Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
Packagist/flightphp/core — 5 CVEs · VulnScope
pkg:Packagist/
flightphp/core
5 total CVEs
HIGH
3
MEDIUM
1
✅ Check your installed version
Check
All known vulnerabilities
HIGH
8.8
CVE-2026-42550
Flight vulnerable to SQL Injection via unvalidated identifiers in SimplePdo::insert / update / delete
from 0, < 3.18.1
HIGH
7.5
CVE-2026-42552
Flight vulnerable to sensitive information disclosure via default error handler
from 0, < 3.18.1
HIGH
7.5
CVE-2026-42551
Flight: HTTP method override enabled by default, facilitating CSRF escalation and middleware bypass
from 0, < 3.18.1
MEDIUM
4.4
Flight has path traversal in `make:controller` CLI that creates arbitrary directories outside project root
from 0, < 3.18.1
—
Flight has reflected XSS through an unvalidated JSONP callback in Flight::jsonp()
from 0, < 3.18.1
CVE-2026-42549
CVE-2026-42548