GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,878 advisories
Filter by severity
jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin
Low
CVE-2025-9910
was published
for
jsondiffpatch
(npm)
Sep 11, 2025
Liferay Portal is vulnerable to Reflected XSS attack through get_editor path
Moderate
CVE-2025-43783
was published
for
com.liferay:com.liferay.frontend.editor.ckeditor.web
(Maven)
Sep 10, 2025
Shopware: Reflective Cross Site-Scripting (XSS) in CMS components
High
GHSA-9v82-vcjx-m76j
was published
for
shopware/core
(Composer)
Sep 10, 2025
Indico vulnerable to Cross-Site Scripting via LaTeX math code
Moderate
CVE-2025-59035
was published
for
indico
(pip)
Sep 10, 2025
Liferay Portal and Liferay DXP vulnerable to Stored Cross-site Scripting
Moderate
CVE-2025-43785
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 10, 2025
Decap CMS Cross Site Scripting (XSS) vulnerability
Low
CVE-2025-57520
was published
for
decap-cms
(npm)
Sep 10, 2025
Webrecorder packages are vulnerable to XSS through 404 error handling logic
High
CVE-2025-58765
was published
for
@webrecorder/archivewebpage
(npm)
Sep 10, 2025
Liferay Portal is vulnerable to XSS attacks via its remote app title field
Moderate
CVE-2025-43775
was published
for
com.liferay:com.liferay.client.extension.web
(Maven)
Sep 9, 2025
Liferay Portal is vulnerable to XSS attack through its search bar portlet
Moderate
CVE-2025-43781
was published
for
com.liferay:com.liferay.portal.search.web
(Maven)
Sep 9, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover
High
CVE-2025-58430
was published
for
github.com/knadh/listmonk
(Go)
Sep 9, 2025
YesWiki Cross Site Scripting vulnerability
Moderate
CVE-2025-52277
was published
for
yeswiki/yeswiki
(Composer)
Sep 9, 2025
Liferay Portal is vulnerable to XSS attack through fieldset name in Kaleo Forms Admin
Moderate
CVE-2025-43778
was published
for
com.liferay:com.liferay.portal.workflow.kaleo.forms.web
(Maven)
Sep 9, 2025
Liferay Portal is vulnerable to XSS attack through its Style Book theme
Low
CVE-2025-43774
was published
for
com.liferay:com.liferay.frontend.taglib.clay
(Maven)
Sep 9, 2025
MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server
High
CVE-2025-58444
was published
for
@modelcontextprotocol/inspector
(npm)
Sep 8, 2025
N8N's Chat Trigger component is vulnerable to XSS
High
CVE-2025-56265
was published
for
@n8n/n8n-nodes-langchain
(npm)
Sep 8, 2025
sanitize-html is vulnerable to XSS through incomprehensive sanitization
Moderate
CVE-2019-25225
was published
for
sanitize-html
(npm)
Sep 8, 2025
Memos Vulnerable to Stored Cross-Site Scripting
Moderate
CVE-2025-56761
was published
for
github.com/usememos/memos
(Go)
Sep 4, 2025
Mautic vulnerable to reflected XSS in lead:addLeadTags - Quick Add
Moderate
CVE-2025-9823
was published
for
mautic/core
(Composer)
Sep 3, 2025
CKEditor 5 cross-site scripting (XSS) vulnerability in the clipboard package
Low
CVE-2025-58064
was published
for
@ckeditor/ckeditor5-clipboard
(npm)
Sep 3, 2025
FormCms avatar upload feature has a stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-56236
was published
for
FormCMS
(NuGet)
Aug 28, 2025
Liferay Portal stored cross-site scripting in text field of the web content structure
Moderate
CVE-2025-43765
was published
for
com.liferay:com.liferay.journal.service
(Maven)
Aug 23, 2025
Liferay Portal vulnerable to Stored XSS in Components portlet
Moderate
CVE-2025-43769
was published
for
com.liferay:com.liferay.plugins.admin.web
(Maven)
Aug 23, 2025
Liferay Portal vulnerable to Reflected XSS with the referer and forward parameter
Moderate
CVE-2025-43770
was published
for
com.liferay.portal:com.liferay.portal.kernel
(Maven)
Aug 23, 2025
Liferay Portal Reflected XSS in CKeditor 4.21.0 endpoint
Moderate
CVE-2025-43761
was published
for
com.liferay:com.liferay.frontend.editor.ckeditor.web
(Maven)
Aug 22, 2025
Liferay Portal Reflected Cross-Site Scripting Vulnerability via PortalUtil.escapeRedirect
Moderate
CVE-2025-43760
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 22, 2025
ProTip!
Advisories are also available from the
GraphQL API