nabeel/phpvms
virtual airline management
Activity
- Latest release
- 3mo ago
- Total releases
- 16
- Cadence
- ~3 months
- Last 12 months
- 4
Reach
- Stars
- 202
Details
- License
- BSD-3-Clause
- First release
- Feb 23, 2018
| Version | Released | |
|---|---|---|
7.0.10
patch
|
7.0.10
patch
Dependencies (71)
+ 63 more
Changelog
Compare changes
|
|
7.0.8
patch
| ||
7.0.7
patch
| ||
7.0.6
patch
| ||
7.0.5
patch
1 CVE
CVE-2026-42569
GHSA-fv26-4939-62fh
May 04, 2026
phpVMS has an /importer authorization bypass causing full database wipe
9.4
/ 10
Critical
Network
Low
None
None
Unchanged
Low
High
High
Security Advisory: Unauthenticated Access to Legacy Import FeatureSeverity: Critical Affected versions: phpVMS 7.x (up to 7.0.5) Fixed in: v7.0.6 Component: Legacy importer SummaryA critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational. ImpactA remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:
No authentication was required. Remediation
Affected Versions
Affected versions
7.0.0
7.0.0-beta.2
7.0.0-beta.3
7.0.0-beta.4
7.0.0-beta.5
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
v7.0.0-alpha2
v7.0.0-beta
Fixed in
7.0.6
References
Updated May 13, 2026 · Source: OSV.dev | ||
7.0.4
patch
1 CVE
CVE-2026-42569
GHSA-fv26-4939-62fh
May 04, 2026
phpVMS has an /importer authorization bypass causing full database wipe
9.4
/ 10
Critical
Network
Low
None
None
Unchanged
Low
High
High
Security Advisory: Unauthenticated Access to Legacy Import FeatureSeverity: Critical Affected versions: phpVMS 7.x (up to 7.0.5) Fixed in: v7.0.6 Component: Legacy importer SummaryA critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational. ImpactA remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:
No authentication was required. Remediation
Affected Versions
Affected versions
7.0.0
7.0.0-beta.2
7.0.0-beta.3
7.0.0-beta.4
7.0.0-beta.5
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
v7.0.0-alpha2
v7.0.0-beta
Fixed in
7.0.6
References
Updated May 13, 2026 · Source: OSV.dev | ||
7.0.3
patch
1 CVE
CVE-2026-42569
GHSA-fv26-4939-62fh
May 04, 2026
phpVMS has an /importer authorization bypass causing full database wipe
9.4
/ 10
Critical
Network
Low
None
None
Unchanged
Low
High
High
Security Advisory: Unauthenticated Access to Legacy Import FeatureSeverity: Critical Affected versions: phpVMS 7.x (up to 7.0.5) Fixed in: v7.0.6 Component: Legacy importer SummaryA critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational. ImpactA remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:
No authentication was required. Remediation
Affected Versions
Affected versions
7.0.0
7.0.0-beta.2
7.0.0-beta.3
7.0.0-beta.4
7.0.0-beta.5
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
v7.0.0-alpha2
v7.0.0-beta
Fixed in
7.0.6
References
Updated May 13, 2026 · Source: OSV.dev | ||
7.0.2
patch
1 CVE
CVE-2026-42569
GHSA-fv26-4939-62fh
May 04, 2026
phpVMS has an /importer authorization bypass causing full database wipe
9.4
/ 10
Critical
Network
Low
None
None
Unchanged
Low
High
High
Security Advisory: Unauthenticated Access to Legacy Import FeatureSeverity: Critical Affected versions: phpVMS 7.x (up to 7.0.5) Fixed in: v7.0.6 Component: Legacy importer SummaryA critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational. ImpactA remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:
No authentication was required. Remediation
Affected Versions
Affected versions
7.0.0
7.0.0-beta.2
7.0.0-beta.3
7.0.0-beta.4
7.0.0-beta.5
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
v7.0.0-alpha2
v7.0.0-beta
Fixed in
7.0.6
References
Updated May 13, 2026 · Source: OSV.dev |
7.0.2
patch
Dependencies (70)
+ 62 more
Changelog
Compare changes
|
|
7.0.1
patch
1 CVE
CVE-2026-42569
GHSA-fv26-4939-62fh
May 04, 2026
phpVMS has an /importer authorization bypass causing full database wipe
9.4
/ 10
Critical
Network
Low
None
None
Unchanged
Low
High
High
Security Advisory: Unauthenticated Access to Legacy Import FeatureSeverity: Critical Affected versions: phpVMS 7.x (up to 7.0.5) Fixed in: v7.0.6 Component: Legacy importer SummaryA critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational. ImpactA remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:
No authentication was required. Remediation
Affected Versions
Affected versions
7.0.0
7.0.0-beta.2
7.0.0-beta.3
7.0.0-beta.4
7.0.0-beta.5
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
v7.0.0-alpha2
v7.0.0-beta
Fixed in
7.0.6
References
Updated May 13, 2026 · Source: OSV.dev | ||
7.0.0
initial
1 CVE
CVE-2026-42569
GHSA-fv26-4939-62fh
May 04, 2026
phpVMS has an /importer authorization bypass causing full database wipe
9.4
/ 10
Critical
Network
Low
None
None
Unchanged
Low
High
High
Security Advisory: Unauthenticated Access to Legacy Import FeatureSeverity: Critical Affected versions: phpVMS 7.x (up to 7.0.5) Fixed in: v7.0.6 Component: Legacy importer SummaryA critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational. ImpactA remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:
No authentication was required. Remediation
Affected Versions
Affected versions
7.0.0
7.0.0-beta.2
7.0.0-beta.3
7.0.0-beta.4
7.0.0-beta.5
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
v7.0.0-alpha2
v7.0.0-beta
Fixed in
7.0.6
References
Updated May 13, 2026 · Source: OSV.dev | ||
7.0.0-beta.5
pre
1 CVE
CVE-2026-42569
GHSA-fv26-4939-62fh
May 04, 2026
phpVMS has an /importer authorization bypass causing full database wipe
9.4
/ 10
Critical
Network
Low
None
None
Unchanged
Low
High
High
Security Advisory: Unauthenticated Access to Legacy Import FeatureSeverity: Critical Affected versions: phpVMS 7.x (up to 7.0.5) Fixed in: v7.0.6 Component: Legacy importer SummaryA critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational. ImpactA remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:
No authentication was required. Remediation
Affected Versions
Affected versions
7.0.0
7.0.0-beta.2
7.0.0-beta.3
7.0.0-beta.4
7.0.0-beta.5
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
v7.0.0-alpha2
v7.0.0-beta
Fixed in
7.0.6
References
Updated May 13, 2026 · Source: OSV.dev |
7.0.0-beta.5
pre
Dependencies (60)
+ 52 more
Changelog
Compare changes
|
|
7.0.0-beta.4
pre
1 CVE
CVE-2026-42569
GHSA-fv26-4939-62fh
May 04, 2026
phpVMS has an /importer authorization bypass causing full database wipe
9.4
/ 10
Critical
Network
Low
None
None
Unchanged
Low
High
High
Security Advisory: Unauthenticated Access to Legacy Import FeatureSeverity: Critical Affected versions: phpVMS 7.x (up to 7.0.5) Fixed in: v7.0.6 Component: Legacy importer SummaryA critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational. ImpactA remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:
No authentication was required. Remediation
Affected Versions
Affected versions
7.0.0
7.0.0-beta.2
7.0.0-beta.3
7.0.0-beta.4
7.0.0-beta.5
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
v7.0.0-alpha2
v7.0.0-beta
Fixed in
7.0.6
References
Updated May 13, 2026 · Source: OSV.dev |
7.0.0-beta.4
pre
Dependencies (45)
+ 37 more
Changelog
Compare changes
|
|
7.0.0-beta.3
pre
1 CVE
CVE-2026-42569
GHSA-fv26-4939-62fh
May 04, 2026
phpVMS has an /importer authorization bypass causing full database wipe
9.4
/ 10
Critical
Network
Low
None
None
Unchanged
Low
High
High
Security Advisory: Unauthenticated Access to Legacy Import FeatureSeverity: Critical Affected versions: phpVMS 7.x (up to 7.0.5) Fixed in: v7.0.6 Component: Legacy importer SummaryA critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational. ImpactA remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:
No authentication was required. Remediation
Affected Versions
Affected versions
7.0.0
7.0.0-beta.2
7.0.0-beta.3
7.0.0-beta.4
7.0.0-beta.5
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
v7.0.0-alpha2
v7.0.0-beta
Fixed in
7.0.6
References
Updated May 13, 2026 · Source: OSV.dev |
7.0.0-beta.3
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
7.0.0-beta.2
pre
1 CVE
CVE-2026-42569
GHSA-fv26-4939-62fh
May 04, 2026
phpVMS has an /importer authorization bypass causing full database wipe
9.4
/ 10
Critical
Network
Low
None
None
Unchanged
Low
High
High
Security Advisory: Unauthenticated Access to Legacy Import FeatureSeverity: Critical Affected versions: phpVMS 7.x (up to 7.0.5) Fixed in: v7.0.6 Component: Legacy importer SummaryA critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational. ImpactA remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:
No authentication was required. Remediation
Affected Versions
Affected versions
7.0.0
7.0.0-beta.2
7.0.0-beta.3
7.0.0-beta.4
7.0.0-beta.5
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
v7.0.0-alpha2
v7.0.0-beta
Fixed in
7.0.6
References
Updated May 13, 2026 · Source: OSV.dev |
7.0.0-beta.2
pre
Dependencies (38)
+ 30 more
Changelog
Compare changes
|
|
v7.0.0-beta
pre
1 CVE
CVE-2026-42569
GHSA-fv26-4939-62fh
May 04, 2026
phpVMS has an /importer authorization bypass causing full database wipe
9.4
/ 10
Critical
Network
Low
None
None
Unchanged
Low
High
High
Security Advisory: Unauthenticated Access to Legacy Import FeatureSeverity: Critical Affected versions: phpVMS 7.x (up to 7.0.5) Fixed in: v7.0.6 Component: Legacy importer SummaryA critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational. ImpactA remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:
No authentication was required. Remediation
Affected Versions
Affected versions
7.0.0
7.0.0-beta.2
7.0.0-beta.3
7.0.0-beta.4
7.0.0-beta.5
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
v7.0.0-alpha2
v7.0.0-beta
Fixed in
7.0.6
References
Updated May 13, 2026 · Source: OSV.dev |
v7.0.0-beta
pre
Dependencies (35)
+ 27 more
Changelog
Compare changes
|
|
v7.0.0-alpha2
pre
1 CVE
CVE-2026-42569
GHSA-fv26-4939-62fh
May 04, 2026
phpVMS has an /importer authorization bypass causing full database wipe
9.4
/ 10
Critical
Network
Low
None
None
Unchanged
Low
High
High
Security Advisory: Unauthenticated Access to Legacy Import FeatureSeverity: Critical Affected versions: phpVMS 7.x (up to 7.0.5) Fixed in: v7.0.6 Component: Legacy importer SummaryA critical vulnerability in phpVMS 7.x allowed unauthenticated access to a legacy import feature. Although this feature is deprecated, parts of it remained accessible and operational. ImpactA remote attacker could trigger internal processes that modify or delete application data, potentially resulting in:
No authentication was required. Remediation
Affected Versions
Affected versions
7.0.0
7.0.0-beta.2
7.0.0-beta.3
7.0.0-beta.4
7.0.0-beta.5
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
v7.0.0-alpha2
v7.0.0-beta
Fixed in
7.0.6
References
Updated May 13, 2026 · Source: OSV.dev |