GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,521
Maven
5,000+
npm
5,000+
NuGet
911
pip
4,760
Pub
13
RubyGems
1,036
Rust
1,229
Swift
53
Unreviewed advisories
All unreviewed
5,000+
829 advisories
Filter by severity
WWBN AVideo is missing CSRF protection in objects/commentDelete.json.php enables mass comment deletion against moderators and content creators
Moderate
GHSA-8qm8-g55h-xmqr
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
WWBN AVideo: Missing CSRF Protection on State-Changing JSON Endpoints Enables Forced Comment Creation, Vote Manipulation, and Category Asset Deletion
Moderate
GHSA-x2pw-9c38-cp2j
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
WWBN AVideo has Multiple CSRF Vulnerabilities in Admin JSON Endpoints (Category CRUD, Plugin Update Script)
High
GHSA-ffw8-fwxp-h64w
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Takeover Including Encoder URL and SMTP Credentials
High
GHSA-vvfw-4m39-fjqf
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
goshs has CSRF in state-changing GET routes enables authenticated file deletion and directory creation
Moderate
CVE-2026-40883
was published
for
github.com/patrickhener/goshs/v2
(Go)
Apr 14, 2026
MetaGPT has an eval injection via a cross-site request forgery attack
Low
CVE-2026-6109
was published
for
metagpt
(pip)
Apr 12, 2026
RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests
High
CVE-2026-39371
was published
for
rwsdk
(npm)
Apr 8, 2026
AVideo: CSRF on Player Skin Configuration via admin/playerUpdate.json.php
Moderate
CVE-2026-35181
was published
for
wwbn/avideo
(Composer)
Apr 3, 2026
OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode
Moderate
GHSA-mhr7-2xmv-4c4q
was published
for
openclaw
(npm)
Apr 3, 2026
Payload has a CSRF Protection Bypass in Authentication Flow
Moderate
CVE-2026-34749
was published
for
payload
(npm)
Apr 1, 2026
AVideo: CSRF on Plugin Enable/Disable Endpoint Allows Disabling Security Plugins
Moderate
CVE-2026-34613
was published
for
wwbn/avideo
(Composer)
Apr 1, 2026
AVideo: CSRF on emailAllUsers.json.php Enables Mass Phishing Email to All Users
Moderate
CVE-2026-34611
was published
for
wwbn/avideo
(Composer)
Apr 1, 2026
AVideo's CSRF on Admin Plugin Configuration Enables Payment Credential Hijacking
High
CVE-2026-34394
was published
for
wwbn/avideo
(Composer)
Mar 31, 2026
Admidio has CSRF and Form Validation Bypass in Inventory Item Save via `imported` Parameter
Moderate
CVE-2026-34383
was published
for
admidio/admidio
(Composer)
Mar 31, 2026
Admidio has Missing CSRF Protection on Registration Approval Actions
Moderate
CVE-2026-34384
was published
for
admidio/admidio
(Composer)
Mar 31, 2026
Admidio has Missing CSRF Protections on Custom List Deletion in mylist_function.php
Moderate
CVE-2026-34382
was published
for
admidio/admidio
(Composer)
Mar 31, 2026
Mattermost doesn't properly validate CSRF tokens
Moderate
CVE-2026-27659
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 25, 2026
AVideo's GET-Based CSRF in setPermission.json.php Enables Privilege Escalation via Arbitrary Permission Modification
High
CVE-2026-33649
was published
for
wwbn/avideo
(Composer)
Mar 25, 2026
AVideo Affected by CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Execution via Malicious Plugin Upload
High
CVE-2026-33507
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
Cross-Site Tool Execution for HTTP Servers without Authorizatrion in github.com/modelcontextprotocol/go-sdk
High
CVE-2026-33252
was published
for
github.com/modelcontextprotocol/go-sdk
(Go)
Mar 19, 2026
Next.js: null origin can bypass Server Actions CSRF checks
Moderate
CVE-2026-27978
was published
for
next
(npm)
Mar 17, 2026
Admidio is Missing CSRF Protection on Role Membership Date Changes
Moderate
CVE-2026-32755
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Admidio is Missing CSRF Validation on Role Delete, Activate, and Deactivate Actions
Moderate
CVE-2026-32816
was published
for
admidio/admidio
(Composer)
Mar 16, 2026
Craft CMS has a potential information disclosure vulnerability in preview tokens
Low
CVE-2026-29113
was published
for
craftcms/cms
(Composer)
Mar 10, 2026
Gokapi has CSRF in Login Endpoint
Moderate
CVE-2026-29084
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
ProTip!
Advisories are also available from the
GraphQL API