GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,739
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
40 advisories
Filter by severity
Poweradmin: Broken access control (IDOR): any zone owner can modify DNS records in zones they do not own
High
GHSA-rm67-g9ch-vxff
was published
for
poweradmin/poweradmin
(Composer)
Jul 24, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
High
CVE-2026-34572
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 1, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
High
CVE-2026-34570
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 1, 2026
Admidio allows Unauthenticated Access to Role-Restricted documents via neutralized .htaccess
High
CVE-2026-34381
was published
for
admidio/admidio
(Composer)
Mar 31, 2026
Connect CMS: Information Disclosure Due to Improper Authorization through the Page Content Retrieval Feature
High
CVE-2026-32299
was published
for
opensource-workshop/connect-cms
(Composer)
Mar 23, 2026
Pterodactyl Panel's SFTP sessions remain active after user account deletion or password change
High
GHSA-hr7j-63v7-vj7g
was published
for
github.com/pterodactyl/wings
(Composer)
Feb 17, 2026
Bagisto has IDOR in Customer Order Reorder Functionality
High
CVE-2026-21447
was published
for
bagisto/bagisto
(Composer)
Jan 2, 2026
phpMyFAQ duplicate email registration allows multiple accounts with the same email
High
CVE-2025-59943
was published
for
thorsten/phpmyfaq
(Composer)
Oct 3, 2025
UnoPim has Broken Access Control
High
CVE-2025-55741
was published
for
unopim/unopim
(Composer)
Aug 22, 2025
yag and pt_extbase extensions for TYPO3 allow remote attackers to bypass access restrictions
High
CVE-2014-6289
was published
for
dl/yag
(Composer)
May 17, 2022
Frontend User Registration extension for TYPO3 does not properly verify access rights
High
CVE-2009-1264
was published
for
sjbr/sr-feuser-register
(Composer)
May 2, 2022
TastyIgniter Has an Incorrect Access Control Vulnerability via `invoice()` Function
High
CVE-2024-44313
was published
for
tastyigniter/tastyigniter
(Composer)
Mar 18, 2025
Mautic vulnerable to Improper Access Control in UI upgrade process
High
CVE-2022-25768
was published
for
mautic/core
(Composer)
Sep 18, 2024
Magento Improper Access Control vulnerability
High
CVE-2025-24411
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Studio 42 elFinder vulnerable to Incorrect Access Control
High
CVE-2024-38909
was published
for
studio-42/elfinder
(Composer)
Jul 30, 2024
Magento Open Source Improper Access Control vulnerability
High
CVE-2024-45118
was published
for
magento/community-edition
(Composer)
Oct 10, 2024
Dolibarr vulnerable to Cross-Site Request Forgery
High
CVE-2024-31503
was published
for
dolibarr/dolibarr
(Composer)
Apr 17, 2024
BookStack Incorrect Access Control vulnerability
High
CVE-2024-36676
was published
for
ssddanbrown/bookstack
(Composer)
Jul 10, 2024
Exposure of Resource to Wrong Sphere in ThinkPHP Framework
High
CVE-2022-25481
was published
for
topthink/framework
(Composer)
Mar 22, 2022
MediaWiki Incorrect Access Control vulnerability
High
CVE-2019-12472
was published
for
mediawiki/core
(Composer)
May 24, 2022
Drupal access control bypass vulnerability
High
CVE-2017-6919
was published
for
drupal/core
(Composer)
May 13, 2022
Drupal access bypass vulnerability
High
CVE-2017-6930
was published
for
drupal/core
(Composer)
May 13, 2022
Drupal Form API ignores access restrictions on submit buttons
High
CVE-2016-3165
was published
for
drupal/core
(Composer)
May 17, 2022
Drupal File upload access bypass and denial of service
High
CVE-2016-3162
was published
for
drupal/core
(Composer)
May 17, 2022
TYPO3 vulnerable to Improper Access Control Persisting File Abstraction Layer Entities via Data Handler
High
CVE-2024-25121
was published
for
typo3/cms-core
(Composer)
Feb 13, 2024
ProTip!
Advisories are also available from the
GraphQL API