GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            1,414 advisories
        Filter by severity
        
      
      
    
                    
                      Drupal CivicTheme Design System allows Cross-Site Scripting (XSS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-12083
                      
                      was published
                        for
                        
                          drupal/civictheme
                        
                        (Composer)
                      Oct 30, 2025 
                    
                  
                    
                      Drupal Plausible tracking is vulnerable to XSS
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-10927
                      
                      was published
                        for
                        
                          drupal/plausible_tracking
                        
                        (Composer)
                      Oct 30, 2025 
                    
                  
                    
                      Drupal JSON Field is vulnerable to XSS
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-10926
                      
                      was published
                        for
                        
                          drupal/json_field
                        
                        (Composer)
                      Oct 30, 2025 
                    
                  
                    
                      Sharp user-provided input can be evaluated in a SharpShowTextField with Vue template syntax
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62798
                      
                      was published
                        for
                        
                          code16/sharp
                        
                        (Composer)
                      Oct 29, 2025 
                    
                  
                    
                      PrivateBin is missing HTML sanitization of attached filename in file size hint
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62796
                      
                      was published
                        for
                        
                          privatebin/privatebin
                        
                        (Composer)
                      Oct 28, 2025 
                    
                  
                    
                      code16 Sharp vulnerable to Cross Site Scripting (XSS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-61457
                      
                      was published
                        for
                        
                          code16/sharp
                        
                        (Composer)
                      Oct 21, 2025 
                    
                  
                    
                      Citizen vulnerable to stored XSS in sticky header button messages
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62508
                      
                      was published
                        for
                        
                          starcitizentools/citizen-skin
                        
                        (Composer)
                      Oct 20, 2025 
                    
                  
                    
                      Cargo Mediawiki Extension vulnerable to Cross-site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62671
                      
                      was published
                        for
                        
                          mediawiki/cargo
                        
                        (Composer)
                      Oct 18, 2025 
                    
                  
                    
                      ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
                    
                      
  Moderate
                    
                
                      
                        GHSA-8c2g-f8jm-5cr7
                      
                      was published
                        for
                        
                          ibexa/fieldtype-richtext
                        
                        (Composer)
                      Oct 17, 2025 
                    
                  
                    
                      ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
                    
                      
  Moderate
                    
                
                      
                        GHSA-2mx6-fq24-g2mh
                      
                      was published
                        for
                        
                          ibexa/admin-ui
                        
                        (Composer)
                      Oct 17, 2025 
                    
                  
                    
                      ezsystems/ezplatform-admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
                    
                      
  Moderate
                    
                
                      
                        GHSA-99c7-c3mw-mxhv
                      
                      was published
                        for
                        
                          ezsystems/ezplatform-admin-ui
                        
                        (Composer)
                      Oct 17, 2025 
                    
                  
                    
                      bagisto has Cross Site Scripting (XSS) in Create New Customer
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62414
                      
                      was published
                        for
                        
                          bagisto/bagisto
                        
                        (Composer)
                      Oct 16, 2025 
                    
                  
                    
                      bagisto has a Cross Site Scripting (XSS) vulnerability in TinyMCE Image Upload (SVG)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62418
                      
                      was published
                        for
                        
                          bagisto/bagisto
                        
                        (Composer)
                      Oct 16, 2025 
                    
                  
                    
                      bagisto has Cross Site Scripting (XSS) issue in TinyMCE Image Upload (HTML)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62415
                      
                      was published
                        for
                        
                          bagisto/bagisto
                        
                        (Composer)
                      Oct 16, 2025 
                    
                  
                    
                      LibreNMS has a Stored XSS vulnerability in its Alert Transport name field
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62411
                      
                      was published
                        for
                        
                          librenms/librenms
                        
                        (Composer)
                      Oct 16, 2025 
                    
                  
                    
                      Magento vulnerable to stored Cross-Site Scripting (XSS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-54266
                      
                      was published
                        for
                        
                          magento/community-edition
                        
                        (Composer)
                      Oct 14, 2025 
                    
                  
                    
                      LibreNMS is vulnerable to Reflected-XSS in `report_this` function
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62365
                      
                      was published
                        for
                        
                          librenms/librenms
                        
                        (Composer)
                      Oct 13, 2025 
                    
                  
                    
                      VaahCMS is vulnerable to XSS through its Avatar Upload endpoint
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-61183
                      
                      was published
                        for
                        
                          webreinvent/vaahcms
                        
                        (Composer)
                      Oct 8, 2025 
                    
                  
                    
                      Joomla! CMS vulnerable to XSS via the input filter
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-54476
                      
                      was published
                        for
                        
                          joomla/filter
                        
                        (Composer)
                      Sep 30, 2025 
                    
                  
                    
                      Snipe-IT allows XSS
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-59712
                      
                      was published
                        for
                        
                          snipe/snipe-it
                        
                        (Composer)
                      Sep 19, 2025 
                    
                  
                    
                      YesWiki Cross Site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-52277
                      
                      was published
                        for
                        
                          yeswiki/yeswiki
                        
                        (Composer)
                      Sep 9, 2025 
                    
                  
                    
                      Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-9823
                      
                      was published
                        for
                        
                          mautic/core
                        
                        (Composer)
                      Sep 3, 2025 
                    
                  
                    
                      UnoPim has Stored Cross-site Scripting vulnerability in user creation functionality
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-55742
                      
                      was published
                        for
                        
                          unopim/unopim
                        
                        (Composer)
                      Aug 21, 2025 
                    
                  
                    
                      moonshine Stored Cross-Site Scripting Vulnerability in Create Article
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-51487
                      
                      was published
                        for
                        
                          moonshine/moonshine
                        
                        (Composer)
                      Aug 19, 2025 
                    
                  
                    
                      moonshine Stored Cross-Site Scripting Vulnerability in Create Admin
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-51488
                      
                      was published
                        for
                        
                          moonshine/moonshine
                        
                        (Composer)
                      Aug 19, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API