GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
55
Go
4,528
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
3,469 advisories
Filter by severity
phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration
Moderate
CVE-2026-47132
was published
for
thorsten/phpmyfaq
(Composer)
Aug 12, 2026
LibreNMS: Reflected XSS via Proxmox instance/vmid GET parameters injected into document.title JavaScript assignment
Moderate
CVE-2026-45694
was published
for
librenms/librenms
(Composer)
Aug 12, 2026
Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads
Moderate
CVE-2026-32639
was published
for
winter/wn-cms-module
(Composer)
Aug 12, 2026
Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax
Moderate
CVE-2026-32593
was published
for
winter/wn-backend-module
(Composer)
Aug 12, 2026
CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()
Moderate
CVE-2026-63220
was published
for
codeigniter4/framework
(Composer)
Aug 7, 2026
API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)
Moderate
CVE-2026-54164
was published
for
api-platform/core
(Composer)
Aug 7, 2026
Smarty Security stream restriction bypass through stream: resource
Moderate
CVE-2026-62996
was published
for
smarty/smarty
(Composer)
Aug 7, 2026
Smarty: Symlink path traversal out of trusted directories
Moderate
CVE-2026-62992
was published
for
smarty/smarty
(Composer)
Aug 7, 2026
Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
Moderate
GHSA-957r-qf9p-67xw
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS: Authenticated leak of secret environment variables
Moderate
GHSA-596p-6jv8-775v
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element
Moderate
GHSA-xxpx-f366-4xpq
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
Moderate
GHSA-rvmm-v933-jgxq
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS: Stored XSS in the control panel via unescaped draft name
Moderate
GHSA-2rp4-x2j7-qmcc
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
Moderate
CVE-2026-14793
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
league/commonmark: Denial of service via deeply nested XML output
Moderate
GHSA-mj63-m3rc-8ppr
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes
Moderate
CVE-2026-71478
was published
for
league/commonmark
(Composer)
Aug 6, 2026
Silverstripe: XSS in breadcrumbs in page list view
Moderate
CVE-2026-54717
was published
for
silverstripe/cms
(Composer)
Aug 6, 2026
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template
Moderate
CVE-2026-71435
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types
Moderate
CVE-2026-71434
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
Moderate
CVE-2026-64662
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Statamic: Unsafe method invocation via Antlers template resolution allows data destruction
Moderate
CVE-2026-64663
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
Moderate
CVE-2026-64664
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Guzzle: Noncanonical cookie domain keeps subdomain scope
Moderate
CVE-2026-69245
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
Moderate
GHSA-3fvr-2jw6-crq4
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers
Moderate
GHSA-32rq-jhr7-m3hh
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API