GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,549
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,798
Pub
13
RubyGems
1,038
Rust
1,237
Swift
53
Unreviewed advisories
All unreviewed
5,000+
5,632 advisories
Filter by severity
YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave()
High
GHSA-f58v-p6j9-24c2
was published
for
yeswiki/yeswiki
(Composer)
Apr 18, 2026
PHPUnit has Argument injection via newline in PHP INI values that are forwarded to child processes
High
GHSA-qrr6-mg7r-m243
was published
for
phpunit/phpunit
(Composer)
Apr 18, 2026
elFinder: Command injection in resize background color parameter when using ImageMagick CLI
High
GHSA-8q4h-8crm-5cvc
was published
for
studio-42/elfinder
(Composer)
Apr 17, 2026
Kimai: Username enumeration via timing on X-AUTH-USER
Low
GHSA-jrc6-fmhw-fpq2
was published
for
kimai/kimai
(Composer)
Apr 17, 2026
Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration
Critical
CVE-2026-23500
was published
for
dolibarr/dolibarr
(Composer)
Apr 17, 2026
Craftql vulnerable to Server-Side Request Forgery
Moderate
CVE-2026-31317
was published
for
markhuot/craftql
(Composer)
Apr 17, 2026
Unauthenticated Information Disclosure (IDOR) via Multisite switch_to_blog in My Calendar
High
CVE-2026-40308
was published
for
joedolson/my-calendar
(Composer)
Apr 16, 2026
Statamic: Unsafe method invocation via query value resolution allows data destruction
High
GHSA-4jjr-vmv7-wh4w
was published
for
statamic/cms
(Composer)
Apr 16, 2026
WWBN AVideo: RCE cause by clonesite plugin
High
GHSA-xr6f-h4x7-r6qp
was published
for
wwbn/avideo
(Composer)
Apr 16, 2026
Silverstripe Assets Module has a DBFile::getURL() permission bypass
Moderate
CVE-2026-24749
was published
for
silverstripe/assets
(Composer)
Apr 16, 2026
Withdrawn Advisory: Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion
High
GHSA-qjfj-3mm5-vrjg
was published
for
google/protobuf
(Composer)
Apr 16, 2026
•
withdrawn
goodoneuz/pay-uz: the /payment/api/editable/update endpoint overwrites existing PHP payment hook files
Critical
CVE-2026-31843
was published
for
goodoneuz/pay-uz
(Composer)
Apr 16, 2026
Froxlor has Local File Inclusion via path traversal in API `def_language` parameter leads to Remote Code Execution
Critical
GHSA-w59f-67xm-rxx7
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
ProcessWire: server-side request forgery vulnerability in the admin panel's 'Add Module From URL' feature
Moderate
CVE-2026-40500
was published
for
processwire/processwire
(Composer)
Apr 16, 2026
Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)
Critical
GHSA-gc9w-cc93-rjv8
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()
High
GHSA-47hf-23pw-3m8c
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
Froxlor has Incomplete Symlink Validation in DataDump.add() Allows Arbitrary Directory Ownership Takeover via Cron
High
GHSA-75h4-c557-j89r
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index Allows Cross-Customer Email Spoofing
Moderate
GHSA-vmjj-qr7v-pxm6
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add()
Moderate
GHSA-jvx4-xv3m-hrj4
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
Kimai's User Preferences API allows standard users to modify restricted attributes: hourly_rate, internal_rate
Moderate
CVE-2026-40486
was published
for
kimai/kimai
(Composer)
Apr 15, 2026
Kimai has Stored XSS via Incomplete HTML Attribute Escaping in Team Member Widget
Moderate
CVE-2026-40479
was published
for
kimai/kimai
(Composer)
Apr 15, 2026
PocketMine-MP has LogDoS by many junk properties in client data JWT in LoginPacket
Moderate
GHSA-xp4f-g2cm-rhg7
was published
for
pocketmine/pocketmine-mp
(Composer)
Apr 15, 2026
Craft CMS has a host header injection leading to SSRF via resource-js endpoint
Moderate
GHSA-95wr-3f2v-v2wh
was published
for
craftcms/cms
(Composer)
Apr 14, 2026
Server-Side Request Forgery (SSRF) in Craft CMS with Asset Uploads Mutations
Moderate
GHSA-3m9m-24vh-39wx
was published
for
craftcms/cms
(Composer)
Apr 14, 2026
Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action
Moderate
GHSA-jq2f-59pj-p3m3
was published
for
craftcms/cms
(Composer)
Apr 14, 2026
ProTip!
Advisories are also available from the
GraphQL API