GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
271 advisories
Filter by severity
The MongoSQL Transition Readiness Tool writes database and collection names into its generated...
Moderate
Unreviewed
CVE-2026-76797
was published
Aug 28, 2026
Snipe-IT has CSV formula injection in Activity Report export
Moderate
CVE-2026-55452
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerability when exporting data...
Moderate
Unreviewed
CVE-2026-56652
was published
Aug 27, 2026
exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at...
High
Unreviewed
CVE-2026-78209
was published
Aug 24, 2026
CSV export functionality in Brainstorm Force SureForms version, <= 2.1.1, fails to neutralize...
High
Unreviewed
CVE-2026-19501
was published
Aug 18, 2026
When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as...
Moderate
Unreviewed
CVE-2026-64955
was published
Aug 12, 2026
Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows...
Moderate
Unreviewed
CVE-2026-18738
was published
Aug 3, 2026
BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a...
Moderate
Unreviewed
CVE-2026-65875
was published
Aug 3, 2026
FacturaScripts: CSV formula injection in CSVExport allows authenticated low-priv users to plant payloads that execute when an admin opens the export
High
CVE-2026-45263
was published
for
facturascripts/facturascripts
(Composer)
Jul 14, 2026
In version 8.2.1 of PrestaShop, there is a vulnerability relating to the incorrect sanitisation...
Moderate
Unreviewed
CVE-2026-14846
was published
Jul 13, 2026
Statamic Vulnerable to CSV formula injection in form submission exports
Moderate
CVE-2026-54243
was published
for
statamic/cms
(Composer)
Jun 26, 2026
@actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields
Moderate
CVE-2026-50179
was published
for
@actual-app/web
(npm)
Jun 22, 2026
@actual-app/cli `--format csv` Output Vulnerable to CSV Formula Injection via Custom `escapeCsv` Helper
Moderate
CVE-2026-46672
was published
for
@actual-app/cli
(npm)
Jun 22, 2026
Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc....
High
Unreviewed
CVE-2026-5242
was published
Jun 15, 2026
Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications
Moderate
CVE-2026-47693
was published
for
poweradmin/poweradmin
(Composer)
Jun 8, 2026
Spree: CSV Formula Injection in Customer Export
Moderate
GHSA-xf4v-w5x5-pv79
was published
for
spree
(RubyGems)
Jun 4, 2026
HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a...
High
Unreviewed
CVE-2025-52612
was published
Jun 4, 2026
json-2-csv vulnerable to CSV Injection via the preventCsvInjection optio
Moderate
CVE-2026-9673
was published
for
json-2-csv
(npm)
May 28, 2026
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0,...
Moderate
Unreviewed
CVE-2026-35157
was published
May 11, 2026
wger: CSV/TSV formula injection in gym member export (first_name/last_name)
High
GHSA-xq9m-hmp9-fw87
was published
for
wger
(pip)
May 6, 2026
Kimai vulnerable to formula Injection via tag names in XLSX export
Moderate
CVE-2026-42267
was published
for
kimai/kimai
(Composer)
May 5, 2026
ERPGo SaaS 3.9 contains a CSV injection vulnerability that allows authenticated attackers to...
High
Unreviewed
CVE-2023-54348
was published
May 5, 2026
An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2026-31049
was published
Apr 14, 2026
If a malformed data is input to the affected product, a CSV file downloaded from the affected...
Moderate
Unreviewed
CVE-2026-24447
was published
Feb 4, 2026
Moodle formula injection vulnerability
Moderate
CVE-2025-67851
was published
for
moodle/moodle
(Composer)
Feb 3, 2026
ProTip!
Advisories are also available from the
GraphQL API