GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,849
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
6,562 advisories
Filter by severity
league/commonmark: DisallowedRawHtml bypassed when a disallowed tag name ends the raw-HTML literal
Moderate
GHSA-97jj-33gv-5xf9
was published
for
league/commonmark
(Composer)
Sep 30, 2026
league/commonmark: Quadratic-time denial of service in the GitHub Flavored Markdown Table extension block-start scan
High
GHSA-3q6v-r5mr-hxv8
was published
for
league/commonmark
(Composer)
Sep 30, 2026
Laravel: XSS in Debug Page Information
Low
CVE-2026-102279
was published
for
laravel/framework
(Composer)
Sep 29, 2026
Flysystem: WhitespacePathNormalizer's control-character (CorruptedPathDetected) check is bypassed by malformed UTF-8 in the path, affecting every adapter
Low
CVE-2026-102601
was published
for
league/flysystem
(Composer)
Sep 29, 2026
PHPCSUtils: Remote code execution via eval() in AbstractArrayDeclarationSniff::getActualArrayKey()
High
CVE-2026-65954
was published
for
phpcsstandards/phpcsutils
(Composer)
Sep 29, 2026
FriendsOfFlarum OAuth: Unauthenticated account takeover via unverified email trust in Discord OAuth provider
Critical
CVE-2026-92161
was published
for
fof/oauth
(Composer)
Sep 25, 2026
Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled
High
CVE-2026-57440
was published
for
starcitizenwiki/embedvideo
(Composer)
Sep 25, 2026
code16 Sharp vulnerable to stored XSS via iframe srcdoc Attribute
High
CVE-2026-61823
was published
for
code16/sharp
(Composer)
Sep 25, 2026
code16/sharp has a stored XSS via data-html-content Sanitizer Bypass
High
CVE-2026-61825
was published
for
code16/sharp
(Composer)
Sep 25, 2026
Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module
Low
CVE-2026-57232
was published
for
contao/contao
(Composer)
Sep 24, 2026
zbateson/mail-mime-parser has CRLF header injection via attachment filename
High
CVE-2026-61815
was published
for
zbateson/mail-mime-parser
(Composer)
Sep 24, 2026
zbateson/mail-mime-parser has uncontrolled resource consumption (CPU/memory DoS) parsing untrusted MIME
High
CVE-2026-61816
was published
for
zbateson/mail-mime-parser
(Composer)
Sep 24, 2026
phpMyFAQ has SQL Injection in `StopWords::add()` — Unescaped Stop Word Insertion
High
CVE-2026-56738
was published
for
phpmyfaq/phpmyfaq
(Composer)
Sep 24, 2026
phpMyFAQ's two-factor authentication login bypasses the password factor
High
CVE-2026-56737
was published
for
phpmyfaq/phpmyfaq
(Composer)
Sep 24, 2026
phpMyFAQ has Stored XSS in Admin FAQ Editor via HTML Entity Bypass in Frontend FAQ Submission
High
CVE-2026-56736
was published
for
phpmyfaq/phpmyfaq
(Composer)
Sep 24, 2026
Snipe-IT: Stored XSS via Inline XML Rendering in the Uploaded Files API
High
CVE-2026-63498
was published
for
snipe/snipe-it
(Composer)
Sep 24, 2026
Snipe-IT: Stored XSS via Custom Field name in asset-list column headers
High
CVE-2026-62368
was published
for
snipe/snipe-it
(Composer)
Sep 24, 2026
Snipe-IT: 2FA bypass via the API token flow
High
CVE-2026-63493
was published
for
snipe/snipe-it
(Composer)
Sep 24, 2026
REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration
Moderate
CVE-2026-62998
was published
for
redaxo/source
(Composer)
Sep 24, 2026
Formie: Missing authorization on sent notification resend modal exposes submission PII
High
CVE-2026-76089
was published
for
verbb/formie
(Composer)
Sep 23, 2026
Formie: Unauthenticated users can overwrite incomplete submissions via submit action
High
CVE-2026-76087
was published
for
verbb/formie
(Composer)
Sep 23, 2026
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials
High
CVE-2026-76086
was published
for
verbb/formie
(Composer)
Sep 23, 2026
Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated)
Moderate
CVE-2026-92692
was published
for
sulu/sulu
(Composer)
Sep 23, 2026
Solspace Freeform: Limited Twig template injection via submitted field values
Moderate
CVE-2026-73858
was published
for
solspace/craft-freeform
(Composer)
Sep 23, 2026
WPGraphQL: Contributor can publish and modify posts without the required capabilities via updatePost
Moderate
CVE-2026-88974
was published
for
wp-graphql/wp-graphql
(Composer)
Sep 23, 2026
ProTip!
Advisories are also available from the
GraphQL API