GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,748
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
437 advisories
Filter by severity
Cross-site Scripting (XSS) in serialize-javascript
Moderate
CVE-2024-11831
was published
for
serialize-javascript
(npm)
Feb 10, 2025
nuxt vulnerable to Cross-site Scripting in navigateTo if used after SSR
Moderate
CVE-2024-34343
was published
for
nuxt
(npm)
Aug 5, 2024
Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data
Moderate
CVE-2025-47204
was published
for
bootstrap-multiselect
(npm)
May 13, 2025
@lumieducation/h5p-server Fails to Sanitize Plain Text Strings
Moderate
CVE-2025-47828
was published
for
@lumieducation/h5p-server
(npm)
May 11, 2025
n8n Vulnerable to Stored XSS through Attachments View Endpoint
Moderate
CVE-2025-46343
was published
for
n8n
(npm)
Apr 28, 2025
QMarkdown Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-43954
was published
for
@quasar/quasar-ui-qmarkdown
(npm)
Apr 20, 2025
@sveltejs/kit vulnerable to Cross-site Scripting via tracked search_params
Moderate
CVE-2025-32388
was published
for
@sveltejs/kit
(npm)
Apr 14, 2025
jquery-validation vulnerable to Cross-site Scripting
Moderate
CVE-2025-3573
was published
for
jquery-validation
(npm)
Apr 15, 2025
Bootstrap Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2024-6531
was published
for
bootstrap
(RubyGems)
Jul 11, 2024
Cross-site Scripting in jquery-ui
Moderate
CVE-2010-5312
was published
for
jQuery.UI.Combined
(RubyGems)
Oct 24, 2017
YUI Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2013-4942
was published
for
moodle/moodle
(Composer)
May 13, 2022
YUI Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2013-4941
was published
for
moodle/moodle
(Composer)
May 13, 2022
YUI Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2013-4940
was published
for
moodle/moodle
(Composer)
May 13, 2022
Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter
Moderate
CVE-2025-26619
was published
for
vega
(npm)
Mar 27, 2025
Koajs vulnerable to Cross-Site Scripting (XSS) at ctx.redirect() function
Moderate
CVE-2025-32379
was published
for
koa
(npm)
Apr 9, 2025
tarteaucitron.js allows url scheme injection via unfiltered inputs
Moderate
CVE-2025-31476
was published
for
tarteaucitronjs
(npm)
Apr 7, 2025
MathLive's Lack of Escaping of HTML allows for XSS
Moderate
CVE-2025-29049
was published
for
mathlive
(npm)
Jan 21, 2025
Duplicate Advisory: MathLive's Lack of Escaping of HTML allows for XSS
Moderate
GHSA-929m-phjg-qwcc
was published
for
mathlive
(npm)
Apr 1, 2025
•
withdrawn
Jellyfin Web Cross-Site Scripting (XSS) via Playlist Name
Moderate
CVE-2023-23636
was published
for
jellyfin-web
(npm)
Feb 3, 2023
Jellyfin Web Cross-Site Scripting (XSS) via Collection Name
Moderate
CVE-2023-23635
was published
for
jellyfin-web
(npm)
Feb 3, 2023
Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace]
Moderate
CVE-2025-27793
was published
for
vega
(npm)
Mar 27, 2025
GetmeUK ContentTools Cross-Site Scripting (XSS)
Moderate
CVE-2025-2699
was published
for
ContentTools
(npm)
Mar 24, 2025
Duplicate Advisory: Code injection in Directus
Moderate
GHSA-qf6h-p3mr-vmh5
was published
for
directus
(npm)
Aug 15, 2024
•
withdrawn
JS Html Sanitizer allows XSS when used with contentEditable
Moderate
CVE-2025-29771
was published
for
@jitbit/htmlsanitizer
(npm)
Mar 14, 2025
ProTip!
Advisories are also available from the
GraphQL API