GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
102 advisories
Filter by severity
Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)
High
CVE-2026-74907
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion
High
CVE-2026-72695
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content
High
CVE-2026-72697
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
High
CVE-2026-69089
was published
for
getgrav/grav
(Composer)
Sep 17, 2026
Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path
High
CVE-2026-84374
was published
for
maatwebsite/excel
(Composer)
Sep 8, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
CVE-2026-75594
was published
for
getkirby/cms
(Composer)
Aug 31, 2026
Duplicate Advisory: Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion
High
GHSA-896w-cw95-xq7w
was published
for
getgrav/grav
(Composer)
Aug 25, 2026
•
withdrawn
Duplicate Advisory: Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content
High
GHSA-rj4c-4q9x-543x
was published
for
getgrav/grav
(Composer)
Aug 25, 2026
•
withdrawn
Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisk
High
CVE-2026-54178
was published
for
backpack/crud
(Composer)
Aug 20, 2026
MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install/Uninstall
High
CVE-2026-55224
was published
for
mineadmin/mineadmin
(Composer)
Aug 18, 2026
Duplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)
High
GHSA-2rhw-8953-48q3
was published
for
getgrav/grav
(Composer)
Aug 18, 2026
•
withdrawn
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
High
CVE-2026-63222
was published
for
codeigniter4/framework
(Composer)
Aug 7, 2026
Duplicate Advisory: Grav: Path Traversal in ImageMedium::watermark() — arbitrary file disclosure via publicly-cached images
High
GHSA-mmwh-j75q-gxp8
was published
for
getgrav/grav
(Composer)
Aug 3, 2026
•
withdrawn
Composer: Arbitrary file write outside vendor via malicious transitive package name
High
CVE-2026-59948
was published
for
composer/composer
(Composer)
Jul 20, 2026
FacturaScripts: Unauthenticated Path Traversal in Static File Controllers Reads Private MyFiles Documents
High
CVE-2026-45693
was published
for
facturascripts/facturascripts
(Composer)
Jul 14, 2026
Laravel-Mediable: path traversal vulnerability in the File::sanitizePath()
High
CVE-2026-49970
was published
for
plank/laravel-mediable
(Composer)
Jul 13, 2026
NukeViet: Path Traversal to Arbitrary File Deletion in Edit Comment Function
High
CVE-2026-54065
was published
for
nukeviet/nukeviet
(Composer)
Jul 13, 2026
NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)
High
GHSA-qv4m-m73m-8hj7
was published
for
notrinos/notrinos-erp
(Composer)
Jul 10, 2026
Duplicate Advisory: Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read
High
GHSA-jcmp-jxh2-4jc3
was published
for
craftcms/cms
(Composer)
Jun 21, 2026
•
withdrawn
symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest
High
CVE-2026-55878
was published
for
symfony/ux-toolkit
(Composer)
Jun 19, 2026
TYPO3 CMS has Broken Access Control in its Media Module
High
CVE-2026-49742
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
Kirby CMS has pre-authentication path traversal and PHP file inclusion during user lookup
High
CVE-2026-44177
was published
for
getkirby/cms
(Composer)
May 26, 2026
SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion
High
CVE-2026-46491
was published
for
simplesamlphp/simplesamlphp-module-casserver
(Composer)
May 15, 2026
Grav has Unauthenticated Path Traversal & Arbitrary File Write in its FormFlash component
High
CVE-2026-42608
was published
for
getgrav/grav
(Composer)
May 5, 2026
AzuraCast has Path Traversal in `currentDirectory` Parameter that Enables Remote Code Execution via Media Upload
High
CVE-2026-42605
was published
for
azuracast/azuracast
(Composer)
May 4, 2026
ProTip!
Advisories are also available from the
GraphQL API