GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,096
Erlang
29
GitHub Actions
19
Go
1,925
Maven
5,000+
npm
3,654
NuGet
638
pip
3,263
Pub
10
RubyGems
873
Rust
823
Swift
35
Unreviewed advisories
All unreviewed
5,000+
6,012 advisories
Filter by severity
The PropertyHive plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
High
Unreviewed
CVE-2024-8490
was published
Sep 17, 2024
The Review Ratings WordPress plugin through 1.6 does not have CSRF check in some places, and is...
Moderate
Unreviewed
CVE-2024-8052
was published
Sep 17, 2024
The Enhanced Search Box WordPress plugin through 0.6.1 does not have CSRF check in place when...
Moderate
Unreviewed
CVE-2024-8091
was published
Sep 17, 2024
The Accordion Image Menu WordPress plugin through 3.1.3 does not have CSRF check in some places,...
Moderate
Unreviewed
CVE-2024-8092
was published
Sep 17, 2024
The Posts reminder WordPress plugin through 0.20 does not have CSRF check in place when updating...
Moderate
Unreviewed
CVE-2024-8093
was published
Sep 17, 2024
The Visual Sound (old) WordPress plugin through 1.06 does not have CSRF check in place when...
Moderate
Unreviewed
CVE-2024-8047
was published
Sep 17, 2024
The Special Feed Items WordPress plugin through 1.0.1 does not have CSRF check in some places,...
Moderate
Unreviewed
CVE-2024-8051
was published
Sep 17, 2024
The Vikinghammer Tweet WordPress plugin through 0.2.4 does not have CSRF check in some places,...
Moderate
Unreviewed
CVE-2024-8043
was published
Sep 17, 2024
The infolinks Ad Wrap WordPress plugin through 1.0.2 does not have CSRF check in place when...
Moderate
Unreviewed
CVE-2024-8044
was published
Sep 17, 2024
Lunary Cross-Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2024-6862
was published
for
lunary
(npm)
Sep 13, 2024
The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to...
High
Unreviewed
CVE-2024-7423
was published
Sep 13, 2024
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not have CSRF and path validation...
Moderate
Unreviewed
CVE-2024-7864
was published
Sep 13, 2024
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded...
High
Unreviewed
CVE-2024-7863
was published
Sep 13, 2024
The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is...
Moderate
Unreviewed
CVE-2024-7816
was published
Sep 12, 2024
The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its...
Moderate
Unreviewed
CVE-2024-7820
was published
Sep 12, 2024
The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places,...
Moderate
Unreviewed
CVE-2024-7817
was published
Sep 12, 2024
The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating...
Moderate
Unreviewed
CVE-2024-7859
was published
Sep 12, 2024
The blogintroduction-wordpress-plugin WordPress plugin through 0.3.0 does not have CSRF check in...
Moderate
Unreviewed
CVE-2024-7862
was published
Sep 12, 2024
The Music Request Manager WordPress plugin through 1.3 does not have CSRF check in some places,...
Moderate
Unreviewed
CVE-2024-6017
was published
Sep 12, 2024
The Easy Property Listings WordPress plugin before 3.5.4 does not have CSRF check when deleting...
Moderate
Unreviewed
CVE-2024-3163
was published
Sep 12, 2024
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an...
Critical
Unreviewed
CVE-2024-44677
was published
Sep 10, 2024
The Tutor LMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to,...
Moderate
Unreviewed
CVE-2023-2919
was published
Sep 10, 2024
The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could...
Moderate
Unreviewed
CVE-2024-7688
was published
Sep 9, 2024
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when...
Moderate
Unreviewed
CVE-2024-6856
was published
Sep 8, 2024
The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its...
Moderate
Unreviewed
CVE-2024-6925
was published
Sep 8, 2024
ProTip!
Advisories are also available from the
GraphQL API