GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
33
GitHub Actions
22
Go
2,121
Maven
5,000+
npm
3,783
NuGet
683
pip
3,465
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,357 advisories
Filter by severity
Arbitrary shell execution
High
GHSA-mhfv-8rc9-w38c
was published
for
squizlabs/php_codesniffer
(Composer)
Mar 26, 2022
XSS Injection Vulnerability
Low
GHSA-wf98-vxv9-jqfv
was published
for
craftcms/cms
(Composer)
Apr 5, 2022
Improper Certificate Validation in node-sass affects eZ Platform
Moderate
GHSA-6v6p-g8cg-2hgg
was published
for
ezsystems/ezplatform-admin-ui
(Composer)
Apr 1, 2022
Automatic named constructor discovery in Valinor
High
GHSA-xhr8-mpwq-2rr2
was published
for
cuyz/valinor
(Composer)
Apr 1, 2022
Buffer length underflow in LoginPacket causing unchecked exceptions to be thrown
High
GHSA-5jfw-35xp-5m42
was published
for
pocketmine/bedrock-protocol
(Composer)
Apr 5, 2022
Denial-of-service vulnerability processing large chat messages containing many newlines
Moderate
GHSA-gj94-v4p9-w672
was published
for
pocketmine/pocketmine-mp
(Composer)
May 25, 2022
Insufficient type validation in pocketmine/pocketmine-mp
High
GHSA-g5rr-p69h-7v3g
was published
for
pocketmine/pocketmine-mp
(Composer)
Apr 22, 2022
Login timing attack in ibexa/core
Critical
GHSA-2x4v-g8cx-jxrq
was published
for
ibexa/core
(Composer)
Jun 2, 2022
Login timing attack in ezsystems/ezplatform-kernel
Critical
GHSA-342c-vcff-2ff2
was published
for
ezsystems/ezplatform-kernel
(Composer)
Jun 2, 2022
XSS in various backend modules due to (un)escaping in JS notification module
Moderate
GHSA-jfxf-4frr-9j3q
was published
for
neos/neos
(Composer)
May 25, 2022
Kirby Panel users could upload PHP Phar archives as content files before v2.5.14 and v3.4.5
Moderate
CVE-2020-26255
was published
for
getkirby/cms
(Composer)
Dec 8, 2020
Improperly checked IDs on itemstacks received from the client leading to server crash in PocketMine-MP
High
GHSA-fqx3-r75h-vc89
was published
for
pocketmine/pocketmine-mp
(Composer)
Jun 7, 2022
XML-RPC for PHP's debugger vulnerable to possible XSS attack
Moderate
GHSA-pxqj-xrv5-qvjf
was published
for
phpxmlrpc/phpxmlrpc
(Composer)
Jan 11, 2023
XML-RPC for PHP's `Wrapper::buildClientWrapperCode` method allows code injection via malicious `$client` argument
Moderate
GHSA-7vcx-v65q-9wpg
was published
for
phpxmlrpc/phpxmlrpc
(Composer)
Jan 11, 2023
XML-RPC for PHP allows access to local files via malicious argument to the Client::send method
Moderate
GHSA-m95x-m25c-w9mp
was published
for
phpxmlrpc/phpxmlrpc
(Composer)
Jan 11, 2023
Bypass of CMS Safe Mode Security Feature
Moderate
GHSA-q37h-jhf3-85cj
was published
for
wintercms/winter
(Composer)
Jul 15, 2022
Potential XSS injection In PrestaShop contactform
High
CVE-2020-15178
was published
for
prestashop/contactform
(Composer)
Sep 15, 2020
OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor
Moderate
GHSA-6f85-3f8q-qc94
was published
for
oro/commerce
(Composer)
Jul 15, 2022
Islandora 2.0 before 2.4.1 could allow any user to upload content into a repository
Critical
GHSA-m58q-qq5h-mgqq
was published
for
islandora/islandora
(Composer)
Jul 21, 2022
mezzio-swoole Applications Using Diactoros Vulnerable to HTTP Host Header Attack
High
GHSA-c8rp-cgf4-937w
was published
for
mezzio/mezzio-swoole
(Composer)
Jul 29, 2022
personnummer/php vulnerable to Improper Input Validation
Low
GHSA-2p6g-gjp8-ggg9
was published
for
personnummer/personnummer
(Composer)
Sep 9, 2020
phpxmlrpc vulnerable to argument injection
Moderate
GHSA-q7qq-9gx2-ggxv
was published
for
phpxmlrpc/phpxmlrpc
(Composer)
Dec 2, 2022
Cross-site scripting from content entered in the tags and multiselect fields
High
GHSA-rv3r-vqjj-8c76
was published
for
getkirby/cms
(Composer)
Aug 30, 2022
PocketMine-MP vulnerable to denial-of-service by sending large modal form responses
Moderate
GHSA-7m9r-rq9j-wmmh
was published
for
pocketmine/pocketmine-mp
(Composer)
Jan 10, 2023
Insufficient output escaping of attachment names in PHPMailer
High
CVE-2020-13625
was published
for
phpmailer/phpmailer
(Composer)
May 27, 2020
ProTip!
Advisories are also available from the
GraphQL API