GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
3,464 advisories
Filter by severity
CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()
Moderate
CVE-2026-63220
was published
for
codeigniter4/framework
(Composer)
Aug 7, 2026
API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)
Moderate
CVE-2026-54164
was published
for
api-platform/core
(Composer)
Aug 7, 2026
Smarty Security stream restriction bypass through stream: resource
Moderate
CVE-2026-62996
was published
for
smarty/smarty
(Composer)
Aug 7, 2026
Smarty: Symlink path traversal out of trusted directories
Moderate
CVE-2026-62992
was published
for
smarty/smarty
(Composer)
Aug 7, 2026
Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
Moderate
GHSA-957r-qf9p-67xw
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS: Authenticated leak of secret environment variables
Moderate
GHSA-596p-6jv8-775v
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element
Moderate
GHSA-xxpx-f366-4xpq
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
Moderate
GHSA-rvmm-v933-jgxq
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS: Stored XSS in the control panel via unescaped draft name
Moderate
GHSA-2rp4-x2j7-qmcc
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
Moderate
CVE-2026-14793
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
league/commonmark: Denial of service via deeply nested XML output
Moderate
GHSA-mj63-m3rc-8ppr
was published
for
league/commonmark
(Composer)
Aug 6, 2026
league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes
Moderate
CVE-2026-71478
was published
for
league/commonmark
(Composer)
Aug 6, 2026
Silverstripe: XSS in breadcrumbs in page list view
Moderate
CVE-2026-54717
was published
for
silverstripe/cms
(Composer)
Aug 6, 2026
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template
Moderate
CVE-2026-71435
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types
Moderate
CVE-2026-71434
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
Moderate
CVE-2026-64662
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Statamic: Unsafe method invocation via Antlers template resolution allows data destruction
Moderate
CVE-2026-64663
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
Moderate
CVE-2026-64664
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Guzzle: Noncanonical cookie domain keeps subdomain scope
Moderate
CVE-2026-69245
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
Moderate
GHSA-3fvr-2jw6-crq4
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers
Moderate
GHSA-32rq-jhr7-m3hh
was published
for
guzzlehttp/guzzle
(Composer)
Aug 1, 2026
•
withdrawn
WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)
Moderate
CVE-2026-54768
was published
for
wp-graphql/wp-graphql
(Composer)
Jul 31, 2026
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
Moderate
CVE-2026-68501
was published
for
sylius/mollie-plugin
(Composer)
Jul 31, 2026
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
Moderate
CVE-2026-52837
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem
Moderate
CVE-2026-59943
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
ProTip!
Advisories are also available from the
GraphQL API