GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,164
Erlang
30
GitHub Actions
19
Go
1,973
Maven
5,000+
npm
3,695
NuGet
654
pip
3,312
Pub
11
RubyGems
881
Rust
831
Swift
35
Unreviewed advisories
All unreviewed
5,000+
1,427 advisories
Filter by severity
Enhavo Cross-site Scripting vulnerability
Moderate
CVE-2024-25876
was published
for
enhavo/enhavo-app
(Composer)
Feb 22, 2024
phpBB's Smiley Pack acp_icons.php main pack vulnerable to cross site scripting
Moderate
CVE-2023-5917
was published
for
phpbb/phpbb
(Composer)
Nov 2, 2023
HTML Purifier Cross-site Scripting vulnerability
Moderate
CVE-2007-3498
was published
for
ezyang/htmlpurifier
(Composer)
May 1, 2022
Fluid Components TYPO3 extension vulnerable to Cross-Site Scripting
Moderate
CVE-2023-28604
was published
for
sitegeist/fluid-components
(Composer)
Mar 27, 2023
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Moderate
CVE-2024-46998
was published
for
baserproject/basercms
(Composer)
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Moderate
CVE-2024-46996
was published
for
baserproject/basercms
(Composer)
Oct 24, 2024
Cross site scripting in ameos_tarteaucitron
Moderate
CVE-2022-33155
was published
for
ameos/ameos_tarteaucitron
(Composer)
Jul 13, 2022
Funadmin Cross-site Scripting vulnerability
Low
CVE-2024-48228
was published
for
funadmin/funadmin
(Composer)
Oct 26, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
Moderate
CVE-2024-46995
was published
for
baserproject/basercms
(Composer)
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
Moderate
CVE-2024-46994
was published
for
baserproject/basercms
(Composer)
Oct 24, 2024
Filament has unvalidated ColorColumn and ColorEntry values that can be used for Cross-site Scripting
Critical
CVE-2024-47186
was published
for
filament/infolists
(Composer)
Sep 27, 2024
Cross-site Scripting via uploaded SVG
Moderate
CVE-2024-47618
was published
for
sulu/sulu
(Composer)
Oct 3, 2024
Injection of arbitrary HTML/JavaScript code through the media download URL
Moderate
CVE-2024-47617
was published
for
sulu/sulu
(Composer)
Oct 3, 2024
Admidio Vulnerable to HTML Injection In The Messages Section
Low
CVE-2024-47836
was published
for
admidio/admidio
(Composer)
Oct 16, 2024
LimeSurvey Cross Site Scripting vulnerability
Moderate
CVE-2024-28710
was published
for
limesurvey/limesurvey
(Composer)
Oct 7, 2024
Magento Open Source Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2024-45116
was published
for
magento/community-edition
(Composer)
Oct 10, 2024
Magento Open Source stored Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2024-45127
was published
for
magento/community-edition
(Composer)
Oct 10, 2024
Magento Open Source reflected Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2024-45123
was published
for
magento/community-edition
(Composer)
Oct 10, 2024
Lara-zeus Dynamic Dashboard and Artemis do not validate paragraph widget values which can be used for XSS
Moderate
CVE-2024-47817
was published
for
lara-zeus/artemis
(Composer)
Oct 7, 2024
PhpSpreadsheet HTML writer is vulnerable to Cross-Site Scripting via JavaScript hyperlinks
Moderate
CVE-2024-45292
was published
for
phpoffice/phpspreadsheet
(Composer)
Oct 7, 2024
PhpSpreadsheet has an Unauthenticated Cross-Site-Scripting (XSS) in sample file
Moderate
CVE-2024-45060
was published
for
phpoffice/phpspreadsheet
(Composer)
Oct 7, 2024
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Moderate
CVE-2024-45932
was published
for
krayin/laravel-crm
(Composer)
Oct 7, 2024
LimeSurvey Cross Site Scripting vulnerability
Moderate
CVE-2024-28709
was published
for
limesurvey/limesurvey
(Composer)
Oct 7, 2024
Mediawiki Cargo extension vulnerable to Cross-site Scripting
Moderate
CVE-2024-47847
was published
for
mediawiki/cargo
(Composer)
Oct 5, 2024
Minecraft MOTD Parser's HtmlGenerator vulnerable to XSS
Moderate
CVE-2024-47765
was published
for
dev-lancer/minecraft-motd-parser
(Composer)
Oct 4, 2024
ProTip!
Advisories are also available from the
GraphQL API