GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,782
Erlang
36
GitHub Actions
29
Go
2,346
Maven
5,000+
npm
3,976
NuGet
720
pip
3,774
Pub
12
RubyGems
923
Rust
980
Swift
38
Unreviewed advisories
All unreviewed
5,000+
19 advisories
Filter by severity
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings...
Critical
Unreviewed
CVE-2025-47916
was published
May 16, 2025
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection...
Critical
Unreviewed
CVE-2024-23692
was published
May 31, 2024
listmonk's Sprig template Injection vulnerability leads to reading of Environment Variable for low privilege user
Critical
CVE-2025-49136
was published
for
github.com/knadh/listmonk
(Go)
Jun 9, 2025
IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because...
Critical
Unreviewed
CVE-2025-46661
was published
Apr 28, 2025
wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3...
Critical
Unreviewed
CVE-2025-32461
was published
Apr 9, 2025
Code injection in RazorEngine
Critical
CVE-2021-46703
was published
for
RazorEngine
(NuGet)
Mar 7, 2022
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Podlove...
Critical
Unreviewed
CVE-2024-52393
was published
Nov 14, 2024
: Improper Neutralization of Special Elements Used in a Template Engine vulnerability in...
Critical
Unreviewed
CVE-2024-49271
was published
Oct 16, 2024
The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and...
Critical
Unreviewed
CVE-2024-12583
was published
Jan 4, 2025
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Supsystic...
Critical
Unreviewed
CVE-2024-52434
was published
Nov 18, 2024
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Saso...
Critical
Unreviewed
CVE-2024-52427
was published
Nov 18, 2024
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
Critical
CVE-2024-37301
was published
for
document-merge-service
(pip)
Jun 11, 2024
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Supsystic...
Critical
Unreviewed
CVE-2024-48042
was published
Oct 16, 2024
changedetection.io has a Server Side Template Injection using Jinja2 which allows Remote Command Execution
Critical
CVE-2024-32651
was published
for
changedetection.io
(pip)
Oct 15, 2024
The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and...
Critical
Unreviewed
CVE-2024-6386
was published
Aug 21, 2024
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template...
Critical
Unreviewed
CVE-2024-24724
was published
Apr 3, 2024
Shopware Remote Code Execution Vulnerability
Critical
GHSA-83jv-4prm-34g7
was published
for
shopware/shopware
(Composer)
May 21, 2024
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio...
Critical
Unreviewed
CVE-2023-2259
was published
Apr 24, 2023
RCE in Mingsoft MCMS
Critical
CVE-2022-22930
was published
for
net.mingsoft:ms-mcms
(Maven)
Jan 22, 2022
ProTip!
Advisories are also available from the
GraphQL API