to 0xRenSec
JellowBeanz26 Credited to JellowBeanz26
Vikunja: Assignee email addresses disclosed to read-only project members via the task assignees endpoint Moderate
GHSA-8wvg-r2j4-3737 was published for code.vikunja.io/api (Go) Oct 9, 2026
JellowBeanz26 Credited to JellowBeanz26
Vikunja: Cross-project task disclosure through subtask expansion Moderate
GHSA-3hc7-r24j-rpwc was published for code.vikunja.io/api (Go) Oct 9, 2026
0xcelien Credited to 0xcelien and JellowBeanz26 JellowBeanz26 JellowBeanz26
Vikunja: CalDAV relation creation bypasses TaskRelation.CanCreate, allowing an unauthorized write into any task by known UID Moderate
GHSA-g38j-7v97-x298 was published for code.vikunja.io/api (Go) Oct 9, 2026
JellowBeanz26 Credited to JellowBeanz26
Contao: Protected page content is disclosed to anonymous visitors after contao.search.index_protected is disabled Moderate
CVE-2026-107842 was published for contao/core-bundle (Composer) Oct 9, 2026
iRevivalx Credited to iRevivalx
Contao: The registration module re-sends activation mails Moderate
CVE-2026-107843 was published for contao/core-bundle (Composer) Oct 9, 2026
HDWSec Credited to HDWSec
Contao: Cross-site request forgery in custom backend actions Low
CVE-2026-107848 was published for contao/core-bundle (Composer) Oct 9, 2026
HDWSec Credited to HDWSec
Contao: Path traversal in the images controller Moderate
CVE-2026-107844 was published for contao/core-bundle (Composer) Oct 9, 2026
HDWSec Credited to HDWSec
Contao: Cross-site scripting in the comments bundle Critical
CVE-2026-107845 was published for contao/comments-bundle (Composer) Oct 9, 2026
HDWSec Credited to HDWSec
Contao: Improper access control in the preview links module Moderate
CVE-2026-107850 was published for contao/core-bundle (Composer) Oct 9, 2026
HDWSec Credited to HDWSec
Contao: Improper access control in the table access voter Moderate
CVE-2026-107851 was published for contao/core-bundle (Composer) Oct 9, 2026
sven-jaeger-git Credited to sven-jaeger-git
Vikunja: Planka migration retains an unbounded aggregate of attacker-served attachments and can OOM the API High
CVE-2026-91970 was published for code.vikunja.io/api (Go) Oct 9, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, and 7thParkk Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk
Vikunja: Unbounded CSV row cardinality permits API process termination High
CVE-2026-91969 was published for code.vikunja.io/api (Go) Oct 9, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, and 7thParkk Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk
ProTip! Advisories are also available from the GraphQL API