GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,791
Maven
5,000+
npm
4,399
NuGet
772
pip
4,175
Pub
12
RubyGems
965
Rust
1,074
Swift
45
Unreviewed advisories
All unreviewed
5,000+
5,112 advisories
Filter by severity
Redaxo has Path Traversal in Backup Addon Leading to Arbitrary File Read
High
CVE-2026-21857
was published
for
redaxo/source
(Composer)
Jan 5, 2026
Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
High
CVE-2025-68455
was published
for
craftcms/cms
(Composer)
Jan 5, 2026
Unauthenticated Craft CMS users can trigger a database backup
High
CVE-2025-68456
was published
for
craftcms/cms
(Composer)
Jan 5, 2026
Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI
Moderate
CVE-2025-68454
was published
for
craftcms/cms
(Composer)
Jan 5, 2026
Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation
Moderate
CVE-2025-68437
was published
for
craftcms/cms
(Composer)
Jan 5, 2026
Craft CMS vulnerable to potential information disclosure via unchecked asset relocation
Moderate
CVE-2025-68436
was published
for
craftcms/cms
(Composer)
Jan 5, 2026
Bagisto is vulnerable to SSTI via name parameters provided by non-admin low-privilege users
High
CVE-2026-21449
was published
for
bagisto/bagisto
(Composer)
Jan 2, 2026
Bagisto has IDOR in Customer Order Reorder Functionality
High
CVE-2026-21447
was published
for
bagisto/bagisto
(Composer)
Jan 2, 2026
Bagisto has Normal & Blind SSTI from low-privilege user when ordering product
High
CVE-2026-21448
was published
for
bagisto/bagisto
(Composer)
Jan 2, 2026
Bagisto SSTI vulnerability in type parameter can lead to RCE
High
CVE-2026-21450
was published
for
bagisto/bagisto
(Composer)
Jan 2, 2026
Bagisto has HTML Filter Bypass that Enables Stored XSS
Moderate
CVE-2026-21451
was published
for
bagisto/bagisto
(Composer)
Jan 2, 2026
Bagisto Missing Authentication on Installer API Endpoints
High
CVE-2026-21446
was published
for
bagisto/bagisto
(Composer)
Jan 2, 2026
FacturaScripts is Vulnerable to Stored Cross-Site Scripting (XSS) via XML File Upload
High
CVE-2025-69210
was published
for
facturascripts/facturascripts
(Composer)
Dec 30, 2025
YOURLS is vulnerable to XSS through JSONP and Callback request parameters
High
GHSA-6mp4-q625-mxjp
was published
for
yourls/yourls
(Composer)
Dec 30, 2025
Composer is vulnerable to ANSI sequence injection
Low
CVE-2025-67746
was published
for
composer/composer
(Composer)
Dec 30, 2025
phpMyFAQ has unauthenticated config backup download via /api/setup/backup
High
CVE-2025-69200
was published
for
thorsten/phpmyfaq
(Composer)
Dec 30, 2025
Pterodactyl has a Reflected XSS vulnerability in “Create New Database Host”
Low
GHSA-mgr9-6c2j-jxrq
was published
for
pterodactyl/panel
(Composer)
Dec 30, 2025
phpMyFAQ has Stored XSS in user list via admin-managed display_name
Moderate
CVE-2025-68951
was published
for
thorsten/phpmyfaq
(Composer)
Dec 29, 2025
Croogo CMS has a path traversal vulnerability
High
CVE-2024-42718
was published
for
croogo/croogo
(Composer)
Dec 26, 2025
Cadmium CMS has a background arbitrary file upload vulnerability
High
CVE-2025-51511
was published
for
cadmium-org/cadmium-cms
(Composer)
Dec 23, 2025
LibreNMS Alert Rule API Cross-Site Scripting Vulnerability
Moderate
CVE-2025-68614
was published
for
librenms/librenms
(Composer)
Dec 23, 2025
AWS SDK for PHP's S3 Encryption Client has a Key Commitment Issue
Moderate
CVE-2025-14761
was published
for
aws/aws-sdk-php
(Composer)
Dec 18, 2025
phpMyFAQ contains a CSV injection vulnerability
Moderate
CVE-2023-53929
was published
for
phpmyfaq/phpmyfaq
(Composer)
Dec 18, 2025
Auth0 WordPress has Improper Audience Validation via Auth0-PHP SDK Dependency
Moderate
GHSA-vvg7-8rmq-92g7
was published
for
auth0/wordpress
(Composer)
Dec 17, 2025
Auth0 Symfony SDK has Improper Audience Validation via Auth0-PHP SDK
Moderate
GHSA-f3r2-88mq-9v4g
was published
for
auth0/symfony
(Composer)
Dec 17, 2025
ProTip!
Advisories are also available from the
GraphQL API