GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,714
Erlang
34
GitHub Actions
28
Go
2,297
Maven
5,000+
npm
3,942
NuGet
708
pip
3,711
Pub
12
RubyGems
920
Rust
959
Swift
38
Unreviewed advisories
All unreviewed
5,000+
68 advisories
Filter by severity
TYPO3 CMS Webhooks Server Side Request Forgery
Low
CVE-2025-47936
was published
for
typo3/cms-webhooks
(Composer)
May 20, 2025
Moodle blind Server-Side Request Forgery (SSRF) vulnerability in LTI provider library
Critical
CVE-2022-45152
was published
for
moodle/moodle
(Composer)
Nov 25, 2022
phpMyAdmin server-side request forgery (SSRF)
High
CVE-2016-6621
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
Browsershot Server-Side Request Forgery (SSRF) via setURL() Function
High
CVE-2025-3192
was published
for
spatie/browsershot
(Composer)
Apr 4, 2025
ShopXO Vulnerable to Server-Side Request Forgery (SSRF) and Cross-Site Scripting (XSS)
Moderate
CVE-2025-28094
was published
for
shopxo/shopxo
(Composer)
Mar 29, 2025
ShopXO Vulnerable to Server-Side Request Forgery (SSRF) via Email Settings
Moderate
CVE-2025-28093
was published
for
shopxo/shopxo
(Composer)
Mar 29, 2025
ShopXO Vulnerable to Server-Side Request Forgery (SSRF) via Image Upload
Moderate
CVE-2025-28092
was published
for
shopxo/shopxo
(Composer)
Mar 29, 2025
PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery in HTML writer when embedding images is enabled
Moderate
CVE-2024-45291
was published
for
phpoffice/phpexcel
(Composer)
Oct 7, 2024
PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery when opening XLSX file
High
CVE-2024-45290
was published
for
phpoffice/phpexcel
(Composer)
Oct 7, 2024
Magento Open Source allows Server-Side Request Forgery (SSRF)
Moderate
CVE-2023-26366
was published
for
magento/community-edition
(Composer)
Oct 13, 2023
Magento Open Source allows Server-Side Request Forgery (SSRF)
Moderate
CVE-2023-29292
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows Server-Side Request Forgery (SSRF)
Moderate
CVE-2023-29291
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2024-45119
was published
for
magento/community-edition
(Composer)
Oct 10, 2024
VuFind Server-Side Request Forgery (SSRF) vulnerability
Critical
CVE-2024-25737
was published
for
vufind/vufind
(Composer)
May 22, 2024
czim/file-handling vulnerable to SSRF and directory traversal
Moderate
CVE-2024-47049
was published
for
czim/file-handling
(Composer)
Sep 17, 2024
Mautic: MST-48 Server-Side Request Forgery in Asset section
Moderate
CVE-2022-25777
was published
for
mautic/core
(Composer)
Apr 12, 2024
Authenticated Blind SSRF in automad/automad
Low
CVE-2023-7037
was published
for
automad/automad
(Composer)
Dec 21, 2023
Magento Open Source Server-Side Request Forgery (SSRF) vulnerability
Moderate
CVE-2024-34111
was published
for
magento/community-edition
(Composer)
Jun 13, 2024
ShopXO Server-Side Request Forgery Vulnerability
Moderate
CVE-2024-6524
was published
for
shopxo/shopxo
(Composer)
Jul 5, 2024
VuFind Server-Side Request Forgery (SSRF) vulnerability
Critical
CVE-2024-25738
was published
for
vufind/vufind
(Composer)
May 22, 2024
Codiad SSRF Vulnerability
High
CVE-2020-14044
was published
for
codiad/codiad
(Composer)
May 24, 2022
Symfony SSRF Vulnerability via Form Component
Moderate
CVE-2017-16790
was published
for
symfony/form
(Composer)
May 14, 2022
phpBB Server-Side Request Forgery (SSRF)
High
CVE-2017-1000419
was published
for
phpbb/phpbb
(Composer)
May 14, 2022
phpBB Server side request forgery (SSRF)
Moderate
CVE-2019-11767
was published
for
phpbb/phpbb
(Composer)
May 24, 2022
phpMyAdmin SSRF in replication
High
CVE-2017-1000017
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API