GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,746
Erlang
35
GitHub Actions
29
Go
2,319
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
920
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,530 advisories
Filter by severity
Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiOS 5.0 Patch 7 build 4457...
Low
Unreviewed
CVE-2015-1451
was published
May 17, 2022
Multiple cross-site scripting (XSS) vulnerabilities in admin/themes/default/pages/manage_users...
Low
Unreviewed
CVE-2014-7264
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in the search_controller in X3 CMS 0.5.1 and 0.5.1.1...
Low
Unreviewed
CVE-2014-8772
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in compfight-search.php in the Compfight plugin 1.4 for...
Low
Unreviewed
CVE-2014-8622
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in compfight-search.php in the Compfight plugin 1.4 for...
Low
Unreviewed
CVE-2014-5202
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2,...
Low
Unreviewed
CVE-2014-5240
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in templates/defaultheader.php in Lamp Design...
Low
Unreviewed
CVE-2014-3737
was published
May 14, 2022
Multiple cross-site scripting (XSS) vulnerabilities in PivotX before 2.3.9 allow remote...
Low
Unreviewed
CVE-2014-0341
was published
May 17, 2022
Multiple cross-site scripting (XSS) vulnerabilities in Domain Technologie Control (DTC) before 0...
Low
Unreviewed
CVE-2011-3199
was published
May 17, 2022
Joomla! Cross-site Scripting vulnerability
Low
CVE-2013-5583
was published
for
joomla/joomla-cms
(Composer)
May 17, 2022
Static Info Tables (static_info_tables) extension TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2013-5323
was published
for
sjbr/static-info-tables
(Composer)
May 17, 2022
Static Methods since 2007 (div2007) extension for TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2013-5100
was published
for
jambagecom/div2007
(Composer)
May 17, 2022
PHPUnit extension for TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2013-4744
was published
for
oliverklee/phpunit
(Composer)
May 13, 2022
Basic SEO Features (seo_basics) extension TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2012-5888
was published
for
b13/seo_basics
(Composer)
May 17, 2022
powermail extension for TYPO3 has Cross-site Scripting vulnerability
Low
CVE-2012-5889
was published
for
in2code/powermail
(Composer)
May 17, 2022
Moodle vulnerable to Cross-site Scripting
Low
CVE-2011-4282
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle vulnerable to Cross-Site Scripting
Low
CVE-2011-4299
was published
for
moodle/moodle
(Composer)
May 13, 2022
Symphony CMS vulnerable to Cross-site Scripting
Low
CVE-2011-4340
was published
for
symphonycms/symphony-2
(Composer)
May 17, 2022
phpMyAdmin Cross-site Scripting vulnerability
Low
CVE-2011-4782
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin vulnerable to Cross-site Scripting
Low
CVE-2011-4634
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
Joomla! vulnerable to Cross-site Scripting
Low
CVE-2011-4332
was published
for
joomla/joomla-cms
(Composer)
May 17, 2022
MantisBT Cross-site Scripting vulnerability
Low
CVE-2010-2574
was published
for
mantisbt/mantisbt
(Composer)
May 14, 2022
Commerce extension for TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2009-4963
was published
for
commerceteam/commerce
(Composer)
May 2, 2022
Piwik (now Matomo) Vulnerable to Cross-Site Scripting (XSS)
Low
CVE-2013-1844
was published
for
matomo/matomo
(Composer)
May 13, 2022
phpMyAdmin Vulnerable to Cross-Site Scripting
Low
CVE-2011-1940
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API