GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,785
Erlang
36
GitHub Actions
29
Go
2,368
Maven
5,000+
npm
3,989
NuGet
720
pip
3,781
Pub
12
RubyGems
926
Rust
982
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,786 advisories
Filter by severity
TYPO3 DB Check Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55945
was published
for
typo3/cms-lowlevel
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Backend User Module
Moderate
CVE-2024-55894
was published
for
typo3/cms-beuser
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Log Module
Moderate
CVE-2024-55893
was published
for
typo3/cms-belog
(Composer)
Jan 14, 2025
CodeIgniter arbitrary code execution
Critical
CVE-2016-10131
was published
for
bcit-ci/codeigniter
(Composer)
May 17, 2022
Froxlor has an HTML Injection Vulnerability
Moderate
CVE-2025-48958
was published
for
froxlor/froxlor
(Composer)
Mar 11, 2025
Moodle allows users to retrieve information they did not have permission to access
Moderate
CVE-2024-45689
was published
for
moodle/moodle
(Composer)
Nov 20, 2024
Drupal Core Cross-Site Scripting (XSS)
Moderate
CVE-2024-12393
was published
for
drupal/core
(Composer)
Dec 10, 2024
Drupal core contains a potential PHP Object Injection vulnerability
High
CVE-2024-55637
was published
for
drupal/core
(Composer)
Dec 10, 2024
Drupal core contains a potential PHP Object Injection vulnerability
Low
CVE-2024-55636
was published
for
drupal/core
(Composer)
Dec 10, 2024
Drupal core contains a potential PHP Object Injection vulnerability
High
CVE-2024-55638
was published
for
drupal/core
(Composer)
Dec 10, 2024
Laravel Rest Api has a Search Validation Bypass
Moderate
CVE-2025-48490
was published
for
lomkit/laravel-rest-api
(Composer)
May 27, 2025
Grokability Snipe-IT has incorrect authorization for accessing asset information
Moderate
CVE-2025-47226
was published
for
snipe/snipe-it
(Composer)
May 2, 2025
Auth0-PHP SDK Deserialization of Untrusted Data vulnerability
Critical
CVE-2025-48951
was published
for
auth0/auth0-php
(Composer)
Jun 4, 2025
MantisBT XSS via my_view_page.php and view_user_page.php
Moderate
CVE-2017-7897
was published
for
mantisbt/mantisbt
(Composer)
May 17, 2022
Auth0 Wordpress Plugin vulnerable to Deserialization of Untrusted Data
Critical
GHSA-862m-5253-832r
was published
for
auth0/wordpress
(Composer)
Jun 5, 2025
Auth0 Symfony SDK Deserialization of Untrusted Data vulnerability
Critical
GHSA-98j6-67v3-mw34
was published
for
auth0/symfony
(Composer)
Jun 6, 2025
laravel-auth0 SDK Deserialization of Untrusted Data vulnerability
Critical
GHSA-c42h-56wx-h85q
was published
for
auth0/login
(Composer)
Jun 6, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Moderate
CVE-2025-48493
was published
for
yiisoft/yii2-redis
(Composer)
Jun 5, 2025
Laravel Translation Manager Vulnerable to Stored Cross-site Scripting
Moderate
CVE-2025-49130
was published
for
barryvdh/laravel-translation-manager
(Composer)
Jun 9, 2025
MantisBT Insufficient Session Expiration cookie string not reset after logout
High
CVE-2009-20001
was published
for
mantisbt/mantisbt
(Composer)
Apr 21, 2022
Hax CMS Stored Cross-Site Scripting vulnerability
High
CVE-2025-49137
was published
for
elmsln/haxcms
(Composer)
Jun 9, 2025
MantisBT vulnerable to XSS due to improper escape in manage_plugin_page.php and manage_plugin_uninstall.php
Moderate
CVE-2022-26144
was published
for
mantisbt/mantisbt
(Composer)
Apr 14, 2022
MantisBT vulnerable to XSS via unescaped output in browser_search_plugin.php
Moderate
CVE-2022-28508
was published
for
mantisbt/mantisbt
(Composer)
May 5, 2022
MantisBT vulnerable to XSS via unsanitized filter field in manage_user_page.php
Moderate
CVE-2017-12062
was published
for
mantisbt/mantisbt
(Composer)
May 17, 2022
MantisBT vulnerable to XSS through config_option parameter in adm_config_report.php
Moderate
CVE-2017-7309
was published
for
mantisbt/mantisbt
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API