Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

67 advisories

Loading
Payload: Field-level write access bypass in Payload on MongoDB High
CVE-2026-106100 was published for @payloadcms/db-mongodb (npm) Oct 7, 2026
webcipher101 Credited to webcipher101
Prototype Pollution via parse() in NodeJS flatted High
CVE-2026-33228 was published for flatted (npm) Mar 19, 2026
yohannslm Credited to yohannslm
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials High
CVE-2026-76086 was published for verbb/formie (Composer) Sep 23, 2026
Pig-Tail Credited to Pig-Tail
9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade High
CVE-2026-56679 was published for 9router (npm) Sep 23, 2026
ngxuankhoi Credited to ngxuankhoi
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass High
CVE-2026-72778 was published for craftcms/cms (Composer) Aug 6, 2026
saladin0x1 Credited to saladin0x1
Duplicate Advisory: Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass High
GHSA-w36c-qxrq-v7fw was published for craftcms/cms (Composer) Aug 11, 2026 • withdrawn
ibondarenko1 Credited to ibondarenko1 and antonisloukis antonisloukis antonisloukis
Aviral2642 Credited to Aviral2642
Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override High
CVE-2026-54351 was published for @budibase/server (npm) Jun 22, 2026
offset Credited to offset
FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover High
CVE-2026-46479 was published for flowise (npm) May 14, 2026
offset Credited to offset
FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover High
CVE-2026-46478 was published for flowise (npm) May 14, 2026
offset Credited to offset
FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover High
CVE-2026-46477 was published for flowise (npm) May 14, 2026
offset Credited to offset
Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements High
CVE-2026-50281 was published for craftcms/cms (Composer) Jul 2, 2026
adrgs Credited to adrgs
flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key High
CVE-2026-55091 was published for flat-to-nested (npm) Jun 19, 2026
moizxsec Credited to moizxsec
FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover High
CVE-2026-46475 was published for flowise (npm) May 14, 2026
offset Credited to offset
FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover High
CVE-2026-46480 was published for flowise (npm) May 14, 2026
offset Credited to offset
offset Credited to offset
berkdedekarginoglu Credited to berkdedekarginoglu
berkdedekarginoglu Credited to berkdedekarginoglu
berkdedekarginoglu Credited to berkdedekarginoglu
berkdedekarginoglu Credited to berkdedekarginoglu
StarPlatinu Credited to StarPlatinu and igalklebanov igalklebanov igalklebanov
ProTip! Advisories are also available from the GraphQL API