GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
299 advisories
Filter by severity
Symfony vulnerable to open redirect via browser-sanitized URLs
Low
CVE-2024-50345
was published
for
symfony/http-foundation
(Composer)
Nov 6, 2024
Symfony has an incorrect response from Validator when input ends with `\n`
Low
CVE-2024-50343
was published
for
symfony/symfony
(Composer)
Nov 6, 2024
Drupal Umami Analytics allows Cross-Site Scripting (XSS)
Low
CVE-2025-10931
was published
for
drupal/umami_analytics
(Composer)
Oct 30, 2025
Magento does not properly protect credentials
Low
CVE-2025-27192
was published
for
magento/community-edition
(Composer)
Apr 8, 2025
Magento Authenticated Security feature bypass
Low
CVE-2025-49549
was published
for
magento/community-edition
(Composer)
Jun 26, 2025
Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoice
Low
GHSA-3cpp-fv95-mpr5
was published
for
shopware/core
(Composer)
Oct 21, 2025
Shopware vulnerable to path traversal via Plugin upload
Low
GHSA-6wh5-mw9h-5c3w
was published
for
shopware/core
(Composer)
Oct 21, 2025
TastyIgniter vulnerable to Cross-Site Scripting
Low
CVE-2025-61417
was published
for
tastyigniter/tastyigniter
(Composer)
Oct 20, 2025
LibreNMS alert-rules has a Cross-Site Scripting Vulnerability
Low
CVE-2025-62412
was published
for
librenms/librenms
(Composer)
Oct 16, 2025
PrestaShop Checkout Target PayPal merchant account hijacking from backoffice
Low
CVE-2025-61924
was published
for
prestashop/ps_checkout
(Composer)
Oct 16, 2025
drupal-pattern-lab/unified-twig-extensions is vulnerable to XXS
Low
CVE-2025-11570
was published
for
drupal-pattern-lab/unified-twig-extensions
(Composer)
Oct 10, 2025
NovoSGA: Manipulation of User Creation Page can lead to weak password requirements
Low
CVE-2025-11322
was published
for
novosga/novosga
(Composer)
Oct 6, 2025
auth0-PHP SDK Does Not Properly Handle File Types in Bulk User Import
Low
CVE-2025-58769
was published
for
auth0/auth0-php
(Composer)
Oct 1, 2025
Auth0 Symfony SDK Does Not Properly Handle File Types in Bulk User Import
Low
GHSA-7jp2-5h22-m432
was published
for
auth0/symfony
(Composer)
Oct 1, 2025
Auth0 Wordpress plugin Does Not Properly Handle File Types in Bulk User Import
Low
GHSA-w22c-pw5m-482x
was published
for
auth0/wordpress
(Composer)
Oct 1, 2025
laravel-auth0 SDK Does Not Properly Handle File Types in Bulk User Import
Low
GHSA-hjfh-5jmm-xr24
was published
for
auth0/login
(Composer)
Oct 1, 2025
Mangati NovoSGA XSS vulnerability in /admin
Low
CVE-2025-10909
was published
for
novosga/novosga
(Composer)
Sep 24, 2025
GP247 and S-Cart have a stored cross-site scripting (XSS) vulnerability
Low
CVE-2025-57407
was published
for
gp247/core
(Composer)
Sep 23, 2025
TYPO3 "Form to Database" extension susceptible to Cross-site Scripting
Low
CVE-2025-10316
was published
for
lavitto/typo3-form-to-database
(Composer)
Sep 16, 2025
Shopware default newsletter opt-in settings allow for mass sign-up abuse
Low
CVE-2025-32378
was published
for
shopware/core
(Composer)
Apr 9, 2025
Mautic vulnerable to SSRF via webhook function
Low
CVE-2025-9821
was published
for
mautic/core
(Composer)
Sep 3, 2025
UnoPim has CSV Injection on Quick Export feature
Low
CVE-2025-55745
was published
for
unopim/unopim
(Composer)
Aug 22, 2025
Concrete CMS is vulnerable to Stored XSS from Home Folder on Members Dashboard page
Low
CVE-2025-8573
was published
for
concrete5/concrete5
(Composer)
Aug 6, 2025
Microweber Has Stored XSS Vulnerability in User Profile Fields
Low
CVE-2025-51503
was published
for
microweber/microweber
(Composer)
Jul 31, 2025
JuzaWeb CMS is vulnerable to Incorrect Privilege Assignment when installing Import Page component
Low
CVE-2025-6735
was published
for
juzaweb/cms
(Composer)
Jun 27, 2025
ProTip!
Advisories are also available from the
GraphQL API