GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
5,067 advisories
Filter by severity
Drupal Email TFA allows Functionality Bypass
Moderate
CVE-2025-12760
was published
for
drupal/email_tfa
(Composer)
Nov 18, 2025
Drupal Simple multi step form allows Cross-Site Scripting
Low
CVE-2025-12761
was published
for
drupal/simple_multistep
(Composer)
Nov 18, 2025
LibreNMS has Weak Password Policy
Low
CVE-2025-65014
was published
for
librenms/librenms
(Composer)
Nov 18, 2025
LibreNMS vulnerable to Reflected Cross-Site Scripting (XSS) in endpoint `/maps/nodeimage` parameter `Image Name`
Moderate
CVE-2025-65013
was published
for
librenms/librenms
(Composer)
Nov 18, 2025
Kirby CMS has cross-site scripting (XSS) in the changes dialog
Moderate
CVE-2025-65012
was published
for
getkirby/cms
(Composer)
Nov 18, 2025
phpMyFAQ has Authenticated SQL Injection in Configuration Update Functionality
High
CVE-2025-62519
was published
for
phpmyfaq/phpmyfaq
(Composer)
Nov 17, 2025
Shopware 6's password recovery link does not expire after email change
Moderate
GHSA-2w46-vq8h-98vh
was published
for
shopware/core
(Composer)
Nov 14, 2025
PrivateBin vulnerable to malicious filename use for self-XSS / HTML injection locally for users
Low
CVE-2025-64711
was published
for
privatebin/privatebin
(Composer)
Nov 14, 2025
PrivateBin's template-switching feature allows arbitrary local file inclusion through path traversal
Moderate
CVE-2025-64714
was published
for
privatebin/privatebin
(Composer)
Nov 14, 2025
Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass
High
CVE-2025-64500
was published
for
symfony/http-foundation
(Composer)
Nov 12, 2025
TYPO3 Modules Extension has Improper Authentication vulnerability
High
CVE-2025-12998
was published
for
codingms/modules
(Composer)
Nov 12, 2025
TorrentPier is Vulnerable to Authenticated SQL Injection through Moderator Control Panel's topic_id parameter
High
CVE-2025-64519
was published
for
torrentpier/torrentpier
(Composer)
Nov 10, 2025
OpenMage vulnerable to XSS in Admin Notifications
Moderate
CVE-2025-64174
was published
for
openmage/magento-lts
(Composer)
Nov 3, 2025
MantisBT unauthorized disclosure of private project column configuration
Moderate
CVE-2025-62520
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
MantisBT lacks verification when changing a user's email address
Moderate
CVE-2025-55155
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
MantisBT Vulnerable to Denial-of-Service (DoS) via Excessive Note Length
Moderate
CVE-2025-46556
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
MantisBT vulnerable to authentication bypass for some passwords due to PHP type juggling
High
CVE-2025-47776
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validation
High
CVE-2025-64112
was published
for
statamic/cms
(Composer)
Oct 30, 2025
Drupal CivicTheme Design System allows Cross-Site Scripting (XSS)
Moderate
CVE-2025-12083
was published
for
drupal/civictheme
(Composer)
Oct 30, 2025
Drupal Acquia DAM allows Forceful Browsing
High
CVE-2025-9954
was published
for
drupal/acquia_dam
(Composer)
Oct 30, 2025
Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass
High
CVE-2025-12466
was published
for
drupal/simple_oauth
(Composer)
Oct 30, 2025
Drupal Umami Analytics allows Cross-Site Scripting (XSS)
Low
CVE-2025-10931
was published
for
drupal/umami_analytics
(Composer)
Oct 30, 2025
Drupal Reverse Proxy Header allows Manipulating User-Controlled Variables
Moderate
CVE-2025-10929
was published
for
drupal/reverse_proxy_header
(Composer)
Oct 30, 2025
Drupal Currency allows Cross Site Request Forgery
Moderate
CVE-2025-10930
was published
for
drupal/currency
(Composer)
Oct 30, 2025
Drupal JSON Field is vulnerable to XSS
Moderate
CVE-2025-10926
was published
for
drupal/json_field
(Composer)
Oct 30, 2025
ProTip!
Advisories are also available from the
GraphQL API