GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,175
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
103 advisories
Filter by severity
Statamic CMS: Missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources
Moderate
CVE-2026-49288
was published
for
statamic/cms
(Composer)
Jun 26, 2026
Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment
Moderate
CVE-2026-48493
was published
for
snipe/snipe-it
(Composer)
Jun 23, 2026
Admidio: IDOR in documents-files.php allows cross-folder file rename and description changes by unauthorized uploaders
Moderate
CVE-2026-47230
was published
for
admidio/admidio
(Composer)
May 29, 2026
Admidio module-administrator can delete or reorder categories owned by other modules via dead authorization check in `modules/categories.php`
Moderate
CVE-2026-47227
was published
for
admidio/admidio
(Composer)
May 29, 2026
Pimcore has a WordExport Authorization Bypass for Unauthorized Document Export
Moderate
CVE-2026-45703
was published
for
pimcore/pimcore
(Composer)
May 27, 2026
Synfony's HEAD Request Bypasses methods: ['GET'] Filter in #[IsGranted] / #[IsSignatureValid] / #[IsCsrfTokenValid]
Moderate
CVE-2026-45075
was published
for
symfony/http-kernel
(Composer)
May 27, 2026
Duplicate Advisory: phpMyFAQ: Ordinary Authenticated User Can Access Admin-Only API Endpoints Due to Insufficient Authorization Check
Moderate
GHSA-9r8r-x3vg-6xh4
was published
for
phpMyFAQ/phpMyFAQ
(Composer)
May 15, 2026
•
withdrawn
MantisBT: Authorization Bypass in Bugnote Editing via Issue Update API
Moderate
CVE-2026-42070
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
phpMyFAQ: Ordinary Authenticated User Can Access Admin-Only API Endpoints Due to Insufficient Authorization Check in phpMyFAQ
Moderate
CVE-2026-45009
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
phpMyFAQ has an Authorization Bypass in All Admin Pages Due to Non-Terminating Permission Check
Moderate
CVE-2026-46362
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
Kimai has Missing Voter Check that Allows Cross-Team Timesheet Manipulation
Moderate
GHSA-9g2q-w3w2-vf7q
was published
for
kimai/kimai
(Composer)
May 6, 2026
Grav Vulnerable to Sensitive Information Disclosure via Accounts Service Bypass
Moderate
CVE-2026-42610
was published
for
getgrav/grav
(Composer)
May 5, 2026
Admidio Exposes Cross-Organization Member Data via Permission Check Mismatch in contacts_data.php
Moderate
CVE-2026-41657
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Moderate
CVE-2026-40099
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
October CMS has Safe Mode Bypass via Twig Database Write Operations
Moderate
CVE-2026-26274
was published
for
october/october
(Composer)
Apr 21, 2026
Silverstripe Assets Module has a DBFile::getURL() permission bypass
Moderate
CVE-2026-24749
was published
for
silverstripe/assets
(Composer)
Apr 16, 2026
Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index Allows Cross-Customer Email Spoofing
Moderate
CVE-2026-41232
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add()
Moderate
CVE-2026-41233
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
AVideo has User Group-Based Category Access Control Bypass via Missing and Broken Group Filtering in categories.json.php
Moderate
CVE-2026-34364
was published
for
wwbn/avideo
(Composer)
Mar 30, 2026
Statamic's live preview token bypasses content protection for unrelated entries
Moderate
CVE-2026-33884
was published
for
statamic/cms
(Composer)
Mar 26, 2026
Firefly III user API endpoints expose all users' information to any authenticated user (IDOR)
Moderate
GHSA-5q8v-j673-m5v4
was published
for
grumpydictator/firefly-iii
(Composer)
Mar 7, 2026
Moodle has an authorization logic flaw
Moderate
CVE-2025-67856
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
TYPO3 CMS Allows Broken Access Control in Edit Document Controller
Moderate
CVE-2025-59020
was published
for
typo3/cms-backend
(Composer)
Jan 13, 2026
Kirby is missing permission checks in the content changes API
Moderate
CVE-2026-21896
was published
for
getkirby/cms
(Composer)
Jan 8, 2026
Auth0 WordPress has Improper Audience Validation via Auth0-PHP SDK Dependency
Moderate
GHSA-vvg7-8rmq-92g7
was published
for
auth0/wordpress
(Composer)
Dec 17, 2025
ProTip!
Advisories are also available from the
GraphQL API