GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
6,562 advisories
Filter by severity
Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled
High
CVE-2026-76846
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths
High
CVE-2026-72698
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection
Low
CVE-2026-72701
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match
Low
CVE-2026-72702
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Chamilo LMS CStudio upload flow allows unauthenticated remote code execution
Critical
CVE-2026-45140
was published
for
chamilo/chamilo-lms
(Composer)
Sep 17, 2026
Grav: Stored XSS via Markdown audio/video media <source> URL
Moderate
CVE-2026-75831
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Stored XSS via quoted-attribute bypass in detectXss
Moderate
CVE-2026-72832
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
High
CVE-2026-69089
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Incomplete callable validation in blueprint dynamic fields allows arbitrary static method invocation and file disclosure
High
CVE-2026-69088
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: FlexDirectory::dynamicDataField() executes arbitrary callables from blueprint data with no validation
High
CVE-2026-65608
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Decompression-bomb size cap bypassed by forged ZIP size in ZipArchiver/Installer
Moderate
CVE-2026-61449
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav
Moderate
CVE-2026-58657
was published
for
getgrav/grav
(Composer)
Sep 16, 2026
Grav: XSS Blueprint Validation Bypass via Twig String Concatenation
Moderate
CVE-2026-61453
was published
for
getgrav/grav
(Composer)
Sep 16, 2026
Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()
Moderate
CVE-2026-59193
was published
for
getgrav/grav
(Composer)
Sep 16, 2026
October CMS: Incomplete Scheme Validation in Image Resizer
Low
GHSA-2xmm-m4wv-3fjh
was published
for
october/october
(Composer)
Sep 14, 2026
October CMS: PHP Object Injection via Backend Widget Session Storage
Low
CVE-2026-49400
was published
for
october/system
(Composer)
Sep 14, 2026
October CMS: Safe Mode Sandbox Bypass via Session Store and Forwarded Builder Calls
Low
CVE-2026-46696
was published
for
october/system
(Composer)
Sep 14, 2026
Shopper: Missing authorization on product removal actions in CollectionProducts component
High
CVE-2026-56825
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
Moderate
CVE-2026-56830
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
High
CVE-2026-56829
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: privilege escalation via improper Livewire admin component authorization
High
CVE-2026-56828
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopping privilege escalation through missing authorization in Settings components
Moderate
CVE-2026-56826
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: Negative discount values accepted and propagated through order calculation pipeline
Moderate
CVE-2026-56831
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
High
CVE-2026-56827
was published
for
shopper/framework
(Composer)
Sep 11, 2026
Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration
High
CVE-2026-55416
was published
for
pimcore/pimcore
(Composer)
Sep 10, 2026
ProTip!
Advisories are also available from the
GraphQL API