GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,489
Maven
5,000+
npm
4,106
NuGet
735
pip
3,928
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
282 advisories
Filter by severity
Drupal OAuth2 Client Cross-Site Request Forgery (CSRF)
Low
CVE-2025-31684
was published
for
drupal/oauth2_client
(Composer)
Apr 1, 2025
Drupal SpamSpan Cross-Site Scripting (XSS) vulnerability
Low
CVE-2025-31687
was published
for
drupal/spamspan
(Composer)
Apr 1, 2025
Drupal Configuration Split Cross-Site Request Forgery (CSRF) vulnerability
Low
CVE-2025-31688
was published
for
drupal/config_split
(Composer)
Apr 1, 2025
Drupal Core Cross-Site Scripting (XSS) Vulnerability
Low
CVE-2025-31675
was published
for
drupal/core
(Composer)
Apr 1, 2025
MODX allows cross-site scripting (XSS) via an SVG file
Low
CVE-2025-28010
was published
for
modx/revolution
(Composer)
Mar 13, 2025
Microweber vulnerable to XSS attack due to insure `group` component in its Settings handler
Low
CVE-2025-2214
was published
for
microweber/microweber
(Composer)
Mar 12, 2025
Magento LTS vulnerable to stored XSS in theme config fields
Low
CVE-2025-27400
was published
for
openmage/magento-lts
(Composer)
Mar 3, 2025
Moodle allows teachers to evade trusttext config when restoring glossary entries
Low
CVE-2025-26532
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle has an IDOR in badges allows disabling of arbitrary badges
Low
CVE-2025-26531
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle has a stored XSS in ddimageortext question type
Low
CVE-2025-26528
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Leantime allows Cross-Site Scripting (XSS)
Low
GHSA-f679-254h-qhvj
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime has Missing Authorization Check for Host Parameter
Low
GHSA-3hfj-qcvj-4hx8
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
Low
CVE-2025-24430
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
Low
CVE-2025-24429
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
Low
CVE-2025-24432
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
DevDojo Voyager vulnerable to reflected Cross-site Scripting
Low
CVE-2024-55416
was published
for
tcg/voyager
(Composer)
Jan 30, 2025
Dolibarr Cross-site Scripting vulnerability
Low
CVE-2024-55227
was published
for
dolibarr/dolibarr
(Composer)
Jan 27, 2025
Dolibarr Cross-site Scripting vulnerability
Low
CVE-2024-55228
was published
for
dolibarr/dolibarr
(Composer)
Jan 27, 2025
Reflected Cross Site Scripting (XSS) in error message
Low
GHSA-74j9-xhqr-6qv3
was published
for
silverstripe/framework
(Composer)
Jan 23, 2025
Silverstripe Framework has a Reflected Cross Site Scripting (XSS) in error message
Low
GHSA-mqf3-qpc3-g26q
was published
for
silverstripe/framework
(Composer)
Jan 14, 2025
TYPO3 Information Disclosure via Exception Handling/Logger
Low
CVE-2024-55891
was published
for
typo3/cms-install
(Composer)
Jan 14, 2025
Grav Cross-site Scripting vulnerability
Low
CVE-2024-35498
was published
for
getgrav/grav
(Composer)
Jan 6, 2025
REDAXO CMS Cross-site Scripting vulnerability
Low
CVE-2024-46209
was published
for
redaxo/source
(Composer)
Jan 6, 2025
Drupal core contains a potential PHP Object Injection vulnerability
Low
CVE-2024-55636
was published
for
drupal/core
(Composer)
Dec 10, 2024
Moodle Cross-site Scripting vulnerability
Low
CVE-2024-43437
was published
for
moodle/moodle
(Composer)
Nov 11, 2024
ProTip!
Advisories are also available from the
GraphQL API