GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
41
Go
3,051
Maven
5,000+
npm
4,791
NuGet
825
pip
4,389
Pub
12
RubyGems
988
Rust
1,145
Swift
50
Unreviewed advisories
All unreviewed
5,000+
2,975 advisories
Filter by severity
Statamic's missing authorization allows access to email addresses
Moderate
CVE-2026-28424
was published
for
statamic/cms
(Composer)
Mar 1, 2026
Statamic Vulnerable to Server-Side Request Forgery via Glide
Moderate
CVE-2026-28423
was published
for
statamic/cms
(Composer)
Mar 1, 2026
TypiCMS Core has Stored Cross-Site Scripting (XSS) via SVG File Upload
Moderate
CVE-2026-27621
was published
for
typicms/core
(Composer)
Feb 25, 2026
Pimcore vulnerable to SQL injection via unsanitized filter value in Dependency Dao RLIKE clause
Moderate
CVE-2026-27461
was published
for
pimcore/pimcore
(Composer)
Feb 24, 2026
Craft CMS: Cloud Metadata SSRF Protection Bypass via IPv6 Resolution
Moderate
CVE-2026-27129
was published
for
craftcms/cms
(Composer)
Feb 24, 2026
Craft CMS Race condition in Token Service potentially allows for token usage greater than the token limit
Moderate
CVE-2026-27128
was published
for
craftcms/cms
(Composer)
Feb 23, 2026
Craft CMS has Stored XSS in Table Field via "HTML" Column Type
Moderate
CVE-2026-27126
was published
for
craftcms/cms
(Composer)
Feb 23, 2026
funadmin exposes sensitive information via getMember function
Moderate
CVE-2026-2894
was published
for
funadmin/funadmin
(Composer)
Feb 22, 2026
funadmin has Incorrect Privilege Assignment in its Configuration Handler
Moderate
CVE-2026-2896
was published
for
funadmin/funadmin
(Composer)
Feb 22, 2026
Moodle TeX formula editor is vulnerable to DoS through lack of execution time limits
Moderate
CVE-2026-26047
was published
for
moodle/moodle
(Composer)
Feb 21, 2026
AVideo has Stored Cross-Site Scripting via Markdown Comment Injection
Moderate
CVE-2026-27568
was published
for
wwbn/avideo
(Composer)
Feb 20, 2026
LibreNMS has a Stored XSS in Alert Rule
Moderate
CVE-2026-26989
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
LibreNMS has a Stored XSS in Custom OID - unit parameter missing strip_tags()
Moderate
CVE-2026-27016
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
LibreNMS /port-groups name Stored Cross-Site Scripting
Moderate
CVE-2026-26992
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
LibreNMS /device-groups name Stored Cross-Site Scripting
Moderate
CVE-2026-26991
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
LibreNMS affected by reflected xss via email field
Moderate
CVE-2026-26987
was published
for
librenms/librenms
(Composer)
Feb 18, 2026
ImapEngine affected by command injection via the ID command parameters
Moderate
CVE-2026-2469
was published
for
directorytree/imapengine
(Composer)
Feb 14, 2026
Statamic CMS's missing authorization allows access to assets
Moderate
CVE-2026-25633
was published
for
statamic/cms
(Composer)
Feb 11, 2026
Kimai 2 vulnerable to persistent cross-site scripting in the timesheet descriptions
Moderate
CVE-2019-25317
was published
for
kimai/kimai
(Composer)
Feb 11, 2026
Phraseanet vulnerable to stored cross-site scripting through crafted file names
Moderate
CVE-2018-25157
was published
for
phraseanet/phraseanet
(Composer)
Feb 11, 2026
amphp/http-server affected by HTTP/2 DDoS vulnerability
Moderate
GHSA-8grv-jq2g-cfhw
was published
for
amphp/http-server
(Composer)
Feb 10, 2026
FroshAdminer Adminer UI is accessible without admin session
Moderate
CVE-2026-25878
was published
for
frosh/adminer-platform
(Composer)
Feb 10, 2026
Craft CMS Vulnerable to Stored XSS in Number Prefix & Suffix Fields
Moderate
CVE-2026-25496
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via Alternative IP Notation
Moderate
CVE-2026-25494
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via HTTP Redirect
Moderate
CVE-2026-25493
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
ProTip!
Advisories are also available from the
GraphQL API