Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

93 advisories

Loading
XWiki Platform Old Core: Resource path traversal via /skin/ action endpoint in Jetty 12+ High
CVE-2026-34151 was published for org.xwiki.platform:xwiki-platform-oldcore (Maven) Jul 7, 2026
khoaln98 Credited to khoaln98
XWiki Platform vulnerable to potential arbitrary file writing using path traversal from (subwiki) admin Moderate
CVE-2026-48047 was published for org.xwiki.platform:xwiki-platform-webjars-api (Maven) May 26, 2026
@joplin/onenote-converter: Path traversal in OneNote importer allows overwriting arbitrary files High
CVE-2026-22810 was published for @joplin/onenote-converter (npm) May 15, 2026
msiemens Credited to msiemens
SiYuan: Publish Reader Path Traversal Delete via `removeUnusedAttributeView` High
CVE-2026-40318 was published for github.com/siyuan-note/siyuan/kernel (Go) Apr 10, 2026
ch1nhpd Credited to ch1nhpd
Fonoster is vulnerable to directory traversal Moderate
CVE-2024-43035 was published for @fonoster/voice (npm) Mar 5, 2026
Path traversal vulnerability in the certificate management module. Impact: Successful... Moderate Unreviewed
CVE-2026-28538 was published Mar 5, 2026
fast-filesystem-mcp has a Path Traversal vulnerability High
CVE-2025-67364 was published for fast-filesystem-mcp (npm) Jan 7, 2026
Redaxo has Path Traversal in Backup Addon Leading to Arbitrary File Read High
CVE-2026-21857 was published for redaxo/source (Composer) Jan 5, 2026
lukasz-rybak Credited to lukasz-rybak
A path traversal in StarNet Communications Corporation FastX v.4 through v4.1.51 allows... Moderate Unreviewed
CVE-2025-57563 was published Oct 14, 2025
ProTip! Advisories are also available from the GraphQL API