GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            161 advisories
        Filter by severity
        
      
      
    
                    
                      Jenkins Applitools Eyes Plugin vulnerable to XSS through its Build page
                    
                      
  High
                    
                
                      
                        CVE-2025-53658
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:applitools-eyes
                        
                        (Maven)
                      Jul 9, 2025 
                    
                  
                    
                      Jenkins Gatling Plugin Vulnerable to Cross-Site Scripting (XSS)
                    
                      
  High
                    
                
                      
                        CVE-2025-5806
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:gatling
                        
                        (Maven)
                      Jun 6, 2025 
                    
                  
                    
                      Jenkins Health Advisor by CloudBees Plugin Vulnerable to Cross-Site Scripting
                    
                      
  High
                    
                
                      
                        CVE-2025-47885
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:cloudbees-jenkins-advisor
                        
                        (Maven)
                      May 14, 2025 
                    
                  
                    
                      Graylog Allows Session Takeover via Insufficient HTML Sanitization
                    
                      
  High
                    
                
                      
                        CVE-2025-46827
                      
                      was published
                        for
                        
                          org.graylog2:graylog2-server
                        
                        (Maven)
                      May 7, 2025 
                    
                  
                    
                      Graylog Allows Stored Cross-Site Scripting via Files Plugin and API Browser
                    
                      
  High
                    
                
                      
                        GHSA-q9q2-3ppx-mwqf
                      
                      was published
                        for
                        
                          org.graylog2:graylog2-server
                        
                        (Maven)
                      May 7, 2025 
                    
                  
                    
                      Jenkins Associated Files Plugin vulnerable to cross-site scripting (XSS)
                    
                      
  High
                    
                
                      
                        CVE-2022-45401
                      
                      was published
                        for
                        
                          org.jenkins-ci.main:associated-files-plugin
                        
                        (Maven)
                      Nov 16, 2022 
                    
                  
                    
                      Jenkins AnchorChain Plugin Has a Cross-Site Scripting (XSS) Vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-30196
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:anchorchain
                        
                        (Maven)
                      Mar 19, 2025 
                    
                  
                    
                      Cross-site Scripting (XSS) in CrafterCMS
                    
                      
  High
                    
                
                      
                        CVE-2023-4136
                      
                      was published
                        for
                        
                          org.craftercms:crafter-engine
                        
                        (Maven)
                      Aug 3, 2023 
                    
                  
                    
                      org.xwiki.platform:xwiki-platform-livedata-macro vulnerable to Basic Cross-site Scripting
                    
                      
  High
                    
                
                      
                        CVE-2023-29508
                      
                      was published
                        for
                        
                          org.xwiki.platform:xwiki-platform-livedata-macro
                        
                        (Maven)
                      Apr 12, 2023 
                    
                  
                    
                      Jenkins HTML Publisher Plugin does not properly sanitize input
                    
                      
  High
                    
                
                      
                        CVE-2024-28149
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:htmlpublisher
                        
                        (Maven)
                      Mar 6, 2024 
                    
                  
                    
                      Jenkins Simple Queue Plugin has stored cross-site scripting (XSS) vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-54003
                      
                      was published
                        for
                        
                          io.jenkins.plugins:simple-queue
                        
                        (Maven)
                      Nov 27, 2024 
                    
                  
                    
                      Jenkins HTML Publisher Plugin Stored XSS vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-28150
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:htmlpublisher
                        
                        (Maven)
                      Mar 6, 2024 
                    
                  
                    
                      Apache Syncope Improper Input Validation vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-38503
                      
                      was published
                        for
                        
                          org.apache.syncope.client.idrepo:syncope-client-idrepo-common-ui
                        
                        (Maven)
                      Jul 22, 2024 
                    
                  
                    
                      Stored XSS vulnerability in Jenkins Authorize Project Plugin 
                    
                      
  High
                    
                
                      
                        CVE-2024-52552
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:authorize-project
                        
                        (Maven)
                      Nov 13, 2024 
                    
                  
                    
                      powertac-server XML External Entity vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-51135
                      
                      was published
                        for
                        
                          org.powertac:server-interface
                        
                        (Maven)
                      Nov 11, 2024 
                    
                  
                    
                      Reposilite artifacts vulnerable to Stored Cross-site Scripting
                    
                      
  High
                    
                
                      
                        CVE-2024-36115
                      
                      was published
                        for
                        
                          com.reposilite:reposilite-backend
                        
                        (Maven)
                      Aug 2, 2024 
                    
                  
                    
                      OpenRefine has a reflected cross-site scripting vulnerability (XSS) from POST request in ExportRowsCommand
                    
                      
  High
                    
                
                      
                        CVE-2024-47880
                      
                      was published
                        for
                        
                          org.openrefine:openrefine
                        
                        (Maven)
                      Oct 24, 2024 
                    
                  
                    
                      OpenRefine has a reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt)
                    
                      
  High
                    
                
                      
                        CVE-2024-47878
                      
                      was published
                        for
                        
                          org.openrefine:extensions
                        
                        (Maven)
                      Oct 24, 2024 
                    
                  
                    
                      Jenkins GitBucket Plugin vulnerable to stored Cross-site Scripting
                    
                      
  High
                    
                
                      
                        CVE-2024-28157
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:gitbucket
                        
                        (Maven)
                      Mar 6, 2024 
                    
                  
                    
                      RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application
                    
                      
  High
                    
                
                      
                        CVE-2020-5398
                      
                      was published
                        for
                        
                          org.springframework:spring-webflux
                        
                        (Maven)
                      Jan 21, 2020 
                    
                  
                    
                      Cross-site Scripting vulnerability in Jenkins
                    
                      
  High
                    
                
                      
                        CVE-2022-34170
                      
                      was published
                        for
                        
                          org.jenkins-ci.main:jenkins-core
                        
                        (Maven)
                      Jun 24, 2022 
                    
                  
                    
                      Improper Neutralization of Input During Web Page Generation in Apache Tomcat
                    
                      
  High
                    
                
                      
                        CVE-2015-5346
                      
                      was published
                        for
                        
                          org.apache.tomcat:tomcat
                        
                        (Maven)
                      May 14, 2022 
                    
                  
                    
                      Content-Security-Policy disabled by Red Hat Dependency Analytics Jenkins Plugin
                    
                      
  High
                    
                
                      
                        CVE-2024-23905
                      
                      was published
                        for
                        
                          io.jenkins.plugins:redhat-dependency-analytics
                        
                        (Maven)
                      Jan 24, 2024 
                    
                  
                    
                      Stored XSS vulnerability in Jenkins Contrast Continuous Application Security Plugin
                    
                      
  High
                    
                
                      
                        CVE-2022-43420
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:contrast-continuous-application-security
                        
                        (Maven)
                      Oct 19, 2022 
                    
                  
                    
                      Cross-site Scripting in Jenkins Deployment Dashboard Plugin
                    
                      
  High
                    
                
                      
                        CVE-2022-34795
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:ec2-deployment-dashboard
                        
                        (Maven)
                      Jul 1, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API