GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,086
Maven
5,000+
npm
3,749
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
3,192 advisories
Filter by severity
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin...
Moderate
Unreviewed
CVE-2024-3215
was published
May 2, 2024
The Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions plugin...
Moderate
Unreviewed
CVE-2024-1407
was published
Jun 19, 2024
The Complianz – GDPR/CCPA Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request...
Moderate
Unreviewed
CVE-2024-1592
was published
Mar 2, 2024
Cross-Site Request Forgery (CSRF) vulnerability in W3speedster W3SPEEDSTER allows Cross Site...
Moderate
Unreviewed
CVE-2025-23765
was published
Jan 16, 2025
The Admin side data storage for Contact Form 7 plugin for WordPress is vulnerable to Cross-Site...
Moderate
Unreviewed
CVE-2024-1777
was published
Feb 23, 2024
The WP User Profile Avatar plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
Moderate
Unreviewed
CVE-2024-10789
was published
Jan 16, 2025
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Cross...
Moderate
Unreviewed
CVE-2024-1503
was published
Mar 21, 2024
The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
Moderate
Unreviewed
CVE-2024-1362
was published
Feb 23, 2024
The Colibri Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
Moderate
Unreviewed
CVE-2024-1361
was published
Feb 23, 2024
The LadiApp plugn for WordPress is vulnerable to Cross-Site Request Forgery due to a missing...
Moderate
Unreviewed
CVE-2023-4731
was published
Mar 12, 2024
The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing...
Moderate
Unreviewed
CVE-2023-4629
was published
Mar 12, 2024
Cross-Site Request Forgery (CSRF) vulnerability in silverplugins217 Build Private Store For...
Moderate
Unreviewed
CVE-2025-22731
was published
Jan 15, 2025
The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing...
Moderate
Unreviewed
CVE-2023-4628
was published
Mar 12, 2024
The LadiApp plugin for WordPress is vulnerable to Cross-Site Request Forgery due to a missing...
Moderate
Unreviewed
CVE-2023-4729
was published
Mar 12, 2024
Active Directory Federation Server Spoofing Vulnerability
Moderate
Unreviewed
CVE-2025-21193
was published
Jan 14, 2025
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Cross-Site Request...
Moderate
Unreviewed
CVE-2025-0393
was published
Jan 14, 2025
The Smart Agenda – Prise de rendez-vous en ligne plugin for WordPress is vulnerable to Cross-Site...
Moderate
Unreviewed
CVE-2024-13348
was published
Jan 14, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Minify JS allows Cross Site Request...
Moderate
Unreviewed
CVE-2024-13304
was published
Jan 9, 2025
The Action Network plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
Moderate
Unreviewed
CVE-2024-12394
was published
Jan 9, 2025
The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3,...
Moderate
Unreviewed
CVE-2024-12605
was published
Jan 9, 2025
The Woocommerce check pincode/zipcode for shipping plugin for WordPress is vulnerable to Cross...
Moderate
Unreviewed
CVE-2024-12218
was published
Jan 9, 2025
The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Cross-Site...
Moderate
Unreviewed
CVE-2024-12206
was published
Jan 9, 2025
A vulnerability was found in kurniaramadhan E-Commerce-PHP 1.0. It has been classified as...
Moderate
Unreviewed
CVE-2024-13203
was published
Jan 9, 2025
The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2024-0767
was published
Feb 28, 2024
The Envo's Elementor Templates & Widgets for WooCommerce plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2024-0768
was published
Feb 28, 2024
ProTip!
Advisories are also available from the
GraphQL API