GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,535
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,515
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
136 advisories
Filter by severity
Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
High
CVE-2026-56382
was published
for
craftcms/cms
(Composer)
Jul 9, 2026
Duplicate Advisory: Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
High
GHSA-pmm4-v8f6-4vpp
was published
for
craftcms/cms
(Composer)
Jun 21, 2026
•
withdrawn
Craft CMS: Potential authenticated Remote Code Execution via referrer redirect
High
CVE-2026-55794
was published
for
craftcms/cms
(Composer)
Jul 6, 2026
CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration
High
CVE-2026-41249
was published
for
coreshop/core-shop
(Composer)
May 14, 2026
Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
High
CVE-2026-46640
was published
for
twig/twig
(Composer)
May 21, 2026
AVideo has an Incomplete Fix for YPTSocket autoEvalCodeOnHTML Strip: Unauthenticated Cross-User JavaScript Execution via `$msg['json']` Relay Bypass
High
CVE-2026-43874
was published
for
wwbn/avideo
(Composer)
May 5, 2026
Krayin CRM allows a remote attacker to execute arbitrary code via compose email function
High
CVE-2026-36340
was published
for
krayin/laravel-crm
(Composer)
Apr 30, 2026
AzuraCast Vulnerable to Liquidsoap Code Injection via Incomplete cleanUpString-to-toRawString Migration in Remote Relay Password Field
High
GHSA-q4ph-8x8g-95f8
was published
for
azuracast/azuracast
(Composer)
May 4, 2026
Dolibarr Allows Code Injection through its Website Module
High
CVE-2026-31018
was published
for
dolibarr/dolibarr
(Composer)
Apr 21, 2026
Statamic vulnerable to remote code execution via Antlers-enabled control panel inputs
High
CVE-2026-28425
was published
for
statamic/cms
(Composer)
Mar 1, 2026
Connect-CMS has Arbitrary Code Execution by an Authenticated User in its Code Study Plugin
High
CVE-2026-32276
was published
for
opensource-workshop/connect-cms
(Composer)
Mar 23, 2026
AVideo has PHP Code Injection via eval() in Gallery saveSort.json.php Exploitable Through CSRF Against Admin
High
CVE-2026-33479
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
TYPO3 Image Processing susceptible to Code Execution
High
CVE-2019-11832
was published
for
typo3/cms
(Composer)
May 24, 2022
CraftCMS has an RCE vulnerability via relational conditionals in the control panel
High
CVE-2026-31857
was published
for
craftcms/cms
(Composer)
Mar 11, 2026
AzuraCast: RCE via Liquidsoap string interpolation injection in station metadata and playlist URLs
High
GHSA-93fx-5qgc-wr38
was published
for
azuracast/azuracast
(Composer)
Mar 9, 2026
Code Injection in microweber
High
CVE-2022-0282
was published
for
microweber/microweber
(Composer)
Jan 21, 2022
Moodle has a Remote Code Execution risk via file restore
High
CVE-2026-26045
was published
for
moodle/moodle
(Composer)
Feb 21, 2026
Moodle affected by a code injection vulnerability
High
CVE-2025-67847
was published
for
moodle/moodle
(Composer)
Jan 23, 2026
Shopware Has Improper Control of Generation of Code in Twig rendered views
High
CVE-2026-23498
was published
for
shopware/core
(Composer)
Jan 14, 2026
Shopware Has Improper Control of Generation of Code in Twig rendered views
High
CVE-2023-2017
was published
for
shopware/core
(Composer)
Apr 18, 2023
Neuron MySQLSelectTool “read-only” bypass via `SELECT ... INTO OUTFILE` (file write → potential RCE)
High
CVE-2025-67509
was published
for
neuron-core/neuron-ai
(Composer)
Dec 9, 2025
Grav is vulnerable to RCE via SSTI through Twig Sandbox Bypass
High
CVE-2025-66294
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is Vulnerable to Security Sandbox Bypass with SSTI (Server Side Template Injection)
High
CVE-2025-66299
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
REDAXO CMS is vulnerable to RCE attack through its template management component
High
CVE-2025-64050
was published
for
redaxo/source
(Composer)
Nov 25, 2025
Smarty vulnerable to PHP Code Injection by malicious attribute in extends-tag
High
CVE-2024-35226
was published
for
smarty/smarty
(Composer)
May 29, 2024
ProTip!
Advisories are also available from the
GraphQL API