GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,491
Maven
5,000+
npm
4,109
NuGet
735
pip
3,933
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,780 advisories
Filter by severity
starcitizentools/citizen-skin allows stored XSS in preference menu heading messages
Moderate
CVE-2025-49577
was published
for
starcitizentools/citizen-skin
(Composer)
Jun 13, 2025
starcitizentools/citizen-skin allows stored XSS in search no result messages
Moderate
CVE-2025-49576
was published
for
starcitizentools/citizen-skin
(Composer)
Jun 13, 2025
Citizen skin vulnerable to stored XSS through multiple system messages
Moderate
CVE-2025-49575
was published
for
starcitizentools/citizen-skin
(Composer)
Jun 11, 2025
Drupal Lightgallery Cross-site Scripting vulnerability
Moderate
CVE-2025-48447
was published
for
drupal/lightgallery
(Composer)
Jun 11, 2025
Drupal Quick Node Block Missing Authorization vulnerability
Moderate
CVE-2025-48444
was published
for
drupal/quick_node_block
(Composer)
Jun 11, 2025
Drupal Quick Node Block Missing Authorization vulnerability
Moderate
CVE-2025-48013
was published
for
drupal/quick_node_block
(Composer)
Jun 11, 2025
HAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameter
Moderate
CVE-2025-49138
was published
for
elmsln/haxcms
(Composer)
Jun 9, 2025
Laravel Translation Manager Vulnerable to Stored Cross-site Scripting
Moderate
CVE-2025-49130
was published
for
barryvdh/laravel-translation-manager
(Composer)
Jun 9, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Moderate
CVE-2025-48493
was published
for
yiisoft/yii2-redis
(Composer)
Jun 5, 2025
juzaweb CMS allows cross-site scripting by uploading an SVG file
Moderate
CVE-2025-5420
was published
for
juzaweb/cms
(Composer)
Jun 2, 2025
Mautic has an Open Redirect vulnerability on user unlock path.
Moderate
CVE-2025-5256
was published
for
mautic/core
(Composer)
May 28, 2025
Mautic segment cloning doesn't have a proper permission check
Moderate
CVE-2024-47055
was published
for
mautic/core
(Composer)
May 28, 2025
Mautic allows user name enumeration due to response time difference on password reset form
Moderate
CVE-2024-47057
was published
for
mautic/core
(Composer)
May 28, 2025
Mautic does not shield .env files from web traffic
Moderate
CVE-2024-47056
was published
for
mautic/core
(Composer)
May 28, 2025
Mautic's Predictable Page Indexing Might Lead to Sensitive Data Exposure
Moderate
CVE-2025-5257
was published
for
mautic/core
(Composer)
May 28, 2025
Chrome PHP is missing encoding in `CssSelector`
Moderate
CVE-2025-48883
was published
for
chrome-php/chrome
(Composer)
May 28, 2025
Laravel Rest Api has a Search Validation Bypass
Moderate
CVE-2025-48490
was published
for
lomkit/laravel-rest-api
(Composer)
May 27, 2025
The Backup Plus extension for TYPO3 (ns_backup) allows command injections
Moderate
CVE-2025-48204
was published
for
nitsan/ns-backup
(Composer)
May 21, 2025
reint_downloadmanager TYPO3 Extension is susceptible to Insecure Direct Object Reference
Moderate
CVE-2025-48207
was published
for
renolit/reint-downloadmanager
(Composer)
May 21, 2025
The femanager TYPO3 extension allows Insecure Direct Object Reference
Moderate
CVE-2025-48202
was published
for
in2code/femanager
(Composer)
May 21, 2025
[clickstorm] SEO (cs_seo) TYPO3 extension Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2025-48203
was published
for
clickstorm/cs-seo
(Composer)
May 21, 2025
TYPO3 Allows Unrestricted File Upload in File Abstraction Layer
Moderate
CVE-2025-47939
was published
for
typo3/cms-core
(Composer)
May 20, 2025
Symfony UX allows unsanitized HTML attribute injection via ComponentAttributes
Moderate
CVE-2025-47946
was published
for
symfony/ux-live-component
(Composer)
May 19, 2025
tarteaucitron-wp WordPress Plugin Vulnerable to Stored Cross-Site Scripting
Moderate
CVE-2024-11718
was published
for
couleurcitron/tarteaucitron-wp
(Composer)
May 15, 2025
Sulu vulnerable to XXE in SVG File upload Inspector
Moderate
CVE-2025-47778
was published
for
sulu/sulu
(Composer)
May 15, 2025
ProTip!
Advisories are also available from the
GraphQL API