GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,895
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
134 advisories
Filter by severity
Formie: Missing authorization on sent notification resend modal exposes submission PII
High
CVE-2026-76089
was published
for
verbb/formie
(Composer)
Sep 23, 2026
Formie: Unauthenticated users can overwrite incomplete submissions via submit action
High
CVE-2026-76087
was published
for
verbb/formie
(Composer)
Sep 23, 2026
Sulu: Media move/update authorization bypass (IDOR)
Moderate
CVE-2026-82395
was published
for
sulu/sulu
(Composer)
Sep 2, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
High
CVE-2026-81892
was published
for
easycorp/easyadmin-bundle
(Composer)
Sep 2, 2026
Snipe-IT vulnerable to cross-company asset maintenance re-parenting via API update
High
CVE-2026-55516
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint
Moderate
CVE-2026-55515
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Snipe-IT has missing object-level authorization in Kits API
Moderate
CVE-2026-55478
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Winter: My Account preview exposes another backend user's profile by record ID
Moderate
GHSA-mpmw-f6h6-3g26
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata
Moderate
CVE-2026-54256
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)
High
CVE-2026-54180
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisk
High
CVE-2026-54178
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover
High
CVE-2026-55694
was published
for
snipe/snipe-it
(Composer)
Aug 19, 2026
Winter: Authenticated backend users can bypass Users controller permission checks
High
CVE-2026-35445
was published
for
winter/wn-backend-module
(Composer)
Aug 12, 2026
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
Moderate
CVE-2026-64662
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
Moderate
CVE-2026-68501
was published
for
sylius/mollie-plugin
(Composer)
Jul 31, 2026
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
High
CVE-2026-68500
was published
for
sylius/mollie-plugin
(Composer)
Jul 31, 2026
Easy!Appointments: Authorization bypass in Google OAuth provider binding lets any backend user rebind a peer provider's Google sync
Low
CVE-2026-52841
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments has unauthenticated customer PII disclosure on booking reschedule page
Moderate
CVE-2026-52837
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Easy!Appointments appointments/store and appointments/update allow cross-provider appointment injection — Authorization Bypass
Low
CVE-2026-52839
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
High
GHSA-rm67-g9ch-vxff
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters
Moderate
CVE-2026-52882
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator
Critical
CVE-2026-47156
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
Kimai: Improper Authorization in Project, Customer, and Activity Rate Edit Endpoints Allows Cross-Scope Rate Manipulation
Moderate
CVE-2026-52826
was published
for
kimai/kimai
(Composer)
Jul 14, 2026
Kimai: Improper Authorization Through Activity Creation with Preset Project Allows Creation Under Unauthorized Projects
Moderate
CVE-2026-52821
was published
for
kimai/kimai
(Composer)
Jul 14, 2026
Kimai: Timesheet PATCH/POST allows assigning to project outside user's team via query_builder OR-bypass
Moderate
CVE-2026-52820
was published
for
kimai/kimai
(Composer)
Jul 13, 2026
ProTip!
Advisories are also available from the
GraphQL API