GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,952
Erlang
39
GitHub Actions
38
Go
2,609
Maven
5,000+
npm
4,252
NuGet
757
pip
4,021
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
38,010 advisories
Filter by severity
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62920
was published
Oct 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62937
was published
Oct 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62923
was published
Oct 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62885
was published
Oct 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62899
was published
Oct 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62904
was published
Oct 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62900
was published
Oct 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62894
was published
Oct 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62905
was published
Oct 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62898
was published
Oct 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62903
was published
Oct 27, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62887
was published
Oct 27, 2025
A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered.
Moderate
Unreviewed
CVE-2025-55757
was published
Oct 25, 2025
The The7 — Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-11897
was published
Oct 25, 2025
The Fast Velocity Minify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-12034
was published
Oct 25, 2025
The SpendeOnline.org plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-11875
was published
Oct 25, 2025
The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-10580
was published
Oct 25, 2025
The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-8666
was published
Oct 25, 2025
The Listeo theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
Moderate
Unreviewed
CVE-2025-8413
was published
Oct 25, 2025
The Gutenberg Blocks – PublishPress Blocks plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2025-8588
was published
Oct 25, 2025
The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP...
High
Unreviewed
CVE-2025-11238
was published
Oct 25, 2025
The Open Source Genesis Framework theme for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-10737
was published
Oct 25, 2025
Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability...
Moderate
Unreviewed
CVE-2025-60936
was published
Oct 24, 2025
SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try...
Moderate
Unreviewed
CVE-2025-5350
was published
Oct 24, 2025
The Simple Excel Pricelist for WooCommerce plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2025-12096
was published
Oct 24, 2025
ProTip!
Advisories are also available from the
GraphQL API