GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,049
Maven
5,000+
npm
4,787
NuGet
825
pip
4,384
Pub
12
RubyGems
988
Rust
1,144
Swift
50
Unreviewed advisories
All unreviewed
5,000+
368 advisories
Filter by severity
Liferay Portal Vulnerable to Cross-Site Request Forgery
High
CVE-2025-43748
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 20, 2025
Jenkins has a CSRF vulnerability on the login form
Low
CVE-2025-67639
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Dec 10, 2025
Liferay Portal Vulnerable to CSRF in Headless APIs
High
CVE-2025-62258
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 28, 2025
Jenkins Publish to Bitbucket Plugin vulnerable to CSRF and missing permissions check
Moderate
CVE-2025-64149
was published
for
org.jenkins-ci.plugins:publish-to-bitbucket
(Maven)
Oct 29, 2025
Jenkins Nexus Task Runner Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64141
was published
for
org.jenkins-ci.plugins:nexus-task-runner
(Maven)
Oct 29, 2025
Jenkins Themis Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64136
was published
for
org.jenkins-ci.plugins:themis
(Maven)
Oct 29, 2025
Jenkins Start Windocks Containers Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64138
was published
for
org.jenkins-ci.plugins:windocks-start-container
(Maven)
Oct 29, 2025
Jenkins Extensible Choice Parameter Plugin vulnerable to cross-site request forgery
Moderate
CVE-2025-64133
was published
for
jp.ikedam.jenkins.plugins:extensible-choice-parameter
(Maven)
Oct 29, 2025
Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system
High
CVE-2025-47410
was published
for
org.apache.geode:geode-web
(Maven)
Oct 18, 2025
Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
Moderate
CVE-2025-41254
was published
for
org.springframework:spring-websocket
(Maven)
Oct 16, 2025
Liferay Portal is vulnerable to CSRF through publication comments
Moderate
CVE-2025-62245
was published
for
com.liferay:com.liferay.change.tracking.web
(Maven)
Oct 10, 2025
Spring Batch Admin vulnerable to Cross-site request forgery (CSRF) in the file upload functionality
High
CVE-2017-12881
was published
for
org.springframework.batch:spring-batch-admin-manager
(Maven)
May 17, 2022
Liferay Portal Cross-Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2025-43809
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 19, 2025
Liferay Portal CSRF Vulnerability via Endpoint Parameter
Moderate
CVE-2025-43745
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 19, 2025
Liferay Portal and Liferay DXP Vulnerable to CSRF via the Layout Module
High
CVE-2023-35030
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Jun 15, 2023
Liferay Portal and Liferay DXP Vulnerable to CSRF in the Script Console
Critical
CVE-2024-8980
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 22, 2024
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery in Terms of Use Page
High
CVE-2021-29050
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Feb 21, 2024
Liferay Portal Layout Module and Liferay DXP Exposes the Cross-Site Request Forgery (CSRF) Token in URLs
High
CVE-2021-33338
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
Jenkins Cadence vManager Plugin Vulnerable to Cross-Site Request Forgery
Moderate
CVE-2025-47886
was published
for
org.jenkins-ci.plugins:vmanager-plugin
(Maven)
May 14, 2025
CSRF protection for any URL can be bypassed in Jenkins Pipeline: Input Step Plugin
High
CVE-2022-43407
was published
for
org.jenkins-ci.plugins:pipeline-input-step
(Maven)
Oct 19, 2022
Cross-Site Request Forgery in OpenNMS Horizon
Moderate
CVE-2021-25930
was published
for
org.opennms:opennms
(Maven)
May 25, 2021
Cross-Site Request Forgery in OpenNMS Horizon
High
CVE-2021-25931
was published
for
org.opennms:opennms
(Maven)
May 25, 2021
Cross-Site Request Forgery in Jenkins Cluster Statistics Plugin
Moderate
CVE-2022-45398
was published
for
org.zeroturnaround:cluster-stats
(Maven)
Nov 16, 2022
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor
High
CVE-2024-26273
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 22, 2024
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor
High
CVE-2024-26272
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Oct 22, 2024
ProTip!
Advisories are also available from the
GraphQL API