GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,819 advisories
Filter by severity
Microweber XSS Vulnerability in the homepage Endpoint
Moderate
CVE-2025-51504
was published
for
microweber/microweber
(Composer)
Aug 1, 2025
Microweber has Reflected XSS Vulnerability in the layout Parameter
Moderate
CVE-2025-51502
was published
for
microweber/microweber
(Composer)
Aug 1, 2025
Microweber has Reflected XSS Vulnerability in the id Parameter
Moderate
CVE-2025-51501
was published
for
microweber/microweber
(Composer)
Aug 1, 2025
Microweber Has Stored XSS Vulnerability in User Profile Fields
Low
CVE-2025-51503
was published
for
microweber/microweber
(Composer)
Jul 31, 2025
Bacula-web SQL Injection Vulnerability
High
CVE-2025-45346
was published
for
bacula-web/bacula-web
(Composer)
Jul 29, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
Critical
CVE-2024-58136
was published
for
yiisoft/yii2
(Composer)
Apr 10, 2025
z-push/z-push-dev SQL Injection Vulnerability
High
CVE-2025-8264
was published
for
z-push/z-push-dev
(Composer)
Jul 29, 2025
Withdrawn Advisory: CodeIgniter4 Cross-Site Scripting Vulnerability in debugbar_time Parameter
Moderate
CVE-2025-45406
was published
for
codeigniter4/framework
(Composer)
Jul 25, 2025
•
withdrawn
LaRecipe is vulnerable to Server-Side Template Injection attacks
Critical
CVE-2025-53833
was published
for
binarytorch/larecipe
(Composer)
Jul 14, 2025
CodeIgniter4's ImageMagick Handler has Command Injection Vulnerability
Critical
CVE-2025-54418
was published
for
codeigniter4/framework
(Composer)
Jul 28, 2025
HAX CMS API Lacks Authorization Checks
High
CVE-2025-54378
was published
for
@haxtheweb/haxcms-nodejs
(Composer)
Jul 25, 2025
simogeo/filemanager arbitrary file upload vulnerability
Critical
CVE-2025-46001
was published
for
simogeo/filemanager
(Composer)
Jul 18, 2025
HAX CMS application pages vulnerable to clickjacking
Moderate
CVE-2025-54139
was published
for
@haxtheweb/haxcms-nodejs
(Composer)
Jul 21, 2025
LibreNMS has Authenticated Remote File Inclusion in ajax_form.php that Allows RCE
High
CVE-2025-54138
was published
for
librenms/librenms
(Composer)
Jul 21, 2025
nova-tiptap has Unauthenticated Arbitrary File Upload Vulnerability
Critical
CVE-2025-54082
was published
for
manogi/nova-tiptap
(Composer)
Jul 21, 2025
pubnub Insufficient Entropy vulnerability
Moderate
CVE-2023-26154
was published
for
Pubnub
(RubyGems)
Dec 6, 2023
Femanager extension for TYPO3 allows Insecure Direct Object Reference
Moderate
CVE-2025-7900
was published
for
in2code/femanager
(Composer)
Jul 22, 2025
Powermail extension for TYPO3 allows Insecure Direct Object Reference
Moderate
CVE-2025-7899
was published
for
in2code/powermail
(Composer)
Jul 22, 2025
Dolibarr has Remote Code Execution Vulnerability (Bypass)
High
GHSA-49xw-hw94-fmv2
was published
for
dolibarr/dolibarr
(Composer)
Jul 21, 2025
Filemanager is vulnerable to Relative Path Traversal through filemanager.php
Moderate
CVE-2025-46002
was published
for
simogeo/filemanager
(Composer)
Jul 18, 2025
Livewire is vulnerable to remote command execution during component property update hydration
Critical
CVE-2025-54068
was published
for
livewire/livewire
(Composer)
Jul 17, 2025
Craft CMS vulnerable to Potential Remote Code Execution via missing path normalization & Twig SSTI
High
CVE-2024-52293
was published
for
craftcms/cms
(Composer)
Nov 13, 2024
Craft CMS vulnerable to Remote Code Execution via validatePath bypass
High
CVE-2023-40035
was published
for
craftcms/cms
(Composer)
Aug 21, 2023
MODX Revolution vulnerable to XSS attack through its User Photo field
Moderate
CVE-2018-20755
was published
for
modx/revolution
(Composer)
May 14, 2022
MODX Revolution allows XSS via document resources
Moderate
CVE-2018-20756
was published
for
modx/revolution
(Composer)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API