GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,886 advisories
Filter by severity
LibreNMS Arbitrary File Read
Moderate
CVE-2017-16759
was published
for
librenms/librenms
(Composer)
May 13, 2022
LibreNMS is vulnerable to SQL Injection (Boolean-Based Blind) in hostname parameter in ajax_output.php endpoint
Moderate
CVE-2025-65093
was published
for
librenms/librenms
(Composer)
Nov 18, 2025
Snipe-IT is vulnerable to stored cross-site scripting
Moderate
CVE-2025-65621
was published
for
snipe/snipe-it
(Composer)
Dec 1, 2025
FeehiCMS Has a Remote Code Execution via Unrestricted File Upload in Ad Management
Moderate
CVE-2025-65657
was published
for
feehi/cms
(Composer)
Dec 2, 2025
Grav CMS is vulnerable to Cross Site Scripting (XSS) in the page editor
Moderate
CVE-2025-65186
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Snipe-IT allows stored XSS via the Locations "Country" field
Moderate
CVE-2025-65622
was published
for
snipe/snipe-it
(Composer)
Dec 2, 2025
FeehiCMS fails to enforce server-side immutability
Moderate
CVE-2025-63523
was published
for
feehi/feehicms
(Composer)
Dec 1, 2025
FeehiCMS is vulnerable to cross-site scripting via the id parameter of the User Update function
Moderate
CVE-2025-63520
was published
for
feehi/feehicms
(Composer)
Dec 1, 2025
FeehiCMS is vulnerable to reverse tabnabbing
Moderate
CVE-2025-63522
was published
for
feehi/feehicms
(Composer)
Dec 1, 2025
Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]` in Advanced Tab
Moderate
CVE-2025-66310
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is vulnerable to Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][content][items], located in the "Blog Config" tab
Moderate
CVE-2025-66309
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav Admin Plugin vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/config/site` parameter `data[taxonomies]`
Moderate
CVE-2025-66308
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Information Disclosure via IDOR in Grav Admin Panel
Moderate
CVE-2025-66306
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Path Traversal allowing server files backup
Moderate
CVE-2025-66302
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav Admin Plugin vulnerable to User Enumeration & Email Disclosure
Moderate
CVE-2025-66307
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav Admin Plugin is vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/accounts/groups/[group]` parameter `data[readableName]`
Moderate
CVE-2025-66312
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` in Multiples parameters
Moderate
CVE-2025-66311
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav Exposes Password Hashes Leading to privilege escalation
Moderate
CVE-2025-66304
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is vulnerable to a DOS on the admin panel
Moderate
CVE-2025-66303
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
REDAXO CMS is vulnerable to Reflected XSS in Mediapool Info Banner via args[types]
Moderate
CVE-2025-66026
was published
for
redaxo/source
(Composer)
Nov 25, 2025
Formwork CMS has Stored Cross-Site Scripting Vulnerebility in Blog Tags
Moderate
CVE-2025-65956
was published
for
getformwork/formwork
(Composer)
Nov 24, 2025
Contao is vulnerable to remote code execution in template closures
Moderate
CVE-2025-65960
was published
for
contao/core-bundle
(Composer)
Nov 25, 2025
Subrion CMS: Authenticated administrators are able to gain escalated access through Run SQL Query tool
Moderate
CVE-2025-56556
was published
for
intelliants/subrion
(Composer)
Sep 11, 2025
Craft CMS Potential Remote Code Execution via Twig SSTI
Moderate
CVE-2025-57811
was published
for
craftcms/cms
(Composer)
Aug 25, 2025
REDAXO CMS is vulnerable to XSS through its module management component
Moderate
CVE-2025-64049
was published
for
redaxo/source
(Composer)
Nov 25, 2025
ProTip!
Advisories are also available from the
GraphQL API