GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
363 advisories
Filter by severity
Ghost : Stored XSS via SVG Files in Content Imports
Moderate
CVE-2026-105644
was published
for
ghost
(npm)
Oct 7, 2026
Ghost: Stored XSS via SVG Uploads Bypassing Sanitization
High
CVE-2026-105649
was published
for
ghost
(npm)
Oct 7, 2026
Payload: Bypassed sanitization of user uploaded SVGs
High
CVE-2026-105862
was published
for
payload
(npm)
Oct 7, 2026
Payload: Uploaded XML files could execute same-origin JavaScript
High
CVE-2026-105868
was published
for
payload
(npm)
Oct 7, 2026
Ghost: Stored XSS via Bookmark Card Images
High
CVE-2026-105651
was published
for
ghost
(npm)
Oct 7, 2026
Ghost: Stored XSS via File Uploads on Local Storage
High
CVE-2026-105679
was published
for
ghost
(npm)
Oct 7, 2026
Kunstmaan CMS: MediaBundle extension blacklist bypass allows authenticated administrators to upload executable PHP files leading to remote code execution
High
CVE-2026-104890
was published
for
kunstmaan/bundles-cms
(Composer)
Oct 7, 2026
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain
Critical
GHSA-v2f8-6655-7grj
was published
for
vibe-trading-ai
(pip)
Oct 2, 2026
Chamilo LMS CStudio upload flow allows unauthenticated remote code execution
Critical
CVE-2026-45140
was published
for
chamilo/chamilo-lms
(Composer)
Sep 17, 2026
elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)
High
CVE-2026-81891
was published
for
Studio-42/elFinder
(Composer)
Sep 2, 2026
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
Moderate
CVE-2026-55419
was published
for
reachy-mini
(pip)
Aug 25, 2026
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
High
GHSA-ghvf-qf6h-g8x5
was published
for
@nocobase/server
(npm)
Aug 20, 2026
Laravel Backpack CRUD: SingleBase64Image accepts any base64 payload behind a `data:image` prefix — SVG-with-script lands on the public disk
Moderate
CVE-2026-54179
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: HasUploadFields keeps the attacker-supplied file extension — public-disk uploads of `shell.php` reach the webserver
Moderate
CVE-2026-54177
was published
for
backpack/crud
(Composer)
Aug 20, 2026
CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules
Critical
CVE-2026-63223
was published
for
codeigniter4/framework
(Composer)
Aug 7, 2026
Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types
Moderate
CVE-2026-71434
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Ghost: File Upload Content-Type Spoofing
Moderate
CVE-2026-53948
was published
for
ghost
(npm)
Aug 4, 2026
Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
High
CVE-2026-53599
was published
for
redaxo/source
(Composer)
Jul 31, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)
Moderate
CVE-2026-58428
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
Flask-Reuploaded: Extension-denylist bypass via case-folding asymmetry in name-override path (incomplete-fix variant of CVE-2026-27641)
High
CVE-2026-54567
was published
for
Flask-Reuploaded
(pip)
Jul 17, 2026
FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE
Critical
GHSA-hgjx-r89m-m7v4
was published
for
facturascripts/facturascripts
(Composer)
Jul 14, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
High
CVE-2026-54087
was published
for
easycorp/easyadmin-bundle
(Composer)
Jul 14, 2026
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode
Critical
CVE-2026-50006
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)
High
GHSA-qv4m-m73m-8hj7
was published
for
notrinos/notrinos-erp
(Composer)
Jul 10, 2026
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE
Critical
CVE-2026-53649
was published
for
github.com/BishopFox/joro
(Go)
Jul 8, 2026
ProTip!
Advisories are also available from the
GraphQL API