GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,300
NuGet
760
pip
4,078
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,868 advisories
Filter by severity
Contao does not properly manage privileges for page and article fields
Moderate
CVE-2025-57759
was published
for
contao/contao
(Composer)
Aug 28, 2025
Contao can disclose sensitive information in the news module
Moderate
CVE-2025-57757
was published
for
contao/contao
(Composer)
Aug 28, 2025
Contao discloses sensitive information in the front end search index
Moderate
CVE-2025-57756
was published
for
contao/contao
(Composer)
Aug 28, 2025
Contao applies improper access control in the back end voters
Moderate
CVE-2025-57758
was published
for
contao/contao
(Composer)
Aug 28, 2025
Easy!Appointments SQL injection vulnerability
Moderate
CVE-2025-50383
was published
for
alextselegidis/easyappointments
(Composer)
Aug 26, 2025
Craft CMS Potential Remote Code Execution via Twig SSTI
Moderate
CVE-2025-57811
was published
for
craftcms/cms
(Composer)
Aug 25, 2025
UnoPim vulnerable to CSRF on Product edit feature and creation of other types
Moderate
CVE-2025-55744
was published
for
unopim/unopim
(Composer)
Aug 21, 2025
UnoPim has Stored Cross-site Scripting vulnerability in user creation functionality
Moderate
CVE-2025-55742
was published
for
unopim/unopim
(Composer)
Aug 21, 2025
WP Crontrol Authenticated (Administrator+) plugin vulnerable to Blind Server-Side Request Forgery
Moderate
CVE-2025-8678
was published
for
johnbillion/wp-crontrol
(Composer)
Aug 19, 2025
MoonShine SQL Injection Vulnerability
Moderate
CVE-2025-51510
was published
for
moonshine/moonshine
(Composer)
Aug 19, 2025
moonshine Stored Cross-Site Scripting Vulnerability in Create Admin
Moderate
CVE-2025-51488
was published
for
moonshine/moonshine
(Composer)
Aug 19, 2025
moonshine Stored Cross-Site Scripting Vulnerability in Create Article
Moderate
CVE-2025-51487
was published
for
moonshine/moonshine
(Composer)
Aug 19, 2025
MoonShine Arbitrary File Upload Vulnerability
Moderate
CVE-2025-51489
was published
for
moonshine/moonshine
(Composer)
Aug 19, 2025
LibreNMS allows stored XSS in Alert Template name field
Moderate
CVE-2025-55296
was published
for
librenms/librenms
(Composer)
Aug 18, 2025
svg-sanitizer Bypasses Attribute Sanitization
Moderate
CVE-2025-55166
was published
for
enshrined/svg-sanitize
(Composer)
Aug 12, 2025
Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
Moderate
CVE-2025-49558
was published
for
magento/community-edition
(Composer)
Aug 12, 2025
Magento vulnerable to path traversal
Moderate
CVE-2025-49559
was published
for
magento/community-edition
(Composer)
Aug 12, 2025
Craft CMS has a theoretical bypass for CVE-2025-23209
Moderate
CVE-2025-54417
was published
for
craftcms/cms
(Composer)
Aug 8, 2025
Shopware race condition bypasses voucher restrictions
Moderate
CVE-2025-7954
was published
for
shopware/platform
(Composer)
Aug 6, 2025
Concrete CMS vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard Page
Moderate
CVE-2025-8571
was published
for
concrete5/concrete5
(Composer)
Aug 6, 2025
FPDI allows Memory Exhaustion (OOM) in PDF Parser which leads to Denial of Service
Moderate
CVE-2025-54869
was published
for
setasign/fpdi
(Composer)
Aug 5, 2025
Microweber XSS Vulnerability in the homepage Endpoint
Moderate
CVE-2025-51504
was published
for
microweber/microweber
(Composer)
Aug 1, 2025
Microweber has Reflected XSS Vulnerability in the id Parameter
Moderate
CVE-2025-51501
was published
for
microweber/microweber
(Composer)
Aug 1, 2025
Microweber has Reflected XSS Vulnerability in the layout Parameter
Moderate
CVE-2025-51502
was published
for
microweber/microweber
(Composer)
Aug 1, 2025
Withdrawn Advisory: CodeIgniter4 Cross-Site Scripting Vulnerability in debugbar_time Parameter
Moderate
CVE-2025-45406
was published
for
codeigniter4/framework
(Composer)
Jul 25, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API