GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
96 advisories
Filter by severity
Microweber vulnerable to stored cross-site scripting (XSS) via X-Forwarded-For header
High
CVE-2023-1881
was published
for
microweber/microweber
(Composer)
Apr 5, 2023
thorsten/phpmyfaq vulnerable to DOM cross-site scripting (XSS) via configuration privacy note URL parameter
High
CVE-2023-1882
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via adminlog
High
CVE-2023-1878
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via FAQ News link parameter
High
CVE-2023-1757
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via artlang parameter
High
CVE-2023-1880
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
smarty Cross-site Scripting vulnerability in Javascript escaping
High
CVE-2023-28447
was published
for
smarty/smarty
(Composer)
Mar 29, 2023
TYPO3 is vulnerable to Cross-Site Scripting via frontend rendering
High
CVE-2023-24814
was published
for
typo3/cms
(Composer)
Feb 8, 2023
Cross-site Scripting in librenms/librenms
High
CVE-2022-4068
was published
for
librenms/librenms
(Composer)
Nov 20, 2022
phpMyFAQ vulnerable to Cross-site Scripting
High
CVE-2022-3608
was published
for
phpmyfaq/phpmyfaq
(Composer)
Oct 19, 2022
Moodle Stored Cross-site Scripting and page denial of service
High
CVE-2022-40313
was published
for
moodle/moodle
(Composer)
Oct 1, 2022
Cross-site scripting from content entered in the tags and multiselect fields
High
GHSA-rv3r-vqjj-8c76
was published
for
getkirby/cms
(Composer)
Aug 30, 2022
Possible cross-site scripting attack via unsanitized SVG files in FoF Upload
High
CVE-2022-30999
was published
for
fof/upload
(Composer)
May 25, 2022
Magento stored cross-site scripting (XSS) in the customer address upload feature
High
CVE-2021-21030
was published
for
magento/community-edition
(Composer)
May 24, 2022
Bookstack Cross-site Scripting vulnerability
High
CVE-2020-26211
was published
for
ssddanbrown/bookstack
(Composer)
May 24, 2022
Cross site scripting via canonical tag in Contao
High
CVE-2022-24899
was published
for
contao/contao
(Composer)
May 20, 2022
Yii Framework reflected Cross-site Scripting
High
CVE-2018-6010
was published
for
yiisoft/yii2
(Composer)
May 13, 2022
Persistent Cross-site Scripting vulnerability in PrivateBin
High
CVE-2022-24833
was published
for
privatebin/privatebin
(Composer)
Apr 12, 2022
Cross-site Scripting in TastyIgniter
High
CVE-2022-0602
was published
for
tastyigniter/tastyigniter
(Composer)
Apr 6, 2022
Parsedown Class-Name Injection
High
CVE-2019-10905
was published
for
erusev/parsedown
(Composer)
Mar 26, 2022
Stored Cross-site Scripting in grav
High
CVE-2022-0970
was published
for
getgrav/grav
(Composer)
Mar 16, 2022
Cross-site Scripting in microweber
High
CVE-2022-0930
was published
for
microweber/microweber
(Composer)
Mar 13, 2022
Cross-site Scripting in Microweber
High
CVE-2022-0719
was published
for
microweber/microweber
(Composer)
Feb 24, 2022
Cross-site Scripting in microweber
High
CVE-2022-0690
was published
for
microweber/microweber
(Composer)
Feb 20, 2022
Cross-site Scripting in HTML2PDF
High
CVE-2021-45394
was published
for
spipu/html2pdf
(Composer)
Jan 21, 2022
ProTip!
Advisories are also available from the
GraphQL API