GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,340
Maven
5,000+
npm
5,000+
NuGet
1,033
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
6,236 advisories
Filter by severity
Formie: Missing authorization in administrative settings allows low-privileged CP users to modify plugin configuration
Moderate
GHSA-cvpc-hccg-wmw4
was published
for
verbb/formie
(Composer)
Jul 17, 2026
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
Critical
CVE-2026-55579
was published
for
pheditor/pheditor
(Composer)
Jul 16, 2026
Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection
High
CVE-2026-55578
was published
for
pheditor/pheditor
(Composer)
Jul 16, 2026
Pheditor has an authenticated terminal command whitelist bypass
High
CVE-2026-54540
was published
for
pheditor/pheditor
(Composer)
Jul 16, 2026
adawolfa/isdoc: Uncontrolled resource consumption (decompression bomb) when reading untrusted ISDOCX or PDF files
Moderate
GHSA-xg43-5579-qw6v
was published
for
adawolfa/isdoc
(Composer)
Jul 15, 2026
MantisBT: Stored XSS in print_all_bug_page_word.php
High
CVE-2026-62944
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs
Moderate
CVE-2026-52883
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters
Moderate
CVE-2026-52882
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: Reflected XSS in admin/install.php via unescaped printf
Critical
CVE-2026-52881
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: Reflected XSS in admin/install.php
Critical
CVE-2026-52847
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
Koel: Full-read SSRF via podcast enclosure URL: isPublicHost() filter_var guard does not reject NAT64 (64:ff9b::/96) or 6to4 (2002::/16) IPv6-transition wrappers of internal IPv4
Moderate
CVE-2026-54494
was published
for
phanan/koel
(Composer)
Jul 15, 2026
Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail
Moderate
CVE-2026-50552
was published
for
phanan/koel
(Composer)
Jul 15, 2026
Koel: Incomplete fix for CVE-2026-47260 — systemic SSRF in podcast & radio fetch paths
High
CVE-2026-54491
was published
for
phanan/koel
(Composer)
Jul 15, 2026
Koel has SSRF through Authenticated Subsonic podcast feed URLs
Moderate
GHSA-8q6q-m837-fv64
was published
for
phanan/koel
(Composer)
Jul 15, 2026
Koel: Authenticated Full-Read SSRF via Subsonic Internet Radio Stations
High
CVE-2026-54493
was published
for
phanan/koel
(Composer)
Jul 15, 2026
Koel: Authenticated Blind SSRF via Subsonic Podcast Channel Creation
Moderate
CVE-2026-54492
was published
for
phanan/koel
(Composer)
Jul 15, 2026
MantisBT: REST API unauthorized Issue status change
Moderate
CVE-2026-49280
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php
High
CVE-2026-49273
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator
Critical
CVE-2026-47156
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: SQL Injection via history_order Configuration Value
High
CVE-2026-47142
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE
Critical
GHSA-hgjx-r89m-m7v4
was published
for
facturascripts/facturascripts
(Composer)
Jul 14, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
High
CVE-2026-54087
was published
for
easycorp/easyadmin-bundle
(Composer)
Jul 14, 2026
Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter
Moderate
CVE-2026-50157
was published
for
auth0/symfony
(Composer)
Jul 14, 2026
FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`
Low
CVE-2026-45710
was published
for
facturascripts/facturascripts
(Composer)
Jul 14, 2026
FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export
High
CVE-2026-45263
was published
for
facturascripts/facturascripts
(Composer)
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API