GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,952
Erlang
39
GitHub Actions
38
Go
2,609
Maven
5,000+
npm
4,252
NuGet
757
pip
4,021
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
925 advisories
Filter by severity
Liferay Portal Vulnerable to Cross-Site Scripting
Moderate
CVE-2025-62263
was published
for
com.liferay:com.liferay.account.admin.web
(Maven)
Oct 27, 2025
MCMS reflected cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-60837
was published
for
net.mingsoft:ms-mcms
(Maven)
Oct 23, 2025
Liferay Portal Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page
Low
CVE-2025-62255
was published
for
com.liferay:com.liferay.knowledge.base.web
(Maven)
Oct 23, 2025
Liferay Portal and Liferay DXP vulnerable to reflected cross-site scripting (XSS)
Moderate
CVE-2025-62248
was published
for
com.liferay:com.liferay.dynamic.data.mapping.web
(Maven)
Oct 22, 2025
Vert.x-Web vulnerable to Stored Cross-site Scripting in directory listings via file names
Low
CVE-2025-11966
was published
for
io.vertx:vertx-web
(Maven)
Oct 22, 2025
Liferay Portal reflected cross-site scripting (XSS) vulnerability in the google_gaget
Moderate
CVE-2025-62249
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Oct 21, 2025
Keycloak error_description injection on error pages that can trigger phishing attacks
Moderate
CVE-2025-10044
was published
for
org.keycloak:keycloak-account-ui
(Maven)
Oct 17, 2025
Apache Geode web-api is vulnerable to Cross-site Scripting
Moderate
CVE-2024-44088
was published
for
org.apache.geode:geode-web-api
(Maven)
Oct 14, 2025
Liferay Mentions Web is Vulnerable to Cross-site Scripting
Moderate
CVE-2025-62246
was published
for
com.liferay:com.liferay.mentions.web
(Maven)
Oct 13, 2025
Liferay Portal is vulnerable to XSS through its workflow process builder
Moderate
CVE-2025-62239
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.designer.web
(Maven)
Oct 10, 2025
Liferay Portal's Membership page is vulnerable to XSS through “name“ text field
Moderate
CVE-2025-62238
was published
for
com.liferay:com.liferay.account.admin.web
(Maven)
Oct 10, 2025
Liferay Portal Commerce is vulnerable to XSS through account "name" field
Moderate
CVE-2025-62237
was published
for
com.liferay.commerce:com.liferay.commerce.order.web
(Maven)
Oct 10, 2025
Liferay Portal is vulnerable to XSS through its Calendar Events parameters
Moderate
CVE-2025-62240
was published
for
com.liferay:com.liferay.calendar.web
(Maven)
Oct 9, 2025
Opencast's Paella Player 7 is vulnerable to Cross-Site Scripting
Moderate
CVE-2025-61788
was published
for
org.opencastproject:opencast-common
(Maven)
Oct 8, 2025
Liferay Portal Commerce Shop is vulnerable to Stored XSS through SVG file
Moderate
CVE-2025-43829
was published
for
com.liferay.commerce:com.liferay.commerce.shop.by.diagram.web
(Maven)
Oct 8, 2025
Liferay Portal Notifications Widget has multiple XSS vulnerabilities through various text fields
Moderate
CVE-2025-43771
was published
for
com.liferay:com.liferay.flags.web
(Maven)
Oct 8, 2025
Liferay Portal is vulnerable to Stored XSS through Forms text type field
Moderate
CVE-2025-43830
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 8, 2025
Liferay Portal is vulnerable to XXS through its Commerce Product's Name text field
Moderate
CVE-2025-43821
was published
for
com.liferay.commerce:com.liferay.commerce.product.service
(Maven)
Oct 8, 2025
Liferay Portal has multiple Stored XSS vulnerabilities on its View Order page
Moderate
CVE-2025-43822
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 8, 2025
Liferay Portal is vulnerable to XSS through its Commerce Search Result widget
Moderate
CVE-2025-43823
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 8, 2025
Liferay Profile Widget does not prevent vCard extension spoofing
Moderate
CVE-2025-43824
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 7, 2025
Liferay Portal Vulnerable to XSS in Web Content translation
Moderate
CVE-2025-43826
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 1, 2025
Liferay Portal vulnerable to cross-site scripting in the Calendar widget
Moderate
CVE-2025-43818
was published
for
com.liferay:com.liferay.calendar.web
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to reflected cross-site scripting via the `redirect` parameter
Moderate
CVE-2025-43817
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Sep 30, 2025
Liferay Portal vulnerable to cross-site scripting in the Calendar widget
Moderate
CVE-2025-43820
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Sep 30, 2025
ProTip!
Advisories are also available from the
GraphQL API