GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,653
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,860
Pub
13
RubyGems
1,050
Rust
1,304
Swift
53
Unreviewed advisories
All unreviewed
5,000+
3,175 advisories
Filter by severity
AzuraCast has Missing Permissions Check on Media File Download, Allowing Cross-Station Data Exfiltration
Moderate
GHSA-qff7-q5fm-8p76
was published
for
azuracast/azuracast
(Composer)
May 4, 2026
AzuraCast's Missing RequireInternalConnection on Liquidsoap API Allows Low-Privilege Metadata Injection and Broadcast Disruption
Moderate
GHSA-4fm3-ggg2-c6qx
was published
for
azuracast/azuracast
(Composer)
May 4, 2026
CI4MS has a Deactivated User Session Bypass (active=0)
Moderate
CVE-2026-41891
was published
for
ci4-cms-erp/ci4ms
(Composer)
May 4, 2026
CI4MS Vulnerable to Arbitrary Database Table Drop via Theme deleteProcess
Moderate
CVE-2026-41890
was published
for
ci4-cms-erp/ci4ms
(Composer)
May 4, 2026
nova-toggle-5: Improper authorization on toggle endpoint allowed non-Nova users to modify boolean fields
Moderate
CVE-2026-42202
was published
for
almirhodzic/nova-toggle-5
(Composer)
Apr 24, 2026
Kirby CMS's system API endpoint leaks installed version and license data to authenticated users
Moderate
CVE-2026-42051
was published
for
getkirby/cms
(Composer)
May 4, 2026
Kirby CMS doesn't gate user avatar creation, replacement and deletion with user update permissions
Moderate
CVE-2026-42174
was published
for
getkirby/cms
(Composer)
May 4, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
Moderate
CVE-2026-41887
was published
for
flarum/core
(Composer)
Apr 22, 2026
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
Moderate
CVE-2026-41201
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 22, 2026
Withdrawn Advisory: Kirby CMS has Persistent DoS via Malformed Image Upload
Moderate
CVE-2026-29905
was published
for
getkirby/cms
(Composer)
Mar 27, 2026
•
withdrawn
Admidio: OIDC Token Introspection Endpoint Returns Active for All Tokens Without Validation
Moderate
CVE-2026-41671
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio Missing Minimum Administrator Check in Role Membership Removal
Moderate
CVE-2026-41662
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio vulnerable to reflected XSS in msg_window.php via Square Bracket to HTML Tag Conversion
Moderate
CVE-2026-41661
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio's Missing Authorization on Inventory Module Destructive Endpoints Allows Any Authenticated User to Delete Items
Moderate
CVE-2026-41658
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio Exposes Cross-Organization Member Data via Permission Check Mismatch in contacts_data.php
Moderate
CVE-2026-41657
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio has Path Traversal via Unvalidated `name` Parameter in Document Add Mode that Enables Arbitrary Server File Read
Moderate
CVE-2026-41656
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio has Path Traversal in ECard Preview that Allows Reading Arbitrary Server Files Including Database Credentials
Moderate
CVE-2026-41655
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
OpenID Connect nonce generated but never validated — ID token replay attack
Moderate
CVE-2026-42206
was published
for
roadiz/openid
(Composer)
Apr 29, 2026
PhpSpreadsheet has XSS via number format code with @ text placeholder bypasses htmlspecialchars in HTML writer
Moderate
CVE-2026-40296
was published
for
phpoffice/phpspreadsheet
(Composer)
Apr 28, 2026
PhpSpreadsheet has XSS via NumberFormat @ Text Substitution in HTML Writer
Moderate
CVE-2026-35453
was published
for
phpoffice/phpspreadsheet
(Composer)
Apr 28, 2026
FacturaScripts has Insecure Parameter Handling: Unauthorized Modification of Immutable 'nick' Field
Moderate
CVE-2026-32699
was published
for
facturascripts/facturascripts
(Composer)
Apr 28, 2026
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
Moderate
CVE-2026-1323
was published
for
cpsit/typo3-mailqueue
(Composer)
Mar 18, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Moderate
CVE-2026-40099
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
Kirby has XML injection in its XML creator toolkit
Moderate
CVE-2026-32870
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
OpenMage LTS: Cross-user wishlist import leads to private option & file disclosure
Moderate
CVE-2026-40098
was published
for
openmage/magento-lts
(Composer)
Apr 21, 2026
ProTip!
Advisories are also available from the
GraphQL API