检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-X2FP-HJ8C-MMXH CVE-2026-8204 | Concrete CMS is vulnerable to authorization bypass in the Calendar Event Frontend Dialog | 中危 | Packagistconcrete5/concrete5 | 已审查 | 2026-05-22 05:30 | 2026-06-25 04:57 |
| GHSA-PRXR-VJGC-2CQ9 CVE-2026-8428 | Concrete CMS is Vulnerable to Cross-Site Request Forgery |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Packagistconcrete5/concrete5 |
| 已审查 |
| 2026-05-22 05:30 |
| 2026-06-25 04:57 |
| GHSA-JR5G-QV3G-RXXX CVE-2026-8417 | Concrete does not validate a CSRF token before processing requests to `/dashboard/extend/update/do_update/<pkgHandle>` | 高危 | Packagistconcrete5/concrete5 | 已审查 | 2026-05-22 05:30 | 2026-06-25 02:28 |
| GHSA-G7XP-JF3X-WCX4 CVE-2026-8350 | Concrete CMS is vulnerable to missing authorization in the bulk_user_assignment.php | 高危 | Packagistconcrete5/concrete5 | 已审查 | 2026-05-22 05:30 | 2026-06-25 04:58 |
| GHSA-9V2G-37MP-QPXF CVE-2026-8203 | Concrete CMS has Stored XSS through its height parameter | 高危 | Packagistconcrete5/concrete5 | 已审查 | 2026-05-22 05:30 | 2026-06-25 04:58 |
| GHSA-5RJ5-GFMR-HRC3 CVE-2026-8426 | Concrete CMS does not validate a CSRF token before processing requests to `/dashboard/extend/update/prepare_remote_upgrade/<remoteMPID>` | 高危 | Packagistconcrete5/concrete5 | 已审查 | 2026-05-22 05:30 | 2026-06-25 02:19 |
| GHSA-4C8M-6FWX-M7XQ CVE-2026-8421 | Concrete CMS contains a CSRF vulnerability | 高危 | Packagistconcrete5/concrete5 | 已审查 | 2026-05-22 05:30 | 2026-06-25 02:37 |
| GHSA-46XH-7854-F568 CVE-2026-8205 | Concrete CMS is vulnerable to authorization bypass in the Calendar Block | 中危 | Packagistconcrete5/concrete5 | 已审查 | 2026-05-22 05:30 | 2026-06-25 04:57 |
| GHSA-WPFP-GWWC-VWQ6 CVE-2026-47102 | LiteLLM allows a user to modify their own user_role via the /user/update endpoint | 高危 | PyPIlitellm | 已审查 | 2026-05-22 05:30 | 2026-06-24 06:48 |
| GHSA-R42C-3RR2-JRFP CVE-2026-8140 | Concrete CMS is Vulnerable to Cross-Site Request Forgery | 高危 | Packagistconcrete5/concrete5 | 已审查 | 2026-05-22 05:30 | 2026-06-24 06:58 |
| GHSA-PV2V-6W2V-97X6 CVE-2026-8135 | Concrete CMS Vulnerable to Deserialization of Untrusted Data | 高危 | Packagistconcrete5/concrete5 | 已审查 | 2026-05-22 05:30 | 2026-06-24 06:57 |
| GHSA-H72C-XX3W-W8H7 CVE-2026-8197 | Concrete CMS is vulnerable to Stored XSS via OAuth integration name | 高危 | Packagistconcrete5/concrete5 | 已审查 | 2026-05-22 05:30 | 2026-06-25 02:07 |
| GHSA-645J-CM4X-3XVW CVE-2026-8134 | Concrete CMS Vulnerable to Relative Path Traversal | 严重 | Packagistconcrete5/concrete5 | 已审查 | 2026-05-22 05:30 | 2026-06-24 06:56 |
| GHSA-4G7Q-44QP-CC5C CVE-2026-6826 | Concrete CMS is vulnerable to unauthenticated file usage disclosure | 中危 | Packagistconcrete5/concrete5 | 已审查 | 2026-05-22 05:30 | 2026-06-24 06:57 |
| GHSA-QRC4-49GV-MV9M CVE-2026-47101 | LiteLLM allows an authenticated internal_user to create API keys with access to routes that their role does not permit | 高危 | PyPIlitellm | 已审查 | 2026-05-22 05:30 | 2026-06-24 06:47 |
| GHSA-7FXW-R6JV-74C8 CVE-2026-46638 | Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411) | 中危 | Packagisttwig/twig | 已审查 | 2026-05-22 05:28 | 2026-05-22 05:28 |
| GHSA-JV8M-2544-3PG3 CVE-2026-46637 | Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']` | 低危 | Packagisttwig/cssinliner-extra+1 | 已审查 | 2026-05-22 05:27 | 2026-05-22 05:27 |
| GHSA-VCC8-PHRV-43WJ CVE-2026-46635 | Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects) | 低危 | Packagisttwig/twig | 已审查 | 2026-05-22 05:25 | 2026-05-22 05:25 |
| GHSA-24X9-R6Q4-Q93W CVE-2026-46634 | Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name | 中危 | Packagisttwig/twig | 已审查 | 2026-05-22 05:25 | 2026-05-22 05:25 |
| GHSA-7P85-W9PX-JPJP CVE-2026-46633 | Twig: PHP code injection via `{% use %}` template name | 严重 | Packagisttwig/twig | 已审查 | 2026-05-22 05:24 | 2026-05-22 05:24 |
| GHSA-35WC-CVQG-78FP CVE-2026-46629 | twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled arguments | 低危 | Packagisttwig/intl-extra | 已审查 | 2026-05-22 05:23 | 2026-05-22 05:23 |
| GHSA-4J38-F5CW-54H7 CVE-2026-46628 | Twig: The `spaceless` filter implicitly marks its output as safe | 低危 | Packagisttwig/twig | 已审查 | 2026-05-22 05:21 | 2026-05-22 05:21 |
| GHSA-QJX8-664M-686J CVE-2026-46625 | JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection | 高危 | npmjs-cookie | 已审查 | 2026-05-22 05:20 | 2026-06-11 22:05 |
| GHSA-G9F8-WQJ9-FJW5 CVE-2026-46673 | Russh: Unchecked CryptoVec allocation and growth handling is reachable | 高危 | crates.iorussh+1 | 已审查 | 2026-05-22 04:49 | 2026-06-11 22:06 |
| GHSA-59F3-7227-WMH4 | @hulumi/policies: Stack-wide evidence bypassed Cloudflare and deployment-governance guardrails | 高危 | npm@hulumi/policies | 已审查 | 2026-05-22 04:47 | 2026-05-22 04:47 |