GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            1,414 advisories
        Filter by severity
        
      
      
    
                    
                      Cross-site scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-32713
                      
                      was published
                        for
                        
                          shopware/shopware
                        
                        (Composer)
                      Sep 8, 2021 
                    
                  
                    
                      Cross-site scripting in LavaLite-CMS
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-23700
                      
                      was published
                        for
                        
                          lavalite/cms
                        
                        (Composer)
                      Sep 8, 2021 
                    
                  
                    
                      XSS vulnerability on password reset page
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-27909
                      
                      was published
                        for
                        
                          mautic/core
                        
                        (Composer)
                      Sep 1, 2021 
                    
                  
                    
                      Cross-site Scripting in the femanager TYPO3 extension
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-36787
                      
                      was published
                        for
                        
                          in2code/femanager
                        
                        (Composer)
                      Sep 1, 2021 
                    
                  
                    
                      Cross-site Scripting in the yoast_seo TYPO3 extension
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-36788
                      
                      was published
                        for
                        
                          yoast-seo-for-typo3/yoast_seo
                        
                        (Composer)
                      Sep 1, 2021 
                    
                  
                    
                      Cross Site Scripting in Subrion CMS
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-22392
                      
                      was published
                        for
                        
                          intelliants/subrion
                        
                        (Composer)
                      Sep 1, 2021 
                    
                  
                    
                      Cross-site Scripting in TYPO3 extension
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-36785
                      
                      was published
                        for
                        
                          miniorange/miniorange-saml
                        
                        (Composer)
                      Aug 30, 2021 
                    
                  
                    
                      Cross-site scripting in imgURL
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-38713
                      
                      was published
                        for
                        
                          helloxz/imgurl
                        
                        (Composer)
                      Aug 30, 2021 
                    
                  
                    
                      Cross-site scripting in feehicms
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-19709
                      
                      was published
                        for
                        
                          feehi/feehicms
                        
                        (Composer)
                      Aug 30, 2021 
                    
                  
                    
                      Cross site scripting via HTML attributes in the back end
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-35955
                      
                      was published
                        for
                        
                          contao/contao
                        
                        (Composer)
                      Aug 25, 2021 
                    
                  
                    
                      Cross-Site Scripting via Rich-Text Content
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-32768
                      
                      was published
                        for
                        
                          typo3/cms
                        
                        (Composer)
                      Aug 19, 2021 
                    
                  
                    
                      Cross Site Scripting in LavaLite CMS
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-23234
                      
                      was published
                        for
                        
                          lavalite/cms
                        
                        (Composer)
                      Aug 9, 2021 
                    
                  
                    
                      Cross-Site Scripting in Backend Grid View
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-32669
                      
                      was published
                        for
                        
                          typo3/cms
                        
                        (Composer)
                      Jul 22, 2021 
                    
                  
                    
                      Cross-Site Scripting in Query Generator & Query View
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-32668
                      
                      was published
                        for
                        
                          typo3/cms
                        
                        (Composer)
                      Jul 22, 2021 
                    
                  
                    
                      Cross-Site Scripting in Page Preview
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-32667
                      
                      was published
                        for
                        
                          typo3/cms
                        
                        (Composer)
                      Jul 22, 2021 
                    
                  
                    
                      Cross-site Scripting in Froala WYSIWYG Editor
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-28114
                      
                      was published
                        for
                        
                          froala/wysiwyg-editor
                        
                        (Composer)
                      Jul 19, 2021 
                    
                  
                    
                      Craft CMS Cross-site Scripting Vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-27902
                      
                      was published
                        for
                        
                          craftcms/cms
                        
                        (Composer)
                      Jul 2, 2021 
                    
                  
                    
                      XSS Injection in Media Collection Title was possible
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-32737
                      
                      was published
                        for
                        
                          sulu/sulu
                        
                        (Composer)
                      Jul 2, 2021 
                    
                  
                    
                      Cross site scripting in the system log
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-35210
                      
                      was published
                        for
                        
                          contao/contao
                        
                        (Composer)
                      Jul 1, 2021 
                    
                  
                    
                      Cross-site Scripting in yii2cmf
                    
                      
  Moderate
                    
                
                      
                        CVE-2018-10704
                      
                      was published
                        for
                        
                          yidashi/yii2cmf
                        
                        (Composer)
                      Jun 22, 2021 
                    
                  
                    
                      Cross-site scripting in PageKit
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-32245
                      
                      was published
                        for
                        
                          pagekit/pagekit
                        
                        (Composer)
                      Jun 22, 2021 
                    
                  
                    
                      ckeditor4 vulnerable to cross-site scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-33829
                      
                      was published
                        for
                        
                          ckeditor4
                        
                        (Composer)
                      Jun 21, 2021 
                    
                  
                    
                      Cross-site scripting in Centreon
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-27676
                      
                      was published
                        for
                        
                          centreon/centreon
                        
                        (Composer)
                      Jun 8, 2021 
                    
                  
                    
                      Cross-site scripting in media2click
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-31778
                      
                      was published
                        for
                        
                          amazing/media2click
                        
                        (Composer)
                      Jun 8, 2021 
                    
                  
                    
                      reflected XSS in tribalsystems/zenario
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-27673
                      
                      was published
                        for
                        
                          tribalsystems/zenario
                        
                        (Composer)
                      Jun 8, 2021 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API