GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,436
Maven
5,000+
npm
5,000+
NuGet
883
pip
4,694
Pub
13
RubyGems
1,029
Rust
1,212
Swift
53
Unreviewed advisories
All unreviewed
5,000+
684 advisories
Filter by severity
Emissary has Stored XSS via Navigation Template Link Injection
Moderate
CVE-2026-35571
was published
for
gov.nsa.emissary:emissary
(Maven)
Apr 7, 2026
Liferay Portal Calendar module and Liferay DXP vulnerable to Cross-site Scripting, content spoofing
Moderate
CVE-2024-25151
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 21, 2024
Cross-site Scripting Vulnerability in Statement Browser
Moderate
CVE-2024-26140
was published
for
com.yetanalytics:lrs
(Maven)
Feb 21, 2024
Apache Ambari: Various Cross site scripting problems
Moderate
CVE-2023-50378
was published
for
org.apache.ambari:ambari
(Maven)
Mar 1, 2024
Apache Archiva Reflected Cross-site Scripting vulnerability
Moderate
CVE-2024-27140
was published
for
org.apache.archiva:archiva-common
(Maven)
Mar 1, 2024
PMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation messages
Moderate
CVE-2026-28338
was published
for
net.sourceforge.pmd:pmd-core
(Maven)
Feb 28, 2026
ThingsBoard vulnerable to stored cross-site scripting (XSS) vulnerability in the dashboard's Image Upload Gallery feature
Moderate
CVE-2025-34281
was published
for
org.thingsboard:application
(Maven)
Oct 17, 2025
Duplicate Advisory: Wildfly HAL Console Cross-Site Scripting
Moderate
GHSA-5wjw-h8x5-v65m
was published
for
org.jboss.hal:hal-console
(Maven)
Jan 14, 2025
•
withdrawn
Apache Syncope: Reflected XSS on Enduser Login
Moderate
CVE-2026-23794
was published
for
org.apache.syncope.client.idrepo:syncope-client-idrepo-common-ui
(Maven)
Feb 3, 2026
Stored Cross-site Scripting in folder-auth plugin
Moderate
CVE-2022-27200
was published
for
io.jenkins.plugins:folder-auth
(Maven)
Mar 18, 2022
Duplicate Advisory: Stored Cross-site Scripting vulnerability in Jenkins Folder-based Authorization Strategy Plugin
Moderate
GHSA-chr6-386q-4m3v
was published
for
io.jenkins.plugins:folder-auth
(Maven)
Mar 16, 2022
•
withdrawn
XWiki Affected by Reflected Cross-Site Scripting (XSS) in Error Messages
Moderate
CVE-2026-24128
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Jan 23, 2026
JavaScript execution via malicious molfiles (XSS)
Moderate
CVE-2024-0758
was published
for
de.ipb-halle:molecularfaces
(Maven)
Apr 16, 2021
Duplicate Advisory: JavaScript execution via malicious molfiles (XSS)
Moderate
GHSA-wc6f-qjxc-622v
was published
for
de.ipb-halle:molecularfaces
(Maven)
Jan 19, 2024
•
withdrawn
jQuery vulnerable to Cross-Site Scripting (XSS)
Moderate
CVE-2011-4969
was published
for
jQuery
(RubyGems)
May 14, 2022
Vaadin vulnerable to Cross-site Scripting
Moderate
CVE-2025-15022
was published
for
com.vaadin:vaadin
(Maven)
Jan 5, 2026
Duplicate Advisory: Keycloak error_description injection on error pages that can trigger phishing attacks
Moderate
GHSA-xmcw-mv9p-7pq2
was published
for
org.keycloak:keycloak-account-ui
(Maven)
Sep 5, 2025
•
withdrawn
Liferay Portal Vulnerable to Cross-Site Scripting
Moderate
CVE-2025-43731
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 18, 2025
Liferay Portal and Liferay DXP vulnerable to store Cross-site Scripting
Moderate
CVE-2025-43776
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 9, 2025
Liferay Cross-site Scripting vulnerability
Moderate
CVE-2025-3760
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Apr 17, 2025
Liferay Portal has stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-43794
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 15, 2025
Liferay Portal's selection modal is vulnerable to XSS
Moderate
CVE-2025-43787
was published
for
com.liferay:com.liferay.users.admin.web
(Maven)
Sep 12, 2025
Liferay Portal is vulnerable to Reflected XSS attack through get_editor path
Moderate
CVE-2025-43783
was published
for
com.liferay:com.liferay.frontend.editor.ckeditor.web
(Maven)
Sep 10, 2025
Liferay Portal and Liferay DXP vulnerable to Stored Cross-site Scripting
Moderate
CVE-2025-43785
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 10, 2025
Liferay Portal is vulnerable to XSS attack through its search bar portlet
Moderate
CVE-2025-43781
was published
for
com.liferay:com.liferay.portal.search.web
(Maven)
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API