GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,411
Erlang
33
GitHub Actions
22
Go
2,146
Maven
5,000+
npm
3,808
NuGet
687
pip
3,481
Pub
12
RubyGems
897
Rust
899
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,527 advisories
Filter by severity
Moodle has a stored XSS in ddimageortext question type
Low
CVE-2025-26528
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle allows reflected XSS via question bank filter
High
CVE-2025-26530
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle has a stored XSS risk in admin live log
High
CVE-2025-26529
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Leantime allows Cross-Site Scripting (XSS)
Low
GHSA-f679-254h-qhvj
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Stored Cross-Site Scripting (XSS)
High
GHSA-c39w-3pjx-qc7m
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Cross Site Scripting (XSS) and SQL Injection (SQLi)
High
GHSA-v4q9-437p-mhpg
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Stored Cross-Site Scripting (XSS)
Moderate
GHSA-63cr-xg3f-8jvr
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Refelected Cross-Site Scripting (XSS)
Moderate
GHSA-52xf-h226-pfgx
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Stored Cross-Site Scripting (XSS)
Moderate
GHSA-mg4c-884j-pcq9
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Magento stored Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-24428
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento stored Cross-Site Scripting (XSS) vulnerability
High
CVE-2025-24438
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24412
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24414
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24415
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24413
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24417
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24416
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24410
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Stored XSS in REDAXO
Moderate
CVE-2024-13209
was published
for
redaxo/source
(Composer)
Feb 10, 2025
PhpSpreadsheet allows bypassing of XSS sanitizer using the javascript protocol and special characters
Moderate
CVE-2025-23210
was published
for
phpoffice/phpspreadsheet
(Composer)
Feb 3, 2025
DevDojo Voyager vulnerable to reflected Cross-site Scripting
Low
CVE-2024-55416
was published
for
tcg/voyager
(Composer)
Jan 30, 2025
Pimcore Authenticated Stored Cross-Site Scripting (XSS) Via Search Document
High
GHSA-xr3m-6gq6-22cg
was published
for
pimcore/pimcore
(Composer)
Jan 28, 2025
Dolibarr Cross-site Scripting vulnerability
Low
CVE-2024-55228
was published
for
dolibarr/dolibarr
(Composer)
Jan 27, 2025
Dolibarr Cross-site Scripting vulnerability
Low
CVE-2024-55227
was published
for
dolibarr/dolibarr
(Composer)
Jan 27, 2025
Reflected Cross Site Scripting (XSS) in error message
Low
GHSA-74j9-xhqr-6qv3
was published
for
silverstripe/framework
(Composer)
Jan 23, 2025
ProTip!
Advisories are also available from the
GraphQL API