GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,748
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
218 advisories
Filter by severity
The Backup Plus extension for TYPO3 (ns_backup) allows XSS
Low
CVE-2025-48206
was published
for
nitsan/ns-backup
(Composer)
May 21, 2025
LibreNMS stored Cross-site Scripting vulnerability in poller group name
Low
CVE-2025-47931
was published
for
librenms/librenms
(Composer)
May 19, 2025
Trix vulnerable to Cross-site Scripting on copy & paste
Low
CVE-2025-46812
was published
for
trix
(npm)
May 8, 2025
Yeswiki Vulnerable to Authenticated Reflected Cross-site Scripting
Low
CVE-2025-46350
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
YesWiki Stored XSS Vulnerability in Comments
Low
CVE-2025-46346
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
Drupal Formatter Suite Vulnerable to Cross-Site Scripting (XSS) via Link Element Attributes
Low
CVE-2025-31697
was published
for
drupal/formatter_suite
(Composer)
Apr 1, 2025
Drupal RapiDoc OAS Field Formatter Cross-Site Scripting (XSS) vulnerability
Low
CVE-2025-31696
was published
for
drupal/rapidoc_elements_field_formatter
(Composer)
Apr 1, 2025
Drupal Link field display mode formatter Cross-Site Scripting (XSS) vulnerability
Low
CVE-2025-31695
was published
for
drupal/link_field_display_mode_formatter
(Composer)
Apr 1, 2025
Drupal SpamSpan Cross-Site Scripting (XSS) vulnerability
Low
CVE-2025-31687
was published
for
drupal/spamspan
(Composer)
Apr 1, 2025
Drupal Core Cross-Site Scripting (XSS) Vulnerability
Low
CVE-2025-31675
was published
for
drupal/core
(Composer)
Apr 1, 2025
Duplicate Advisory: Contao allows admin an account to upload SVG file containing malicious JavaScript
Low
CVE-2024-45965
was published
for
contao/contao
(Composer)
Oct 2, 2024
•
withdrawn
OpenCMS Cross-Site Scripting vulnerability
Low
CVE-2024-42699
was published
for
org.opencms:opencms-core
(Maven)
Apr 21, 2025
concrete5 vulnerable to Cross-site Scripting
Low
CVE-2015-3989
was published
for
concrete5/concrete5
(Composer)
May 17, 2022
WEC Map (wec_map) extension for TYPO3 allows Cross-site Scripting
Low
CVE-2014-6296
was published
for
jbartels/wec-map
(Composer)
May 17, 2022
Joomla! Cross-site Scripting vulnerability
Low
CVE-2013-5583
was published
for
joomla/joomla-cms
(Composer)
May 17, 2022
Static Info Tables (static_info_tables) extension TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2013-5323
was published
for
sjbr/static-info-tables
(Composer)
May 17, 2022
Static Methods since 2007 (div2007) extension for TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2013-5100
was published
for
jambagecom/div2007
(Composer)
May 17, 2022
PHPUnit extension for TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2013-4744
was published
for
oliverklee/phpunit
(Composer)
May 13, 2022
Basic SEO Features (seo_basics) extension TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2012-5888
was published
for
b13/seo_basics
(Composer)
May 17, 2022
powermail extension for TYPO3 has Cross-site Scripting vulnerability
Low
CVE-2012-5889
was published
for
in2code/powermail
(Composer)
May 17, 2022
Moodle vulnerable to Cross-site Scripting
Low
CVE-2011-4282
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle vulnerable to Cross-Site Scripting
Low
CVE-2011-4299
was published
for
moodle/moodle
(Composer)
May 13, 2022
Symphony CMS vulnerable to Cross-site Scripting
Low
CVE-2011-4340
was published
for
symphonycms/symphony-2
(Composer)
May 17, 2022
phpMyAdmin Cross-site Scripting vulnerability
Low
CVE-2011-4782
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API