GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            1,414 advisories
        Filter by severity
        
      
      
    
                    
                       tarteaucitron-wp WordPress Plugin Vulnerable to Stored Cross-Site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-11718
                      
                      was published
                        for
                        
                          couleurcitron/tarteaucitron-wp
                        
                        (Composer)
                      May 15, 2025 
                    
                  
                    
                      Koillection Cross Site Scripting vulnerability 
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-29746
                      
                      was published
                        for
                        
                          koillection/koillection
                        
                        (Composer)
                      May 7, 2025 
                    
                  
                    
                      league/commonmark contains a XSS vulnerability in Attributes extension
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-46734
                      
                      was published
                        for
                        
                          league/commonmark
                        
                        (Composer)
                      May 5, 2025 
                    
                  
                    
                      Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-46550
                      
                      was published
                        for
                        
                          yeswiki/yeswiki
                        
                        (Composer)
                      Apr 29, 2025 
                    
                  
                    
                      Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-46549
                      
                      was published
                        for
                        
                          yeswiki/yeswiki
                        
                        (Composer)
                      Apr 29, 2025 
                    
                  
                    
                      Moodle has reflected Cross-site Scripting risk in policy tool
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-3643
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      Apr 25, 2025 
                    
                  
                    
                      Laravel Starter Cross Site Scripting (XSS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-26159
                      
                      was published
                        for
                        
                          nasirkhan/laravel-starter
                        
                        (Composer)
                      Apr 22, 2025 
                    
                  
                    
                      PEAR HTTP_Request2 vulnerable to Cross-site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-43717
                      
                      was published
                        for
                        
                          pear/http_request2
                        
                        (Composer)
                      Apr 17, 2025 
                    
                  
                    
                      Formie has XSS vulnerability for email notification content for preview
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-32426
                      
                      was published
                        for
                        
                          verbb/formie
                        
                        (Composer)
                      Apr 11, 2025 
                    
                  
                    
                      Formie has XSS vulnerability for importing forms
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-32427
                      
                      was published
                        for
                        
                          verbb/formie
                        
                        (Composer)
                      Apr 11, 2025 
                    
                  
                    
                      Yii does not prevent XSS in scenarios where fallback error renderer is used
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-32027
                      
                      was published
                        for
                        
                          yiisoft/yii
                        
                        (Composer)
                      Apr 11, 2025 
                    
                  
                    
                      Silverstripe Framework has a XSS vulnerability in HTML editor
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-30148
                      
                      was published
                        for
                        
                          silverstripe/framework
                        
                        (Composer)
                      Apr 10, 2025 
                    
                  
                    
                      Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-25197
                      
                      was published
                        for
                        
                          dnadesign/silverstripe-elemental
                        
                        (Composer)
                      Apr 10, 2025 
                    
                  
                    
                      Concrete CMS Vulnerable to Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-3153
                      
                      was published
                        for
                        
                          concrete5/concrete5
                        
                        (Composer)
                      Apr 3, 2025 
                    
                  
                    
                      Drupal Obfuscate Vulnerable to Stored Cross-Site Scripting (XSS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-3130
                      
                      was published
                        for
                        
                          drupal/obfuscate
                        
                        (Composer)
                      Apr 3, 2025 
                    
                  
                    
                      Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-3057
                      
                      was published
                        for
                        
                          drupal/core
                        
                        (Composer)
                      Apr 1, 2025 
                    
                  
                    
                      Drupal Google Tag Cross-Site Scripting (XSS) vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-31682
                      
                      was published
                        for
                        
                          drupal/google_tag
                        
                        (Composer)
                      Apr 1, 2025 
                    
                  
                    
                      Drupal Ignition Cross-Site Scripting (XSS) vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-31679
                      
                      was published
                        for
                        
                          drupal/ignition
                        
                        (Composer)
                      Apr 1, 2025 
                    
                  
                    
                      ConcreteCMS Cross-Site Scripting (XSS) via HTML Block Text Field
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-2967
                      
                      was published
                        for
                        
                          concrete5/concrete5
                        
                        (Composer)
                      Mar 31, 2025 
                    
                  
                    
                      ShopXO Vulnerable to Server-Side Request Forgery (SSRF) and Cross-Site Scripting (XSS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-28094
                      
                      was published
                        for
                        
                          shopxo/shopxo
                        
                        (Composer)
                      Mar 29, 2025 
                    
                  
                    
                      wp-svg-upload WordPress plugin vulnerable to Stored Cross-site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-11847
                      
                      was published
                        for
                        
                          digimix/wp-svg-upload
                        
                        (Composer)
                      Mar 26, 2025 
                    
                  
                    
                      Clickstorm SEO Allows Cross-Site Scripting (XSS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-30081
                      
                      was published
                        for
                        
                          clickstorm/cs-seo
                        
                        (Composer)
                      Mar 19, 2025 
                    
                  
                    
                      Additional TCA Allows Cross-Site Scripting (XSS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-30083
                      
                      was published
                        for
                        
                          codingms/additional-tca
                        
                        (Composer)
                      Mar 19, 2025 
                    
                  
                    
                      Contao Vulnerable to Cross-Site Scripting (XSS) through SVG uploads
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-29790
                      
                      was published
                        for
                        
                          contao/core-bundle
                        
                        (Composer)
                      Mar 18, 2025 
                    
                  
                    
                      Froxlor has an HTML Injection Vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-48958
                      
                      was published
                        for
                        
                          froxlor/froxlor
                        
                        (Composer)
                      Mar 11, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API