GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,344
Erlang
31
GitHub Actions
22
Go
2,112
Maven
5,000+
npm
3,767
NuGet
680
pip
3,453
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,503 advisories
Filter by severity
PhpSpreadsheet allows bypassing of XSS sanitizer using the javascript protocol and special characters
Moderate
CVE-2025-23210
was published
for
phpoffice/phpspreadsheet
(Composer)
Feb 3, 2025
DevDojo Voyager vulnerable to reflected Cross-site Scripting
Low
CVE-2024-55416
was published
for
tcg/voyager
(Composer)
Jan 30, 2025
Pimcore Authenticated Stored Cross-Site Scripting (XSS) Via Search Document
High
GHSA-xr3m-6gq6-22cg
was published
for
pimcore/pimcore
(Composer)
Jan 28, 2025
Dolibarr Cross-site Scripting vulnerability
Low
CVE-2024-55227
was published
for
dolibarr/dolibarr
(Composer)
Jan 27, 2025
Dolibarr Cross-site Scripting vulnerability
Low
CVE-2024-55228
was published
for
dolibarr/dolibarr
(Composer)
Jan 27, 2025
Reflected Cross Site Scripting (XSS) in error message
Low
GHSA-74j9-xhqr-6qv3
was published
for
silverstripe/framework
(Composer)
Jan 23, 2025
phpMyAdmin XSS when checking tables
Moderate
CVE-2025-24530
was published
for
phpmyadmin/phpmyadmin
(Composer)
Jan 23, 2025
ps_contactinfo has a potential XSS due to usage of the nofilter tag in template
Moderate
CVE-2025-24027
was published
for
prestashop/ps_contactinfo
(Composer)
Jan 22, 2025
Cross-Site Scripting (XSS) vulnerability in generateNavigation() function in PhpSpreadsheet
Moderate
CVE-2025-22131
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 21, 2025
Authenticated Stored XSS in YesWiki
High
CVE-2025-24018
was published
for
yeswiki/yeswiki
(Composer)
Jan 21, 2025
Unauthenticated DOM Based XSS in YesWiki
High
CVE-2025-24017
was published
for
yeswiki/yeswiki
(Composer)
Jan 21, 2025
Librenms has a reflected XSS on error alert
Moderate
CVE-2025-23201
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
LibreNMS Misc Section Stored Cross-site Scripting vulnerability
Moderate
CVE-2025-23200
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
LibreNMS Ports Stored Cross-site Scripting vulnerability
Moderate
CVE-2025-23199
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
LibreNMS Display Name Stored Cross-site Scripting vulnerability
Moderate
CVE-2025-23198
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
LibreNMS Display Name 2 Stored Cross-site Scripting vulnerability
Moderate
CVE-2024-56144
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
Silverstripe Framework has a Reflected Cross Site Scripting (XSS) in error message
Low
GHSA-mqf3-qpc3-g26q
was published
for
silverstripe/framework
(Composer)
Jan 14, 2025
Silverstripe Framework has a XSS in form messages
Moderate
CVE-2024-53277
was published
for
silverstripe/framework
(Composer)
Jan 14, 2025
Silverstripe Framework has a XSS via insert media remote file oembed
Moderate
CVE-2024-47605
was published
for
silverstripe/framework
(Composer)
Jan 14, 2025
Mediawiki - DataTransfer Extension Cross-Site Request Forgery (CSRF) and Cross-site Scripting (XSS)
Moderate
CVE-2025-23081
was published
for
mediawiki/data-transfer
(Composer)
Jan 14, 2025
Microweber Cross-site Scripting vulnerability
Moderate
CVE-2024-33297
was published
for
microweber/microweber
(Composer)
Jan 10, 2025
Microweber Cross-site Scripting vulnerability
Moderate
CVE-2024-33298
was published
for
microweber/microweber
(Composer)
Jan 10, 2025
Microweber Cross-site Scripting vulnerability
Moderate
CVE-2024-33299
was published
for
microweber/microweber
(Composer)
Jan 10, 2025
PHP-Textile has persistent XSS vulnerability in image link handling
High
GHSA-95m2-chm4-mq7m
was published
for
netcarver/textile
(Composer)
Jan 7, 2025
REDAXO CMS Cross-site Scripting vulnerability
Low
CVE-2024-46209
was published
for
redaxo/source
(Composer)
Jan 6, 2025
ProTip!
Advisories are also available from the
GraphQL API