GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,768
Erlang
35
GitHub Actions
29
Go
2,332
Maven
5,000+
npm
3,965
NuGet
713
pip
3,748
Pub
12
RubyGems
921
Rust
975
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,651 advisories
Filter by severity
Cross-Site Scripting in Page Preview
Moderate
CVE-2021-32667
was published
for
typo3/cms
(Composer)
Jul 22, 2021
Cross-site Scripting in Froala WYSIWYG Editor
Moderate
CVE-2021-28114
was published
for
froala/wysiwyg-editor
(Composer)
Jul 19, 2021
Craft CMS Cross-site Scripting Vulnerability
Moderate
CVE-2021-27902
was published
for
craftcms/cms
(Composer)
Jul 2, 2021
XSS Injection in Media Collection Title was possible
Moderate
CVE-2021-32737
was published
for
sulu/sulu
(Composer)
Jul 2, 2021
Cross site scripting in the system log
Moderate
CVE-2021-35210
was published
for
contao/contao
(Composer)
Jul 1, 2021
Cross-site Scripting in yii2cmf
Moderate
CVE-2018-10704
was published
for
yidashi/yii2cmf
(Composer)
Jun 22, 2021
Croos-site scripting in Croogo
Low
CVE-2019-20789
was published
for
croogo/croogo
(Composer)
Jun 22, 2021
Cross-site scripting in PageKit
Moderate
CVE-2021-32245
was published
for
pagekit/pagekit
(Composer)
Jun 22, 2021
ckeditor4 vulnerable to cross-site scripting
Moderate
CVE-2021-33829
was published
for
ckeditor4
(Composer)
Jun 21, 2021
Cross-site scripting in Centreon
Moderate
CVE-2021-27676
was published
for
centreon/centreon
(Composer)
Jun 8, 2021
Cross-site scripting in media2click
Moderate
CVE-2021-31778
was published
for
amazing/media2click
(Composer)
Jun 8, 2021
reflected XSS in tribalsystems/zenario
Moderate
CVE-2021-27673
was published
for
tribalsystems/zenario
(Composer)
Jun 8, 2021
Cross-site Scripting (XSS) in baserCMS
Moderate
CVE-2021-20683
was published
for
baserproject/basercms
(Composer)
Jun 8, 2021
Cross-site Scripting (XSS) in baserCMS
Moderate
CVE-2021-20681
was published
for
baserproject/basercms
(Composer)
Jun 8, 2021
XSS vulnerability with translator
Critical
CVE-2021-32671
was published
for
flarum/core
(Composer)
Jun 7, 2021
Authenticated Stored XSS in Administration
Moderate
GHSA-f6p7-8xfw-fjqq
was published
for
shopware/shopware
(Composer)
May 21, 2021
Reflected cross-site scripting in francoisjacquet/rosariosis
Moderate
CVE-2020-13278
was published
for
francoisjacquet/rosariosis
(Composer)
May 6, 2021
Cross-site Scripting in OpenCart
Moderate
CVE-2020-10596
was published
for
opencart/opencart
(Composer)
May 6, 2021
Cross-site scripting in ThinkAdmin
Moderate
CVE-2020-29315
was published
for
zoujingli/thinkadmin
(Composer)
May 6, 2021
Cross-site scripting in phpoffice/phpspreadsheet
Moderate
CVE-2020-7776
was published
for
phpoffice/phpexcel
(Composer)
May 6, 2021
Cross-site scripting (XSS) from unsanitized uploaded SVG files in Kirby
High
CVE-2021-29460
was published
for
getkirby/cms
(Composer)
Apr 30, 2021
Cross-Site Scripting in Bootstrap Package
Moderate
CVE-2021-21365
was published
for
bk2k/bootstrap-package
(Composer)
Apr 29, 2021
Potential XSS injection in the newsletter conditions field
Moderate
CVE-2021-21418
was published
for
prestashop/ps_emailsubscription
(Composer)
Apr 6, 2021
Cross site-scripting (XSS) moodle
Moderate
CVE-2020-25628
was published
for
moodle/moodle
(Composer)
Mar 29, 2021
Cross-site Scripting (XSS) in moodle
Moderate
CVE-2020-25702
was published
for
moodle/moodle
(Composer)
Mar 29, 2021
ProTip!
Advisories are also available from the
GraphQL API