GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,930
Maven
5,000+
npm
4,587
NuGet
786
pip
4,294
Pub
12
RubyGems
981
Rust
1,114
Swift
49
Unreviewed advisories
All unreviewed
5,000+
99 advisories
Filter by severity
Veramo is Vulnerable to SQL Injection in Veramo Data Store ORM
Moderate
GHSA-38cw-85xc-xr9x
was published
for
@veramo/data-store
(npm)
Jan 16, 2026
Apache Camel camel-neo4j component is vulnerable to cypher injection
Moderate
CVE-2025-66169
was published
for
org.apache.camel:camel-neo4j
(Maven)
Jan 14, 2026
Ghost has SQL Injection in Members Activity Feed
Moderate
CVE-2026-22596
was published
for
ghost
(npm)
Jan 8, 2026
CoreShop Vulnerable to SQL Injection via Admin Reports
Moderate
CVE-2026-22242
was published
for
coreshop/core-shop
(Composer)
Jan 7, 2026
Parsl Monitoring Visualization Vulnerable to SQL Injection
Moderate
CVE-2026-21892
was published
for
parsl
(pip)
Jan 6, 2026
Django is vulnerable to SQL injection in column aliases
Moderate
CVE-2025-13372
was published
for
Django
(pip)
Dec 2, 2025
phppgadmin contains a SQL injection vulnerability
Moderate
CVE-2025-60798
was published
for
phppgadmin/phppgadmin
(Composer)
Nov 20, 2025
phppgadmin contains a SQL injection vulnerability
Moderate
CVE-2025-60797
was published
for
phppgadmin/phppgadmin
(Composer)
Nov 20, 2025
LibreNMS is vulnerable to SQL Injection (Boolean-Based Blind) in hostname parameter in ajax_output.php endpoint
Moderate
CVE-2025-65093
was published
for
librenms/librenms
(Composer)
Nov 18, 2025
Apache Flink CDC is vulnerable to SQL Injection through maliciously crafted identifiers
Moderate
CVE-2025-62228
was published
for
org.apache.flink:flink-cdc-pipeline-connectors
(Maven)
Oct 9, 2025
Open Web Analytics Server is vulnerable to SQL Injection
Moderate
CVE-2025-59397
was published
for
open-web-analytics/open-web-analytics
(Composer)
Sep 15, 2025
Easy!Appointments SQL injection vulnerability
Moderate
CVE-2025-50383
was published
for
alextselegidis/easyappointments
(Composer)
Aug 26, 2025
JeecgBoot SQL Injection Vulnerability
Moderate
CVE-2025-51825
was published
for
org.jeecgframework.boot:jeecg-boot-base-core
(Maven)
Aug 22, 2025
MoonShine SQL Injection Vulnerability
Moderate
CVE-2025-51510
was published
for
moonshine/moonshine
(Composer)
Aug 19, 2025
Apache Superset has bypass of `DISALLOWED_SQL_FUNCTIONS` that allows execution of blocked SQL functions
Moderate
CVE-2025-55674
was published
for
apache-superset
(pip)
Aug 14, 2025
Matrix Rust SDK vulnerable to SQL Injection through its EventCache implementation
Moderate
CVE-2025-53549
was published
for
matrix-sdk
(Rust)
Jul 10, 2025
uptrace pgdriver SQL injection vulnerability
Moderate
CVE-2024-44906
was published
for
github.com/uptrace/bun/driver/pgdriver
(Go)
Jun 12, 2025
pg-promise SQL Injection vulnerability
Moderate
CVE-2025-29744
was published
for
pg-promise
(npm)
Jun 12, 2025
go-pg SQL injection vulnerability via the component /types/append_value.go
Moderate
CVE-2024-44905
was published
for
github.com/go-pg/pg
(Go)
Jun 12, 2025
SeaweedFS Vulnerable to SQL Injection
Moderate
CVE-2024-40120
was published
for
github.com/seaweedfs/seaweedfs
(Go)
May 16, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Moderate
CVE-2025-25226
was published
for
joomla/database
(Composer)
Apr 8, 2025
Frappe has possibility of SQL injection due to improper validations
Moderate
CVE-2025-30217
was published
for
frappe
(pip)
Mar 26, 2025
Frappe has possibility of SQL injection due to improper validations
Moderate
CVE-2025-30212
was published
for
frappe
(pip)
Mar 25, 2025
Apache Airflow MySQL Provider is Vulnerable to SQL Injection
Moderate
CVE-2025-27018
was published
for
apache-airflow-providers-mysql
(pip)
Mar 19, 2025
Pimcore Vulnerable to SQL Injection in getRelationFilterCondition
Moderate
CVE-2025-27617
was published
for
pimcore/pimcore
(Composer)
Mar 11, 2025
ProTip!
Advisories are also available from the
GraphQL API