GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,651
Maven
5,000+
npm
4,279
NuGet
760
pip
4,066
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,854 advisories
Filter by severity
OctoberCMS Cross-Site Scripting
Moderate
CVE-2017-15284
was published
for
october/rain
(Composer)
May 13, 2022
Laravel Starter Cross Site Scripting (XSS)
Moderate
CVE-2025-26159
was published
for
nasirkhan/laravel-starter
(Composer)
Apr 22, 2025
MantisBT vulnerable to CSRF and Open Redirect attacks
Moderate
CVE-2017-7620
was published
for
mantisbt/mantisbt
(Composer)
May 17, 2022
MODX Revolution XSS via HTTP Host header
Moderate
CVE-2017-9071
was published
for
modx/revolution
(Composer)
May 17, 2022
MODX Revolution cross-site scripting vulnerability
Moderate
CVE-2017-9070
was published
for
modx/revolution
(Composer)
May 17, 2022
MODX Revolution Reflected XSS
Moderate
CVE-2017-9068
was published
for
modx/revolution
(Composer)
May 17, 2022
TeamPass vulnerable to Cross-site Scripting
Moderate
CVE-2015-7562
was published
for
nilsteampassnet/teampass
(Composer)
May 17, 2022
juzawebCMS Incorrect Access Control vulnerability
Moderate
CVE-2023-46906
was published
for
juzaweb/cms
(Composer)
Jan 9, 2024
SilverStripe Subsite weakens file permissions
Moderate
CVE-2022-42949
was published
for
silverstripe/subsites
(Composer)
Dec 19, 2022
PEAR HTTP_Request2 vulnerable to Cross-site Scripting
Moderate
CVE-2025-43717
was published
for
pear/http_request2
(Composer)
Apr 17, 2025
Cross site scripting in the system log
Moderate
CVE-2021-35210
was published
for
contao/contao
(Composer)
Jul 1, 2021
Cross site scripting via input unit widget
Moderate
CVE-2023-36806
was published
for
contao/core-bundle
(Composer)
Jul 25, 2023
Cross-site Scripting in MobileDetect
Moderate
CVE-2018-25080
was published
for
mobiledetect/mobiledetectlib
(Composer)
Feb 4, 2023
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24436
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24437
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Drupal AI Vulnerable to OS Command Injection
Moderate
CVE-2025-31693
was published
for
drupal/ai
(Composer)
Apr 1, 2025
Snipe-IT allows attackers to check whether a user account exists
Moderate
CVE-2022-44381
was published
for
snipe/snipe-it
(Composer)
Dec 25, 2022
Snipe-IT vulnerable to Cross Site Scripting for View Assigned Assets
Moderate
CVE-2022-44380
was published
for
snipe/snipe-it
(Composer)
Dec 25, 2022
Typo3 Host Header Spoofing Vulnerability
Moderate
CVE-2014-3941
was published
for
typo3/cms
(Composer)
May 14, 2022
Typo3 Information Disclosure
Moderate
CVE-2014-3946
was published
for
typo3/cms
(Composer)
May 17, 2022
phpMyAdmin vulnerable to Cross-site Scripting
Moderate
CVE-2016-5733
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin vulnerable to Cross-site Scripting
Moderate
CVE-2016-5705
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin vulnerable to Cross-site Scripting
Moderate
CVE-2016-5701
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
TYPO3 Cross-site Scripting vulnerability
Moderate
CVE-2015-8759
was published
for
typo3/cms
(Composer)
May 17, 2022
TYPO3 CMS indexed search Cross-site Scripting vulnerability
Moderate
CVE-2015-8756
was published
for
typo3/cms
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API