Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

903
Quick preset (or use dates below)
Clear Filters
📅 Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 101 - 120 of 27,228 CVEs

Twig: Sandbox property and method bypass via object-destructuring assignment

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

Twig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`

Vendor: composer
Product: twig/markdown-extra
Published: May 21, 2026
Source: GitHub

Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

Twig: PHP code injection via `{% use %}` template name

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub

twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled arguments

Vendor: composer
Product: twig/intl-extra
Published: May 21, 2026
Source: GitHub

Twig: The `spaceless` filter implicitly marks its output as safe

Vendor: composer
Product: twig/twig
Published: May 21, 2026
Source: GitHub
CVE-2026-46625 HIGH - 7.5

JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection

Vendor: npm
Product: js-cookie
Published: May 21, 2026
Source: GitHub

Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but the corresponding do_update() method in concrete/controllers/single_page/dashboard/system/update/update.php never calls $this->token->validate('do_update&#...

Published: May 21, 2026
Source: NVD

Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepare_remote_upgrade/<remoteMPID>. An attacker who controls the remote package returned for a known marketplace item ID can overwrite the package PHP on disk and force its upgra...

Published: May 21, 2026
Source: NVD

Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/single_page/dashboard/extend/install.php.  An attacker who can cause an authenticated administrator to visit a crafted page,  and who has placed or caused a package to be present under ...

Published: May 21, 2026
Source: NVD

Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_update/<pkgHandle>. The do_update() method in concrete/controllers/single_page/dashboard/extend/update.php checks only canInstallPackages() before executing upgradeCoreData() a...

Published: May 21, 2026
Source: NVD

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

Published: May 21, 2026
Source: NVD

Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative Group. Any authenticated user with access to the bulk user assignment dashboard page can add any user email to any group and can remove legitim...

Published: May 21, 2026
Source: NVD

Concrete CMS 9.5.0 and below is vulnerable to authorization bypass in the Calendar Block since action_get_events does not check canView on the calendar which results in restricted event details being disclosed. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 6.3 with vec...

Published: May 21, 2026
Source: NVD

Concrete CMS 9.5.0 and below is vulnerable to authorization Bypass in the Calendar Event Frontend Dialog which can allow cross-calendar data disclosure. A public calendar block can be used as a pivot point to access private calendar data. The Concrete CMS security team gave this vulnerability a CVSS...

Published: May 21, 2026
Source: NVD

Concrete CMS 9.5.0 and below has Stored XSS on the height parameter. The controller does not validate or sanitize $height. Any user with editor privileges can inject malicious JavaScript that executes in the context of any visitor's browser, potentially leading to session hijacking, credential ...

Published: May 21, 2026
Source: NVD

Concrete CMS 9.5.0 and below is vulnerable to Stored XSS via OAuth integration name. The OAuth authorize template renders the integration name (admin-controlled) through Concrete's t() translation helper as a sprintf-style format. The <strong>...</strong> wrap is built by PHP string...

Published: May 21, 2026
Source: NVD

Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/install/download/<remoteId>. The download() method in concrete/controllers/single_page/dashboard/extend/install.php checks only the canInstallPackages() permission before fetching a remo...

Published: May 21, 2026
Source: NVD