GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
172,613 advisories
Filter by severity
The PDF Builder for WooCommerce. Create invoices,packing slips and more plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-11899
was published
Sep 19, 2026
The WP Customer Reviews plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2026-11608
was published
Sep 19, 2026
The OTP Login & Register Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2026-12402
was published
Sep 19, 2026
The Create plugin for WordPress is vulnerable to generic SQL Injection via the 'order' parameter...
Moderate
Unreviewed
CVE-2026-13200
was published
Sep 19, 2026
The Real3D Flipbook Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2026-15098
was published
Sep 19, 2026
The AppMySite – WordPress & WooCommerce Mobile App Builder (No-Code Android & iOS App Maker)...
Moderate
Unreviewed
CVE-2026-13770
was published
Sep 19, 2026
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.3 does...
Moderate
Unreviewed
CVE-2026-92421
was published
Sep 19, 2026
The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.4 does...
Moderate
Unreviewed
CVE-2026-92425
was published
Sep 19, 2026
The Rede Itaú for WooCommerce — Payment PIX, Credit Card and Debit WordPress plugin before 5.4.7...
Moderate
Unreviewed
CVE-2026-92430
was published
Sep 19, 2026
The Online Scheduling and Appointment Booking System WordPress plugin before 28.2 does not...
Moderate
Unreviewed
CVE-2026-91847
was published
Sep 19, 2026
The Mailchimp for WooCommerce WordPress plugin before 6.1.1 does not verify that the requesting...
Moderate
Unreviewed
CVE-2026-92435
was published
Sep 19, 2026
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not...
Moderate
Unreviewed
CVE-2026-19860
was published
Sep 19, 2026
The Nimble Page Builder WordPress plugin through 3.3.8 does not perform an authorization check...
Moderate
Unreviewed
CVE-2026-16557
was published
Sep 19, 2026
The Ultra Addons for Contact Form 7 WordPress plugin before 3.5.51 does not validate the type or...
Moderate
Unreviewed
CVE-2026-84750
was published
Sep 19, 2026
The Pochipp plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'keyword...
Moderate
Unreviewed
CVE-2026-92967
was published
Sep 19, 2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for...
Moderate
Unreviewed
CVE-2026-89093
was published
Sep 19, 2026
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-89081
was published
Sep 19, 2026
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-89333
was published
Sep 19, 2026
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-88944
was published
Sep 19, 2026
The Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots plugin for...
Moderate
Unreviewed
CVE-2026-89334
was published
Sep 19, 2026
The WP2Social Auto Publish plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2026-12042
was published
Sep 19, 2026
The Divi Essential plugin for WordPress is vulnerable to sensitive information exposure in...
Moderate
Unreviewed
CVE-2026-15760
was published
Sep 19, 2026
The SEO Booster plugin for WordPress is vulnerable to Missing Authorization in versions up to,...
Moderate
Unreviewed
CVE-2026-15660
was published
Sep 19, 2026
The WPComplete plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'empty'...
Moderate
Unreviewed
CVE-2026-77820
was published
Sep 19, 2026
SiYuan versions through 3.8.4 fail to enforce publish access control in the getDynamicIcon...
Moderate
Unreviewed
CVE-2026-93921
was published
Sep 19, 2026
ProTip!
Advisories are also available from the
GraphQL API