GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,517
Rust
20
20 advisories
Filter by severity
MantisBT HTML Injection vulnerability
Moderate
CVE-2020-25830
was published
for
mantisbt/mantisbt
(Composer)
May 24, 2022
MantisBT Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2024-34080
was published
for
mantisbt/mantisbt
(Composer)
May 13, 2024
Mantis Bug Tracker (MantisBT) vulnerable to cross-site scripting
Moderate
CVE-2024-34081
was published
for
mantisbt/mantisbt
(Composer)
May 13, 2024
MantisBT vulnerable to information disclosure with user profiles
Moderate
CVE-2024-45792
was published
for
mantisbt/mantisbt
(Composer)
Sep 30, 2024
MantisBT Vulnerable to Denial-of-Service (DoS) via Excessive Note Length
Moderate
CVE-2025-46556
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
MantisBT lacks verification when changing a user's email address
Moderate
CVE-2025-55155
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
MantisBT unauthorized disclosure of private project column configuration
Moderate
CVE-2025-62520
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
MantisBT Has Authorization Bypass in Global Profile Creation
Moderate
CVE-2026-33052
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT Vulnerable to Privilege Escalation from Manager to Administrator
Moderate
CVE-2026-34390
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT has an authorization bypass in private issue monitoring
Moderate
CVE-2026-34579
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT has an authorization bypass that allows reading attachments after losing access to a private issue
Moderate
CVE-2026-34744
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT has an Authorization Bypass that Allows Uploading Attachments to Private Issues via REST API
Moderate
CVE-2026-34754
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT: Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is Revoked
Moderate
CVE-2026-34970
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT is Vulnerable to Stored XSS in Custom Field Textarea Values
Moderate
CVE-2026-39960
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Page
Moderate
CVE-2026-40598
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT is Vulnerable to Reflected XSS in Rendering Dynamic Custom Textarea Field
Moderate
CVE-2026-41897
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API
Moderate
CVE-2026-42070
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT: REST API unauthorized Issue status change
Moderate
CVE-2026-49280
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters
Moderate
CVE-2026-52882
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs
Moderate
CVE-2026-52883
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
ProTip!
Advisories are also available from the
GraphQL API