GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
445 advisories
Filter by severity
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete
Low
CVE-2026-8409
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id)
Low
CVE-2026-8427
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate
Low
CVE-2026-8414
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star()
Low
CVE-2026-8432
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple()
Low
CVE-2026-8434
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder
Low
CVE-2026-8415
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id)
Low
CVE-2026-8416
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design
Low
CVE-2026-8413
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file approveVersion()
Low
CVE-2026-8435
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete
Low
CVE-2026-8411
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache
Low
CVE-2026-8412
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan()
Low
CVE-2026-8433
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to Stored XSS via external-link page cvName
Low
CVE-2026-8139
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to IDOR in AddMessage/UpdateMessage
Low
CVE-2026-7886
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS's RSS Displayer block accepts a feed URL from any page editor and fetches it server-side without validation
Low
CVE-2026-7890
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS: OAuth 2.0 Authorization-Code Handler Bypasses Account Status
Low
CVE-2026-7887
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Concrete CMS is vulnerable to unauthorized file deletion
Low
CVE-2026-7882
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Twig: HTML-output filters in twig/* extras incorrectly declared `is_safe => ['all']`
Low
CVE-2026-46637
was published
for
twig/cssinliner-extra
(Composer)
May 21, 2026
Twig: Sandbox property allowlist bypass via the `column` filter (array_column on objects)
Low
CVE-2026-46635
was published
for
twig/twig
(Composer)
May 21, 2026
twig/intl-extra: Unbounded formatter memoisation in keyed on template-controlled arguments
Low
CVE-2026-46629
was published
for
twig/intl-extra
(Composer)
May 21, 2026
Twig: The `spaceless` filter implicitly marks its output as safe
Low
CVE-2026-46628
was published
for
twig/twig
(Composer)
May 21, 2026
Sulu: Used API Keys may be available via Admin API
Low
GHSA-9m6v-8fxc-4r44
was published
for
sulu/sulu
(Composer)
May 18, 2026
LibreNMS: Cross-Site Scripting in ShowConfigController
Low
CVE-2026-2728
was published
for
librenms/librenms
(Composer)
May 18, 2026
Webauthn has a User Verification Downgrade via Default-Open ClientOverridePolicy
Low
GHSA-h4fw-6r7f-w494
was published
for
web-auth/webauthn-framework
(Composer)
May 7, 2026
FacturaScripts vulnerable to Reflected Cross-Site Scripting (XSS) via Cookie Manipulation
Low
CVE-2026-27964
was published
for
facturascripts/facturascripts
(Composer)
May 7, 2026
ProTip!
Advisories are also available from the
GraphQL API