GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,904
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,374
Swift
54
Unreviewed advisories
All unreviewed
5,000+
78 advisories
Filter by severity
shopper/framework: Authorization bypass in multiple Livewire admin components
High
GHSA-f946-9qp6-vgch
was published
for
shopper/framework
(Composer)
May 18, 2026
AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticated user enumeration sibling that survives `d9cdc7024`
Moderate
CVE-2026-45620
was published
for
WWBN/AVideo
(Composer)
May 18, 2026
Grav Vulnerable to Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic
High
CVE-2026-42609
was published
for
getgrav/grav
(Composer)
May 5, 2026
nova-toggle-5: Improper authorization on toggle endpoint allowed non-Nova users to modify boolean fields
Moderate
CVE-2026-42202
was published
for
almirhodzic/nova-toggle-5
(Composer)
Apr 24, 2026
CI4MS has a Hidden Items Authorization Bypass in Fileeditor Allows Reading Secrets and Writing Protected Files
Moderate
CVE-2026-39389
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 8, 2026
AVideo: Video Publishing Workflow Bypass via Unauthorized overrideStatus Request Parameter
Moderate
CVE-2026-34738
was published
for
wwbn/avideo
(Composer)
Apr 1, 2026
baserCMS has Mail Form Acceptance Bypass via Public API
Moderate
CVE-2026-30878
was published
for
baserproject/basercms
(Composer)
Mar 31, 2026
Craft CMS has an authorization bypass which allows any control panel user to move entries without permissions
Moderate
CVE-2026-33162
was published
for
craftcms/cms
(Composer)
Mar 24, 2026
Connect CMS: Improper Authorization in the My Page Profile Update Feature Allows Modification of Arbitrary User Information
High
CVE-2026-32300
was published
for
opensource-workshop/connect-cms
(Composer)
Mar 23, 2026
Kimai's API invoice endpoint missing customer-level access control (IDOR)
Moderate
CVE-2026-28685
was published
for
kimai/kimai
(Composer)
Mar 4, 2026
phpMyFAQ: /api/setup/backup accessible to any authenticated user (authz missing)
Moderate
CVE-2026-24421
was published
for
phpmyfaq/phpmyfaq
(Composer)
Jan 23, 2026
Grav has Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actions
High
CVE-2025-66301
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
MantisBT unauthorized disclosure of private project column configuration
Moderate
CVE-2025-62520
was published
for
mantisbt/mantisbt
(Composer)
Nov 3, 2025
Moodle has a time restriction bypass
Moderate
CVE-2025-62401
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
HAX CMS API Lacks Authorization Checks
High
CVE-2025-54378
was published
for
@haxtheweb/haxcms-nodejs
(Composer)
Jul 25, 2025
Magento Improper Authorization leading to security feature bypass
High
CVE-2025-43585
was published
for
magento/community-edition
(Composer)
Jun 10, 2025
Magento Improper Authorization vulnerability
Moderate
CVE-2025-27188
was published
for
magento/community-edition
(Composer)
Apr 8, 2025
TastyIgniter Has an Incorrect Access Control Vulnerability
Moderate
CVE-2024-44314
was published
for
tastyigniter/tastyigniter
(Composer)
Mar 18, 2025
Mautic allows Improper Authorization in Reporting API
High
CVE-2024-47053
was published
for
mautic/core
(Composer)
Feb 26, 2025
Improper Authorization vulnerability in Magento and Adobe Commerce
Critical
CVE-2025-24434
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Adobe Commerce Improper Authorization vulnerability
High
CVE-2025-24409
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
TeamPass does not properly check whether a folder is in a user's allowed folders list
Moderate
CVE-2024-50701
was published
for
nilsteampassnet/teampass
(Composer)
Dec 30, 2024
TeamPass mail_me operation authorization issue
Moderate
CVE-2024-50702
was published
for
nilsteampassnet/teampass
(Composer)
Dec 30, 2024
Moodle Lesson activity password bypass through PHP loose comparison
Moderate
CVE-2024-45691
was published
for
moodle/moodle
(Composer)
Nov 20, 2024
Moodle allows users to retrieve information they did not have permission to access
Moderate
CVE-2024-45689
was published
for
moodle/moodle
(Composer)
Nov 20, 2024
ProTip!
Advisories are also available from the
GraphQL API