GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,606
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,831
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
205 advisories
Filter by severity
Kirby is vulnerable to authorization bypass during page, file and user creation via blueprint injection
High
CVE-2026-41325
was published
for
getkirby/cms
(Composer)
Apr 24, 2026
Kirby's page creation API bypasses the changeStatus permission check via unfiltered isDraft parameter
Moderate
CVE-2026-40099
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
Kirby has Server-Side Template Injection (SSTI) via double template resolution in option rendering
High
CVE-2026-34587
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
Astro: XSS in define:vars via incomplete </script> tag sanitization
Moderate
CVE-2026-41067
was published
for
astro
(npm)
Apr 21, 2026
Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
High
CVE-2026-40938
was published
for
github.com/tektoncd/pipeline
(Go)
Apr 21, 2026
Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service via Memory Exhaustion
Moderate
CVE-2026-40924
was published
for
github.com/tektoncd/pipeline
(Go)
Apr 21, 2026
Tekton Pipelines has VerificationPolicy regex pattern bypass via substring matching
Moderate
CVE-2026-25542
was published
for
github.com/tektoncd/pipeline
(Go)
Apr 21, 2026
Paperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise
Critical
GHSA-3xx2-mqjm-hg9x
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
Paperclip: Stored XSS via javascript: URLs in MarkdownBody — urlTransform override disables react-markdown sanitization
Moderate
GHSA-fpw4-p57j-hqmq
was published
for
@paperclipai/ui
(npm)
Apr 16, 2026
Paperclip: Approval decision attribution spoofing via client-controlled `decidedByUserId` in paperclip server
Moderate
GHSA-p7mm-r948-4q3q
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
sanitize-html allowedTags Bypass via Entity-Decoded Text in nonTextTags Elements
Moderate
CVE-2026-40186
was published
for
sanitize-html
(npm)
Apr 16, 2026
ApostropheCMS: Information Disclosure via choices/counts Query Parameters Bypassing publicApiProjection Field Restrictions
Moderate
CVE-2026-39857
was published
for
apostrophe
(npm)
Apr 16, 2026
ApostropheCMS: Stored XSS via CSS Custom Property Injection in @apostrophecms/color-field Escaping Style Tag Context
Moderate
CVE-2026-33889
was published
for
apostrophe
(npm)
Apr 16, 2026
ApostropheCMS: publicApiProjection Bypass via project Query Builder in Piece-Type REST API
Moderate
CVE-2026-33888
was published
for
apostrophe
(npm)
Apr 16, 2026
ApostropheCMS: User Enumeration via Timing Side Channel in Password Reset Endpoint
Low
CVE-2026-33877
was published
for
apostrophe
(npm)
Apr 16, 2026
pyLoad has a Session Cookie Security Downgrade via Untrusted X-Forwarded-Proto Header Spoofing (Global State Race Condition)
Moderate
CVE-2026-40594
was published
for
pyload-ng
(pip)
Apr 16, 2026
Froxlor has Local File Inclusion via path traversal in API `def_language` parameter leads to Remote Code Execution
Critical
CVE-2026-41228
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
Froxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)
Critical
CVE-2026-41229
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
Froxlor has a BIND Zone File Injection via Unsanitized DNS Record Content in DomainZones::add()
High
CVE-2026-41230
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
Froxlor has Incomplete Symlink Validation in DataDump.add() Allows Arbitrary Directory Ownership Takeover via Cron
High
CVE-2026-41231
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
Froxlor has an Email Sender Alias Domain Ownership Bypass via Wrong Array Index Allows Cross-Customer Email Spoofing
Moderate
CVE-2026-41232
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
Froxlor has a Reseller Domain Quota Bypass via Unvalidated adminid Parameter in Domains.add()
Moderate
CVE-2026-41233
was published
for
froxlor/froxlor
(Composer)
Apr 16, 2026
WWBN AVideo has Stored XSS via Unanchored Duration Regex in Video Encoder Receiver
Moderate
CVE-2026-41061
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
WWBN AVideo has a SSRF via same-domain hostname with alternate port bypasses isSSRFSafeURL
High
CVE-2026-41060
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
WWBN AVideo has a CORS Origin Reflection Bypass via plugin/API/router.php and allowOrigin(true) Exposes Authenticated API Responses
High
CVE-2026-41057
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
ProTip!
Advisories are also available from the
GraphQL API