GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            141 advisories
        Filter by severity
        
      
      
    
                    
                      Cross-site scripting in SimpleSAMLphp
                    
                      
  Low
                    
                
                      
                        CVE-2020-5226
                      
                      was published
                        for
                        
                          simplesamlphp/simplesamlphp
                        
                        (Composer)
                      Jan 24, 2020 
                    
                  
                    
                      Cross-site Scripting in October
                    
                      
  Low
                    
                
                      
                        CVE-2020-4061
                      
                      was published
                        for
                        
                          october/backend
                        
                        (Composer)
                      Jul 2, 2020 
                    
                  
                    
                      Cross Site Scripting in baserCMS
                    
                      
  Low
                    
                
                      
                        CVE-2020-15154
                      
                      was published
                        for
                        
                          baserproject/basercms
                        
                        (Composer)
                      Aug 28, 2020 
                    
                  
                    
                      Cross Site Scripting(XSS) Vulnerability in Latest Release 4.3.6 Site basic settings
                    
                      
  Low
                    
                
                      
                        CVE-2020-15155
                      
                      was published
                        for
                        
                          baserproject/basercms
                        
                        (Composer)
                      Aug 28, 2020 
                    
                  
                    
                      Cross Site Scripting and RCE in baserCMS
                    
                      
  Low
                    
                
                      
                        CVE-2020-15159
                      
                      was published
                        for
                        
                          baserproject/basercms
                        
                        (Composer)
                      Aug 28, 2020 
                    
                  
                    
                      Non-persistent XSS in the Storefront in Shopware
                    
                      
  Low
                    
                
                      
                        GHSA-qvhr-55hg-3qwv
                      
                      was published
                        for
                        
                          shopware/core
                        
                        (Composer)
                      Sep 23, 2020 
                    
                  
                    
                      Blog comment posting, Cross Site Scripting(XSS) Vulnerability in Latest Release 4.4.0
                    
                      
  Low
                    
                
                      
                        CVE-2020-15276
                      
                      was published
                        for
                        
                          baserproject/basercms
                        
                        (Composer)
                      Oct 30, 2020 
                    
                  
                    
                      Edit feed settings  and others, Cross Site Scripting(XSS) Vulnerability in Latest Release 4.4.0
                    
                      
  Low
                    
                
                      
                        CVE-2020-15273
                      
                      was published
                        for
                        
                          baserproject/basercms
                        
                        (Composer)
                      Nov 4, 2020 
                    
                  
                    
                      Persistent XSS in customer module in Shopware
                    
                      
  Low
                    
                
                      
                        GHSA-6gv9-7q4g-pmvm
                      
                      was published
                        for
                        
                          shopware/shopware
                        
                        (Composer)
                      Nov 13, 2020 
                    
                  
                    
                      Persistent XSS in shopping worlds
                    
                      
  Low
                    
                
                      
                        GHSA-28fw-88hq-6jmm
                      
                      was published
                        for
                        
                          shopware/shopware
                        
                        (Composer)
                      Nov 13, 2020 
                    
                  
                    
                      Persistent XSS in newsletter module in Shopware
                    
                      
  Low
                    
                
                      
                        GHSA-hrfh-fp4x-crrq
                      
                      was published
                        for
                        
                          shopware/shopware
                        
                        (Composer)
                      Nov 13, 2020 
                    
                  
                    
                      Stored XSS by authenticated backend user with access to upload files
                    
                      
  Low
                    
                
                      
                        CVE-2020-15249
                      
                      was published
                        for
                        
                          october/backend
                        
                        (Composer)
                      Nov 23, 2020 
                    
                  
                    
                      Croos-site scripting in Croogo
                    
                      
  Low
                    
                
                      
                        CVE-2019-20789
                      
                      was published
                        for
                        
                          croogo/croogo
                        
                        (Composer)
                      Jun 22, 2021 
                    
                  
                    
                      snipe-it is vulnerable to Cross-site Scripting
                    
                      
  Low
                    
                
                      
                        CVE-2021-3938
                      
                      was published
                        for
                        
                          snipe/snipe-it
                        
                        (Composer)
                      Nov 15, 2021 
                    
                  
                    
                      TYPO3 Backend vulnerable to Cross-site Scripting
                    
                      
  Low
                    
                
                      
                        CVE-2009-3629
                      
                      was published
                        for
                        
                          typo3/cms-backend
                        
                        (Composer)
                      May 2, 2022 
                    
                  
                    
                      TYPO3 Direct Mail Extension Vulnerable to Cross-Site Scripting (XSS)
                    
                      
  Low
                    
                
                      
                        CVE-2009-4159
                      
                      was published
                        for
                        
                          directmailteam/direct-mail
                        
                        (Composer)
                      May 2, 2022 
                    
                  
                    
                      Commerce extension for TYPO3 vulnerable to Cross-site Scripting
                    
                      
  Low
                    
                
                      
                        CVE-2009-4963
                      
                      was published
                        for
                        
                          commerceteam/commerce
                        
                        (Composer)
                      May 2, 2022 
                    
                  
                    
                      Moodle cross-site scripting (XSS) vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2014-3544
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle multiple cross-site scripting (XSS) vulnerabilities
                    
                      
  Low
                    
                
                      
                        CVE-2014-3551
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle cross-site scripting (XSS) vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2014-7830
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle allows attackers to upload files containing JavaScript
                    
                      
  Low
                    
                
                      
                        CVE-2014-7835
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle cross-site scripting (XSS) vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2015-0212
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle cross-site scripting (XSS) vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2015-2273
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle does not set the RISK_XSS bit for graders
                    
                      
  Low
                    
                
                      
                        CVE-2015-3174
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API