GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,790
Erlang
36
GitHub Actions
29
Go
2,370
Maven
5,000+
npm
3,994
NuGet
720
pip
3,783
Pub
12
RubyGems
927
Rust
982
Swift
38
Unreviewed advisories
All unreviewed
5,000+
379 advisories
Filter by severity
Withdrawn Advisory: Lunary Cross-Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2024-6862
was published
for
@lunary/backend
(npm)
Sep 13, 2024
•
withdrawn
TYPO3 Cross-Site Request Forgery in Log Module
Moderate
CVE-2024-55893
was published
for
typo3/cms-belog
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Backend User Module
Moderate
CVE-2024-55894
was published
for
typo3/cms-beuser
(Composer)
Jan 14, 2025
TYPO3 DB Check Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55945
was published
for
typo3/cms-lowlevel
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Dashboard Module
Moderate
CVE-2024-55920
was published
for
typo3/cms-dashboard
(Composer)
Jan 14, 2025
TYPO3 Form Framework Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55922
was published
for
typo3/cms-form
(Composer)
Jan 14, 2025
TYPO3 Indexed Search Module vulnerable to Cross-Site Request Forgery
Moderate
CVE-2024-55923
was published
for
typo3/cms-indexed-search
(Composer)
Jan 14, 2025
Jenkins Cadence vManager Plugin Vulnerable to Cross-Site Request Forgery
Moderate
CVE-2025-47886
was published
for
org.jenkins-ci.plugins:vmanager-plugin
(Maven)
May 14, 2025
Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data
Moderate
CVE-2025-47204
was published
for
bootstrap-multiselect
(npm)
May 13, 2025
nosurf vulnerable to CSRF due to non-functional same-origin request checks
Moderate
CVE-2025-46721
was published
for
github.com/justinas/nosurf
(Go)
May 14, 2025
gorilla/csrf CSRF vulnerability due to broken Referer validation
Moderate
CVE-2025-24358
was published
for
github.com/gorilla/csrf
(Go)
Apr 14, 2025
Cross-Site Request Forgery in OpenNMS Horizon
Moderate
CVE-2021-25930
was published
for
org.opennms:opennms
(Maven)
May 25, 2021
Cross-Site Request Forgery in Jenkins Cluster Statistics Plugin
Moderate
CVE-2022-45398
was published
for
org.zeroturnaround:cluster-stats
(Maven)
Nov 16, 2022
Drupal Cache Utility Cross-Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2025-31690
was published
for
drupal/cache_utility
(Composer)
Apr 1, 2025
Drupal General Data Protection Regulation Cross-Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2025-31689
was published
for
drupal/gdpr
(Composer)
Apr 1, 2025
Drupal Google Tag Cross-Site Request Forgery (CSRF)
Moderate
CVE-2025-31683
was published
for
drupal/google_tag
(Composer)
Apr 1, 2025
Drupal AI Cross-Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2025-31677
was published
for
drupal/ai
(Composer)
Apr 1, 2025
MantisBT vulnerable to CSRF and Open Redirect attacks
Moderate
CVE-2017-7620
was published
for
mantisbt/mantisbt
(Composer)
May 17, 2022
Doorkeeper vulnerable to Cross-site Request Forgery
Moderate
CVE-2014-8144
was published
for
doorkeeper
(RubyGems)
Sep 17, 2018
Moodle vulnerable to Cross-Site Request Forgery
Moderate
CVE-2011-4281
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle vulnerable to Cross-Site Request Forgery
Moderate
CVE-2011-4133
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle vulnerable to Cross-Site Request Forgery
Moderate
CVE-2011-4298
was published
for
moodle/moodle
(Composer)
May 13, 2022
rails is vulnerable to CRLF injection
Moderate
CVE-2008-5189
was published
for
rails
(RubyGems)
Oct 24, 2017
wallabag/wallabag Has Multiple Cross-Site Request Forgery (CSRF) Vulnerabilities
Moderate
GHSA-5pm7-cp8f-p2c2
was published
for
wallabag/wallabag
(Composer)
Apr 9, 2025
Jenkins Simple Queue Plugin Cross-Site Request Forgery (CSRF)
Moderate
CVE-2025-31723
was published
for
io.jenkins.plugins:simple-queue
(Maven)
Apr 2, 2025
ProTip!
Advisories are also available from the
GraphQL API