FLAT-ENQH8 (CVE-2026-55584)
Spoofing In phpsysinfo/phpsysinfo
6.6
Medium
Ecosystem: Packagist
Component: phpsysinfo/phpsysinfo
FLAT-ADM5E (CVE-2026-54713)
Lack of data validation In cakephp/queue
0.6
Low
Ecosystem: Packagist
Component: cakephp/queue
FLAT-K5BOR (CVE-2026-54614)
Remote command execution In cakephp/debug_kit
2.4
Low
Ecosystem: Packagist
Component: cakephp/debug_kit
FLAT-ZJISK (GHSA-pg62-f8g4-4wqh)
Excessive privileges In thorsten/phpmyfaq
6.3
Medium
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-JYGZI (CVE-2026-57995)
Excessive privileges In thorsten/phpmyfaq
5.2
Medium
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-MYYC5 (GHSA-mf8r-wm2w-f8c5)
Improper authorization control for web services In phpmyfaq/phpmyfaq
2.7
Low
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-M2K4R (CVE-2026-57994)
Improper authorization control for web services In thorsten/phpmyfaq
2.7
Low
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-9NDP9 (GHSA-88g4-74f3-63x9)
Lack of data validation - Path Traversal In phpmyfaq/phpmyfaq
4.9
Medium
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-LLADM (CVE-2026-57961)
Lack of data validation - Path Traversal In thorsten/phpmyfaq
4.6
Medium
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-7OB4T (CVE-2026-54133)
Lack of data validation In mtdowling/jmespath.php
7.2
High
Ecosystem: Packagist
Component: mtdowling/jmespath.php
FLAT-CTGXU (CVE-2026-47132)
SQL injection In thorsten/phpmyfaq
1.3
Low
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-DJQF5 (CVE-2026-67434)
OS Command Injection In squizlabs/php_codesniffer
4.4
Medium
Ecosystem: Packagist
Component: squizlabs/php_codesniffer
FLAT-T3SB5 (CVE-2026-59933)
Improper resource allocation In phpoffice/phpspreadsheet
4.6
Medium
Ecosystem: Packagist
Component: phpoffice/phpspreadsheet
FLAT-VAW9K (CVE-2026-59932)
Asymmetric denial of service - ReDoS In phpoffice/phpspreadsheet
6.6
Medium
Ecosystem: Packagist
Component: phpoffice/phpspreadsheet
FLAT-3V4DM (CVE-2026-59931)
Server-side request forgery (SSRF) In phpoffice/phpspreadsheet
8.0
High
Ecosystem: Packagist
Component: phpoffice/phpspreadsheet
FLAT-I81FK (CVE-2026-49359)
Server-side request forgery (SSRF) In pontedilana/php-weasyprint
4.9
Medium
Ecosystem: Packagist
Component: pontedilana/php-weasyprint
FLAT-26J4M (CVE-2026-49358)
Lack of data validation - Path Traversal In pontedilana/php-weasyprint
0.2
Low
Ecosystem: Packagist
Component: pontedilana/php-weasyprint
FLAT-QR09X (CVE-2026-49286)
Insecure deserialization In pontedilana/php-weasyprint
7.2
High
Ecosystem: Packagist
Component: pontedilana/php-weasyprint
FLAT-RPJ7A (CVE-2026-49260)
Remote command execution In pontedilana/php-weasyprint
7.3
High
Ecosystem: Packagist
Component: pontedilana/php-weasyprint
FLAT-9BS55 (CVE-2026-56396)
Privilege escalation In phpmyfaq/phpmyfaq
4.9
Medium
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-R2HBE (GHSA-985r-q3qp-299h)
Privilege escalation In phpmyfaq/phpmyfaq
6.2
Medium
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-1OW1Y (CVE-2026-48820)
Lack of data validation - Path Traversal In cakephp/cakephp
1.7
Low
Ecosystem: Packagist
Component: cakephp/cakephp
FLAT-7ZPE5 (CVE-2026-48979)
HTTP request smuggling In php-standard-library/php-standard-library
6.6
Medium
Ecosystem: Packagist
Component: php-standard-library/php-standard-library
FLAT-3GVLL (CVE-2026-49205)
Improper authorization control for web services In thorsten/phpmyfaq
4.9
Medium
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-05L9N (CVE-2026-48488)
Insecure encryption algorithm In thorsten/phpmyfaq
2.7
Low
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-IP26G (GHSA-2jx3-65f3-xr8r)
Authentication mechanism absence or evasion In spomky-labs/otphp
2.7
Low
Ecosystem: Packagist
Component: spomky-labs/otphp
FLAT-F4SQI (GHSA-g7m4-839x-ch6v)
Lack of data validation In spomky-labs/otphp
6.6
Medium
Ecosystem: Packagist
Component: spomky-labs/otphp
FLAT-4BOU5 (CVE-2026-55590)
Cross-site request forgery In cakephp/authentication
1.2
Low
Ecosystem: Packagist
Component: cakephp/authentication
FLAT-I7XT0 (CVE-2026-45034)
Insecure deserialization In phpoffice/phpspreadsheet
7.2
High
Ecosystem: Packagist
Component: phpoffice/phpspreadsheet
FLAT-ZTOH8 (CVE-2026-35675)
Account Takeover In phpmyfaq/phpmyfaq
8.1
High
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-LYFNO (CVE-2026-35672)
Insecure functionality In thorsten/phpmyfaq
6.6
Medium
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-OZYX1 (CVE-2026-35671)
Improper authorization control for web services In thorsten/phpmyfaq
5.2
Medium
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-KQ2O7 (CVE-2026-35676)
Account lockout In thorsten/phpmyfaq
6.8
Medium
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-QRH1A (GHSA-5h62-f8fg-4w7q)
Improper authorization control for web services In thorsten/phpmyfaq
1.3
Low
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-ENDXW (GHSA-9r8r-x3vg-6xh4)
Authentication mechanism absence or evasion In thorsten/phpmyfaq
1.3
Low
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-KC10S (GHSA-p9wc-4pjv-rg82)
SQL injection In phpmyfaq/phpmyfaq
6.1
Medium
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-WNRK1 (GHSA-w9mj-gfrm-hj5x)
Authentication mechanism absence or evasion In phpmyfaq/phpmyfaq
3.8
Low
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-4XPQK (GHSA-wj3q-vw2v-3rj3)
Server side cross-site scripting In thorsten/phpmyfaq
0.4
Low
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-ZQQZS (CVE-2026-46367)
Server side cross-site scripting In phpmyfaq/phpmyfaq
7.3
High
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-9XMLG (GHSA-478m-mrw4-qf2w)
Server side cross-site scripting In thorsten/phpmyfaq
3.8
Low
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-HVWWQ (GHSA-6626-79jh-5ccr)
Lack of protection against brute force attacks In phpmyfaq/phpmyfaq
8.9
High
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-ILQDY (GHSA-w42g-jj8w-fj77)
Server side cross-site scripting In phpmyfaq/phpmyfaq
5.9
Medium
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-4MBFQ (GHSA-ch9q-c9mp-j5gq)
SQL injection In thorsten/phpmyfaq
9.0
Critical
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-GU63Z (CVE-2026-45008)
Lack of data validation - Path Traversal In phpmyfaq/phpmyfaq
4.8
Medium
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-6GVDX (GHSA-rmqr-h98c-qg2m)
Lack of data validation - Path Traversal In phpmyfaq/phpmyfaq
5.7
Medium
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-I37OE (GHSA-cqrw-j4qc-7f9w)
Authentication mechanism absence or evasion In phpmyfaq/phpmyfaq
6.6
Medium
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-O30L8 (CVE-2026-46360)
Server side cross-site scripting In thorsten/phpmyfaq
0.4
Low
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-WSOW4 (CVE-2026-45009)
Authentication mechanism absence or evasion In thorsten/phpmyfaq
1.3
Low
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-NAQ2C (CVE-2026-46363)
Server side cross-site scripting In phpmyfaq/phpmyfaq
0.5
Low
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-O33GP (GHSA-h36g-93qx-rxgr)
Server side cross-site scripting In phpmyfaq/phpmyfaq
0.6
Low
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-S6183 (GHSA-p26v-fx3x-r2rp)
Improper authorization control for web services In phpmyfaq/phpmyfaq
0.6
Low
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-Z3WRV (CVE-2026-46491)
Lack of data validation - Path Traversal In simplesamlphp/simplesamlphp-module-casserver
4.9
Medium
Ecosystem: Packagist
Component: simplesamlphp/simplesamlphp-module-casserver
FLAT-FFE1N (CVE-2025-65954)
Server-side request forgery (SSRF) In simplesamlphp/simplesamlphp-module-casserver
0.5
Low
Ecosystem: Packagist
Component: simplesamlphp/simplesamlphp-module-casserver
FLAT-JFTGJ (CVE-2026-46365)
Improper authorization control for web services In phpmyfaq/phpmyfaq
1.3
Low
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-8VBKF (MAL-2026-3637)
Use of software with malware In intercom/intercom-php
5.2
Medium
Ecosystem: Packagist
Component: intercom/intercom-php
FLAT-MM39P (GHSA-gr3r-crp5-qrrm)
Use of software with malware In intercom/intercom-php
6.0
Medium
Ecosystem: Packagist
Component: intercom/intercom-php
FLAT-F60DU (CVE-2026-42552)
Technical information leak In flightphp/core
6.6
Medium
Ecosystem: Packagist
Component: flightphp/core
FLAT-BR9OL (CVE-2026-42551)
Lack of data validation In flightphp/core
4.9
Medium
Ecosystem: Packagist
Component: flightphp/core
FLAT-S7Q6Z (CVE-2026-42550)
SQL injection In flightphp/core
7.2
High
Ecosystem: Packagist
Component: flightphp/core
FLAT-R0XJU (CVE-2026-42549)
Lack of data validation - Path Traversal In flightphp/core
0.4
Low
Ecosystem: Packagist
Component: flightphp/core
FLAT-3R9DC (CVE-2026-42548)
Reflected cross-site scripting (XSS) In flightphp/core
6.2
Medium
Ecosystem: Packagist
Component: flightphp/core
FLAT-IEWF0 (CVE-2026-46364)
SQL injection In thorsten/phpmyfaq
8.1
High
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-L3AIK (CVE-2026-46366)
Authentication mechanism absence or evasion In thorsten/phpmyfaq
6.6
Medium
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-81BAY (CVE-2026-46359)
SQL injection In thorsten/phpmyfaq
7.2
High
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-0PR8T (CVE-2026-45010)
Lack of protection against brute force attacks In phpmyfaq/phpmyfaq
8.0
High
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-WX3CS (CVE-2026-46361)
Server side cross-site scripting In thorsten/phpmyfaq
5.8
Medium
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-AF0XA (CVE-2026-45007)
Improper authorization control for web services In phpmyfaq/phpmyfaq
1.3
Low
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-LCK1F (GHSA-7cx3-2qx2-3g6w)
Improper authorization control for web services In phpmyfaq/phpmyfaq
1.3
Low
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-EVYWD (CVE-2026-46362)
Authentication mechanism absence or evasion In phpmyfaq/phpmyfaq
2.3
Low
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-42RMU (GHSA-r7cg-qjjm-xhqq)
Improper resource allocation In webonyx/graphql-php
6.7
Medium
Ecosystem: Packagist
Component: webonyx/graphql-php
FLAT-68R80 (GHSA-fc86-6rv6-2jpm)
Improper resource allocation In webonyx/graphql-php
6.6
Medium
Ecosystem: Packagist
Component: webonyx/graphql-php
FLAT-TARMR (CVE-2026-42569)
Improper authorization control for web services In nabeel/phpvms
6.8
Medium
Ecosystem: Packagist
Component: nabeel/phpvms
FLAT-U1WLN (CVE-2026-29199)
Account lockout In phpbb/phpbb
4.8
Medium
Ecosystem: Packagist
Component: phpbb/phpbb
FLAT-5TEB6 (CVE-2026-40902)
Improper resource allocation In phpoffice/phpspreadsheet
6.6
Medium
Ecosystem: Packagist
Component: phpoffice/phpspreadsheet
FLAT-32YY7 (CVE-2026-40863)
Asymmetric denial of service - ReDoS In phpoffice/phpspreadsheet
6.6
Medium
Ecosystem: Packagist
Component: phpoffice/phpspreadsheet
FLAT-BG04V (CVE-2026-34084)
Insecure deserialization In phpoffice/phpspreadsheet
7.2
High
Ecosystem: Packagist
Component: phpoffice/phpspreadsheet
FLAT-2A5LL (CVE-2026-40296)
Server side cross-site scripting In phpoffice/phpspreadsheet
0.5
Low
Ecosystem: Packagist
Component: phpoffice/phpspreadsheet
FLAT-FA9NE (CVE-2026-35453)
Reflected cross-site scripting (XSS) In phpoffice/phpspreadsheet
1.3
Low
Ecosystem: Packagist
Component: phpoffice/phpspreadsheet
FLAT-1MMXB (GHSA-mh6w-vxff-9wqp)
Lack of data validation In phpunit/phpunit
4.4
Medium
Ecosystem: Packagist
Component: phpunit/phpunit
FLAT-6RNFW (CVE-2026-41570)
Lack of data validation In phpunit/phpunit
4.4
Medium
Ecosystem: Packagist
Component: phpunit/phpunit
FLAT-SX9CG (CVE-2026-40476)
Improper resource allocation In webonyx/graphql-php
2.7
Low
Ecosystem: Packagist
Component: webonyx/graphql-php
FLAT-Q1ZJ6 (CVE-2026-34974)
Server side cross-site scripting In thorsten/phpmyfaq
5.6
Medium
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-KL6V2 (CVE-2026-34973)
NoSQL injection In thorsten/phpmyfaq
2.7
Low
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-3AM1J (CVE-2026-34729)
Server side cross-site scripting In phpmyfaq/phpmyfaq
5.8
Medium
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-0WT6J (CVE-2026-34728)
Lack of data validation - Path Traversal In phpmyfaq/phpmyfaq
5.7
Medium
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-6X6YO (CVE-2026-34236)
Insecure generation of random numbers In auth0/auth0-php
8.1
High
Ecosystem: Packagist
Component: auth0/auth0-php
FLAT-593LC (CVE-2026-32629)
Server side cross-site scripting In thorsten/phpmyfaq
2.4
Low
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-Q8SBU (GHSA-27qh-8cxx-2cr5)
Lack of data validation In aws/aws-sdk-php
4.4
Medium
Ecosystem: Packagist
Component: aws/aws-sdk-php
FLAT-MCHBK (CVE-2026-33942)
Insecure deserialization In saloonphp/saloon
8.1
High
Ecosystem: Packagist
Component: saloonphp/saloon
FLAT-U066W (CVE-2026-33183)
Out-of-bounds read In saloonphp/saloon
1.7
Low
Ecosystem: Packagist
Component: saloonphp/saloon
FLAT-RKB89 (CVE-2026-33182)
Server-side request forgery (SSRF) In saloonphp/saloon
6.6
Medium
Ecosystem: Packagist
Component: saloonphp/saloon
FLAT-8IVXL (CVE-2026-32600)
Missing subresource integrity check In simplesamlphp/xml-security
6.9
Medium
Ecosystem: Packagist
Component: simplesamlphp/xml-security
FLAT-CRALW (CVE-2026-27836)
Improper authorization control for web services In thorsten/phpmyfaq
6.9
Medium
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-6VC5O (GHSA-8grv-jq2g-cfhw)
Asymmetric denial of service - ReDoS In amphp/http-server
4.6
Medium
Ecosystem: Packagist
Component: amphp/http-server
FLAT-AP5UL (CVE-2026-24765)
Insecure deserialization In phpunit/phpunit
4.4
Medium
Ecosystem: Packagist
Component: phpunit/phpunit
FLAT-WBGJG (CVE-2026-24422)
Business information leak In thorsten/phpmyfaq
2.7
Low
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-4V4ZK (CVE-2026-24421)
Improper authorization control for web services In thorsten/phpmyfaq
2.3
Low
Ecosystem: Packagist
Component: thorsten/phpmyfaq
FLAT-4NTF9 (CVE-2026-24420)
Improper authorization control for web services In phpmyfaq/phpmyfaq
2.3
Low
Ecosystem: Packagist
Component: phpmyfaq/phpmyfaq
FLAT-IH085 (CVE-2021-47853)
Remote command execution In phppgadmin/phppgadmin
6.1
Medium
Ecosystem: Packagist
Component: phppgadmin/phppgadmin
FLAT-9K611 (CVE-2026-23643)
Reflected cross-site scripting (XSS) In cakephp/cakephp
1.2
Low
Ecosystem: Packagist
Component: cakephp/cakephp