GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,599
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,828
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
8,810 advisories
Filter by severity
Redaxo CMS 5.2 contains a cross-site request forgery vulnerability that allows unauthenticated...
Moderate
Unreviewed
CVE-2016-20053
was published
Apr 4, 2026
Snews CMS 1.7 contains a cross-site request forgery vulnerability that allows attackers to change...
Moderate
Unreviewed
CVE-2016-20051
was published
Apr 4, 2026
AVideo: CSRF on Player Skin Configuration via admin/playerUpdate.json.php
Moderate
CVE-2026-35181
was published
for
wwbn/avideo
(Composer)
Apr 3, 2026
OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode
Moderate
GHSA-mhr7-2xmv-4c4q
was published
for
openclaw
(npm)
Apr 3, 2026
IBM DataPower Gateway 10.6CD 10.6.1.0 through 10.6.5.0 and IBM DataPower Gateway 10.5.0 10.5.0.0...
Moderate
Unreviewed
CVE-2025-36375
was published
Apr 2, 2026
Payload has a CSRF Protection Bypass in Authentication Flow
Moderate
CVE-2026-34749
was published
for
payload
(npm)
Apr 1, 2026
AVideo: CSRF on Plugin Enable/Disable Endpoint Allows Disabling Security Plugins
Moderate
CVE-2026-34613
was published
for
wwbn/avideo
(Composer)
Apr 1, 2026
AVideo: CSRF on emailAllUsers.json.php Enables Mass Phishing Email to All Users
Moderate
CVE-2026-34611
was published
for
wwbn/avideo
(Composer)
Apr 1, 2026
AVideo's CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking
High
CVE-2026-34394
was published
for
wwbn/avideo
(Composer)
Mar 31, 2026
Admidio has CSRF and Form Validation Bypass in Inventory Item Save via `imported` Parameter
Moderate
CVE-2026-34383
was published
for
admidio/admidio
(Composer)
Mar 31, 2026
Admidio has Missing CSRF Protection on Registration Approval Actions
Moderate
CVE-2026-34384
was published
for
admidio/admidio
(Composer)
Mar 31, 2026
Admidio has Missing CSRF Protections on Custom List Deletion in mylist_function.php
Moderate
CVE-2026-34382
was published
for
admidio/admidio
(Composer)
Mar 31, 2026
The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
Moderate
Unreviewed
CVE-2026-3191
was published
Mar 31, 2026
An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. A Cross-Site Request Forgery...
High
Unreviewed
CVE-2026-33373
was published
Mar 30, 2026
A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow...
High
Unreviewed
CVE-2026-4315
was published
Mar 30, 2026
A weakness has been identified in SourceCodester Note Taking App up to 1.0. This impacts an...
Moderate
Unreviewed
CVE-2026-4971
was published
Mar 27, 2026
A vulnerability was determined in SourceCodester Diary App 1.0. The affected element is an...
Moderate
Unreviewed
CVE-2026-4968
was published
Mar 27, 2026
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Automated Logout allows Cross Site...
Moderate
Unreviewed
CVE-2026-4393
was published
Mar 26, 2026
The Conditional Menus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
Moderate
Unreviewed
CVE-2026-1032
was published
Mar 26, 2026
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 IBM InfoSphere DataStage Flow...
Moderate
Unreviewed
CVE-2025-36422
was published
Mar 25, 2026
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7,...
High
Unreviewed
CVE-2026-3857
was published
Mar 25, 2026
Mattermost doesn't properly validate CSRF tokens
Moderate
CVE-2026-27659
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 25, 2026
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Theme Negotiation by Rules allows Cross...
Moderate
Unreviewed
CVE-2026-3211
was published
Mar 25, 2026
AVideo's GET-Based CSRF in setPermission.json.php Enables Privilege Escalation via Arbitrary Permission Modification
High
CVE-2026-33649
was published
for
wwbn/avideo
(Composer)
Mar 25, 2026
Ericsson Indoor Connect 8855 versions prior to 2025.Q3 contains a
Cross-Site Request Forgery ...
Moderate
Unreviewed
CVE-2025-40841
was published
Mar 25, 2026
ProTip!
Advisories are also available from the
GraphQL API