GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
6,565 advisories
Filter by severity
Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content
High
CVE-2026-72697
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()
High
CVE-2026-76839
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled
High
CVE-2026-76846
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths
High
CVE-2026-72698
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection
Low
CVE-2026-72701
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match
Low
CVE-2026-72702
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Chamilo LMS CStudio upload flow allows unauthenticated remote code execution
Critical
CVE-2026-45140
was published
for
chamilo/chamilo-lms
(Composer)
Sep 17, 2026
Grav: Stored XSS via Markdown audio/video media <source> URL
Moderate
CVE-2026-75831
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Stored XSS via quoted-attribute bypass in detectXss
Moderate
CVE-2026-72832
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
High
CVE-2026-69089
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
High
CVE-2026-69088
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
High
CVE-2026-65608
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
Moderate
CVE-2026-61449
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
Moderate
CVE-2026-58657
was published
for
getgrav/grav
(Composer)
Sep 16, 2026
Grav: XSS Blueprint Validation Bypass via Twig String Concatenation
Moderate
CVE-2026-61453
was published
for
getgrav/grav
(Composer)
Sep 16, 2026
Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()
Moderate
CVE-2026-59193
was published
for
getgrav/grav
(Composer)
Sep 16, 2026
October CMS: Incomplete Scheme Validation in Image Resizer
Low
GHSA-2xmm-m4wv-3fjh
was published
for
october/october
(Composer)
Sep 14, 2026
October CMS: PHP Object Injection via Backend Widget Session Storage
Low
CVE-2026-49400
was published
for
october/system
(Composer)
Sep 14, 2026
October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
Low
CVE-2026-46696
was published
for
october/system
(Composer)
Sep 14, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
High
CVE-2026-56825
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
Moderate
CVE-2026-56830
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
High
CVE-2026-56829
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: privilege escalation via improper Livewire admin component authorization
High
CVE-2026-56828
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
Moderate
CVE-2026-56826
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
Moderate
CVE-2026-56831
was published
for
shopper/framework
(Composer)
Sep 11, 2026
ProTip!
Advisories are also available from the
GraphQL API