GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,746
Erlang
35
GitHub Actions
29
Go
2,319
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
920
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,639 advisories
Filter by severity
Cross-site Scripting (XSS) in baserCMS
Moderate
CVE-2021-20683
was published
for
baserproject/basercms
(Composer)
Jun 8, 2021
Cross-site Scripting (XSS) in baserCMS
Moderate
CVE-2021-20681
was published
for
baserproject/basercms
(Composer)
Jun 8, 2021
XSS vulnerability with translator
Critical
CVE-2021-32671
was published
for
flarum/core
(Composer)
Jun 7, 2021
Authenticated Stored XSS in Administration
Moderate
GHSA-f6p7-8xfw-fjqq
was published
for
shopware/shopware
(Composer)
May 21, 2021
Reflected cross-site scripting in francoisjacquet/rosariosis
Moderate
CVE-2020-13278
was published
for
francoisjacquet/rosariosis
(Composer)
May 6, 2021
Cross-site Scripting in OpenCart
Moderate
CVE-2020-10596
was published
for
opencart/opencart
(Composer)
May 6, 2021
Cross-site scripting in ThinkAdmin
Moderate
CVE-2020-29315
was published
for
zoujingli/thinkadmin
(Composer)
May 6, 2021
Cross-site scripting in phpoffice/phpspreadsheet
Moderate
CVE-2020-7776
was published
for
phpoffice/phpexcel
(Composer)
May 6, 2021
Cross-site scripting (XSS) from unsanitized uploaded SVG files in Kirby
High
CVE-2021-29460
was published
for
getkirby/cms
(Composer)
Apr 30, 2021
Cross-Site Scripting in Bootstrap Package
Moderate
CVE-2021-21365
was published
for
bk2k/bootstrap-package
(Composer)
Apr 29, 2021
Potential XSS injection in the newsletter conditions field
Moderate
CVE-2021-21418
was published
for
prestashop/ps_emailsubscription
(Composer)
Apr 6, 2021
Cross site-scripting (XSS) moodle
Moderate
CVE-2020-25628
was published
for
moodle/moodle
(Composer)
Mar 29, 2021
Cross-site Scripting (XSS) in moodle
Moderate
CVE-2020-25702
was published
for
moodle/moodle
(Composer)
Mar 29, 2021
Cross-site scripting (XSS) and Server side request forgery (SSRF) in moodle
Moderate
CVE-2021-20280
was published
for
moodle/moodle
(Composer)
Mar 29, 2021
Stored cross-site scripting in PressBooks
Moderate
CVE-2021-3271
was published
for
pressbooks/pressbooks
(Composer)
Mar 29, 2021
XSS in CreateQueuedJobTask
Moderate
CVE-2021-27938
was published
for
symbiote/silverstripe-queuedjobs
(Composer)
Mar 24, 2021
Cross-Site Scripting in Content Preview (CType menu)
Moderate
CVE-2021-21370
was published
for
typo3/cms
(Composer)
Mar 23, 2021
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in typo3/cms-form
Moderate
CVE-2021-21358
was published
for
typo3/cms
(Composer)
Mar 23, 2021
Cross-Site Scripting in Content Preview
Moderate
CVE-2021-21340
was published
for
typo3/cms
(Composer)
Mar 23, 2021
Cross-site scripting in eZ Platform Kernel
High
GHSA-mrvj-7q4f-5p42
was published
for
ezsystems/ezplatform-kernel
(Composer)
Mar 19, 2021
Cross-site scripting (XSS)
Moderate
CVE-2020-17551
was published
for
impresscms/impresscms
(Composer)
Mar 12, 2021
Cross-site scripting (XSS)
Moderate
CVE-2021-28088
was published
for
impresscms/impresscms
(Composer)
Mar 12, 2021
XSS in Adminer
Moderate
GHSA-m56g-3g8v-2rxw
was published
for
vrana/adminer
(Composer)
Feb 11, 2021
•
withdrawn
vrana/adminer via XSS in the history parameter in SQL command
Moderate
CVE-2020-35572
was published
for
vrana/adminer
(Composer)
Feb 11, 2021
ProTip!
Advisories are also available from the
GraphQL API