GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
342 advisories
Filter by severity
Cross-Site Request Forgery in sqlite-web
High
CVE-2021-23404
was published
for
sqlite-web
(pip)
Sep 9, 2021
Liferay Portal Vulnerable to CSRF in Headless APIs
High
CVE-2025-62258
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 28, 2025
Canonical LXD CSRF Vulnerability When Using Client Certificate Authentication with the LXD-UI
High
CVE-2025-54286
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system
High
CVE-2025-47410
was published
for
org.apache.geode:geode-web
(Maven)
Oct 18, 2025
Magento Cross-Site Request Forgery (CSRF) vulnerability
High
CVE-2025-49555
was published
for
magento/community-edition
(Composer)
Aug 12, 2025
Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass
High
CVE-2025-59845
was published
for
@apollo/explorer
(npm)
Sep 26, 2025
Spring Batch Admin vulnerable to Cross-site request forgery (CSRF) in the file upload functionality
High
CVE-2017-12881
was published
for
org.springframework.batch:spring-batch-admin-manager
(Maven)
May 17, 2022
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover
High
CVE-2025-58430
was published
for
github.com/knadh/listmonk
(Go)
Sep 9, 2025
Liferay Portal Vulnerable to Cross-Site Request Forgery
High
CVE-2025-43748
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 20, 2025
Liferay Portal and Liferay DXP Vulnerable to CSRF via the Layout Module
High
CVE-2023-35030
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Jun 15, 2023
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery in Terms of Use Page
High
CVE-2021-29050
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Feb 21, 2024
Aim vulnerable to Cross-Site Request Forgery
High
CVE-2024-7760
was published
for
aim
(pip)
Mar 20, 2025
TYPO3 Scheduler Module vulnerable to Cross-Site Request Forgery
High
CVE-2024-55924
was published
for
typo3/cms-scheduler
(Composer)
Jan 14, 2025
Liferay Portal Layout Module and Liferay DXP Exposes the Cross-Site Request Forgery (CSRF) Token in URLs
High
CVE-2021-33338
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
TYPO3 Extension Manager Module vulnerable to Cross-Site Request Forgery
High
CVE-2024-55921
was published
for
typo3/cms-extensionmanager
(Composer)
Jan 14, 2025
Moodle CSRF risk in analytics management of models
High
CVE-2024-34008
was published
for
moodle/moodle
(Composer)
May 31, 2024
Moodle CSRF risk in admin preset tool management of presets
High
CVE-2024-34001
was published
for
moodle/moodle
(Composer)
May 31, 2024
CSRF protection for any URL can be bypassed in Jenkins Pipeline: Input Step Plugin
High
CVE-2022-43407
was published
for
org.jenkins-ci.plugins:pipeline-input-step
(Maven)
Oct 19, 2022
Cross-Site Request Forgery in OpenNMS Horizon
High
CVE-2021-25931
was published
for
org.opennms:opennms
(Maven)
May 25, 2021
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor
High
CVE-2024-26273
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 22, 2024
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor
High
CVE-2024-26272
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 22, 2024
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the My Account Widget
High
CVE-2024-26271
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 22, 2024
Apache Wicket vulnerable to CSRF attacks
High
CVE-2016-6806
was published
for
org.apache.wicket:wicket-core
(Maven)
May 17, 2022
Apache Brooklyn is vulnerable to cross-site request forgery (CSRF)
High
CVE-2016-8737
was published
for
org.apache.brooklyn:brooklyn-jsgui
(Maven)
May 17, 2022
Neo4J vulnerable to Cross-Site Request Forgery
High
CVE-2013-7259
was published
for
org.neo4j:neo4j
(Maven)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API