GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,087
Maven
5,000+
npm
3,751
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
1,264 advisories
Filter by severity
Librenms has a reflected XSS on error alert
Moderate
CVE-2025-23201
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
LibreNMS Misc Section Stored Cross-site Scripting vulnerability
Moderate
CVE-2025-23200
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
LibreNMS Ports Stored Cross-site Scripting vulnerability
Moderate
CVE-2025-23199
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
LibreNMS Display Name Stored Cross-site Scripting vulnerability
Moderate
CVE-2025-23198
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
LibreNMS Display Name 2 Stored Cross-site Scripting vulnerability
Moderate
CVE-2024-56144
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
Silverstripe Framework has a XSS in form messages
Moderate
CVE-2024-53277
was published
for
silverstripe/framework
(Composer)
Jan 14, 2025
Silverstripe Framework has a XSS via insert media remote file oembed
Moderate
CVE-2024-47605
was published
for
silverstripe/framework
(Composer)
Jan 14, 2025
Mediawiki - DataTransfer Extension Cross-Site Request Forgery (CSRF) and Cross-site Scripting (XSS)
Moderate
CVE-2025-23081
was published
for
mediawiki/data-transfer
(Composer)
Jan 14, 2025
Microweber Cross-site Scripting vulnerability
Moderate
CVE-2024-33299
was published
for
microweber/microweber
(Composer)
Jan 10, 2025
Microweber Cross-site Scripting vulnerability
Moderate
CVE-2024-33298
was published
for
microweber/microweber
(Composer)
Jan 10, 2025
Microweber Cross-site Scripting vulnerability
Moderate
CVE-2024-33297
was published
for
microweber/microweber
(Composer)
Jan 10, 2025
PhpSpreadsheet allows bypass XSS sanitizer using the javascript protocol and special characters
Moderate
CVE-2024-56412
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet has a Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page header
Moderate
CVE-2024-56411
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet has a Cross-Site Scripting (XSS) vulnerability in custom properties
Moderate
CVE-2024-56410
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
phpMyFAQ Vulnerable to Stored HTML Injection at FAQ
Moderate
CVE-2024-56199
was published
for
phpmyfaq/phpmyfaq
(Composer)
Jan 2, 2025
LGSL has a reflected XSS at /lgsl_files/lgsl_list.php
Moderate
CVE-2024-56517
was published
for
tltneon/lgsl
(Composer)
Dec 30, 2024
Dcat Admin Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2024-54774
was published
for
dcat/laravel-admin
(Composer)
Dec 28, 2024
Dcat-Admin Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2024-54775
was published
for
dcat/laravel-admin
(Composer)
Dec 28, 2024
TCPDF missing character escape on error messages
Moderate
CVE-2024-56527
was published
for
tecnickcom/tcpdf
(Composer)
Dec 27, 2024
TCPDF lacks SVG sanitization
Moderate
CVE-2024-56519
was published
for
tecnickcom/tcpdf
(Composer)
Dec 27, 2024
Cross-site Scripting vulnerability in SimpleXLSXEx::readThemeColors, SimpleXLSXEx::getColorValue and SimpleXLSX::toHTMLEx
Moderate
CVE-2024-56364
was published
for
shuchkin/simplexlsx
(Composer)
Dec 23, 2024
Cross-site Scripting vulnerability in SimpleXLSXEx::readXfs and SimpeXLSX::toHTMLEx
Moderate
CVE-2024-55878
was published
for
shuchkin/simplexlsx
(Composer)
Dec 12, 2024
Drupal Core Cross-Site Scripting (XSS)
Moderate
CVE-2024-12393
was published
for
drupal/core
(Composer)
Dec 10, 2024
LibreNMS stored cross-site scripting (XSS) vulnerability in the Device Settings section
Moderate
CVE-2024-53457
was published
for
librenms/librenms
(Composer)
Dec 6, 2024
Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern
Moderate
CVE-2024-53864
was published
for
ibexa/admin-ui
(Composer)
Dec 2, 2024
ProTip!
Advisories are also available from the
GraphQL API