GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
235 advisories
Filter by severity
Contao: Path traversal in the images controller
Moderate
CVE-2026-107844
was published
for
contao/core-bundle
(Composer)
Oct 9, 2026
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path
Moderate
CVE-2026-59944
was published
for
composer/composer
(Composer)
Oct 2, 2026
Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)
High
CVE-2026-74907
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion
High
CVE-2026-72695
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content
High
CVE-2026-72697
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Chamilo LMS CStudio upload flow allows unauthenticated remote code execution
Critical
CVE-2026-45140
was published
for
chamilo/chamilo-lms
(Composer)
Sep 17, 2026
Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
High
CVE-2026-69089
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path
High
CVE-2026-84374
was published
for
maatwebsite/excel
(Composer)
Sep 8, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Moderate
CVE-2026-75592
was published
for
getkirby/cms
(Composer)
Sep 2, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
CVE-2026-75594
was published
for
getkirby/cms
(Composer)
Aug 31, 2026
Snipe-IT has a path traversal vulnerability via CSV import `image` field
Low
CVE-2026-55469
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
phpMyFAQ has Potential Authenticated Path Traversal in PDF Export
Moderate
GHSA-88g4-74f3-63x9
was published
for
phpmyfaq/phpmyfaq
(Composer)
Aug 25, 2026
Duplicate Advisory: Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content
High
GHSA-rj4c-4q9x-543x
was published
for
getgrav/grav
(Composer)
Aug 25, 2026
•
withdrawn
Duplicate Advisory: Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion
High
GHSA-896w-cw95-xq7w
was published
for
getgrav/grav
(Composer)
Aug 25, 2026
•
withdrawn
Winter: Local File Inclusion through =include directives in JavaScript asset compilation
Moderate
GHSA-2223-f22x-24cq
was published
for
winter/wn-system-module
(Composer)
Aug 20, 2026
Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets
Moderate
CVE-2026-63179
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisk
High
CVE-2026-54178
was published
for
backpack/crud
(Composer)
Aug 20, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
CVE-2026-55224
was published
for
mineadmin/mineadmin
(Composer)
Aug 18, 2026
Duplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)
High
GHSA-2rhw-8953-48q3
was published
for
getgrav/grav
(Composer)
Aug 18, 2026
•
withdrawn
Duplicate Advisory: Craft CMS: Incorrect path validation could potentially lead to path traversal
Moderate
GHSA-9w6w-8x3c-hfqp
was published
for
craftcms/cms
(Composer)
Aug 11, 2026
•
withdrawn
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
High
CVE-2026-63222
was published
for
codeigniter4/framework
(Composer)
Aug 7, 2026
Smarty Security stream restriction bypass through stream: resource
Moderate
CVE-2026-62996
was published
for
smarty/smarty
(Composer)
Aug 7, 2026
Smarty: Symlink path traversal out of trusted directories
Moderate
CVE-2026-62992
was published
for
smarty/smarty
(Composer)
Aug 7, 2026
Craft CMS: Incorrect path validation could potentially lead to path traversal
Low
CVE-2026-72783
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
Contao: Possible path traversal in job download URIs
Low
CVE-2026-55825
was published
for
contao/contao
(Composer)
Aug 6, 2026
ProTip!
Advisories are also available from the
GraphQL API