GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,585
Maven
5,000+
npm
5,000+
NuGet
923
pip
4,817
Pub
13
RubyGems
1,043
Rust
1,251
Swift
53
Unreviewed advisories
All unreviewed
5,000+
5,650 advisories
Filter by severity
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Moderate
CVE-2026-40099
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
CVE-2026-34587
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Moderate
CVE-2026-32870
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
Moderate
GHSA-xjvc-pw2r-6878
was published
for
flarum/core
(Composer)
Apr 22, 2026
CI4MS Theme::upload is vulnerable to Zip Slip leading to RCE
Critical
CVE-2026-41203
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 22, 2026
CI4MS Backup::restore is vulnerable to Zip Slip leading to RCE
Critical
CVE-2026-41202
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
Moderate
CVE-2026-41201
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 22, 2026
PHPUnit: Argument injection via newline in PHP INI values forwarded to child processes
High
GHSA-mh6w-vxff-9wqp
was published
for
phpunit/phpunit
(Composer)
Apr 22, 2026
OpenMage LTS: Customer File Upload Extension Blocklist Bypass → Remote Code Execution
High
CVE-2026-40488
was published
for
openmage/magento-lts
(Composer)
Apr 21, 2026
October CMS: Editor Sub-Permission Bypass for Asset and Blueprint File Operations
Low
CVE-2026-29179
was published
for
october/system
(Composer)
Apr 21, 2026
October CMS: Reflected XSS via DataTable Form Widget
Low
CVE-2026-27937
was published
for
october/system
(Composer)
Apr 21, 2026
October CMS has Safe Mode Bypass via Twig Database Write Operations
Moderate
CVE-2026-26274
was published
for
october/october
(Composer)
Apr 21, 2026
October CMS has Safe Mode Bypass via CSS Preprocessor Compilers
Moderate
CVE-2026-26067
was published
for
october/system
(Composer)
Apr 21, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Moderate
CVE-2026-40098
was published
for
openmage/magento-lts
(Composer)
Apr 21, 2026
OpenMage LTS has a Path Traversal Filter Bypass in Dataflow Module
Moderate
CVE-2026-25525
was published
for
openmage/magento-lts
(Composer)
Apr 21, 2026
OpenMage LTS: Phar Deserialization leads to Remote Code Execution
High
CVE-2026-25524
was published
for
openmage/magento-lts
(Composer)
Apr 21, 2026
Cockpit has NoSQL Injection Through Content Aggregation Pipelines
Low
CVE-2026-6626
was published
for
cockpit-hq/cockpit
(Composer)
Apr 20, 2026
YesWiki vulnerable to authenticated SQL Injection via id_fiche in EntryManager::formatDataBeforeSave()
High
GHSA-f58v-p6j9-24c2
was published
for
yeswiki/yeswiki
(Composer)
Apr 18, 2026
PHPUnit has Argument injection via newline in PHP INI values that are forwarded to child processes
High
GHSA-qrr6-mg7r-m243
was published
for
phpunit/phpunit
(Composer)
Apr 18, 2026
elFinder: Command injection in resize background color parameter when using ImageMagick CLI
High
GHSA-8q4h-8crm-5cvc
was published
for
studio-42/elfinder
(Composer)
Apr 17, 2026
Kimai: Username enumeration via timing on X-AUTH-USER
Low
GHSA-jrc6-fmhw-fpq2
was published
for
kimai/kimai
(Composer)
Apr 17, 2026
Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration
Critical
CVE-2026-23500
was published
for
dolibarr/dolibarr
(Composer)
Apr 17, 2026
Craftql vulnerable to Server-Side Request Forgery
Moderate
CVE-2026-31317
was published
for
markhuot/craftql
(Composer)
Apr 17, 2026
Unauthenticated Information Disclosure (IDOR) via Multisite switch_to_blog in My Calendar
High
CVE-2026-40308
was published
for
joedolson/my-calendar
(Composer)
Apr 16, 2026
Statamic: Unsafe method invocation via query value resolution allows data destruction
High
GHSA-4jjr-vmv7-wh4w
was published
for
statamic/cms
(Composer)
Apr 16, 2026
ProTip!
Advisories are also available from the
GraphQL API