GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,758
Maven
5,000+
npm
4,364
NuGet
766
pip
4,132
Pub
12
RubyGems
961
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
344 advisories
Filter by severity
1Panel contains a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality
High
CVE-2025-34429
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 10, 2025
1Panel contains a cross-site request forgery (CSRF) vulnerability in the Change Username functionality
High
CVE-2025-34410
was published
for
github.com/1Panel-dev/1Panel
(Go)
Dec 10, 2025
Liferay Portal Vulnerable to CSRF in Headless APIs
High
CVE-2025-62258
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 28, 2025
Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system
High
CVE-2025-47410
was published
for
org.apache.geode:geode-web
(Maven)
Oct 18, 2025
Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI
High
CVE-2025-54286
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass
High
CVE-2025-59845
was published
for
@apollo/explorer
(npm)
Sep 26, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover
High
CVE-2025-58430
was published
for
github.com/knadh/listmonk
(Go)
Sep 9, 2025
Liferay Portal Vulnerable to Cross-Site Request Forgery
High
CVE-2025-43748
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 20, 2025
Magento Cross-Site Request Forgery (CSRF) vulnerability
High
CVE-2025-49555
was published
for
magento/community-edition
(Composer)
Aug 12, 2025
Aim vulnerable to Cross-Site Request Forgery
High
CVE-2024-7760
was published
for
aim
(pip)
Mar 20, 2025
Open WebUI Cross-Site Request Forgery (CSRF) Vulnerability
High
CVE-2024-7806
was published
for
open-webui
(pip)
Mar 20, 2025
DB-GPT vulnerable to Cross-Site Request Forgery
High
CVE-2024-10906
was published
for
dbgpt
(pip)
Mar 20, 2025
Bitbucket Server Integration Plugin allows bypassing CSRF protection for any URL
High
CVE-2025-24398
was published
for
io.jenkins.plugins:atlassian-bitbucket-server-integration
(Maven)
Jan 22, 2025
Cross-Site Request Forgery in CodeChecker API
High
CVE-2024-53829
was published
for
codechecker
(pip)
Jan 21, 2025
TYPO3 Scheduler Module vulnerable to Cross-Site Request Forgery
High
CVE-2024-55924
was published
for
typo3/cms-scheduler
(Composer)
Jan 14, 2025
TYPO3 Extension Manager Module vulnerable to Cross-Site Request Forgery
High
CVE-2024-55921
was published
for
typo3/cms-extensionmanager
(Composer)
Jan 14, 2025
Avenwu Whistle Cross-Site Request Forgery (CSRF)
High
CVE-2024-55500
was published
for
whistle
(npm)
Dec 10, 2024
pyspider Cross-Site Request Forgery (CSRF) via the Flask endpoints
High
CVE-2024-39163
was published
for
pyspider
(pip)
Dec 4, 2024
Moodle has CSRF risk in Feedback non-respondents report
High
CVE-2024-43434
was published
for
moodle/moodle
(Composer)
Nov 7, 2024
OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)
High
CVE-2024-47879
was published
for
org.openrefine:main
(Maven)
Oct 24, 2024
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the My Account Widget
High
CVE-2024-26271
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 22, 2024
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor
High
CVE-2024-26272
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 22, 2024
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor
High
CVE-2024-26273
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 22, 2024
gotortc vulnerable to Cross-Site Request Forgery
High
CVE-2024-29192
was published
for
github.com/AlexxIT/go2rtc
(Go)
Aug 5, 2024
Owncast Cross-Site Request Forgery vulnerability
High
CVE-2024-29026
was published
for
github.com/owncast/owncast
(Go)
Aug 5, 2024
ProTip!
Advisories are also available from the
GraphQL API