GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
2,891
Erlang
24
GitHub Actions
39
Go
2,240
Maven
2,698
npm
2,899
NuGet
500
pip
2,728
Pub
5
RubyGems
364
Rust
889
Swift
19
Unreviewed advisories
All unreviewed
5,000+
27 advisories
Filter by severity
verbb/formie Server-Side Template Injection for variable-enabled settings
Moderate
CVE-2024-35191
was published
for
verbb/formie
(Composer)
May 20, 2024
Ansible template injection vulnerability
Moderate
CVE-2023-5764
was published
for
ansible-core
(pip)
Dec 13, 2023
SiYuan has an SSTI via /api/template/renderSprig
Moderate
CVE-2024-55660
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Dec 11, 2024
openCart Server-Side Template Injection (SSTI) vulnerability
Moderate
CVE-2024-36694
was published
for
opencart/opencart
(Composer)
Jul 17, 2024
A improper neutralization of special elements used in a template engine [CWE-1336] in...
Moderate
Unreviewed
CVE-2023-47542
was published
Apr 9, 2024
An issue was discovered in Logpoint AgentX before 1.5.0. A vulnerability caused by limited access...
Moderate
Unreviewed
CVE-2025-26789
was published
Feb 14, 2025
Nautobot vulnerable to secrets exposure and data manipulation through Jinja2 templating
Moderate
CVE-2025-49142
was published
for
nautobot
(pip)
Jun 10, 2025
Agiloft Release 28 does not properly neutralize special elements used in an EUI template engine,...
Moderate
Unreviewed
CVE-2025-35113
was published
Aug 27, 2025
bagisto has Server Side Template Injection (SSTI) in Product Description
Moderate
CVE-2025-62416
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
Uptime Kuma Server-side Template Injection (SSTI) in Notification Templates Allows Arbitrary File Read
Moderate
GHSA-vffh-c9pq-4crh
was published
for
uptime-kuma
(npm)
Oct 20, 2025
Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
Moderate
CVE-2025-27516
was published
for
Jinja2
(pip)
Mar 5, 2025
Craft CMS Potential Remote Code Execution via Twig SSTI
Moderate
CVE-2025-57811
was published
for
craftcms/cms
(Composer)
Aug 25, 2025
An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System...
Moderate
Unreviewed
CVE-2025-66361
was published
Nov 28, 2025
CouchAuth has a Server-Side Template Injection vulnerability in its email functionality
Moderate
CVE-2024-57177
was published
for
@perfood/couch-auth
(npm)
Feb 10, 2025
An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method...
Moderate
Unreviewed
CVE-2025-66435
was published
Dec 15, 2025
An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions...
Moderate
Unreviewed
CVE-2025-66436
was published
Dec 15, 2025
Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI
Moderate
CVE-2025-68454
was published
for
craftcms/cms
(Composer)
Jan 5, 2026
Kimai has an Authenticated Server-Side Template Injection (SSTI)
Moderate
CVE-2026-23626
was published
for
kimai/kimai
(Composer)
Jan 20, 2026
Dell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of...
Moderate
Unreviewed
CVE-2025-46699
was published
Jan 23, 2026
Craft CMS Vulnerable to Authenticated RCE via Twig SSTI - create() function + Symfony Process gadget
Moderate
CVE-2026-28695
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS has Twig Function Blocklist Bypass
Moderate
CVE-2026-28783
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS has potential authenticated Remote Code Execution via Twig SSTI
Moderate
CVE-2026-28784
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
LangChain has incomplete f-string validation in prompt templates
Moderate
CVE-2026-40087
was published
for
langchain-core
(pip)
Apr 8, 2026
Giskard has Unsandboxed Jinja2 Template Rendering in ConformityCheck
Moderate
CVE-2026-40320
was published
for
giskard-checks
(pip)
Apr 14, 2026
ProTip!
Advisories are also available from the
GraphQL API