GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
239 advisories
Filter by severity
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
High
CVE-2026-64850
was published
for
getgrav/grav
(Composer)
Sep 2, 2026
Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name
Critical
CVE-2026-55634
was published
for
pimcore/pimcore
(Composer)
Aug 28, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
High
CVE-2026-54721
was published
for
silverstripe/userforms
(Composer)
Aug 27, 2026
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)
Critical
CVE-2026-59989
was published
for
phalcon/cphalcon
(Composer)
Aug 21, 2026
jmespath.php has CompilerRuntime code injection via unescaped function names
Critical
CVE-2026-54133
was published
for
mtdowling/jmespath.php
(Composer)
Aug 18, 2026
YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service
Critical
CVE-2026-52778
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
High
CVE-2026-56382
was published
for
craftcms/cms
(Composer)
Jul 9, 2026
EGroupware has a Remote Code Execution Vulnerability
Critical
CVE-2026-27823
was published
for
egroupware/egroupware
(Composer)
Jul 7, 2026
Craft CMS: Potential authenticated Remote Code Execution via referrer redirect
High
CVE-2026-55794
was published
for
craftcms/cms
(Composer)
Jul 6, 2026
Duplicate Advisory: Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
High
GHSA-pmm4-v8f6-4vpp
was published
for
craftcms/cms
(Composer)
Jun 21, 2026
•
withdrawn
Dolibarr ERP CRM contains a remote code evaluation vulnerability
Critical
CVE-2018-25357
was published
for
dolibarr/dolibarr
(Composer)
May 26, 2026
Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
High
CVE-2026-46640
was published
for
twig/twig
(Composer)
May 21, 2026
Twig: PHP code injection via `{% use %}` template name
Critical
CVE-2026-46633
was published
for
twig/twig
(Composer)
May 21, 2026
Formie: Pre-authenticated server-side template injection in Hidden fields
Critical
CVE-2026-45697
was published
for
verbb/formie
(Composer)
May 18, 2026
CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration
High
CVE-2026-41249
was published
for
coreshop/core-shop
(Composer)
May 14, 2026
FacturaScripts Vulnerable to Authenticated Remote Code Execution (RCE) via GIF Image Upload in Product Images
Moderate
CVE-2026-42879
was published
for
facturascripts/facturascripts
(Composer)
May 7, 2026
Scramble vulnerable to remote code execution via evaluation of user-controlled input in validation rules
Critical
CVE-2026-44262
was published
for
dedoc/scramble
(Composer)
May 6, 2026
Grav Vulnerable to Remote Code Execution (RCE) via Malicious Plugin ZIP Upload in Direct Install Feature
Critical
CVE-2026-42607
was published
for
getgrav/grav
(Composer)
May 5, 2026
AVideo has an Incomplete Fix for YPTSocket autoEvalCodeOnHTML Strip: Unauthenticated Cross-User JavaScript Execution via `$msg['json']` Relay Bypass
High
CVE-2026-43874
was published
for
wwbn/avideo
(Composer)
May 5, 2026
AzuraCast Vulnerable to Liquidsoap Code Injection via Incomplete cleanUpString-to-toRawString Migration in Remote Relay Password Field
High
GHSA-q4ph-8x8g-95f8
was published
for
azuracast/azuracast
(Composer)
May 4, 2026
Krayin CRM allows a remote attacker to execute arbitrary code via compose email function
High
CVE-2026-36340
was published
for
krayin/laravel-crm
(Composer)
Apr 30, 2026
Cockpit is vulnerable to arbitrary code execution
Critical
CVE-2026-38992
was published
for
cockpit-hq/cockpit
(Composer)
Apr 29, 2026
Dolibarr Allows Code Injection through its Website Module
High
CVE-2026-31018
was published
for
dolibarr/dolibarr
(Composer)
Apr 21, 2026
Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)
Critical
CVE-2026-41229
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
WWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaScript Execution via Client-Side eval() Sinks
Critical
CVE-2026-40911
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
ProTip!
Advisories are also available from the
GraphQL API