GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,758
Maven
5,000+
npm
4,364
NuGet
766
pip
4,132
Pub
12
RubyGems
961
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
73 advisories
Filter by severity
Backdrop CMS Host Header Injection vulnerability
Moderate
CVE-2025-63828
was published
for
backdrop/backdrop
(Composer)
Nov 18, 2025
Symfony vulnerable to open redirect via browser-sanitized URLs
Low
CVE-2024-50345
was published
for
symfony/http-foundation
(Composer)
Nov 6, 2024
PrivateBin is missing HTML sanitization of attached filename in file size hint
Moderate
CVE-2025-62796
was published
for
privatebin/privatebin
(Composer)
Oct 28, 2025
TYPO3 CMS has an open‑redirect vulnerability
Moderate
CVE-2025-59013
was published
for
typo3/cms-core
(Composer)
Sep 9, 2025
svg-sanitizer Bypasses Attribute Sanitization
Moderate
CVE-2025-55166
was published
for
enshrined/svg-sanitize
(Composer)
Aug 12, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
Moderate
CVE-2025-5256
was published
for
mautic/core
(Composer)
May 28, 2025
TYPO3 Potential Open Redirect via Parsing Differences
Moderate
CVE-2024-55892
was published
for
typo3/cms-core
(Composer)
Jan 14, 2025
TYPO3 allows remote attackers to embed Flash videos from external domain
Moderate
CVE-2015-8760
was published
for
typo3/cms
(Composer)
May 17, 2022
Flarum's logout Route allows open redirects
Moderate
CVE-2024-21641
was published
for
flarum/core
(Composer)
Jan 5, 2024
Drupal has open redirect vulnerability in the Overlay module
High
CVE-2013-6389
was published
for
drupal/drupal
(Composer)
May 17, 2022
EC-CUBE Open redirect vulnerability
Moderate
CVE-2018-16191
was published
for
ec-cube/ec-cube
(Composer)
May 14, 2022
October System module has an Open Redirect for Administrator Accounts
Low
CVE-2024-24764
was published
for
october/system
(Composer)
Jun 26, 2024
Zendframework Remote Address Spoofing Vector in `Zend\Http\PhpEnvironment\RemoteAddress`
High
GHSA-xffp-6w68-4775
was published
for
zendframework/zendframework
(Composer)
Jun 7, 2024
silverstripe/framework BackURL validation bypass with malformed URLs
High
GHSA-m5q3-mvcr-gc5m
was published
for
silverstripe/framework
(Composer)
May 27, 2024
Silverstripe External redirection risk in Security?ReturnURL
Moderate
GHSA-vp8p-c6xj-xpj7
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe X-Forwarded-Host request hostname injection
High
GHSA-25gq-jvx2-vg9x
was published
for
silverstripe/framework
(Composer)
May 23, 2024
OroPlatform Forced Redirect to External Website
Moderate
GHSA-3vhm-q4w3-rw8q
was published
for
oro/platform
(Composer)
May 20, 2024
OroCRM Forced Redirect to External Website
Moderate
GHSA-v8hp-239v-9367
was published
for
oro/crm
(Composer)
May 20, 2024
MediaWiki Open Redirect vulnerability
Moderate
CVE-2020-10959
was published
for
mediawiki/core
(Composer)
May 24, 2022
Possible to circumvent title-blacklist
Moderate
CVE-2019-19709
was published
for
mediawiki/core
(Composer)
May 24, 2022
Drupal core Open Redirect vulnerability
Moderate
GHSA-wxfg-253g-m7r4
was published
for
drupal/drupal
(Composer)
May 15, 2024
Drupal Anonymous Open Redirect
Moderate
GHSA-x6v2-xmrq-574j
was published
for
drupal/drupal
(Composer)
May 15, 2024
Drupal External URL injection through URL aliases leading to Open Redirect
Moderate
GHSA-r67r-42wx-c8r7
was published
for
drupal/drupal
(Composer)
May 15, 2024
Drupal core Open Redirect vulnerability
Moderate
GHSA-6gf6-24h2-66j4
was published
for
drupal/core
(Composer)
May 15, 2024
Drupal Anonymous Open Redirect
Moderate
GHSA-gfvf-2f25-f34r
was published
for
drupal/core
(Composer)
May 15, 2024
ProTip!
Advisories are also available from the
GraphQL API