Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

19 advisories

Loading
Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration Critical
CVE-2026-23500 was published for dolibarr/dolibarr (Composer) Apr 17, 2026
lukasz-rybak Credited to lukasz-rybak
October Rain has a Twig Sandbox Bypass via Collection Methods Moderate
CVE-2026-22692 was published for october/rain (Composer) Apr 14, 2026
lukasz-rybak Credited to lukasz-rybak and daftspunk daftspunk daftspunk
XWiki Blog Application home page vulnerable to Stored XSS via Post Title High
CVE-2025-66024 was published for org.xwiki.contrib.blog:application-blog-ui (Maven) Mar 4, 2026
lukasz-rybak Credited to lukasz-rybak
OpenSTAManager Affected by XSS in modifica_iva.php via righe parameter Moderate
CVE-2026-24415 was published for devcode-it/openstamanager (Composer) Mar 3, 2026
lukasz-rybak Credited to lukasz-rybak
TypiCMS Core has Stored Cross-Site Scripting (XSS) via SVG File Upload Moderate
CVE-2026-27621 was published for typicms/core (Composer) Feb 25, 2026
lukasz-rybak Credited to lukasz-rybak
OpenSTAManager has a SQL Injection in the Prima Nota module High
CVE-2026-24419 was published for devcode-it/openstamanager (Composer) Feb 6, 2026
lukasz-rybak Credited to lukasz-rybak
OpenSTAManager has a SQL Injection vulnerability in the Scadenzario bulk operations module High
CVE-2026-24418 was published for devcode-it/openstamanager (Composer) Feb 6, 2026
lukasz-rybak Credited to lukasz-rybak
OpenSTAManager has a Time-Based Blind SQL Injection with Amplified Denial of Service High
CVE-2026-24417 was published for devcode-it/openstamanager (Composer) Feb 6, 2026
lukasz-rybak Credited to lukasz-rybak
OpenSTAManager has a Time-Based Blind SQL Injection in Article Pricing Module High
CVE-2026-24416 was published for devcode-it/openstamanager (Composer) Feb 6, 2026
lukasz-rybak Credited to lukasz-rybak
OpenSTAManager has a SQL Injection in Scadenzario Print Template High
CVE-2025-69216 was published for devcode-it/openstamanager (Composer) Feb 6, 2026
lukasz-rybak Credited to lukasz-rybak
OpenSTAManager has a SQL Injection in ajax_select.php (componenti endpoint) High
CVE-2025-69214 was published for devcode-it/openstamanager (Composer) Feb 6, 2026
lukasz-rybak Credited to lukasz-rybak
OpenSTAManager has an OS Command Injection in P7M File Processing Critical
CVE-2025-69212 was published for devcode-it/openstamanager (Composer) Feb 6, 2026
lukasz-rybak Credited to lukasz-rybak
OpenSTAManager has an SQL Injection in the Stampe Module High
CVE-2025-69215 was published for devcode-it/openstamanager (Composer) Feb 3, 2026
lukasz-rybak Credited to lukasz-rybak
OpenSTAManager has a SQL Injection in ajax_complete.php (get_sedi endpoint) High
CVE-2025-69213 was published for devcode-it/openstamanager (Composer) Feb 3, 2026
lukasz-rybak Credited to lukasz-rybak
FacturaScripts has SQL Injection in Autocomplete Actions High
CVE-2026-25514 was published for facturascripts/facturascripts (Composer) Feb 3, 2026
lukasz-rybak Credited to lukasz-rybak
FacturaScripts has SQL Injection in API ORDER BY Clause High
CVE-2026-25513 was published for facturascripts/facturascripts (Composer) Feb 3, 2026
lukasz-rybak Credited to lukasz-rybak
EGroupware has SQL Injection in Nextmatch Filter Processing High
CVE-2026-22243 was published for egroupware/egroupware (Composer) Jan 28, 2026
lukasz-rybak Credited to lukasz-rybak
Shopware Has Improper Control of Generation of Code in Twig rendered views High
CVE-2026-23498 was published for shopware/core (Composer) Jan 14, 2026
lukasz-rybak Credited to lukasz-rybak and andreisss andreisss andreisss
Redaxo has Path Traversal in Backup Addon Leading to Arbitrary File Read High
CVE-2026-21857 was published for redaxo/source (Composer) Jan 5, 2026
lukasz-rybak Credited to lukasz-rybak
ProTip! Advisories are also available from the GraphQL API