GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,227
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,502
Pub
12
RubyGems
995
Rust
1,187
Swift
51
Unreviewed advisories
All unreviewed
5,000+
339 advisories
Filter by severity
Broken Access Control in extension "Redirect Tab" (redirect_tab)
Low
CVE-2026-4202
was published
for
ayacoo/redirect-tab
(Composer)
Mar 17, 2026
Google Cloud Storage for Craft CMS has an Information Disclosure Vulnerability
Low
CVE-2026-32266
was published
for
craftcms/google-cloud
(Composer)
Mar 16, 2026
Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page
Low
GHSA-g3hp-vvqf-8vw6
was published
for
craftcms/cms
(Composer)
Mar 11, 2026
Craft Commerce has stored XSS in Craft Commerce Order Details Slideout
Low
CVE-2026-29177
was published
for
craftcms/commerce
(Composer)
Mar 10, 2026
Craft Commerce is Vulnerable to Stored XSS while updating Order Status from Orders Table
Low
CVE-2026-29173
was published
for
craftcms/commerce
(Composer)
Mar 10, 2026
Craft CMS has a potential information disclosure vulnerability in preview tokens
Low
CVE-2026-29113
was published
for
craftcms/cms
(Composer)
Mar 10, 2026
Concrete CMS vulnerable to Cross-Site Request Forgery (CSRF)
Low
CVE-2026-2994
was published
for
concrete5/concrete5
(Composer)
Mar 4, 2026
Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options
Low
GHSA-4mgv-366x-qxvx
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type
Low
GHSA-6j87-m5qx-9fqp
was published
for
craftcms/cms
(Composer)
Feb 25, 2026
funadmin: Deserialization Vulnerability in Backend Endpoint via AuthCloudService getMember Function
Low
CVE-2026-2898
was published
for
funadmin/funadmin
(Composer)
Feb 22, 2026
funadmin: XSS through Value argument in Backend Interface component
Low
CVE-2026-2897
was published
for
funadmin/funadmin
(Composer)
Feb 22, 2026
funadmin has Weak Password Recovery Mechanism for Forgotten Password
Low
CVE-2026-2895
was published
for
funadmin/funadmin
(Composer)
Feb 22, 2026
Craft CMS Vulnerable to Stored XSS in Entry Types Name
Low
CVE-2026-25491
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Microweber has a Cross-site Scripting vulnerability
Low
CVE-2025-70791
was published
for
microweber/microweber
(Composer)
Feb 5, 2026
Microweber Cross-site Scripting vulnerability
Low
CVE-2025-70792
was published
for
microweber/microweber
(Composer)
Feb 5, 2026
Winter CMS has Stored Cross-site Scripting (XSS) in Asset Manager
Low
CVE-2026-22254
was published
for
winter/wn-cms-module
(Composer)
Feb 4, 2026
Moodle Open Redirect vulnerability
Low
CVE-2025-67852
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
Freeform Craft Plugin CP UI (builder/integrations) has Stored Cross-Site Scripting (XSS) issue
Low
CVE-2026-26188
was published
for
solspace/craft-freeform
(Composer)
Jan 22, 2026
MineAdmin improperly refreshes tokens
Low
CVE-2026-1195
was published
for
mineadmin/mineadmin
(Composer)
Jan 20, 2026
MineAdmin May Expose Sensitive Information to an Unauthorized Actor
Low
CVE-2026-1196
was published
for
mineadmin/mineadmin
(Composer)
Jan 20, 2026
MineAdmin has Incorrect Privilege Assignment
Low
CVE-2026-1193
was published
for
mineadmin/mineadmin
(Composer)
Jan 20, 2026
solspace/craft-freeform Exposed to Known Axios Vulnerabilities via Precompiled Assets
Low
GHSA-rwr8-xrpw-9qf5
was published
for
solspace/craft-freeform
(Composer)
Jan 15, 2026
solspace/craft-freeform Vulnerable to XSS in `PhpSpreadsheet` HTML Writer Due to Unsanitized Styling Data
Low
GHSA-44jg-mv3h-wj6g
was published
for
solspace/craft-freeform
(Composer)
Jan 15, 2026
solspace/craft-freeform Has a DoS Vulnerability
Low
GHSA-58q2-9x27-h2jm
was published
for
solspace/craft-freeform
(Composer)
Jan 15, 2026
Composer is vulnerable to ANSI sequence injection
Low
CVE-2025-67746
was published
for
composer/composer
(Composer)
Dec 30, 2025
ProTip!
Advisories are also available from the
GraphQL API