GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,310
Maven
5,000+
npm
3,949
NuGet
711
pip
3,728
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
34,809 advisories
Filter by severity
MantisBT allows XSS on the Edit Filter page via crafted filter name
Moderate
CVE-2018-14504
was published
for
mantisbt/mantisbt
(Composer)
May 14, 2022
MantisBT allows XSS via View Filters page
Moderate
CVE-2018-13055
was published
for
mantisbt/mantisbt
(Composer)
May 14, 2022
MantisBT allows XSS via the Manage Filter page
Moderate
CVE-2018-17782
was published
for
mantisbt/mantisbt
(Composer)
May 14, 2022
MantisBT allows XSS via Edit Filter page
Moderate
CVE-2018-17783
was published
for
mantisbt/mantisbt
(Composer)
May 14, 2022
MantisBT XSS allows unsanitized input via admin/install.php
Moderate
CVE-2017-12061
was published
for
mantisbt/mantisbt
(Composer)
May 13, 2022
MantisBT XSS in manage_custom_field_update.php
Moderate
CVE-2020-35571
was published
for
mantisbt/mantisbt
(Composer)
May 24, 2022
The OpenSheetMusicDisplay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-5235
was published
May 30, 2025
An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content...
High
Unreviewed
CVE-2025-1763
was published
May 30, 2025
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-4944
was published
May 30, 2025
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-4943
was published
May 30, 2025
The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-5236
was published
May 30, 2025
Cross-site scripting vulnerability exists in wivia 5 all versions. If exploited, when a user...
Moderate
Unreviewed
CVE-2025-41406
was published
May 30, 2025
The Minimal Share Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-5259
was published
May 30, 2025
IBM Aspera Faspex 5.0.0 through 5.0.12 is vulnerable to HTML injection. A remote attacker could...
Moderate
Unreviewed
CVE-2025-33138
was published
May 22, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-47497
was published
May 7, 2025
Argo CD allows cross-site scripting on repositories page
Critical
CVE-2025-47933
was published
for
github.com/argoproj/argo-cd
(Go)
May 28, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2023-46310
was published
Jun 4, 2024
The Events Calendar WordPress plugin before 6.4.0.1 does not properly sanitize user-submitted...
Critical
Unreviewed
CVE-2024-4180
was published
Jun 4, 2024
The Essential Real Estate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2024-4273
was published
Jun 4, 2024
Chrome PHP is missing encoding in `CssSelector`
Moderate
CVE-2025-48883
was published
for
chrome-php/chrome
(Composer)
May 28, 2025
MantisBT allows XSS in manage_custom_field_edit_page.php
Moderate
CVE-2021-33557
was published
for
mantisbt/mantisbt
(Composer)
May 24, 2022
A reflected cross-site scripting (XSS) vulnerability in the component mcgs/download-medical-cards...
Moderate
Unreviewed
CVE-2024-51099
was published
May 23, 2025
The TJ Shortcodes WordPress plugin through 0.1.3 does not validate and escape some of its...
Moderate
Unreviewed
CVE-2023-6530
was published
Jan 29, 2024
The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not sanitise and...
Moderate
Unreviewed
CVE-2024-6223
was published
Jul 30, 2024
The WpStickyBar WordPress plugin through 2.1.0 does not sanitise and escape a parameter before...
Moderate
Unreviewed
CVE-2024-6226
was published
Jul 30, 2024
ProTip!
Advisories are also available from the
GraphQL API