GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            3,105 advisories
        Filter by severity
        
      
      
    
                    
                      Drupal JSON Field is vulnerable to XSS
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-10926
                      
                      was published
                        for
                        
                          drupal/json_field
                        
                        (Composer)
                      Oct 30, 2025 
                    
                  
                    
                      Drupal Plausible tracking is vulnerable to XSS
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-10927
                      
                      was published
                        for
                        
                          drupal/plausible_tracking
                        
                        (Composer)
                      Oct 30, 2025 
                    
                  
                    
                      Drupal CivicTheme Design System allows Cross-Site Scripting (XSS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-12083
                      
                      was published
                        for
                        
                          drupal/civictheme
                        
                        (Composer)
                      Oct 30, 2025 
                    
                  
                    
                      DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-64094
                      
                      was published
                        for
                        
                          DotNetNuke.Core
                        
                        (NuGet)
                      Oct 29, 2025 
                    
                  
                    
                      CKAN vulnerable to stored XSS in resource description
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-54384
                      
                      was published
                        for
                        
                          ckan
                        
                        (pip)
                      Oct 29, 2025 
                    
                  
                    
                      FastMCP vulnerable to reflected XSS in client's callback page
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62800
                      
                      was published
                        for
                        
                          fastmcp
                        
                        (pip)
                      Oct 29, 2025 
                    
                  
                    
                      PrivateBin is missing HTML sanitization of attached filename in file size hint
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62796
                      
                      was published
                        for
                        
                          privatebin/privatebin
                        
                        (Composer)
                      Oct 28, 2025 
                    
                  
                    
                      Sharp user-provided input can be evaluated in a SharpShowTextField with Vue template syntax
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62798
                      
                      was published
                        for
                        
                          code16/sharp
                        
                        (Composer)
                      Oct 29, 2025 
                    
                  
                    
                      Liferay Portal Vulnerable to Cross-Site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62263
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.account.admin.web
                        
                        (Maven)
                      Oct 27, 2025 
                    
                  
                    
                      Piranha CMS vulnerable to stored cross-site scripting (XSS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-61413
                      
                      was published
                        for
                        
                          Piranha
                        
                        (NuGet)
                      Oct 23, 2025 
                    
                  
                    
                      validator.js has a URL validation bypass vulnerability in its isURL function
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-56200
                      
                      was published
                        for
                        
                          validator
                        
                        (npm)
                      Sep 30, 2025 
                    
                  
                    
                      MCMS reflected cross-site scripting (XSS) vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-60837
                      
                      was published
                        for
                        
                          net.mingsoft:ms-mcms
                        
                        (Maven)
                      Oct 23, 2025 
                    
                  
                    
                      Mattermost Server allows XSS via CSRF
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-11084
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      Mattermost Server: Files may be rendered inline instead of downloaded, allowing script execution
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-11083
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      Mattermost Server is vulnerable to XSS through crafted links
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-11082
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      Liferay Portal and Liferay DXP vulnerable to reflected cross-site scripting (XSS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62248
                      
                      was published
                        for
                        
                          com.liferay:com.liferay.dynamic.data.mapping.web
                        
                        (Maven)
                      Oct 22, 2025 
                    
                  
                    
                       Mattermost Server allows XSS via redirect URL
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-11079
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      Mattermost Server is vulnerable to XSS through lack of link relationship attributes `noreferrer` and `noopener`
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-11071
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      Mattermost Server is vulnerable to XSS via a Legal or Support setting
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-11073
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      Mattermost Server is vulnerable to XSS through customizable theme color-code values
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-11070
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      Potential XSS vulnerability in jQuery
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-11023
                      
                      was published
                        for
                        
                          components/jquery
                        
                        (RubyGems)
                      Apr 29, 2020 
                    
                  
                    
                      Liferay Portal reflected cross-site scripting (XSS) vulnerability in the google_gaget
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62249
                      
                      was published
                        for
                        
                          com.liferay.portal:com.liferay.portal.impl
                        
                        (Maven)
                      Oct 21, 2025 
                    
                  
                    
                      Mattermost Server vulnerable to Cross-site Scripting through file preview feature
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-11063
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      code16 Sharp vulnerable to Cross Site Scripting (XSS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-61457
                      
                      was published
                        for
                        
                          code16/sharp
                        
                        (Composer)
                      Oct 21, 2025 
                    
                  
                    
                      Magento vulnerable to stored Cross-Site Scripting (XSS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-54266
                      
                      was published
                        for
                        
                          magento/community-edition
                        
                        (Composer)
                      Oct 14, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API