GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,714
Erlang
34
GitHub Actions
28
Go
2,297
Maven
5,000+
npm
3,942
NuGet
708
pip
3,711
Pub
12
RubyGems
920
Rust
959
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,715 advisories
Filter by severity
The Front End User Registration extension for TYPO3 (sr_feuser_register) Remote Code Execution
Critical
CVE-2025-48200
was published
for
sjbr/sr-feuser-register
(Composer)
May 21, 2025
The Backup Plus extension for TYPO3 (ns_backup) has a Predictable Resource Location
High
CVE-2025-48201
was published
for
nitsan/ns-backup
(Composer)
May 21, 2025
The Front End User Registration extension for TYPO3 (sr_feuser_register) allows Insecure Direct Object Reference
High
CVE-2025-48205
was published
for
sjbr/sr-feuser-register
(Composer)
May 21, 2025
The Backup Plus extension for TYPO3 (ns_backup) allows XSS
Low
CVE-2025-48206
was published
for
nitsan/ns-backup
(Composer)
May 21, 2025
The Backup Plus extension for TYPO3 (ns_backup) allows command injections
Moderate
CVE-2025-48204
was published
for
nitsan/ns-backup
(Composer)
May 21, 2025
reint_downloadmanager TYPO3 Extension is susceptible to Insecure Direct Object Reference
Moderate
CVE-2025-48207
was published
for
renolit/reint-downloadmanager
(Composer)
May 21, 2025
The femanager TYPO3 extension allows Insecure Direct Object Reference
Moderate
CVE-2025-48202
was published
for
in2code/femanager
(Composer)
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2025-48203
was published
for
clickstorm/cs-seo
(Composer)
May 21, 2025
The TYPO3 CMS Backend has Broken Authentication in Backend MFA
High
CVE-2025-47941
was published
for
typo3/cms-backend
(Composer)
May 20, 2025
TYPO3 Allows Privilege Escalation to System Maintainer
High
CVE-2025-47940
was published
for
typo3/cms-core
(Composer)
May 20, 2025
TYPO3 Allows Unrestricted File Upload in File Abstraction Layer
Moderate
CVE-2025-47939
was published
for
typo3/cms-core
(Composer)
May 20, 2025
TYPO3 Unverified Password Change for Backend Users
Low
CVE-2025-47938
was published
for
typo3/cms-core
(Composer)
May 20, 2025
TYPO3 Allows Information Disclosure via DBAL Restriction Handling
Low
CVE-2025-47937
was published
for
typo3/cms-core
(Composer)
May 20, 2025
TYPO3 CMS Webhooks Server Side Request Forgery
Low
CVE-2025-47936
was published
for
typo3/cms-webhooks
(Composer)
May 20, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
Moderate
CVE-2025-47946
was published
for
symfony/ux-live-component
(Composer)
May 19, 2025
LibreNMS stored Cross-site Scripting vulnerability in poller group name
Low
CVE-2025-47931
was published
for
librenms/librenms
(Composer)
May 19, 2025
laravel-auth0 SDK Vulnerable to Brute Force Authentication Tags of CookieStore Sessions
Critical
GHSA-9fwj-9mjf-rhj3
was published
for
auth0/login
(Composer)
May 17, 2025
Auth0 Wordpress plugin Vulnerable to Brute Force Authentication Tags of CookieStore Sessions
Critical
GHSA-2f4r-34m4-3w8q
was published
for
auth0/wordpress
(Composer)
May 17, 2025
Auth0 Symfony SDK Vulnerable to Brute Force Authentication Tags of CookieStore Sessions
Critical
GHSA-9wg9-93h9-j8ch
was published
for
auth0/symfony
(Composer)
May 17, 2025
Forgeable Encrypted Session Cookie in Apps Using Auth0-PHP SDK
Critical
CVE-2025-47275
was published
for
auth0/auth0-php
(Composer)
May 16, 2025
tarteaucitron-wp WordPress Plugin Vulnerable to Stored Cross-Site Scripting
Moderate
CVE-2024-11718
was published
for
couleurcitron/tarteaucitron-wp
(Composer)
May 15, 2025
Sulu vulnerable to XXE in SVG File upload Inspector
Moderate
CVE-2025-47778
was published
for
sulu/sulu
(Composer)
May 15, 2025
Kirby vulnerable to path traversal of snippet names in the `snippet()` helper
Moderate
CVE-2025-30159
was published
for
getkirby/kirby
(Composer)
May 13, 2025
Kirby vulnerable to path traversal in the router for PHP's built-in server
Low
CVE-2025-30207
was published
for
getkirby/cms
(Composer)
May 13, 2025
Kirby vulnerable to path traversal of collection names during file system lookup
Moderate
CVE-2025-31493
was published
for
getkirby/cms
(Composer)
May 13, 2025
ProTip!
Advisories are also available from the
GraphQL API