GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
6,441 advisories
Filter by severity
phpMyFAQ public FAQ APIs expose inactive FAQ content
Moderate
GHSA-mf8r-wm2w-f8c5
was published
for
phpmyfaq/phpmyfaq
(Composer)
Aug 25, 2026
phpMyFAQ has Potential Authenticated Path Traversal in PDF Export
Moderate
GHSA-88g4-74f3-63x9
was published
for
phpmyfaq/phpmyfaq
(Composer)
Aug 25, 2026
YOURLS has stored XSS in referrer statistics chart via crafted Referer header
High
CVE-2026-63135
was published
for
yourls/yourls
(Composer)
Aug 21, 2026
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)
Critical
CVE-2026-59989
was published
for
phalcon/cphalcon
(Composer)
Aug 21, 2026
Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox's assets.addJs/addCss allowlist, escalating to super-admin
Moderate
GHSA-8hgv-xc77-jmcr
was published
for
getgrav/grav
(Composer)
Aug 21, 2026
Winter: Reflected XSS through the search query parameter in the backend Table widget
Moderate
GHSA-hq84-x37p-j6q5
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Winter: CSRF through AJAX handler names reachable as backend page actions
Moderate
GHSA-p2ch-c2c3-4xm5
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles
Moderate
GHSA-5cwr-5jxg-pcf6
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
High
GHSA-fm29-4mq3-phg6
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Winter: My Account preview exposes another backend user's profile by record ID
Moderate
GHSA-mpmw-f6h6-3g26
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Winter: Stored XSS through Backend List widget image columns
Low
GHSA-7mpf-4465-7fc2
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)
High
GHSA-8cfw-pcwh-v63w
was published
for
winter/wn-system-module
(Composer)
Aug 20, 2026
Winter: Local File Inclusion through =include directives in JavaScript asset compilation
Moderate
GHSA-2223-f22x-24cq
was published
for
winter/wn-system-module
(Composer)
Aug 20, 2026
Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets
Moderate
CVE-2026-63179
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: HasMany/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelation
Moderate
CVE-2026-57570
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata
Moderate
CVE-2026-54256
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)
High
CVE-2026-54182
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: Stored XSS in the color column — the `@if($column['escaped'])` branches are inverted
Moderate
CVE-2026-54181
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)
High
CVE-2026-54180
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: SingleBase64Image accepts any base64 payload behind a `data:image` prefix — SVG-with-script lands on the public disk
Moderate
CVE-2026-54179
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisk
High
CVE-2026-54178
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: HasUploadFields keeps the attacker-supplied file extension — public-disk uploads of `shell.php` reach the webserver
Moderate
CVE-2026-54177
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check
Moderate
CVE-2026-54176
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: Unverified password change in MyAccountController via mass assignment
High
CVE-2026-54175
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems
High
CVE-2026-62673
was published
for
getgrav/grav
(Composer)
Aug 19, 2026
ProTip!
Advisories are also available from the
GraphQL API