GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,646
Maven
5,000+
npm
4,273
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,852 advisories
Filter by severity
Magento Improper Access Control leads to Security feature bypass
Moderate
CVE-2025-27191
was published
for
magento/community-edition
(Composer)
Apr 8, 2025
Magento Improper Access Control leads to Security feature bypass
Moderate
CVE-2025-27190
was published
for
magento/community-edition
(Composer)
Apr 8, 2025
Magento Improper Access Control leads to security feature bypass
Moderate
CVE-2025-27206
was published
for
magento/community-edition
(Composer)
Jun 10, 2025
Magento Security feature bypass
Moderate
CVE-2025-49550
was published
for
magento/community-edition
(Composer)
Jun 26, 2025
Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
Moderate
CVE-2025-49558
was published
for
magento/community-edition
(Composer)
Aug 12, 2025
Craft CMS stores arbitrary content provided by unauthenticated users in session files
Moderate
CVE-2025-35939
was published
for
craftcms/cms
(Composer)
May 8, 2025
Potential XSS vulnerability in jQuery
Moderate
CVE-2020-11023
was published
for
components/jquery
(RubyGems)
Apr 29, 2020
code16 Sharp vulnerable to Cross Site Scripting (XSS)
Moderate
CVE-2025-61457
was published
for
code16/sharp
(Composer)
Oct 21, 2025
Magento vulnerable to path traversal
Moderate
CVE-2025-49559
was published
for
magento/community-edition
(Composer)
Aug 12, 2025
Magento vulnerable to stored Cross-Site Scripting (XSS)
Moderate
CVE-2025-54266
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
Magento vulnerable to privilege escalation due to incorrect authorization
Moderate
CVE-2025-54267
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
Shopware Customer Orders can be canceled, even if refunds are disabled
Moderate
GHSA-r2vg-hvjm-fg38
was published
for
shopware/core
(Composer)
Oct 21, 2025
Shopware exposes sensitive user information via CSV export mapping
Moderate
GHSA-27c9-vp3w-6ww8
was published
for
shopware/core
(Composer)
Oct 21, 2025
Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individually
Moderate
GHSA-m895-2hj3-8cg9
was published
for
shopware/core
(Composer)
Oct 21, 2025
Magento allows incorrect authorization
Moderate
CVE-2025-54265
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
Cargo Mediawiki Extension vulnerable to Cross-site Scripting
Moderate
CVE-2025-62671
was published
for
mediawiki/cargo
(Composer)
Oct 18, 2025
Citizen vulnerable to stored XSS in sticky header button messages
Moderate
CVE-2025-62508
was published
for
starcitizentools/citizen-skin
(Composer)
Oct 20, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Moderate
GHSA-8c2g-f8jm-5cr7
was published
for
ibexa/fieldtype-richtext
(Composer)
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Moderate
GHSA-2mx6-fq24-g2mh
was published
for
ibexa/admin-ui
(Composer)
Oct 17, 2025
ezsystems/ezplatform-admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Moderate
GHSA-99c7-c3mw-mxhv
was published
for
ezsystems/ezplatform-admin-ui
(Composer)
Oct 17, 2025
ibexa/user login enumerates user accounts
Moderate
GHSA-q3x8-6898-23g3
was published
for
ibexa/user
(Composer)
Oct 17, 2025
bagisto has Cross Site Scripting (XSS) in Create New Customer
Moderate
CVE-2025-62414
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has a Cross Site Scripting (XSS) vulnerability in TinyMCE Image Upload (SVG)
Moderate
CVE-2025-62418
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has Server Side Template Injection (SSTI) in Product Description
Moderate
CVE-2025-62416
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has Cross Site Scripting (XSS) issue in TinyMCE Image Upload (HTML)
Moderate
CVE-2025-62415
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
ProTip!
Advisories are also available from the
GraphQL API