GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,781 advisories
Filter by severity
Reflected cross-site scripting in francoisjacquet/rosariosis
Moderate
CVE-2020-13278
was published
for
francoisjacquet/rosariosis
(Composer)
May 6, 2021
Cross-site Scripting in RosarioSIS
Moderate
CVE-2020-15721
was published
for
francoisjacquet/rosariosis
(Composer)
Feb 10, 2022
Cross-site scripting in forkcms
Moderate
CVE-2020-23263
was published
for
forkcms/forkcms
(Composer)
Feb 10, 2022
Cross-site scripting in media2click
Moderate
CVE-2021-31778
was published
for
amazing/media2click
(Composer)
Jun 8, 2021
Cross-Site Scripting in Bootstrap Package
Moderate
CVE-2021-21365
was published
for
bk2k/bootstrap-package
(Composer)
Apr 29, 2021
Bypass of fix for CVE-2020-26231, Twig sandbox escape
Moderate
CVE-2021-21264
was published
for
october/cms
(Composer)
May 4, 2021
Cross-site Scripting in yii2cmf
Moderate
CVE-2018-10704
was published
for
yidashi/yii2cmf
(Composer)
Jun 22, 2021
Cross-Site Request Forgery in MAGMI
Moderate
CVE-2020-5776
was published
for
dweeves/magmi
(Composer)
May 6, 2021
Unrestricted Uploads in Concrete5
Moderate
CVE-2020-14961
was published
for
concrete5/concrete5
(Composer)
Feb 10, 2022
SQL Injection in tribalsystems/zenario
Moderate
CVE-2021-27672
was published
for
tribalsystems/zenario
(Composer)
Jun 8, 2021
OS Command injection in Bolt
Moderate
CVE-2020-28925
was published
for
bolt/bolt
(Composer)
May 6, 2021
Potential XSS injection in the newsletter conditions field
Moderate
CVE-2021-21418
was published
for
prestashop/ps_emailsubscription
(Composer)
Apr 6, 2021
XSS in CreateQueuedJobTask
Moderate
CVE-2021-27938
was published
for
symbiote/silverstripe-queuedjobs
(Composer)
Mar 24, 2021
Cross-site scripting (XSS)
Moderate
CVE-2021-28088
was published
for
impresscms/impresscms
(Composer)
Mar 12, 2021
Cross-site scripting (XSS)
Moderate
CVE-2020-17551
was published
for
impresscms/impresscms
(Composer)
Mar 12, 2021
Cross-site Scripting (XSS) in baserCMS
Moderate
CVE-2021-20683
was published
for
baserproject/basercms
(Composer)
Jun 8, 2021
Stored cross-site scripting in PressBooks
Moderate
CVE-2021-3271
was published
for
pressbooks/pressbooks
(Composer)
Mar 29, 2021
Cross-site Scripting (XSS) in moodle
Moderate
CVE-2020-25702
was published
for
moodle/moodle
(Composer)
Mar 29, 2021
XSS in Flarum Sticky extension
Moderate
CVE-2021-21283
was published
for
flarum/sticky
(Composer)
Jan 29, 2021
Twig Sandbox Escape by authenticated users with access to editing CMS templates when safemode is enabled.
Moderate
CVE-2020-15247
was published
for
october/cms
(Composer)
Nov 23, 2020
Inline JS XSS vulnerability in Mautic
Moderate
CVE-2017-1000488
was published
for
mautic/core
(Composer)
Jan 19, 2021
Information Disclosure in TYPO3 extension sf_event_mgt
Moderate
CVE-2020-25026
was published
for
derhansen/sf_event_mgt
(Composer)
Sep 2, 2020
Tribal Systems Zenario CMS vulnerable to Cross-site Scripting
Moderate
CVE-2020-36608
was published
for
tribalsystems/zenario
(Composer)
Nov 3, 2022
HyperDown vulnerable to Cross-site Scripting
Moderate
CVE-2022-25849
was published
for
joyqi/hyper-down
(Composer)
Oct 26, 2022
ProTip!
Advisories are also available from the
GraphQL API