GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,479
Maven
5,000+
npm
5,000+
NuGet
886
pip
4,740
Pub
13
RubyGems
1,031
Rust
1,225
Swift
53
Unreviewed advisories
All unreviewed
5,000+
5,567 advisories
Filter by severity
rhukster/dom-sanitizer: SVG <style> tag allows CSS injection via unfiltered url() and @import directives
Moderate
GHSA-93vf-569f-22cq
was published
for
rhukster/dom-sanitizer
(Composer)
Apr 10, 2026
phpseclib has a variable-time HMAC comparison in SSH2::get_binary_packet() using != instead of hash_equals()
Low
CVE-2026-40194
was published
for
phpseclib/phpseclib
(Composer)
Apr 10, 2026
REDAXO has reflected XSS backend packages API via function parameter (CSRF token required)
Low
GHSA-xq4j-g85q-wf97
was published
for
redaxo/source
(Composer)
Apr 10, 2026
REDAXO has reflected XSS in backend Metainfo API via type parameter (CSRF token required)
Low
GHSA-m662-8jrj-cw6v
was published
for
redaxo/source
(Composer)
Apr 10, 2026
Laravel Passport: TokenGuard Authenticates Unrelated User for Client Credentials Tokens
High
GHSA-349c-2h2f-mxf6
was published
for
laravel/passport
(Composer)
Apr 8, 2026
CI4MS Vulnerable to .env CRLF Injection via Unvalidated `host` Parameter in Install Controller
High
CVE-2026-39394
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 8, 2026
CI4MS Vulnerable to Post-Installation Re-entry via Cache-Dependent Install Guard Bypass
High
CVE-2026-39393
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 8, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
Moderate
CVE-2026-39392
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 8, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
Moderate
CVE-2026-39391
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 8, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
Moderate
CVE-2026-39390
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 8, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
Moderate
CVE-2026-39389
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 8, 2026
WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and enable internal response exfiltration (Incomplete fix for CVE-2026-27732)
High
CVE-2026-39370
was published
for
WWBN/AVideo
(Composer)
Apr 8, 2026
WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files through public media URLs
High
CVE-2026-39369
was published
for
WWBN/AVideo
(Composer)
Apr 8, 2026
WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal services
Moderate
CVE-2026-39368
was published
for
WWBN/AVideo
(Composer)
Apr 8, 2026
WWBN AVideo has Stored XSS via Malicious EPG XML Program Titles in AVideo EPG Page
Moderate
CVE-2026-39367
was published
for
wwbn/avideo
(Composer)
Apr 8, 2026
WWBN AVideo Affected by a PayPal IPN Replay Attack Enabling Wallet Balance Inflation via Missing Transaction Deduplication in ipn.php
Moderate
CVE-2026-39366
was published
for
wwbn/avideo
(Composer)
Apr 8, 2026
yaffa vulnerable to Cross Site Scripting
Moderate
CVE-2025-70844
was published
for
kantorge/yaffa
(Composer)
Apr 7, 2026
PocketMine-MP: Player entities can still die and drop items in flaggedForDespawn state
Low
GHSA-f9jp-856v-8642
was published
for
pocketmine/pocketmine-mp
(Composer)
Apr 6, 2026
PocketMine-MP: Network amplification vulnerability with `ActorEventPacket`
Moderate
GHSA-7hmv-4j2j-pp6f
was published
for
pocketmine/pocketmine-mp
(Composer)
Apr 6, 2026
PocketMine-MP: JSON decoding of unlimited size large arrays/objects in ModalFormResponse Handling
High
GHSA-788v-5pfp-93ff
was published
for
pocketmine/pocketmine-mp
(Composer)
Apr 6, 2026
PocketMine-MP: LogDoS by large complex unknown property logging in clientData in LoginPacket
High
GHSA-h6rj-3m53-887h
was published
for
pocketmine/pocketmine-mp
(Composer)
Apr 6, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the creation/editing module
Moderate
CVE-2026-31313
was published
for
feehi/cms
(Composer)
Apr 6, 2026
Feehi CMS has authenticated stored cross-site scripting (XSS) vulnerabilities via the Permissions module
Moderate
CVE-2026-31354
was published
for
feehi/cms
(Composer)
Apr 6, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Category module
Moderate
CVE-2026-31353
was published
for
feehi/cms
(Composer)
Apr 6, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the creation/editing module
Moderate
CVE-2026-31351
was published
for
feehi/cms
(Composer)
Apr 6, 2026
ProTip!
Advisories are also available from the
GraphQL API