GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
42 advisories
Filter by severity
Authentication Bypass in ADOdb/ADOdb
Critical
CVE-2021-3850
was published
for
adodb/adodb-php
(Composer)
Jan 27, 2022
MantisBT HTML Injection vulnerability
Moderate
CVE-2020-25830
was published
for
mantisbt/mantisbt
(Composer)
May 24, 2022
MantisBT Host Header Injection vulnerability
High
CVE-2024-23830
was published
for
mantisbt/mantisbt
(Composer)
Feb 20, 2024
Mantis Bug Tracker (MantisBT) allows user account takeover in the signup/reset password process
High
CVE-2024-34077
was published
for
mantisbt/mantisbt
(Composer)
May 13, 2024
MantisBT Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2024-34080
was published
for
mantisbt/mantisbt
(Composer)
May 13, 2024
Mantis Bug Tracker (MantisBT) vulnerable to cross-site scripting
Moderate
CVE-2024-34081
was published
for
mantisbt/mantisbt
(Composer)
May 13, 2024
MantisBT vulnerable to information disclosure with user profiles
Moderate
CVE-2024-45792
was published
for
mantisbt/mantisbt
(Composer)
Sep 30, 2024
SQL injection in ADOdb PostgreSQL driver pg_insert_id() method
Critical
CVE-2025-46337
was published
for
adodb/adodb-php
(Composer)
May 1, 2025
The ADOdb sqlite3 driver allows SQL injection
Critical
CVE-2025-54119
was published
for
adodb/adodb-php
(Composer)
Aug 4, 2025
MantisBT vulnerable to authentication bypass for some passwords due to PHP type juggling
High
CVE-2025-47776
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
MantisBT Vulnerable to Denial-of-Service (DoS) via Excessive Note Length
Moderate
CVE-2025-46556
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
MantisBT lacks verification when changing a user's email address
Moderate
CVE-2025-55155
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
MantisBT unauthorized disclosure of private project column configuration
Moderate
CVE-2025-62520
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
MantisBT is vulnerable to authentication bypass through the SOAP API on MySQL
Critical
CVE-2026-30849
was published
for
mantisbt/mantisbt
(Composer)
Mar 23, 2026
MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmation
High
CVE-2026-33517
was published
for
mantisbt/mantisbt
(Composer)
Mar 25, 2026
MantisBT has Stored HTML Injection/XSS when displaying Tags in Timeline
High
CVE-2026-33548
was published
for
mantisbt/mantisbt
(Composer)
Mar 25, 2026
MantisBT Has Authorization Bypass in Global Profile Creation
Moderate
CVE-2026-33052
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT Vulnerable to Privilege Escalation from Manager to Administrator
Moderate
CVE-2026-34390
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT is Vulnerable to Stored HTML Injection/XSS in Clone Issue Form
High
CVE-2026-34463
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT has an authorization bypass in private issue monitoring
Moderate
CVE-2026-34579
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT has an authorization bypass that allows reading attachments after losing access to a private issue
Moderate
CVE-2026-34744
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT has an Authorization Bypass that Allows Uploading Attachments to Private Issues via REST API
Moderate
CVE-2026-34754
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT: Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is Revoked
Moderate
CVE-2026-34970
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT is Vulnerable to Stored XSS in Custom Field Textarea Values
Moderate
CVE-2026-39960
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT is Vulnerable to XSS leading to account takeover via updating a user's font family preference
High
CVE-2026-40596
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
ProTip!
Advisories are also available from the
GraphQL API