GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
52 advisories
Filter by severity
Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets
High
CVE-2026-50284
was published
for
craftcms/cms
(Composer)
Jul 2, 2026
Admidio has IDOR in `documents-files.php` `mode=move_save` that lets any folder-uploader exfiltrate files from private folders
High
CVE-2026-47231
was published
for
admidio/admidio
(Composer)
May 29, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
CVE-2026-45368
was published
for
getkirby/cms
(Composer)
May 27, 2026
Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup
High
CVE-2026-44177
was published
for
getkirby/cms
(Composer)
May 26, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
CVE-2026-44175
was published
for
getkirby/cms
(Composer)
May 26, 2026
AVideo: OS command injection in on_publish.php execAsync via unescaped m3u8 URL
High
CVE-2026-45578
was published
for
WWBN/AVideo
(Composer)
May 15, 2026
AVideo's Meet plugin: `uploadRecordedVideo.json.php` derives `users_id` from the uploaded filename and calls passwordless `User->login()`, allowing any caller with the Meet shared secret to obtain a session as arbitrary users including admin
High
GHSA-qxvm-r42f-5p8j
was published
for
WWBN/AVideo
(Composer)
May 15, 2026
Craft CMS's Missing Volume Permission Check in AssetsController::actionShowInFolder Allows Information Disclosure
High
CVE-2026-44012
was published
for
craftcms/cms
(Composer)
May 6, 2026
AVideo has an Incomplete Fix for YPTSocket autoEvalCodeOnHTML Strip: Unauthenticated Cross-User JavaScript Execution via `$msg['json']` Relay Bypass
High
CVE-2026-43874
was published
for
wwbn/avideo
(Composer)
May 5, 2026
AVideo: Unauthenticated Disclosure of CloneSite `myKey` via Error Echo in `cloneClient.json.php` Enables Cross-Site DB Dump of the Configured Clone Server
High
CVE-2026-43873
was published
for
wwbn/avideo
(Composer)
May 5, 2026
AzuraCast Vulnerable to Liquidsoap Code Injection via Incomplete cleanUpString-to-toRawString Migration in Remote Relay Password Field
High
GHSA-q4ph-8x8g-95f8
was published
for
azuracast/azuracast
(Composer)
May 4, 2026
AzuraCast has Password Reset Poisoning via Untrusted X-Forwarded-Host Header that Leads to Account Takeover and 2FA Bypass
High
CVE-2026-42606
was published
for
azuracast/azuracast
(Composer)
May 4, 2026
AzuraCast has Path Traversal in `currentDirectory` Parameter that Enables Remote Code Execution via Media Upload
High
CVE-2026-42605
was published
for
azuracast/azuracast
(Composer)
May 4, 2026
Admidio Sends SAML Response to Unvalidated Assertion Consumer Service URL from AuthnRequest
High
CVE-2026-41670
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio Ignores SAML Signature Validation Result, Processes Forged AuthnRequests and LogoutRequests
High
CVE-2026-41669
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
PhpSpreadsheet has CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions
High
CVE-2026-40902
was published
for
phpoffice/phpspreadsheet
(Composer)
Apr 29, 2026
PhpSpreadsheet has CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader
High
CVE-2026-40863
was published
for
phpoffice/phpspreadsheet
(Composer)
Apr 29, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
CVE-2026-41325
was published
for
getkirby/cms
(Composer)
Apr 24, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
CVE-2026-34587
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()
High
CVE-2026-41230
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
Froxlor has Incomplete Symlink Validation in DataDump.add() Allows Arbitrary Directory Ownership Takeover via Cron
High
CVE-2026-41231
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
WWBN AVideo has a SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL
High
CVE-2026-41060
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
WWBN AVideo has a CORS Origin Reflection Bypass via plugin/API/router.php and allowOrigin(true) Exposes Authenticated API Responses
High
CVE-2026-41057
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
WWBN AVideo has CORS Origin Reflection with Credentials on Sensitive API Endpoints Enables Cross-Origin Account Takeover
High
CVE-2026-41056
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
WWBN AVideo has Multiple CSRF Vulnerabilities in Admin JSON Endpoints (Category CRUD, Plugin Update Script)
High
CVE-2026-40926
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
ProTip!
Advisories are also available from the
GraphQL API