GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,950
Erlang
39
GitHub Actions
38
Go
2,603
Maven
5,000+
npm
4,250
NuGet
755
pip
4,013
Pub
12
RubyGems
953
Rust
1,048
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,951 advisories
Filter by severity
Moodle's error handling leads to sensitive information disclosure
Moderate
CVE-2025-62396
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
Moodle exposed the names of hidden groups to users
Moderate
CVE-2025-62400
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
Moodle has a time restriction bypass
Moderate
CVE-2025-62401
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
Moodle vulnerable to brute-force password guesses
High
CVE-2025-62399
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
Moodle does not properly enforce MFA
Moderate
CVE-2025-62398
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
Moodle course access permissions are not properly checked in course_output_fragment_course_overview
Moderate
CVE-2025-62393
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
Moodle sends quiz-related messages to inactive/suspended users
Moderate
CVE-2025-62394
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
Admidio Vulnerable to Authenticated SQL Injection in Member Assignment Functionality
High
CVE-2025-62617
was published
for
admidio/admidio
(Composer)
Oct 22, 2025
code16 Sharp vulnerable to Cross Site Scripting (XSS)
Moderate
CVE-2025-61457
was published
for
code16/sharp
(Composer)
Oct 21, 2025
ProcessWire CMS vulnerable to resource-exhaustion Denial of Service
Moderate
CVE-2025-60790
was published
for
processwire/processwire
(Composer)
Oct 21, 2025
Shopware Customer Orders can be canceled, even if refunds are disabled
Moderate
GHSA-r2vg-hvjm-fg38
was published
for
shopware/core
(Composer)
Oct 21, 2025
Shopware exposes sensitive user information via CSV export mapping
Moderate
GHSA-27c9-vp3w-6ww8
was published
for
shopware/core
(Composer)
Oct 21, 2025
Shopware vulnerable to Server-Side Request Forgery (SSRF) – order invoice
Low
GHSA-3cpp-fv95-mpr5
was published
for
shopware/core
(Composer)
Oct 21, 2025
Shopware vulnerable to path traversal via Plugin upload
Low
GHSA-6wh5-mw9h-5c3w
was published
for
shopware/core
(Composer)
Oct 21, 2025
Shopware vulnerable to MediaVisibilityRestrictionSubscriber bypass when reading media entities by aggregating fields individually
Moderate
GHSA-m895-2hj3-8cg9
was published
for
shopware/core
(Composer)
Oct 21, 2025
Citizen vulnerable to stored XSS in sticky header button messages
Moderate
CVE-2025-62508
was published
for
starcitizentools/citizen-skin
(Composer)
Oct 20, 2025
TastyIgniter vulnerable to Cross-Site Scripting
Low
CVE-2025-61417
was published
for
tastyigniter/tastyigniter
(Composer)
Oct 20, 2025
Cargo Mediawiki Extension vulnerable to Cross-site Scripting
Moderate
CVE-2025-62671
was published
for
mediawiki/cargo
(Composer)
Oct 18, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Moderate
GHSA-8c2g-f8jm-5cr7
was published
for
ibexa/fieldtype-richtext
(Composer)
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Moderate
GHSA-2mx6-fq24-g2mh
was published
for
ibexa/admin-ui
(Composer)
Oct 17, 2025
ezsystems/ezplatform-admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Moderate
GHSA-99c7-c3mw-mxhv
was published
for
ezsystems/ezplatform-admin-ui
(Composer)
Oct 17, 2025
ibexa/user login enumerates user accounts
Moderate
GHSA-q3x8-6898-23g3
was published
for
ibexa/user
(Composer)
Oct 17, 2025
bagisto has Cross Site Scripting (XSS) in Create New Customer
Moderate
CVE-2025-62414
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has CSV Formula Injection in Create New Product
Critical
CVE-2025-62417
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has a Cross Site Scripting (XSS) vulnerability in TinyMCE Image Upload (SVG)
Moderate
CVE-2025-62418
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
ProTip!
Advisories are also available from the
GraphQL API