GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,340
Erlang
31
GitHub Actions
22
Go
2,101
Maven
5,000+
npm
3,764
NuGet
679
pip
3,451
Pub
12
RubyGems
892
Rust
885
Swift
37
Unreviewed advisories
All unreviewed
5,000+
4,341 advisories
Filter by severity
Twig security issue where escaping was missing when using null coalesce operator
Moderate
CVE-2025-24374
was published
for
twig/twig
(Composer)
Jan 29, 2025
Pimcore Authenticated Stored Cross-Site Scripting (XSS) Via Search Document
High
GHSA-xr3m-6gq6-22cg
was published
for
pimcore/pimcore
(Composer)
Jan 28, 2025
Dolibarr Cross-site Scripting vulnerability
Low
CVE-2024-55228
was published
for
dolibarr/dolibarr
(Composer)
Jan 27, 2025
TYPO3-EXT-SA-2025-001: Account Takeover in extension "OpenID Connect Authentication" (oidc)
Moderate
CVE-2025-24856
was published
for
causal/oidc
(Composer)
Jan 28, 2025
pimcore/customer-data-framework vulnerable to SQL Injection
Moderate
CVE-2024-11956
was published
for
pimcore/customer-management-framework-bundle
(Composer)
Jan 28, 2025
Duplicate Advisory: pimcore/customer-data-framework vulnerable to SQL Injection: Hibernate
Moderate
GHSA-8m8m-98c9-vw7q
was published
for
pimcore/customer-data-framework
(Composer)
Jan 28, 2025
•
withdrawn
Dolibarr Cross-site Scripting vulnerability
Low
CVE-2024-55227
was published
for
dolibarr/dolibarr
(Composer)
Jan 27, 2025
LavaLite vulnerable to web cache poisoning
Critical
CVE-2023-27238
was published
for
lavalite/cms
(Composer)
May 12, 2023
CraftCMS allows remote attacker to execute arbitrary code via crafted script to Section parameter
High
CVE-2023-30130
was published
for
craftcms/cms
(Composer)
May 12, 2023
Duplicate Advisory: openCart Server-Side Template Injection (SSTI) vulnerability
High
GHSA-j2v2-3784-vr44
was published
for
opencart/opencart
(Composer)
Dec 18, 2024
•
withdrawn
Improper Handling of Parameters in moodle
Moderate
CVE-2024-25979
was published
for
moodle/moodle
(Composer)
Feb 19, 2024
Uncontrolled Resource Consumption in moodle
High
CVE-2024-25978
was published
for
moodle/moodle
(Composer)
Feb 19, 2024
Improper Access Control in moodle
Moderate
CVE-2024-25980
was published
for
moodle/moodle
(Composer)
Feb 19, 2024
Improper Access Control in moodle
Moderate
CVE-2024-25981
was published
for
moodle/moodle
(Composer)
Feb 19, 2024
Cross-Site Request Forgery in moodle
High
CVE-2024-25982
was published
for
moodle/moodle
(Composer)
Feb 19, 2024
Authorization Bypass in moodle
Moderate
CVE-2024-25983
was published
for
moodle/moodle
(Composer)
Feb 19, 2024
Reflected Cross Site Scripting (XSS) in error message
Low
GHSA-74j9-xhqr-6qv3
was published
for
silverstripe/framework
(Composer)
Jan 23, 2025
pimcore/customer-management-framework-bundle Cross-site Scripting vulnerability in Segment name
Moderate
CVE-2023-4145
was published
for
pimcore/customer-management-framework-bundle
(Composer)
Aug 3, 2023
phpMyAdmin XSS when checking tables
Moderate
CVE-2025-24530
was published
for
phpmyadmin/phpmyadmin
(Composer)
Jan 23, 2025
Silverstripe Framework has a XSS in form messages
Moderate
CVE-2024-53277
was published
for
silverstripe/framework
(Composer)
Jan 14, 2025
Silverstripe Framework has a XSS via insert media remote file oembed
Moderate
CVE-2024-47605
was published
for
silverstripe/framework
(Composer)
Jan 14, 2025
ps_contactinfo has a potential XSS due to usage of the nofilter tag in template
Moderate
CVE-2025-24027
was published
for
prestashop/ps_contactinfo
(Composer)
Jan 22, 2025
Webtrees Path Traversal vulnerability
Moderate
CVE-2024-22723
was published
for
fisharebest/webtrees
(Composer)
Feb 28, 2024
Missing validation of header name and value in codeigniter4/framework
Moderate
CVE-2025-24013
was published
for
codeigniter4/framework
(Composer)
Jan 21, 2025
Cross-Site Scripting (XSS) vulnerability in generateNavigation() function in PhpSpreadsheet
Moderate
CVE-2025-22131
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 21, 2025
ProTip!
Advisories are also available from the
GraphQL API