GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,411
Erlang
33
GitHub Actions
22
Go
2,146
Maven
5,000+
npm
3,808
NuGet
687
pip
3,481
Pub
12
RubyGems
897
Rust
899
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,283 advisories
Filter by severity
Silverstripe Flash Clipboard Reflected XSS
Moderate
CVE-2019-12205
was published
for
silverstripe/admin
(Composer)
May 24, 2022
Magento stored Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-24428
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
MediaWiki UnlinkedWikibase Cross-site Scripting vulnerability
Moderate
CVE-2024-34500
was published
for
samwilson/unlinked-wikibase
(Composer)
May 5, 2024
Leantime allows Stored Cross-Site Scripting (XSS)
Moderate
GHSA-63cr-xg3f-8jvr
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Refelected Cross-Site Scripting (XSS)
Moderate
GHSA-52xf-h226-pfgx
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Stored Cross-Site Scripting (XSS)
Moderate
GHSA-mg4c-884j-pcq9
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
The Preview plugin in CKEditor allows Cross-site scripting (XSS)
Moderate
CVE-2014-5191
was published
for
ckeditor/ckeditor
(Composer)
May 17, 2022
Code Snippet GeSHi plugin in CKEditor 4 has reflected cross-site scripting (XSS) vulnerability
Moderate
CVE-2024-43407
was published
for
ckeditor/ckeditor
(Composer)
Aug 21, 2024
Uvdesk vulnerable to stored cross-site scripting (XSS)
Moderate
CVE-2023-0325
was published
for
uvdesk/community-skeleton
(Composer)
Apr 5, 2023
Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies
Moderate
CVE-2021-28556
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento stored cross-site scripting vulnerability in the admin console
Moderate
CVE-2021-21023
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Stored cross-site scripting
Moderate
CVE-2020-9584
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento stored cross-site scripting vulnerability
Moderate
CVE-2020-9581
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento stored cross-site scripting vulnerability
Moderate
CVE-2020-9577
was published
for
magento/community-edition
(Composer)
May 24, 2022
Stored XSS in REDAXO
Moderate
CVE-2024-13209
was published
for
redaxo/source
(Composer)
Feb 10, 2025
Duplicate Advisory: Stored XSS in REDAXO
Moderate
GHSA-mfx6-jvw8-53fm
was published
for
redaxo/redaxo
(Composer)
Jan 9, 2025
•
withdrawn
The wp-enable-svg WordPress plugin does not sanitize SVG files when uploaded
Moderate
CVE-2024-11184
was published
for
mwdelaney/wp-enable-svg
(Composer)
Jan 2, 2025
Shopware vulnerable to cross-site scripting (XSS)
Moderate
CVE-2022-48150
was published
for
shopware/shopware
(Composer)
Apr 21, 2023
PhpSpreadsheet allows bypassing of XSS sanitizer using the javascript protocol and special characters
Moderate
CVE-2025-23210
was published
for
phpoffice/phpspreadsheet
(Composer)
Feb 3, 2025
Potential XSS vulnerability in jQuery
Moderate
CVE-2020-11023
was published
for
components/jquery
(RubyGems)
Apr 29, 2020
Potential XSS vulnerability in jQuery
Moderate
CVE-2020-11022
was published
for
athlon1600/youtube-downloader
(RubyGems)
Apr 29, 2020
Bootstrap Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2024-6484
was published
for
bootstrap
(RubyGems)
Jul 11, 2024
phpMyFAQ vulnerable to Stored Cross-site Scripting
Moderate
CVE-2023-2428
was published
for
thorsten/phpmyfaq
(Composer)
Apr 30, 2023
pimcore/customer-management-framework-bundle Cross-site Scripting vulnerability in Segment name
Moderate
CVE-2023-4145
was published
for
pimcore/customer-management-framework-bundle
(Composer)
Aug 3, 2023
phpMyAdmin XSS when checking tables
Moderate
CVE-2025-24530
was published
for
phpmyadmin/phpmyadmin
(Composer)
Jan 23, 2025
ProTip!
Advisories are also available from the
GraphQL API