GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,629
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,149
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
42 advisories
Filter by severity
silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template
High
CVE-2026-54718
was published
for
symbiote/silverstripe-advancedworkflow
(Composer)
Aug 27, 2026
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)
Critical
CVE-2026-59989
was published
for
phalcon/cphalcon
(Composer)
Aug 21, 2026
YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates
High
CVE-2026-52762
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
Formie Hidden field defaults vulnerable to Server-Side Template Injection
Critical
CVE-2026-52889
was published
for
verbb/formie
(Composer)
Jul 6, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
Critical
CVE-2026-9558
was published
for
mautic/core
(Composer)
Jul 2, 2026
Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
High
CVE-2026-11407
was published
for
pimcore/pimcore
(Composer)
Jun 17, 2026
Formie: Pre-authenticated server-side template injection in Hidden fields
Critical
CVE-2026-45697
was published
for
verbb/formie
(Composer)
May 18, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
CVE-2026-34587
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugin
High
CVE-2026-32261
was published
for
craftcms/webhooks
(Composer)
Mar 16, 2026
Craft CMS has potential authenticated Remote Code Execution via Twig SSTI
Moderate
CVE-2026-28784
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS has Twig Function Blocklist Bypass
Moderate
CVE-2026-28783
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS Vulnerable to Authenticated RCE via "craft.app.fs.write()" in Twig Templates
Critical
CVE-2026-28697
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS Vulnerable to Authenticated RCE via Twig SSTI - create() function + Symfony Process gadget
Moderate
CVE-2026-28695
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Kimai has an Authenticated Server-Side Template Injection (SSTI)
Moderate
CVE-2026-23626
was published
for
kimai/kimai
(Composer)
Jan 20, 2026
Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI
Moderate
CVE-2025-68454
was published
for
craftcms/cms
(Composer)
Jan 5, 2026
Bagisto is vulnerable to SSTI via name parameters provided by non-admin low-privilege users
High
CVE-2026-21449
was published
for
bagisto/bagisto
(Composer)
Jan 2, 2026
Bagisto has Normal & Blind SSTI from low-privilege user when ordering product
High
CVE-2026-21448
was published
for
bagisto/bagisto
(Composer)
Jan 2, 2026
Bagisto SSTI vulnerability in type parameter can lead to RCE
High
CVE-2026-21450
was published
for
bagisto/bagisto
(Composer)
Jan 2, 2026
FoF Pretty Mail has a server-side template injection vulnerability
High
CVE-2024-58303
was published
for
fof/pretty-mail
(Composer)
Dec 12, 2025
Grav is vulnerable to Server-Side Template Injection (SSTI) via Forms
High
CVE-2025-66298
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
High
CVE-2025-66294
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Privilege Escalation and Authenticated Remote Code Execution via Twig Injection
High
CVE-2025-66297
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is Vulnerable to Security Sandbox Bypass with SSTI (Server Side Template Injection)
High
CVE-2025-66299
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
bagisto has Server Side Template Injection (SSTI) in Product Description
Moderate
CVE-2025-62416
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
Craft CMS Potential Remote Code Execution via Twig SSTI
Moderate
CVE-2025-57811
was published
for
craftcms/cms
(Composer)
Aug 25, 2025
ProTip!
Advisories are also available from the
GraphQL API