Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.

150,381 advisories

Loading
Unauthenticated Broken Access Control in Civi <= 2.2.4 versions. Moderate Unreviewed
CVE-2026-65476 was published Jul 23, 2026
Subscriber Broken Access Control in ListingPro <= 2.9.10 versions. Moderate Unreviewed
CVE-2026-65478 was published Jul 23, 2026
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions. Moderate Unreviewed
CVE-2026-65474 was published Jul 23, 2026
Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions. Moderate Unreviewed
CVE-2026-65457 was published Jul 23, 2026
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. Moderate Unreviewed
CVE-2026-65453 was published Jul 23, 2026
Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions. Moderate Unreviewed
CVE-2026-65452 was published Jul 23, 2026
Contributor Sensitive Data Exposure in Polylang <= 3.8.5 versions. Moderate Unreviewed
CVE-2026-65458 was published Jul 23, 2026
Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions. Moderate Unreviewed
CVE-2026-65460 was published Jul 23, 2026
Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions. Moderate Unreviewed
CVE-2026-61972 was published Jul 23, 2026
Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions. Moderate Unreviewed
CVE-2026-61973 was published Jul 23, 2026
Contributor Cross Site Scripting (XSS) in MapSVG <= 8.14.0 versions. Moderate Unreviewed
CVE-2026-65449 was published Jul 23, 2026
Subscriber Arbitrary Content Deletion in WP EasyPay <= 4.5.0 versions. Moderate Unreviewed
CVE-2026-57808 was published Jul 23, 2026
Subscriber Broken Access Control in Sunshine Photo Cart <= 3.6.10.1 versions. Moderate Unreviewed
CVE-2026-57703 was published Jul 23, 2026
Unauthenticated Broken Access Control in Knit Pay <= 9.6.0.0 versions. Moderate Unreviewed
CVE-2026-57717 was published Jul 23, 2026
Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions. Moderate Unreviewed
CVE-2026-57716 was published Jul 23, 2026
Subscriber Broken Access Control in WP ERP <= 1.17.5 versions. Moderate Unreviewed
CVE-2026-59522 was published Jul 23, 2026
Unauthenticated Broken Authentication in Easy Digital Downloads <= 3.6.7 versions. Moderate Unreviewed
CVE-2026-59524 was published Jul 23, 2026
Subscriber Cross Site Scripting (XSS) in Masteriyo - LMS <= 2.3.0 versions. Moderate Unreviewed
CVE-2026-59513 was published Jul 23, 2026
ProTip! Advisories are also available from the GraphQL API