GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,632
Erlang
34
GitHub Actions
25
Go
2,238
Maven
5,000+
npm
3,900
NuGet
701
pip
3,666
Pub
12
RubyGems
914
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,632 advisories
Filter by severity
DevDojo Voyager Argument Injection vulnerability
Critical
CVE-2025-32931
was published
for
tcg/voyager
(Composer)
Apr 14, 2025
Formie has XSS vulnerability for email notification content for preview
Moderate
CVE-2025-32426
was published
for
verbb/formie
(Composer)
Apr 11, 2025
Formie has XSS vulnerability for importing forms
Moderate
CVE-2025-32427
was published
for
verbb/formie
(Composer)
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
Moderate
CVE-2025-32027
was published
for
yiisoft/yii
(Composer)
Apr 11, 2025
Silverstripe Framework user enumeration via timing attack on login and password reset forms
Moderate
GHSA-256q-hx8w-xcqx
was published
for
silverstripe/framework
(Composer)
Apr 10, 2025
Silverstripe Framework has a XSS vulnerability in HTML editor
Moderate
CVE-2025-30148
was published
for
silverstripe/framework
(Composer)
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
Moderate
CVE-2025-25197
was published
for
dnadesign/silverstripe-elemental
(Composer)
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
GHSA-cj3w-g42v-wcj6
was published
for
ibexa/fieldtype-richtext
(Composer)
Apr 10, 2025
ezsystems/ezplatform-richtext allows access to external entities in XML
High
GHSA-2jqj-5qv2-xvcg
was published
for
ezsystems/ezplatform-richtext
(Composer)
Apr 10, 2025
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
Critical
CVE-2024-58136
was published
for
yiisoft/yii2
(Composer)
Apr 10, 2025
Shopware default newsletter opt-in settings allow for mass sign-up abuse
Low
CVE-2025-32378
was published
for
shopware/core
(Composer)
Apr 9, 2025
wallabag/wallabag Has Multiple Cross-Site Request Forgery (CSRF) Vulnerabilities
Moderate
GHSA-5pm7-cp8f-p2c2
was published
for
wallabag/wallabag
(Composer)
Apr 9, 2025
Joomla CMS Multi-Factor Authentication Bypass
High
CVE-2025-25227
was published
for
joomla/joomla-cms
(Composer)
Apr 8, 2025
Joomla Framework Database Package Vulnerable to SQL Injection
Moderate
CVE-2025-25226
was published
for
joomla/database
(Composer)
Apr 8, 2025
Shopware Broken ACL on Document retrieval to access other customers documents
Moderate
GHSA-68wv-g3fw-pq7q
was published
for
shopware/core
(Composer)
Apr 8, 2025
Shopware Vulnerable to Blind SQL-injection in DAL aggregations
High
CVE-2025-27892
was published
for
shopware/core
(Composer)
Apr 8, 2025
Pimcore's Admin Classic Bundle allows HTML Injection
Low
CVE-2025-30166
was published
for
pimcore/admin-ui-classic-bundle
(Composer)
Apr 8, 2025
Shopware allows Denial Of Service via password length
High
CVE-2025-30151
was published
for
shopware/core
(Composer)
Apr 8, 2025
Shopware 6 allows attackers to check for registered accounts through the store-api
Moderate
CVE-2025-30150
was published
for
shopware/core
(Composer)
Apr 8, 2025
GraphQL grant on a property might be cached with different objects
High
CVE-2025-31485
was published
for
api-platform/core
(Composer)
Apr 4, 2025
GraphQL query operations security can be bypassed
High
CVE-2025-31481
was published
for
api-platform/core
(Composer)
Apr 4, 2025
Browsershot Server-Side Request Forgery (SSRF) via setURL() Function
High
CVE-2025-3192
was published
for
spatie/browsershot
(Composer)
Apr 4, 2025
API Platform Core can leak exceptions message that may contain sensitive information
Moderate
CVE-2023-47639
was published
for
api-platform/core
(Composer)
Apr 3, 2025
Concrete CMS Vulnerable to Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Moderate
CVE-2025-3153
was published
for
concrete5/concrete5
(Composer)
Apr 3, 2025
Drupal Obfuscate Vulnerable to Stored Cross-Site Scripting (XSS)
Moderate
CVE-2025-3130
was published
for
drupal/obfuscate
(Composer)
Apr 3, 2025
ProTip!
Advisories are also available from the
GraphQL API