GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
98 advisories
Filter by severity
Contao: Path traversal in the images controller
Moderate
CVE-2026-107844
was published
for
contao/core-bundle
(Composer)
Oct 9, 2026
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path
Moderate
CVE-2026-59944
was published
for
composer/composer
(Composer)
Oct 2, 2026
Kirby: Access to image files outside of the site root via path traversal in the media handling
Moderate
CVE-2026-75592
was published
for
getkirby/cms
(Composer)
Sep 2, 2026
phpMyFAQ has Potential Authenticated Path Traversal in PDF Export
Moderate
GHSA-88g4-74f3-63x9
was published
for
phpmyfaq/phpmyfaq
(Composer)
Aug 25, 2026
Winter: Local File Inclusion through =include directives in JavaScript asset compilation
Moderate
GHSA-2223-f22x-24cq
was published
for
winter/wn-system-module
(Composer)
Aug 20, 2026
Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets
Moderate
CVE-2026-63179
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Duplicate Advisory: Craft CMS: Incorrect path validation could potentially lead to path traversal
Moderate
GHSA-9w6w-8x3c-hfqp
was published
for
craftcms/cms
(Composer)
Aug 11, 2026
•
withdrawn
Smarty Security stream restriction bypass through stream: resource
Moderate
CVE-2026-62996
was published
for
smarty/smarty
(Composer)
Aug 7, 2026
Smarty: Symlink path traversal out of trusted directories
Moderate
CVE-2026-62992
was published
for
smarty/smarty
(Composer)
Aug 7, 2026
Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI
Moderate
CVE-2026-56722
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files
Moderate
CVE-2026-59946
was published
for
composer/composer
(Composer)
Jul 20, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
Moderate
GHSA-2wwr-9x6f-88gp
was published
for
easycorp/easyadmin-bundle
(Composer)
Jul 1, 2026
CakePHP: View::element() is missing a path containment check
Moderate
CVE-2026-48820
was published
for
cakephp/cakephp
(Composer)
Jun 26, 2026
Microweber vulnerable to Path Traversal
Moderate
CVE-2026-12198
was published
for
microweber/microweber
(Composer)
Jun 15, 2026
AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`
Moderate
CVE-2026-46337
was published
for
WWBN/AVideo
(Composer)
May 19, 2026
TYPO3 ke_search path traversal due to lack of normalization on config directory from file indexer
Moderate
CVE-2026-46724
was published
for
tpwd/ke_search
(Composer)
May 19, 2026
AVideo: Authenticated Arbitrary File Read in view/update.php
Moderate
CVE-2026-45731
was published
for
WWBN/AVideo
(Composer)
May 18, 2026
Kimai has an arbitrary file read in its invoice PDF renderer (admin)
Moderate
CVE-2026-44298
was published
for
kimai/kimai
(Composer)
May 8, 2026
Flight has path traversal in `make:controller` CLI that creates arbitrary directories outside project root
Moderate
CVE-2026-42549
was published
for
flightphp/core
(Composer)
May 6, 2026
phpMyFAQ: Path Traversal in Client::deleteClientFolder enables arbitrary directory deletion by non-super-admin admins
Moderate
CVE-2026-45008
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
Admidio has Path Traversal via Unvalidated `name` Parameter in Document Add Mode that Enables Arbitrary Server File Read
Moderate
CVE-2026-41656
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Admidio has Path Traversal in ECard Preview that Allows Reading Arbitrary Server Files Including Database Credentials
Moderate
CVE-2026-41655
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
Cockpit is vulnerable to directory traversal
Moderate
CVE-2026-38993
was published
for
cockpit-hq/cockpit
(Composer)
Apr 29, 2026
Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-2023-27577)
Moderate
CVE-2026-41887
was published
for
flarum/core
(Composer)
Apr 22, 2026
October CMS has Safe Mode Bypass via CSS Preprocessor Compilers
Moderate
CVE-2026-26067
was published
for
october/system
(Composer)
Apr 21, 2026
ProTip!
Advisories are also available from the
GraphQL API