GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            141 advisories
        Filter by severity
        
      
      
    
                    
                      Drupal Umami Analytics allows Cross-Site Scripting (XSS)
                    
                      
  Low
                    
                
                      
                        CVE-2025-10931
                      
                      was published
                        for
                        
                          drupal/umami_analytics
                        
                        (Composer)
                      Oct 30, 2025 
                    
                  
                    
                      TastyIgniter vulnerable to Cross-Site Scripting
                    
                      
  Low
                    
                
                      
                        CVE-2025-61417
                      
                      was published
                        for
                        
                          tastyigniter/tastyigniter
                        
                        (Composer)
                      Oct 20, 2025 
                    
                  
                    
                      LibreNMS alert-rules has a Cross-Site Scripting Vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-62412
                      
                      was published
                        for
                        
                          librenms/librenms
                        
                        (Composer)
                      Oct 16, 2025 
                    
                  
                    
                      drupal-pattern-lab/unified-twig-extensions is vulnerable to XXS
                    
                      
  Low
                    
                
                      
                        CVE-2025-11570
                      
                      was published
                        for
                        
                          drupal-pattern-lab/unified-twig-extensions
                        
                        (Composer)
                      Oct 10, 2025 
                    
                  
                    
                      Mangati NovoSGA XSS vulnerability in /admin
                    
                      
  Low
                    
                
                      
                        CVE-2025-10909
                      
                      was published
                        for
                        
                          novosga/novosga
                        
                        (Composer)
                      Sep 24, 2025 
                    
                  
                    
                      GP247 and S-Cart have a stored cross-site scripting (XSS) vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-57407
                      
                      was published
                        for
                        
                          gp247/core
                        
                        (Composer)
                      Sep 23, 2025 
                    
                  
                    
                      TYPO3 "Form to Database" extension susceptible to Cross-site Scripting
                    
                      
  Low
                    
                
                      
                        CVE-2025-10316
                      
                      was published
                        for
                        
                          lavitto/typo3-form-to-database
                        
                        (Composer)
                      Sep 16, 2025 
                    
                  
                    
                      Concrete CMS is vulnerable to Stored XSS from Home Folder on Members Dashboard page
                    
                      
  Low
                    
                
                      
                        CVE-2025-8573
                      
                      was published
                        for
                        
                          concrete5/concrete5
                        
                        (Composer)
                      Aug 6, 2025 
                    
                  
                    
                      Microweber Has Stored XSS Vulnerability in User Profile Fields
                    
                      
  Low
                    
                
                      
                        CVE-2025-51503
                      
                      was published
                        for
                        
                          microweber/microweber
                        
                        (Composer)
                      Jul 31, 2025 
                    
                  
                    
                      Microweber vulnerable to XSS attack due to insure `group` component in its Settings handler
                    
                      
  Low
                    
                
                      
                        CVE-2025-2214
                      
                      was published
                        for
                        
                          microweber/microweber
                        
                        (Composer)
                      Mar 12, 2025 
                    
                  
                    
                      The Backup Plus extension for TYPO3 (ns_backup) allows XSS
                    
                      
  Low
                    
                
                      
                        CVE-2025-48206
                      
                      was published
                        for
                        
                          nitsan/ns-backup
                        
                        (Composer)
                      May 21, 2025 
                    
                  
                    
                      LibreNMS stored Cross-site Scripting vulnerability in poller group name
                    
                      
  Low
                    
                
                      
                        CVE-2025-47931
                      
                      was published
                        for
                        
                          librenms/librenms
                        
                        (Composer)
                      May 19, 2025 
                    
                  
                    
                      Yeswiki Vulnerable to Authenticated Reflected Cross-site Scripting
                    
                      
  Low
                    
                
                      
                        CVE-2025-46350
                      
                      was published
                        for
                        
                          yeswiki/yeswiki
                        
                        (Composer)
                      Apr 29, 2025 
                    
                  
                    
                      YesWiki Stored XSS Vulnerability in Comments 
                    
                      
  Low
                    
                
                      
                        CVE-2025-46346
                      
                      was published
                        for
                        
                          yeswiki/yeswiki
                        
                        (Composer)
                      Apr 29, 2025 
                    
                  
                    
                      Drupal Formatter Suite Vulnerable to Cross-Site Scripting (XSS) via Link Element Attributes
                    
                      
  Low
                    
                
                      
                        CVE-2025-31697
                      
                      was published
                        for
                        
                          drupal/formatter_suite
                        
                        (Composer)
                      Apr 1, 2025 
                    
                  
                    
                      Drupal RapiDoc OAS Field Formatter Cross-Site Scripting (XSS) vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-31696
                      
                      was published
                        for
                        
                          drupal/rapidoc_elements_field_formatter
                        
                        (Composer)
                      Apr 1, 2025 
                    
                  
                    
                      Drupal Link field display mode formatter Cross-Site Scripting (XSS) vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-31695
                      
                      was published
                        for
                        
                          drupal/link_field_display_mode_formatter
                        
                        (Composer)
                      Apr 1, 2025 
                    
                  
                    
                      Drupal SpamSpan Cross-Site Scripting (XSS) vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-31687
                      
                      was published
                        for
                        
                          drupal/spamspan
                        
                        (Composer)
                      Apr 1, 2025 
                    
                  
                    
                      Drupal Core Cross-Site Scripting (XSS) Vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2025-31675
                      
                      was published
                        for
                        
                          drupal/core
                        
                        (Composer)
                      Apr 1, 2025 
                    
                  
                    
                      Duplicate Advisory: Contao allows admin an account to upload SVG file containing malicious JavaScript
                    
                      
  Low
                    
                
                      
                        CVE-2024-45965
                      
                      was published
                        for
                        
                          contao/contao
                        
                        (Composer)
                      Oct 2, 2024 
                        •
                        
                          withdrawn
                    
                  
                    
                      concrete5 vulnerable to Cross-site Scripting
                    
                      
  Low
                    
                
                      
                        CVE-2015-3989
                      
                      was published
                        for
                        
                          concrete5/concrete5
                        
                        (Composer)
                      May 17, 2022 
                    
                  
                    
                      WEC Map (wec_map) extension for TYPO3 allows Cross-site Scripting
                    
                      
  Low
                    
                
                      
                        CVE-2014-6296
                      
                      was published
                        for
                        
                          jbartels/wec-map
                        
                        (Composer)
                      May 17, 2022 
                    
                  
                    
                      Joomla! Cross-site Scripting vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2013-5583
                      
                      was published
                        for
                        
                          joomla/joomla-cms
                        
                        (Composer)
                      May 17, 2022 
                    
                  
                    
                      Static Info Tables (static_info_tables) extension TYPO3 vulnerable to Cross-site Scripting
                    
                      
  Low
                    
                
                      
                        CVE-2013-5323
                      
                      was published
                        for
                        
                          sjbr/static-info-tables
                        
                        (Composer)
                      May 17, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API