GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,748
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,884 advisories
Filter by severity
io.jmix.rest:jmix-rest allows XSS in the /files Endpoint of the Generic REST API
Moderate
CVE-2025-32951
was published
for
io.jmix.rest:jmix-rest
(Maven)
Apr 22, 2025
OpenCMS cross-site scripting (XSS) vulnerability
Moderate
CVE-2024-41446
was published
for
org.opencms:opencms-core
(Maven)
Apr 21, 2025
QMarkdown Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-43954
was published
for
@quasar/quasar-ui-qmarkdown
(npm)
Apr 20, 2025
one-api Cross-site Scripting vulnerability
Moderate
CVE-2025-3801
was published
for
github.com/songquanpeng/one-api
(Go)
Apr 19, 2025
Alkacon OpenCMS stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2024-41447
was published
for
org.opencms:opencms-core
(Maven)
Apr 18, 2025
Liferay Cross-site Scripting vulnerability
Moderate
CVE-2025-3760
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Apr 17, 2025
PEAR HTTP_Request2 vulnerable to Cross-site Scripting
Moderate
CVE-2025-43717
was published
for
pear/http_request2
(Composer)
Apr 17, 2025
golang.org/x/net vulnerable to Cross-site Scripting
Moderate
CVE-2025-22872
was published
for
golang.org/x/net
(Go)
Apr 16, 2025
jquery-validation vulnerable to Cross-site Scripting
Moderate
CVE-2025-3573
was published
for
jquery-validation
(npm)
Apr 15, 2025
@sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params
Moderate
CVE-2025-32388
was published
for
@sveltejs/kit
(npm)
Apr 14, 2025
Formie has XSS vulnerability for email notification content for preview
Moderate
CVE-2025-32426
was published
for
verbb/formie
(Composer)
Apr 11, 2025
Formie has XSS vulnerability for importing forms
Moderate
CVE-2025-32427
was published
for
verbb/formie
(Composer)
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
Moderate
CVE-2025-32027
was published
for
yiisoft/yii
(Composer)
Apr 11, 2025
Silverstripe Framework has a XSS vulnerability in HTML editor
Moderate
CVE-2025-30148
was published
for
silverstripe/framework
(Composer)
Apr 10, 2025
Silverstripe cross-site scripting (XSS) attack in elemental "Content blocks in use" report
Moderate
CVE-2025-25197
was published
for
dnadesign/silverstripe-elemental
(Composer)
Apr 10, 2025
Koajs vulnerable to Cross-Site Scripting (XSS) at ctx.redirect() function
Moderate
CVE-2025-32379
was published
for
koa
(npm)
Apr 9, 2025
tarteaucitron.js allows url scheme injection via unfiltered inputs
Moderate
CVE-2025-31476
was published
for
tarteaucitronjs
(npm)
Apr 7, 2025
Miniflux Media Proxy vulnerable to Stored Cross-site Scripting due to improper Content-Security-Policy configuration
Moderate
CVE-2025-31483
was published
for
miniflux.app/v2
(Go)
Apr 4, 2025
Concrete CMS Vulnerable to Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS)
Moderate
CVE-2025-3153
was published
for
concrete5/concrete5
(Composer)
Apr 3, 2025
Drupal Obfuscate Vulnerable to Stored Cross-Site Scripting (XSS)
Moderate
CVE-2025-3130
was published
for
drupal/obfuscate
(Composer)
Apr 3, 2025
Stored XSS in Miniflux when opening a broken image due to unescaped ServerError in proxy handler
Moderate
CVE-2023-27592
was published
for
miniflux.app/v2
(Go)
Apr 2, 2025
Duplicate Advisory: MathLive's Lack of Escaping of HTML allows for XSS
Moderate
GHSA-929m-phjg-qwcc
was published
for
mathlive
(npm)
Apr 1, 2025
•
withdrawn
Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages
Moderate
CVE-2025-3057
was published
for
drupal/core
(Composer)
Apr 1, 2025
Drupal Google Tag Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-31682
was published
for
drupal/google_tag
(Composer)
Apr 1, 2025
Drupal Ignition Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-31679
was published
for
drupal/ignition
(Composer)
Apr 1, 2025
ProTip!
Advisories are also available from the
GraphQL API