Threats / Contributors / GitHub Security Advisories
Registry & coordination
contributor
GitHub Security Advisories
cited as evidence in 53 · CNA assigner on 35 (independent) of 59 known-exploited records. Every aggregate on this page is recomputed from the records listed below — each one already cited to its public source.
github.com ↗ · home of the cited advisories
Independent CNA
59
records cited in
deterministic count0
finder / reporter credits
CVE.org credits35
CVE records catalogued (CNA)
independent67%
avg modeled exploit prob.
FIRST EPSS, 59/5910%
ransomware-associated
6 of 59 · CISA flag01
Known for
— recomputed from this contributor’s own recordsSurfacesApplication / other (53), Server / web platform (2), Operating system / kernel (2), Edge / remote-access infra (1), Hypervisor / virtualization (1)
WeaknessInjection (22), Authentication (8), Path traversal / file (6), Web / client (5), Authorization / access control (4)
PortfolioCraft CMS (4), OSGeo (3), Roundcube (3), Langflow (3), OpenPLC (2), Laravel (2)
02
Narrative reach
— how far this contributor’s records carry an attacker, front door → lights out1Front door
58reach this stage2Keys to the kingdom
58reach this stage3Lateral reach
55reach this stage4Data at risk
8reach this stage5Lights out
0reach this stageFurthest any of these records carries an attacker: 4 · Data at risk. 8 of 58 narrative-framed records reach data-at-risk or lights-out. (furthest-position idiom, reused from the landing map; the stage mapping is a model output over cited evidence.)
03
Recent highlights
— this contributor’s newest known-exploited records04
Every record they’re cited in
— all 59, each linked to its cited sourceThis is the evidence behind every number above. Sorted ransomware-first, then by modeled exploit probability.
CVE-2021-3129Laravel100%RWKEVCVE-2025-55182Meta100%RWKEVCVE-2023-43208NextGen Healthcare83%RWKEVCVE-2020-2021Palo Alto Networks4%RWKEVCVE-2026-45321TanStack2%RWKEVCVE-2026-48027Nx1%RWKEVCVE-2023-32315Ignite Realtime100%KEVCVE-2025-3248Langflow100%KEVCVE-2021-39226Grafana Labs100%KEVCVE-2025-24893XWiki100%KEVCVE-2022-46169Cacti100%KEVCVE-2024-36401OSGeo100%KEVCVE-2025-32432Craft CMS100%KEVCVE-2016-10033PHP100%KEVCVE-2024-23692Rejetto99%KEVCVE-2022-24816OSGeo99%KEVCVE-2021-39144XStream99%KEVCVE-2026-33017Langflow98%KEVCVE-2025-68613n8n98%KEVCVE-2025-32433Erlang98%KEVCVE-2024-56145Craft CMS97%KEVCVE-2021-41277Metabase97%KEVCVE-2026-39987Marimo96%KEVCVE-2026-42208BerriAI93%KEVCVE-2025-24016Wazuh93%KEVCVE-2025-54068Laravel92%KEVCVE-2024-11680ProjectSend92%KEVCVE-2021-21311Adminer90%KEVCVE-2021-32648October CMS90%KEVCVE-2021-21315Npm package90%KEVCVE-2025-49113Roundcube89%KEVCVE-2021-43798Grafana Labs89%KEVCVE-2025-57819Sangoma87%KEVCVE-2025-64328Sangoma84%KEVCVE-2023-28432MinIO84%KEVCVE-2020-11023JQuery84%KEVCVE-2021-22555Linux79%KEVCVE-2025-8110Gogs77%KEVCVE-2024-37383Roundcube73%KEVCVE-2020-36193PEAR71%KEVCVE-2025-58360OSGeo67%KEVCVE-2025-11953React Native Community62%KEVCVE-2026-33634Aquasecurity60%KEVCVE-2025-31125Vite60%KEVCVE-2026-42271BerriAI54%KEVCVE-2021-26829OpenPLC48%KEVCVE-2025-30066tj-actions45%KEVCVE-2021-26828OpenPLC39%KEVCVE-2025-34291Langflow25%KEVCVE-2025-68461Roundcube20%KEVCVE-2024-6047GeoVision10%KEVCVE-2023-28434MinIO7%KEVCVE-2018-0161Cisco4%KEVCVE-2025-54313Prettier4%KEVCVE-2025-23209Craft CMS4%KEVCVE-2025-48384Git3%KEVCVE-2025-30154reviewdog2%KEVCVE-2025-22226VMware2%KEVCVE-2025-35939Craft CMS1%KEV
05