GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            1,414 advisories
        Filter by severity
        
      
      
    
                    
                      MoonShine Arbitrary File Upload Vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-51489
                      
                      was published
                        for
                        
                          moonshine/moonshine
                        
                        (Composer)
                      Aug 19, 2025 
                    
                  
                    
                      LibreNMS allows stored XSS in Alert Template name field
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-55296
                      
                      was published
                        for
                        
                          librenms/librenms
                        
                        (Composer)
                      Aug 18, 2025 
                    
                  
                    
                      svg-sanitizer Bypasses Attribute Sanitization
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-55166
                      
                      was published
                        for
                        
                          enshrined/svg-sanitize
                        
                        (Composer)
                      Aug 12, 2025 
                    
                  
                    
                      Concrete CMS vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard Page
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-8571
                      
                      was published
                        for
                        
                          concrete5/concrete5
                        
                        (Composer)
                      Aug 6, 2025 
                    
                  
                    
                      Microweber has Reflected XSS Vulnerability in the id Parameter
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-51501
                      
                      was published
                        for
                        
                          microweber/microweber
                        
                        (Composer)
                      Aug 1, 2025 
                    
                  
                    
                      Microweber has Reflected XSS Vulnerability in the layout Parameter
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-51502
                      
                      was published
                        for
                        
                          microweber/microweber
                        
                        (Composer)
                      Aug 1, 2025 
                    
                  
                    
                      Microweber XSS Vulnerability in the homepage Endpoint 
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-51504
                      
                      was published
                        for
                        
                          microweber/microweber
                        
                        (Composer)
                      Aug 1, 2025 
                    
                  
                    
                      Withdrawn Advisory: CodeIgniter4 Cross-Site Scripting Vulnerability in debugbar_time Parameter
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-45406
                      
                      was published
                        for
                        
                          codeigniter4/framework
                        
                        (Composer)
                      Jul 25, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Cockpit - Content Platform vulnerable to XSS through name or email argument names
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-7053
                      
                      was published
                        for
                        
                          cockpit-hq/cockpit
                        
                        (Composer)
                      Jul 4, 2025 
                    
                  
                    
                      Ibexa RichText Field Type XSS vulnerabilities in back office
                    
                      
  Moderate
                    
                
                      
                        GHSA-9qv6-4pwm-m68f
                      
                      was published
                        for
                        
                          ibexa/fieldtype-richtext
                        
                        (Composer)
                      Jun 13, 2025 
                    
                  
                    
                      Ibexa Admin UI XSS vulnerabilities in back office
                    
                      
  Moderate
                    
                
                      
                        GHSA-5r6x-g6jv-4v87
                      
                      was published
                        for
                        
                          ibexa/admin-ui
                        
                        (Composer)
                      Jun 13, 2025 
                    
                  
                    
                      Ibexa Admin UI assets XSS vulnerabilities in back office
                    
                      
  Moderate
                    
                
                      
                        GHSA-vhgq-r8gx-5fpv
                      
                      was published
                        for
                        
                          ibexa/admin-ui-assets
                        
                        (Composer)
                      Jun 13, 2025 
                    
                  
                    
                      Ibexa eZ Platform Admin UI assets XSS vulnerabilities in back office
                    
                      
  Moderate
                    
                
                      
                        GHSA-r5rx-53g9-25rj
                      
                      was published
                        for
                        
                          ezsystems/ezplatform-admin-ui-assets
                        
                        (Composer)
                      Jun 13, 2025 
                    
                  
                    
                      Ibexa eZ Platform Admin UI XSS vulnerabilities in back office
                    
                      
  Moderate
                    
                
                      
                        GHSA-r7pm-mw8g-p7px
                      
                      was published
                        for
                        
                          ezsystems/ezplatform-admin-ui
                        
                        (Composer)
                      Jun 13, 2025 
                    
                  
                    
                      starcitizentools/citizen-skin allows stored XSS in user registration date message
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-49578
                      
                      was published
                        for
                        
                          starcitizentools/citizen-skin
                        
                        (Composer)
                      Jun 13, 2025 
                    
                  
                    
                      starcitizentools/citizen-skin allows stored XSS in menu heading message
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-49579
                      
                      was published
                        for
                        
                          starcitizentools/citizen-skin
                        
                        (Composer)
                      Jun 13, 2025 
                    
                  
                    
                      starcitizentools/citizen-skin allows stored XSS in preference menu heading messages
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-49577
                      
                      was published
                        for
                        
                          starcitizentools/citizen-skin
                        
                        (Composer)
                      Jun 13, 2025 
                    
                  
                    
                      starcitizentools/citizen-skin allows stored XSS in search no result messages
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-49576
                      
                      was published
                        for
                        
                          starcitizentools/citizen-skin
                        
                        (Composer)
                      Jun 13, 2025 
                    
                  
                    
                      Citizen skin vulnerable to stored XSS through multiple system messages
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-49575
                      
                      was published
                        for
                        
                          starcitizentools/citizen-skin
                        
                        (Composer)
                      Jun 11, 2025 
                    
                  
                    
                      Drupal Lightgallery Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-48447
                      
                      was published
                        for
                        
                          drupal/lightgallery
                        
                        (Composer)
                      Jun 11, 2025 
                    
                  
                    
                      Laravel Translation Manager Vulnerable to Stored Cross-site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-49130
                      
                      was published
                        for
                        
                          barryvdh/laravel-translation-manager
                        
                        (Composer)
                      Jun 9, 2025 
                    
                  
                    
                      juzaweb CMS allows cross-site scripting by uploading an SVG file
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-5420
                      
                      was published
                        for
                        
                          juzaweb/cms
                        
                        (Composer)
                      Jun 2, 2025 
                    
                  
                    
                      Chrome PHP is missing encoding in `CssSelector`
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-48883
                      
                      was published
                        for
                        
                          chrome-php/chrome
                        
                        (Composer)
                      May 28, 2025 
                    
                  
                    
                      [clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-48203
                      
                      was published
                        for
                        
                          clickstorm/cs-seo
                        
                        (Composer)
                      May 21, 2025 
                    
                  
                    
                      Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-47946
                      
                      was published
                        for
                        
                          symfony/ux-live-component
                        
                        (Composer)
                      May 19, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API