GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
438 advisories
Filter by severity
Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read
Low
CVE-2026-56394
was published
for
craftcms/cms
(Composer)
Jul 9, 2026
Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata
Low
CVE-2026-56385
was published
for
craftcms/cms
(Composer)
Mar 26, 2026
Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options
Low
CVE-2026-56393
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page
Low
CVE-2026-56381
was published
for
craftcms/cms
(Composer)
Mar 11, 2026
Craft CMS: Incorrect path validation could potentially lead to path traversal
Low
GHSA-7hxc-f267-h5q7
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type
Low
CVE-2026-56383
was published
for
craftcms/cms
(Composer)
Feb 25, 2026
Contao: Possible path traversal in job download URIs
Low
CVE-2026-55825
was published
for
contao/contao
(Composer)
Aug 6, 2026
Contao crawler leaks auth credentials to external hosts
Low
CVE-2026-55824
was published
for
contao/contao
(Composer)
Aug 6, 2026
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
Low
CVE-2026-52838
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
Low
CVE-2026-52841
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
Low
CVE-2026-52839
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments has server-side request forgery in CalDAV connection test that exposes the deployment's internal network
Low
CVE-2026-52840
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Dompdf: File existence oracle via font-face stylesheet declaration
Low
CVE-2026-55555
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
Dompdf: Chroot Validation Bypass
Low
CVE-2026-55554
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`
Low
CVE-2026-45710
was published
for
facturascripts/facturascripts
(Composer)
Jul 14, 2026
Dolibarr ERP CRM is vulnerable to Improper Authorization through its Leave Request REST API
Low
CVE-2026-10215
was published
for
dolibarr/dolibarr
(Composer)
Jun 1, 2026
Webauthn: SimpleFakeCredentialGenerator with an empty secret produces predictable fake credentials, weakening username enumeration protection
Low
GHSA-gq4g-fpc9-vjfq
was published
for
web-auth/webauthn-lib
(Composer)
Jul 7, 2026
Kimai Favorite Timesheet Add and Remove Endpoints Allows Cross-User Bookmark Manipulation
Low
GHSA-j5mc-p8qg-39j7
was published
for
kimai/kimai
(Composer)
Jul 2, 2026
Kimai Password Reset Link Remains Valid After Password Change
Low
GHSA-m492-gv72-xvxj
was published
for
kimai/kimai
(Composer)
Jul 1, 2026
Schema.org has cross-site scripting (XSS) via script break-out in toScript() output
Low
GHSA-hwmc-r6mf-jh83
was published
for
spatie/schema-org
(Composer)
Jul 1, 2026
Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
Low
CVE-2026-48805
was published
for
twig/twig
(Composer)
Jun 30, 2026
Concrete CMS is vulnerable to Stored XSS via page name in the Atomik theme
Low
CVE-2026-8353
was published
for
concrete5/concrete5
(Composer)
May 26, 2026
Concrete CMS is vulnerable to CSRF via Backend\File::approveVersion
Low
CVE-2026-8340
was published
for
concrete5/concrete5
(Composer)
May 26, 2026
Concrete CMS is vulnerable to IDOR + wrong-authorization-level in the Express association Reorder dialog
Low
CVE-2026-8347
was published
for
concrete5/concrete5
(Composer)
May 26, 2026
Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors
Low
CVE-2026-54244
was published
for
statamic/cms
(Composer)
Jun 26, 2026
ProTip!
Advisories are also available from the
GraphQL API