GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,752
Maven
5,000+
npm
4,357
NuGet
765
pip
4,123
Pub
12
RubyGems
961
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
5,082 advisories
Filter by severity
Grav vulnerable to Denial of Service via Improper Input Handling in 'Supported' Parameter
High
CVE-2025-66305
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Information Disclosure via IDOR in Grav Admin Panel
Moderate
CVE-2025-66306
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Path Traversal allowing server files backup
Moderate
CVE-2025-66302
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav Admin Plugin vulnerable to User Enumeration & Email Disclosure
Moderate
CVE-2025-66307
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav Admin Plugin is vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/accounts/groups/[group]` parameter `data[readableName]`
Moderate
CVE-2025-66312
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` in Multiples parameters
Moderate
CVE-2025-66311
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav Exposes Password Hashes Leading to privilege escalation
Moderate
CVE-2025-66304
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is vulnerable to a DOS on the admin panel
Moderate
CVE-2025-66303
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav has Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
High
CVE-2025-66301
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is vulnerable to Arbitrary File Read
High
CVE-2025-66300
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav is Vulnerable to Security Sandbox Bypass with SSTI (Server Side Template Injection)
High
CVE-2025-66299
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Privilege Escalation in Grav Admin: Missing Username Uniqueness Check Allows Admin Account Takeover
High
CVE-2025-66296
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Snipe-IT allows stored XSS via the Locations "Country" field
Moderate
CVE-2025-65622
was published
for
snipe/snipe-it
(Composer)
Dec 2, 2025
Snipe-IT is vulnerable to stored cross-site scripting
Moderate
CVE-2025-65621
was published
for
snipe/snipe-it
(Composer)
Dec 1, 2025
FeehiCMS is vulnerable to reverse tabnabbing
Moderate
CVE-2025-63522
was published
for
feehi/feehicms
(Composer)
Dec 1, 2025
FeehiCMS fails to enforce server-side immutability
Moderate
CVE-2025-63523
was published
for
feehi/feehicms
(Composer)
Dec 1, 2025
FeehiCMS is vulnerable to cross-site scripting via the id parameter of the User Update function
Moderate
CVE-2025-63520
was published
for
feehi/feehicms
(Composer)
Dec 1, 2025
yungifez Skuul School Management System vulnerable to XSS via SVG
Low
CVE-2025-13784
was published
for
yungifez/skuul
(Composer)
Nov 30, 2025
Skuul School Management System has a Sensitive Data Exposure Vulnerability in Uploaded Images
Low
CVE-2025-13785
was published
for
yungifez/skuul
(Composer)
Nov 30, 2025
REDAXO CMS is vulnerable to Reflected XSS in Mediapool Info Banner via args[types]
Moderate
CVE-2025-66026
was published
for
redaxo/source
(Composer)
Nov 25, 2025
Contao is vulnerable to cross-site scripting in templates
Low
CVE-2025-65961
was published
for
contao/core-bundle
(Composer)
Nov 25, 2025
Contao is vulnerable to remote code execution in template closures
Moderate
CVE-2025-65960
was published
for
contao/core-bundle
(Composer)
Nov 25, 2025
REDAXO CMS is vulnerable to XSS through its module management component
Moderate
CVE-2025-64049
was published
for
redaxo/source
(Composer)
Nov 25, 2025
REDAXO CMS is vulnerable to RCE attack through its template management component
High
CVE-2025-64050
was published
for
redaxo/source
(Composer)
Nov 25, 2025
Formwork CMS has Stored Cross-Site Scripting Vulnerebility in Blog Tags
Moderate
CVE-2025-65956
was published
for
getformwork/formwork
(Composer)
Nov 24, 2025
ProTip!
Advisories are also available from the
GraphQL API