GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,464
Erlang
33
GitHub Actions
22
Go
2,164
Maven
5,000+
npm
3,821
NuGet
696
pip
3,503
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
6,963 advisories
Filter by severity
Cross-Site Request Forgery in Filebrowser
High
CVE-2021-46398
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Feb 5, 2022
IBM Financial Transaction Manager 3.2.4 is vulnerable to cross-site request forgery which could...
High
Unreviewed
CVE-2021-39044
was published
Feb 3, 2022
The Perfect Survey WordPress plugin before 1.5.2 does not have proper authorisation nor CSRF...
High
Unreviewed
CVE-2021-24763
was published
Feb 2, 2022
The Error Log Viewer WordPress plugin through 1.1.1 does not perform nonce check when deleting a...
Moderate
Unreviewed
CVE-2021-24761
was published
Feb 2, 2022
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.3.25 does not have CSRF...
Moderate
Unreviewed
CVE-2021-25072
was published
Feb 2, 2022
The Link Library WordPress plugin before 7.2.8 does not have CSRF check when resetting library...
Moderate
Unreviewed
CVE-2021-25092
was published
Feb 2, 2022
The LabTools WordPress plugin through 1.0 does not have proper authorisation and CSRF check in...
Moderate
Unreviewed
CVE-2021-25097
was published
Feb 2, 2022
CSRF token missing in Symfony
High
CVE-2022-23601
was published
for
symfony/framework-bundle
(Composer)
Feb 1, 2022
A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to...
High
Unreviewed
CVE-2021-22725
was published
Jan 29, 2022
A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to...
High
Unreviewed
CVE-2021-22724
was published
Jan 29, 2022
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers...
Moderate
Unreviewed
CVE-2022-23887
was published
Jan 29, 2022
YzmCMS v6.3 was discovered to contain a Cross-Site Request Forgey (CSRF) via the component ...
High
Unreviewed
CVE-2022-23888
was published
Jan 29, 2022
Cross Site Request Forgery in Moodle
High
CVE-2022-0335
was published
for
moodle/moodle
(Composer)
Jan 28, 2022
Cross-Site Request Forgery in yetiforce
High
CVE-2022-0269
was published
for
yetiforce/yetiforce-crm
(Composer)
Jan 27, 2022
SPIP 4.0.0 is affected by a Cross Site Request Forgery (CSRF) vulnerability in ecrire/public...
High
Unreviewed
CVE-2021-44122
was published
Jan 27, 2022
Cross-Site Request Forgery (CSRF) in livehelperchat
Moderate
CVE-2022-0231
was published
for
remdex/livehelperchat
(Composer)
Jan 26, 2022
Cross-Site Request Forgery (CSRF) in livehelperchat
Moderate
CVE-2022-0226
was published
for
remdex/livehelperchat
(Composer)
Jan 26, 2022
The Simple Download Monitor WordPress plugin before 3.9.9 does not enforce nonce checks, which...
High
Unreviewed
CVE-2021-24696
was published
Jan 25, 2022
The WP Extra File Types WordPress plugin before 0.5.1 does not have CSRF check when saving its...
High
Unreviewed
CVE-2021-24936
was published
Jan 25, 2022
The Ultimate FAQ WordPress plugin before 2.1.2 does not have capability and CSRF checks in the...
Moderate
Unreviewed
CVE-2021-24968
was published
Jan 25, 2022
The Accept Donations with PayPal WordPress plugin before 1.3.4 does not have CSRF check in place...
Moderate
Unreviewed
CVE-2021-24989
was published
Jan 25, 2022
The Qubely WordPress plugin before 1.7.8 does not have authorisation and CSRF check on the...
Moderate
Unreviewed
CVE-2021-25013
was published
Jan 25, 2022
The WP125 WordPress plugin before 1.5.5 does not have CSRF checks in various action, for example...
High
Unreviewed
CVE-2021-25073
was published
Jan 25, 2022
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
High
CVE-2021-4164
was published
for
calibreweb
(pip)
Jan 21, 2022
Cross-Site Request Forgery in Jenkins
Moderate
CVE-2022-20612
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jan 21, 2022
ProTip!
Advisories are also available from the
GraphQL API