GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
83 advisories
Filter by severity
dingfanzu CMS V1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the...
Low
Unreviewed
CVE-2024-48341
was published
Sep 8, 2025
In JetBrains TeamCity before 2025.07 a CSRF was possible in external OAuth login integration
Low
Unreviewed
CVE-2025-54529
was published
Jul 28, 2025
Cross-site scripting in certain Zoom Clients before version 6.4.5 may allow an authenticated...
Low
Unreviewed
CVE-2025-49462
was published
Jul 10, 2025
Cross-site request forgery vulnerability exists in Active! mail 6 BuildInfo: 6.60.06008562 and...
Low
Unreviewed
CVE-2025-52463
was published
Jul 2, 2025
Dell Wyse Management Suite, versions prior to WMS 5.2, contain a Cross-Site Request Forgery (CSRF...
Low
Unreviewed
CVE-2025-36576
was published
Jun 10, 2025
Moodle has a CSRF risk in user tours manager that allows tour duplication
Low
CVE-2025-3635
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has a CSRF risk in Brickfield tool's analysis request action
Low
CVE-2025-3638
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Drupal Configuration Split Cross-Site Request Forgery (CSRF) vulnerability
Low
CVE-2025-31688
was published
for
drupal/config_split
(Composer)
Apr 1, 2025
Drupal OAuth2 Client Cross-Site Request Forgery (CSRF)
Low
CVE-2025-31684
was published
for
drupal/oauth2_client
(Composer)
Apr 1, 2025
Drupal Matomo Analytics Cross-Site Request Forgery (CSRF) vulnerability
Low
CVE-2025-31680
was published
for
drupal/matomo
(Composer)
Apr 1, 2025
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net...
Low
Unreviewed
CVE-2024-57159
was published
Jan 16, 2025
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin...
Low
Unreviewed
CVE-2024-57611
was published
Jan 16, 2025
An issue was discovered in REDCap 14.9.6. It has an action=myprojects&logout=1 CSRF issue in the...
Low
Unreviewed
CVE-2025-23113
was published
Jan 11, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Acquia DAM allows Cross Site Request...
Low
Unreviewed
CVE-2024-13261
was published
Jan 9, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Drupal POST File allows Cross Site Request...
Low
Unreviewed
CVE-2024-13293
was published
Jan 9, 2025
The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when...
Low
Unreviewed
CVE-2024-5030
was published
Nov 18, 2024
LocalAI Cross-site Scripting vulnerability
Low
CVE-2024-48057
was published
for
github.com/mudler/LocalAI
(Go)
Nov 5, 2024
A Cross-Site Request Forgery (CSRF) vulnerability was found in Kashipara Music Management System...
Low
Unreviewed
CVE-2024-42792
was published
Aug 26, 2024
Hono CSRF middleware can be bypassed using crafted Content-Type header
Low
CVE-2024-43787
was published
for
hono
(npm)
Aug 22, 2024
ipl/web's `ipl\Web\Common\CsrfCounterMeasure` is susceptible to CSRF
Low
CVE-2024-41811
was published
for
ipl/web
(Composer)
Aug 5, 2024
ProcessWire Cross Site Request Forgery vulnerability
Low
CVE-2024-41597
was published
for
processwire/processwire
(Composer)
Jul 19, 2024
An arbitrary file deletion vulnerability in ThinkSAAS v3.7 allows attackers to delete arbitrary...
Low
Unreviewed
CVE-2024-40455
was published
Jul 16, 2024
Cross-site request forgery vulnerability exists in ajaxterm module of Webmin versions prior to 2...
Low
Unreviewed
CVE-2024-36452
was published
Jul 10, 2024
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component ...
Low
Unreviewed
CVE-2024-39157
was published
Jun 27, 2024
ProTip!
Advisories are also available from the
GraphQL API