GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
486 advisories
Filter by severity
YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
High
CVE-2025-46349
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
Open WebUI stored cross-site scripting (XSS) vulnerability
High
CVE-2024-7990
was published
for
open-webui
(pip)
Mar 20, 2025
Open WebUI Vulnerable to a Session Fixation Attack
High
CVE-2024-7053
was published
for
open-webui
(pip)
Mar 20, 2025
Jenkins AnchorChain Plugin Has a Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-30196
was published
for
org.jenkins-ci.plugins:anchorchain
(Maven)
Mar 19, 2025
DOM Expressions has a Cross-Site Scripting (XSS) vulnerability due to improper use of string.replace
High
CVE-2025-27108
was published
for
dom-expressions
(npm)
Feb 25, 2025
Solid Lacks Escaping of HTML in JSX Fragments allows for Cross-Site Scripting (XSS)
High
CVE-2025-27109
was published
for
solid-js
(npm)
Feb 25, 2025
Moodle has a stored XSS risk in admin live log
High
CVE-2025-26529
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle allows reflected XSS via question bank filter
High
CVE-2025-26530
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Leantime allows Stored Cross-Site Scripting (XSS)
High
GHSA-c39w-3pjx-qc7m
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Cross Site Scripting (XSS) and SQL Injection (SQLi)
High
GHSA-v4q9-437p-mhpg
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
S3-Proxy allows Reflected Cross-site Scripting (XSS) in template implementation
High
CVE-2025-27088
was published
for
github.com/oxyno-zeta/s3-proxy/cmd/s3-proxy
(Go)
Feb 20, 2025
Magento stored Cross-Site Scripting (XSS) vulnerability
High
CVE-2025-24438
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24410
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24412
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24414
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24413
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24415
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24417
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24416
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
MobSF Stored Cross-Site Scripting (XSS)
High
CVE-2025-24803
was published
for
mobsf
(pip)
Feb 5, 2025
CKAN has an XSS vector in user uploaded images in group/org and user profiles
High
CVE-2025-24372
was published
for
ckan
(pip)
Feb 5, 2025
Pimcore Authenticated Stored Cross-Site Scripting (XSS) Via Search Document
High
GHSA-xr3m-6gq6-22cg
was published
for
pimcore/pimcore
(Composer)
Jan 28, 2025
Authenticated Stored XSS in YesWiki
High
CVE-2025-24018
was published
for
yeswiki/yeswiki
(Composer)
Jan 21, 2025
Unauthenticated DOM Based XSS in YesWiki
High
CVE-2025-24017
was published
for
yeswiki/yeswiki
(Composer)
Jan 21, 2025
Rancher UI has Stored Cross-site Scripting vulnerability
High
CVE-2024-52281
was published
for
github.com/rancher/rancher
(Go)
Jan 14, 2025
ProTip!
Advisories are also available from the
GraphQL API