GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,722
Maven
5,000+
npm
4,329
NuGet
762
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,887 advisories
Filter by severity
Grav is vulnerable to Cross-Site Scripting (XSS) Reflected endpoint /admin/pages/[page], parameter data[header][content][items], located in the "Blog Config" tab
Moderate
CVE-2025-66309
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
Grav vulnerable to Cross-Site Scripting (XSS) Stored endpoint `/admin/pages/[page]` parameter `data[header][template]` in Advanced Tab
Moderate
CVE-2025-66310
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
FeehiCMS is vulnerable to reverse tabnabbing
Moderate
CVE-2025-63522
was published
for
feehi/feehicms
(Composer)
Dec 1, 2025
FeehiCMS is vulnerable to cross-site scripting via the id parameter of the User Update function
Moderate
CVE-2025-63520
was published
for
feehi/feehicms
(Composer)
Dec 1, 2025
FeehiCMS fails to enforce server-side immutability
Moderate
CVE-2025-63523
was published
for
feehi/feehicms
(Composer)
Dec 1, 2025
Snipe-IT allows stored XSS via the Locations "Country" field
Moderate
CVE-2025-65622
was published
for
snipe/snipe-it
(Composer)
Dec 2, 2025
Grav CMS is vulnerable to Cross Site Scripting (XSS) in the page editor
Moderate
CVE-2025-65186
was published
for
getgrav/grav
(Composer)
Dec 2, 2025
FeehiCMS Has a Remote Code Execution via Unrestricted File Upload in Ad Management
Moderate
CVE-2025-65657
was published
for
feehi/cms
(Composer)
Dec 2, 2025
Snipe-IT is vulnerable to stored cross-site scripting
Moderate
CVE-2025-65621
was published
for
snipe/snipe-it
(Composer)
Dec 1, 2025
LibreNMS is vulnerable to SQL Injection (Boolean-Based Blind) in hostname parameter in ajax_output.php endpoint
Moderate
CVE-2025-65093
was published
for
librenms/librenms
(Composer)
Nov 18, 2025
LibreNMS Arbitrary File Read
Moderate
CVE-2017-16759
was published
for
librenms/librenms
(Composer)
May 13, 2022
robrichards/xmlseclibs has an Libxml2 Canonicalization error which can bypass Digest/Signature validation
Moderate
CVE-2025-66578
was published
for
robrichards/xmlseclibs
(Composer)
Dec 8, 2025
ProTip!
Advisories are also available from the
GraphQL API