GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,950
Erlang
39
GitHub Actions
38
Go
2,603
Maven
5,000+
npm
4,250
NuGet
755
pip
4,013
Pub
12
RubyGems
953
Rust
1,048
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,582 advisories
Filter by severity
Liferay Portal Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page
Low
CVE-2025-62255
was published
for
com.liferay:com.liferay.knowledge.base.web
(Maven)
Oct 23, 2025
Vert.x-Web vulnerable to Stored Cross-site Scripting in directory listings via file names
Low
CVE-2025-11966
was published
for
io.vertx:vertx-web
(Maven)
Oct 22, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Low
Unreviewed
CVE-2025-62659
was published
Oct 22, 2025
TastyIgniter vulnerable to Cross-Site Scripting
Low
CVE-2025-61417
was published
for
tastyigniter/tastyigniter
(Composer)
Oct 20, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Low
Unreviewed
CVE-2025-62653
was published
Oct 18, 2025
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Low
Unreviewed
CVE-2025-62654
was published
Oct 18, 2025
LibreNMS alert-rules has a Cross-Site Scripting Vulnerability
Low
CVE-2025-62412
was published
for
librenms/librenms
(Composer)
Oct 16, 2025
Mailgen has HTML Injection and XSS Filter Bypass in Plaintext Emails
Low
CVE-2025-62380
was published
for
mailgen
(npm)
Oct 15, 2025
Mailgen has HTML Injection and XSS Filter Bypass in Plaintext Emails
Low
CVE-2025-62366
was published
for
mailgen
(npm)
Oct 14, 2025
Ericsson Network Manager versions prior to ENM 25.2 GA contain a vulnerability that, if exploited...
Low
Unreviewed
CVE-2025-27259
was published
Oct 13, 2025
drupal-pattern-lab/unified-twig-extensions is vulnerable to XXS
Low
CVE-2025-11570
was published
for
drupal-pattern-lab/unified-twig-extensions
(Composer)
Oct 10, 2025
Fiora chat group avatar is vulnerable to XSS via SVG files
Low
CVE-2025-56515
was published
for
fiora
(npm)
Oct 1, 2025
Fiora chat user avatar is vulnerable to XSS via SVG files
Low
CVE-2025-56514
was published
for
fiora
(npm)
Oct 1, 2025
Mangati NovoSGA XSS vulnerability in /admin
Low
CVE-2025-10909
was published
for
novosga/novosga
(Composer)
Sep 24, 2025
GP247 and S-Cart have a stored cross-site scripting (XSS) vulnerability
Low
CVE-2025-57407
was published
for
gp247/core
(Composer)
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
Low
CVE-2025-59546
was published
for
DotNetNuke.Core
(NuGet)
Sep 23, 2025
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
Low
GHSA-mm7x-qfjj-5g2c
was published
for
ammonia
(Rust)
Sep 22, 2025
TYPO3 "Form to Database" extension susceptible to Cross-site Scripting
Low
CVE-2025-10316
was published
for
lavitto/typo3-form-to-database
(Composer)
Sep 16, 2025
Liferay Portal is vulnerable to XSS attack through its Style Book theme
Low
CVE-2025-43774
was published
for
com.liferay:com.liferay.frontend.taglib.clay
(Maven)
Sep 9, 2025
CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package
Low
CVE-2025-58064
was published
for
@ckeditor/ckeditor5-clipboard
(npm)
Sep 3, 2025
A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote...
Low
Unreviewed
CVE-2024-12923
was published
Aug 29, 2025
Liferay Portal Reflected Cross-Site Scripting Vulnerability via Form Container
Low
CVE-2025-43753
was published
for
com.liferay:com.liferay.layout.taglib
(Maven)
Aug 22, 2025
Liferay Portal Vulnerable to Cross-Site Scripting
Low
CVE-2025-43733
was published
for
com.liferay:com.liferay.layout.taglib
(Maven)
Aug 18, 2025
A vulnerability was found in Protected Total WebShield Extension up to 3.2.0 on Chrome. It has...
Low
Unreviewed
CVE-2025-8751
was published
Aug 9, 2025
Concrete CMS is vulnerable to Stored XSS from Home Folder on Members Dashboard page
Low
CVE-2025-8573
was published
for
concrete5/concrete5
(Composer)
Aug 6, 2025
ProTip!
Advisories are also available from the
GraphQL API