GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,651
Erlang
34
GitHub Actions
26
Go
2,252
Maven
5,000+
npm
3,904
NuGet
702
pip
3,676
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,831 advisories
Filter by severity
Drupal Core Potential Cross-Site Scripting (XSS) via Error Messages
Moderate
CVE-2025-3057
was published
for
drupal/core
(Composer)
Apr 1, 2025
Drupal Google Tag Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-31682
was published
for
drupal/google_tag
(Composer)
Apr 1, 2025
Drupal Ignition Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-31679
was published
for
drupal/ignition
(Composer)
Apr 1, 2025
ConcreteCMS Cross-Site Scripting (XSS) via HTML Block Text Field
Moderate
CVE-2025-2967
was published
for
concrete5/concrete5
(Composer)
Mar 31, 2025
ShopXO Vulnerable to Server-Side Request Forgery (SSRF) and Cross-Site Scripting (XSS)
Moderate
CVE-2025-28094
was published
for
shopxo/shopxo
(Composer)
Mar 29, 2025
Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace]
Moderate
CVE-2025-27793
was published
for
vega
(npm)
Mar 27, 2025
Vega Cross-Site Scripting (XSS) via event filter when not using CSP mode expressionInterpeter
Moderate
CVE-2025-26619
was published
for
vega
(npm)
Mar 27, 2025
wp-svg-upload WordPress plugin vulnerable to Stored Cross-site Scripting
Moderate
CVE-2024-11847
was published
for
digimix/wp-svg-upload
(Composer)
Mar 26, 2025
GetmeUK ContentTools Cross-Site Scripting (XSS)
Moderate
CVE-2025-2699
was published
for
ContentTools
(npm)
Mar 24, 2025
Apache Oozie Cross-Site Scripting (XSS)
Moderate
CVE-2025-26796
was published
for
org.apache.oozie:oozie-core
(Maven)
Mar 22, 2025
Apache Druid vulnerable to Server-Side Request Forgery, Cross-site Scripting, Open Redirect
Moderate
CVE-2025-27888
was published
for
org.apache.druid:druid
(Maven)
Mar 20, 2025
LocalAI Cross-Site Scripting (XSS) vulnerability in its search functionality
Moderate
CVE-2024-9900
was published
for
github.com/mudler/LocalAI
(Go)
Mar 20, 2025
AgentScope stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2024-8556
was published
for
agentscope
(pip)
Mar 20, 2025
Open WebUI Vulnerable to Cross-Site Scripting (XSS) via Chat File Upload
Moderate
CVE-2024-7044
was published
for
open-webui
(pip)
Mar 20, 2025
Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
Moderate
CVE-2025-2536
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
Moderate
CVE-2025-30081
was published
for
clickstorm/cs-seo
(Composer)
Mar 19, 2025
Additional TCA Allows Cross-Site Scripting (XSS)
Moderate
CVE-2025-30083
was published
for
codingms/additional-tca
(Composer)
Mar 19, 2025
Contao Vulnerable to Cross-Site Scripting (XSS) through SVG uploads
Moderate
CVE-2025-29790
was published
for
contao/core-bundle
(Composer)
Mar 18, 2025
JS Html Sanitizer allows XSS when used with contentEditable
Moderate
CVE-2025-29771
was published
for
@jitbit/htmlsanitizer
(npm)
Mar 14, 2025
Apache Felix HTTP Webconsole Plugin: XSS in HTTP Webconsole Plugin
Moderate
CVE-2025-27867
was published
for
org.apache.felix:org.apache.felix.http.webconsoleplugin
(Maven)
Mar 12, 2025
Froxlor has an HTML Injection Vulnerability
Moderate
GHSA-26xq-m8xw-6373
was published
for
froxlor/froxlor
(Composer)
Mar 11, 2025
Concrete CMS affected by a stored XSS in Folder Function.The "Add Folder" functionality
Moderate
CVE-2025-0660
was published
for
concrete5/concrete5
(Composer)
Mar 10, 2025
LF Edge eKuiper allows Stored XSS in Rules Functionality
Moderate
CVE-2024-52812
was published
for
github.com/lf-edge/ekuiper
(Go)
Mar 10, 2025
Laravel framework susceptible to reflected cross-site scripting
Moderate
CVE-2024-13918
was published
for
laravel/framework
(Composer)
Mar 10, 2025
ProTip!
Advisories are also available from the
GraphQL API