GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            142 advisories
        Filter by severity
        
      
      
    
                    
                      Mattermost Server allows XSS via CSRF
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-11084
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      Mattermost Server: Files may be rendered inline instead of downloaded, allowing script execution
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-11083
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      Mattermost Server is vulnerable to XSS through crafted links
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-11082
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                       Mattermost Server allows XSS via redirect URL
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-11079
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      Mattermost Server is vulnerable to XSS through lack of link relationship attributes `noreferrer` and `noopener`
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-11071
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      Mattermost Server is vulnerable to XSS via a Legal or Support setting
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-11073
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      Mattermost Server is vulnerable to XSS through customizable theme color-code values
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-11070
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      Mattermost Server vulnerable to Cross-site Scripting through file preview feature
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-11063
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server
                        
                        (Go)
                      May 24, 2022 
                    
                  
                    
                      Memos Vulnerable to Stored Cross-Site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-56761
                      
                      was published
                        for
                        
                          github.com/usememos/memos
                        
                        (Go)
                      Sep 4, 2025 
                    
                  
                    
                      Gokapi has stored XSS vulnerability in friendly name for API keys
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-48495
                      
                      was published
                        for
                        
                          github.com/forceu/gokapi
                        
                        (Go)
                      Jun 3, 2025 
                    
                  
                    
                      Gokapi vulnerable to stored XSS via uploading file with malicious file name
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-48494
                      
                      was published
                        for
                        
                          github.com/forceu/gokapi
                        
                        (Go)
                      Jun 3, 2025 
                    
                  
                    
                      Memos has Cross-Site Scripting (XSS) Vulnerability in Image URLs
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-50738
                      
                      was published
                        for
                        
                          github.com/usememos/memos
                        
                        (Go)
                      Jul 29, 2025 
                    
                  
                    
                      Gogs XSS allowed by stored call in PDF renderer
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-47943
                      
                      was published
                        for
                        
                          github.com/gogs/gogs
                        
                        (Go)
                      Jun 26, 2025 
                    
                  
                    
                      Harbor repository description page has Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-32019
                      
                      was published
                        for
                        
                          github.com/goharbor/harbor
                        
                        (Go)
                      Jul 23, 2025 
                    
                  
                    
                      ZITADEL has improper HTML sanitization in emails and Console UI
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-41953
                      
                      was published
                        for
                        
                          github.com/zitadel/zitadel
                        
                        (Go)
                      Jul 31, 2024 
                    
                  
                    
                      golang.org/x/net vulnerable to Cross-site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-22872
                      
                      was published
                        for
                        
                          golang.org/x/net
                        
                        (Go)
                      Apr 16, 2025 
                    
                  
                    
                      LF Edge eKuiper Vulnerable to Stored XSS in Configuration Key Functionality
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-52290
                      
                      was published
                        for
                        
                          github.com/lf-edge/ekuiper
                        
                        (Go)
                      May 14, 2025 
                    
                  
                    
                      Authentication Bypass by Spoofing in github.com/greenpau/caddy-security
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-21494
                      
                      was published
                        for
                        
                          github.com/greenpau/caddy-security
                        
                        (Go)
                      Feb 17, 2024 
                    
                  
                    
                      csaf-poc/csaf_distribution Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-43996
                      
                      was published
                        for
                        
                          github.com/csaf-poc/csaf_distribution
                        
                        (Go)
                      Dec 14, 2022 
                    
                  
                    
                      one-api Cross-site Scripting vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-3801
                      
                      was published
                        for
                        
                          github.com/songquanpeng/one-api
                        
                        (Go)
                      Apr 19, 2025 
                    
                  
                    
                      Miniflux Media Proxy vulnerable to Stored Cross-site Scripting due to improper Content-Security-Policy configuration
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-31483
                      
                      was published
                        for
                        
                          miniflux.app/v2
                        
                        (Go)
                      Apr 4, 2025 
                    
                  
                    
                      LocalAI Cross-Site Scripting (XSS) vulnerability in its search functionality
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-9900
                      
                      was published
                        for
                        
                          github.com/mudler/LocalAI
                        
                        (Go)
                      Mar 20, 2025 
                    
                  
                    
                      Stored XSS in Miniflux when opening a broken image due to unescaped ServerError in proxy handler
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-27592
                      
                      was published
                        for
                        
                          miniflux.app/v2
                        
                        (Go)
                      Apr 2, 2025 
                    
                  
                    
                      LF Edge eKuiper allows Stored XSS in Rules Functionality
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-52812
                      
                      was published
                        for
                        
                          github.com/lf-edge/ekuiper
                        
                        (Go)
                      Mar 10, 2025 
                    
                  
                    
                      In-memory stored Cross-site scripting (XSS) vulnerability in pineconesim
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-27155
                      
                      was published
                        for
                        
                          github.com/matrix-org/pinecone
                        
                        (Go)
                      Mar 4, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API