GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
49 advisories
Filter by severity
Formie: Missing authorization on sent notification resend modal exposes submission PII
High
CVE-2026-76089
was published
for
verbb/formie
(Composer)
Sep 23, 2026
Formie: Unauthenticated users can overwrite incomplete submissions via submit action
High
CVE-2026-76087
was published
for
verbb/formie
(Composer)
Sep 23, 2026
Formie: Integration form-settings action allows SSRF and exfiltration of stored integration credentials
High
CVE-2026-76086
was published
for
verbb/formie
(Composer)
Sep 23, 2026
Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks
High
GHSA-jr78-w6w5-m8f8
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin
High
CVE-2026-75837
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
High
CVE-2026-56825
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
High
CVE-2026-56829
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: privilege escalation via improper Livewire admin component authorization
High
CVE-2026-56828
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
High
CVE-2026-56827
was published
for
shopper/framework
(Composer)
Sep 11, 2026
EasyAdmin custom-action dispatcher bypasses access_control on other routes
High
CVE-2026-81892
was published
for
easycorp/easyadmin-bundle
(Composer)
Sep 2, 2026
Kirby: File upload permissions are not checked during processing of chunk data
High
CVE-2026-71415
was published
for
getkirby/cms
(Composer)
Aug 31, 2026
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
High
GHSA-fm29-4mq3-phg6
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Poweradmin: API user-update endpoint leads to a non-admin reset any user's password and take over the superuser account
High
GHSA-h4hf-v6w5-897x
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
High
CVE-2026-50282
was published
for
craftcms/cms
(Composer)
Jul 2, 2026
Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets
High
CVE-2026-50284
was published
for
craftcms/cms
(Composer)
Jul 2, 2026
SolidInvoice: IDOR in LiveComponent allows same-company cross-user access to API tokens and notification transport settings
High
GHSA-7vfx-4246-jcfh
was published
for
solidinvoice/solidinvoice
(Composer)
Jun 26, 2026
Duplicate Advisory: AVideo: Unauthenticated Access to Payment Log DataTables Endpoints Exposes Transaction Data, PayPal Tokens, and User Financial Records
High
GHSA-rg7q-4223-phjw
was published
for
wwbn/avideo
(Composer)
Jun 20, 2026
•
withdrawn
Kirby: `pages.access` permission is not checked in the `site/find` REST API route
High
CVE-2026-54005
was published
for
getkirby/cms
(Composer)
Jun 18, 2026
TYPO3 CMS has Broken Access Control in its Form Framework
High
CVE-2026-11607
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS: Destructive Actions on File Mount Folders
High
CVE-2026-47343
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Privilege Escalation & SQL Injection in its Form Framework
High
CVE-2026-49741
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in its Form Framework
High
CVE-2026-47346
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling
High
CVE-2026-45260
was published
for
pimcore/pimcore
(Composer)
May 27, 2026
phpMyFAQ: IDOR Account Takeover
High
CVE-2026-35671
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 20, 2026
shopper/framework: Authorization bypass in multiple Livewire admin components
High
CVE-2026-47740
was published
for
shopper/framework
(Composer)
May 18, 2026
ProTip!
Advisories are also available from the
GraphQL API