GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            496 advisories
        Filter by severity
        
      
      
    
                    
                      Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validation
                    
                      
  High
                    
                
                      
                        CVE-2025-64112
                      
                      was published
                        for
                        
                          statamic/cms
                        
                        (Composer)
                      Oct 30, 2025 
                    
                  
                    
                      Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
                    
                      
  High
                    
                
                      
                        CVE-2025-59837
                      
                      was published
                        for
                        
                          astro
                        
                        (npm)
                      Oct 28, 2025 
                    
                  
                    
                      Magento vulnerable to stored Cross-Site Scripting (XSS)
                    
                      
  High
                    
                
                      
                        CVE-2025-54264
                      
                      was published
                        for
                        
                          magento/community-edition
                        
                        (Composer)
                      Oct 14, 2025 
                    
                  
                    
                      Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
                    
                      
  High
                    
                
                      
                        CVE-2025-62172
                      
                      was published
                        for
                        
                          homeassistant
                        
                        (pip)
                      Oct 14, 2025 
                    
                  
                    
                      Cross-site Scripting (XSS) in @scullyio/scully
                    
                      
  High
                    
                
                      
                        CVE-2020-28470
                      
                      was published
                        for
                        
                          @scullyio/ng-lib
                        
                        (npm)
                      Apr 13, 2021 
                    
                  
                    
                      Bagisto is vulnerable to XSS through Admin Panel's product creation path
                    
                      
  High
                    
                
                      
                        CVE-2025-60880
                      
                      was published
                        for
                        
                          bagisto/bagisto
                        
                        (Composer)
                      Oct 10, 2025 
                    
                  
                    
                      pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
                    
                      
  High
                    
                
                      
                        CVE-2025-61773
                      
                      was published
                        for
                        
                          pyload-ng
                        
                        (pip)
                      Oct 9, 2025 
                    
                  
                    
                      Duplicate Advisory: Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
                    
                      
  High
                    
                
                      
                        GHSA-7rgr-72hp-9wp3
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Oct 6, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Duplicate Advisory: Flowise Stored XSS vulnerability through logs in chatbot
                    
                      
  High
                    
                
                      
                        GHSA-wq95-wr7m-26h4
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Oct 6, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server
                    
                      
  High
                    
                
                      
                        CVE-2025-58444
                      
                      was published
                        for
                        
                          @modelcontextprotocol/inspector
                        
                        (npm)
                      Sep 8, 2025 
                    
                  
                    
                      Star Citizen  EmbedVideo Extension Stored XSS through wikitext caused by usage of non-reserved data attributes
                    
                      
  High
                    
                
                      
                        CVE-2025-59839
                      
                      was published
                        for
                        
                          starcitizenwiki/embedvideo
                        
                        (Composer)
                      Sep 24, 2025 
                    
                  
                    
                      Mesh Connect JS SDK Vulnerable to Cross Site Scripting via createLink.openLink
                    
                      
  High
                    
                
                      
                        CVE-2025-59430
                      
                      was published
                        for
                        
                          @meshconnect/web-link-sdk
                        
                        (npm)
                      Sep 22, 2025 
                    
                  
                    
                      listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover
                    
                      
  High
                    
                
                      
                        CVE-2025-58430
                      
                      was published
                        for
                        
                          github.com/knadh/listmonk
                        
                        (Go)
                      Sep 9, 2025 
                    
                  
                    
                      Shopware: Reflective Cross Site-Scripting (XSS) in CMS components
                    
                      
  High
                    
                
                      
                        GHSA-9v82-vcjx-m76j
                      
                      was published
                        for
                        
                          shopware/core
                        
                        (Composer)
                      Sep 10, 2025 
                    
                  
                    
                      Webrecorder packages are vulnerable to XSS through 404 error handling logic
                    
                      
  High
                    
                
                      
                        CVE-2025-58765
                      
                      was published
                        for
                        
                          @webrecorder/archivewebpage
                        
                        (npm)
                      Sep 10, 2025 
                    
                  
                    
                      N8N's Chat Trigger component is vulnerable to XSS
                    
                      
  High
                    
                
                      
                        CVE-2025-56265
                      
                      was published
                        for
                        
                          @n8n/n8n-nodes-langchain
                        
                        (npm)
                      Sep 8, 2025 
                    
                  
                    
                      LLama Factory Remote OS Command Injection Vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-52803
                      
                      was published
                        for
                        
                          llamafactory
                        
                        (pip)
                      Nov 21, 2024 
                    
                  
                    
                      NocoDB Vulnerable to Stored Cross-Site Scripting in Formula.vue
                    
                      
  High
                    
                
                      
                        CVE-2023-49781
                      
                      was published
                        for
                        
                          nocodb
                        
                        (npm)
                      May 13, 2024 
                    
                  
                    
                      Stored XSS in n8n Form Trigger allows Account Takeover via injected iframe and video/source
                    
                      
  High
                    
                
                      
                        CVE-2025-52478
                      
                      was published
                        for
                        
                          n8n
                        
                        (npm)
                      Aug 19, 2025 
                    
                  
                    
                      Magento Cross-site Scripting vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-49557
                      
                      was published
                        for
                        
                          magento/community-edition
                        
                        (Composer)
                      Aug 12, 2025 
                    
                  
                    
                      filebrowser allows Stored Cross-Site Scripting through the Markdown preview function
                    
                      
  High
                    
                
                      
                        CVE-2025-52902
                      
                      was published
                        for
                        
                          github.com/filebrowser/filebrowser
                        
                        (Go)
                      Jun 27, 2025 
                    
                  
                    
                      Cadwyn vulnerable to XSS on the docs page
                    
                      
  High
                    
                
                      
                        CVE-2025-53528
                      
                      was published
                        for
                        
                          cadwyn
                        
                        (pip)
                      Jul 21, 2025 
                    
                  
                    
                      NodeJS version of HAX CMS Has Disabled Content Security Policy That Enables Cross-Site Scripting
                    
                      
  High
                    
                
                      
                        CVE-2025-54128
                      
                      was published
                        for
                        
                          @haxtheweb/haxcms-nodejs
                        
                        (npm)
                      Jul 21, 2025 
                    
                  
                    
                      Grafana Cross-Site-Scripting (XSS) via custom loaded frontend plugin
                    
                      
  High
                    
                
                      
                        CVE-2025-4123
                      
                      was published
                        for
                        
                          github.com/grafana/grafana
                        
                        (Go)
                      May 22, 2025 
                    
                  
                    
                      Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering
                    
                      
  High
                    
                
                      
                        CVE-2025-54075
                      
                      was published
                        for
                        
                          @nuxtjs/mdc
                        
                        (npm)
                      Jul 20, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API