GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,715
Erlang
34
GitHub Actions
28
Go
2,302
Maven
5,000+
npm
3,946
NuGet
711
pip
3,716
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
535 advisories
Filter by severity
SQL injection in ADOdb PostgreSQL driver pg_insert_id() method
Critical
CVE-2025-46337
was published
for
adodb/adodb-php
(Composer)
May 1, 2025
SeaweedFS Vulnerable to SQL Injection
Moderate
CVE-2024-40120
was published
for
github.com/seaweedfs/seaweedfs
(Go)
May 16, 2025
Liferay Portal and Liferay DXP Vulnerable to Multiple SQL Injections
High
CVE-2021-29053
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Shopware Vulnerable to Blind SQL-injection in DAL aggregations
High
CVE-2025-27892
was published
for
shopware/core
(Composer)
Apr 8, 2025
Moodle has a SQL injection risk in course search module list filter
High
CVE-2025-26533
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
org.xwiki.platform:xwiki-platform-rest-server allows SQL injection in query endpoint of REST API
Critical
CVE-2025-32969
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Apr 23, 2025
Blind SQL Injection via GridFieldSortableHeader
High
CVE-2022-38148
was published
for
silverstripe/framework
(Composer)
Nov 22, 2022
Jeecg-boot vulnerable to SQL Injection
Moderate
CVE-2022-45210
was published
for
org.jeecgframework.boot:jeecg-boot-common
(Maven)
Nov 25, 2022
Jeecg-boot vulnerable to SQL injection via /sys/user/putRecycleBin
Moderate
CVE-2022-45208
was published
for
org.jeecgframework.boot:jeecg-boot-common
(Maven)
Nov 25, 2022
Jeecg-boot vulnerable to SQL injection via updateNullByEmptyString
Critical
CVE-2022-45207
was published
for
org.jeecgframework.boot:jeecg-boot-common
(Maven)
Nov 25, 2022
owncast is vulnerable to SQL Injection
Critical
CVE-2022-3751
was published
for
github.com/owncast/owncast
(Go)
Nov 29, 2022
OpenMetadata SQL Injection
High
CVE-2024-55238
was published
for
org.open-metadata:openmetadata-service
(Maven)
Apr 17, 2025
PostHog Plugin Server SQL Injection Vulnerability
High
CVE-2025-1520
was published
for
@posthog/plugin-server
(npm)
Apr 23, 2025
org.xwiki.platform:xwiki-platform-oldcore allows SQL injection in short form select requests through the script query API
High
CVE-2025-32968
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Apr 23, 2025
MetalGenix GeniXCMS vulnerable to SQL Injection
Critical
CVE-2015-3933
was published
for
genix/cms
(Composer)
May 17, 2022
TeamPass vulnerable to SQL Injection
Critical
CVE-2015-7564
was published
for
nilsteampassnet/teampass
(Composer)
May 17, 2022
phpMyAdmin SQL injection in user accounts page
High
CVE-2020-5504
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 24, 2022
Apache Jetspeed vulnerable to SQL Injection
High
CVE-2016-0710
was published
for
org.apache.portals.jetspeed-2:jetspeed
(Maven)
May 17, 2022
WEC Map (wec_map) extension for TYPO3 allows SQL Injection
High
CVE-2014-6295
was published
for
jbartels/wec-map
(Composer)
May 17, 2022
CoolURI extension for TYPO3 vulnerable to SQL Injection
High
CVE-2013-5322
was published
for
bednee/cooluri
(Composer)
May 17, 2022
News system (news) extension for TYPO3 vulnerable to SQL Injection
High
CVE-2013-4748
was published
for
georgringer/news
(Composer)
May 17, 2022
Multishop extension for TYPO3 has SQL Injection vulnerability
High
CVE-2013-4682
was published
for
bvbmedia/multishop
(Composer)
May 17, 2022
Moodle allows remote authenticated users to cause a denial of service (invalid database records)
Moderate
CVE-2011-4292
was published
for
moodle/moodle
(Composer)
May 13, 2022
TYPO3 SQL Injection vulnerability
Moderate
CVE-2010-5103
was published
for
typo3/cms
(Composer)
May 17, 2022
Webkit PDFs for TYPO3 has SQL Injection vulnerability
High
CVE-2010-4961
was published
for
dmk/webkitpdf
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API