GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,630
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,850
Pub
13
RubyGems
1,045
Rust
1,301
Swift
53
Unreviewed advisories
All unreviewed
5,000+
5,678 advisories
Filter by severity
Kirby CMS's `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API
High
CVE-2026-42137
was published
for
getkirby/cms
(Composer)
Apr 30, 2026
ps_checkout allows unauthorized method invocation through unvalidated parameter
Low
GHSA-mqq7-wxx5-mp8h
was published
for
prestashop/ps_checkout
(Composer)
Apr 30, 2026
Admidio: OIDC Token Introspection Endpoint Returns Active for All Tokens Without Validation
Moderate
CVE-2026-41671
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio Sends SAML Response to Unvalidated Assertion Consumer Service URL from AuthnRequest
High
CVE-2026-41670
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio Ignores SAML Signature Validation Result, Processes Forged AuthnRequests and LogoutRequests
High
CVE-2026-41669
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio has CSRF on Admin Preferences that Triggers Unauthorized Backup, .htaccess Write, and Email Send
Low
CVE-2026-41663
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio Missing Minimum Administrator Check in Role Membership Removal
Moderate
CVE-2026-41662
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio vulnerable to reflected XSS in msg_window.php via Square Bracket to HTML Tag Conversion
Moderate
CVE-2026-41661
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio has Inverted 2FA Reset Authorization Check that Lets Group Leaders Strip Admin TOTP
High
CVE-2026-41660
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio Leaks Hidden Profile Field Values via Blind Search Oracle in Member Assignment
Low
CVE-2026-41659
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio's Missing Authorization on Inventory Module Destructive Endpoints Allows Any Authenticated User to Delete Items
Moderate
CVE-2026-41658
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio Exposes Cross-Organization Member Data via Permission Check Mismatch in contacts_data.php
Moderate
CVE-2026-41657
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio has Path Traversal via Unvalidated `name` Parameter in Document Add Mode that Enables Arbitrary Server File Read
Moderate
CVE-2026-41656
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio has Path Traversal in ECard Preview that Allows Reading Arbitrary Server Files Including Database Credentials
Moderate
CVE-2026-41655
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
ipl/web is vulnerable to reflected XSS by malformed search requests
High
CVE-2026-42224
was published
for
ipl/web
(Composer)
Apr 29, 2026
OpenID Connect nonce generated but never validated — ID token replay attack
Moderate
CVE-2026-42206
was published
for
roadiz/openid
(Composer)
Apr 29, 2026
CI4MS has Unrestricted PHP File Upload via Theme Installation that Leads to Authenticated Remote Code Execution
High
CVE-2026-41587
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 29, 2026
PhpSpreadsheet has CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions
High
CVE-2026-40902
was published
for
phpoffice/phpspreadsheet
(Composer)
Apr 29, 2026
PhpSpreadsheet has CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader
High
CVE-2026-40863
was published
for
phpoffice/phpspreadsheet
(Composer)
Apr 29, 2026
PhpSpreadsheet has SSRF/RCE in IOFactory::load when $filename is user controlled
High
CVE-2026-34084
was published
for
phpoffice/phpspreadsheet
(Composer)
Apr 29, 2026
PhpSpreadsheet has XSS via number format code with @ text placeholder bypasses htmlspecialchars in HTML writer
Moderate
CVE-2026-40296
was published
for
phpoffice/phpspreadsheet
(Composer)
Apr 28, 2026
PhpSpreadsheet has XSS via NumberFormat @ Text Substitution in HTML Writer
Moderate
CVE-2026-35453
was published
for
phpoffice/phpspreadsheet
(Composer)
Apr 28, 2026
FacturaScripts has Insecure Parameter Handling: Unauthorized Modification of Immutable 'nick' Field
Moderate
CVE-2026-32699
was published
for
facturascripts/facturascripts
(Composer)
Apr 28, 2026
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
CVE-2026-41325
was published
for
getkirby/cms
(Composer)
Apr 24, 2026
TYPO3 CMS Stores Cleartext Password in User Settings Module
High
CVE-2026-6553
was published
for
typo3/cms-backend
(Composer)
Apr 24, 2026
ProTip!
Advisories are also available from the
GraphQL API