GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
47
Go
3,340
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,549
Pub
12
RubyGems
1,012
Rust
1,202
Swift
51
Unreviewed advisories
All unreviewed
5,000+
159 advisories
Filter by severity
Concrete CMS vulnerable to stored XSS via the Role Name field
Low
CVE-2024-1247
was published
for
concrete5/concrete5
(Composer)
Feb 9, 2024
Concrete CMS vulnerable to reflected XSS via the Image URL Import Feature
Low
CVE-2024-1246
was published
for
concrete5/concrete5
(Composer)
Feb 9, 2024
Concrete CMS vulnerable to stored XSS in file tags and description attributes
Low
CVE-2024-1245
was published
for
concrete5/concrete5
(Composer)
Feb 9, 2024
Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page
Low
GHSA-g3hp-vvqf-8vw6
was published
for
craftcms/cms
(Composer)
Mar 11, 2026
Craft Commerce is Vulnerable to Stored XSS while updating Order Status from Orders Table
Low
CVE-2026-29173
was published
for
craftcms/commerce
(Composer)
Mar 10, 2026
Craft Commerce has stored XSS in Craft Commerce Order Details Slideout
Low
CVE-2026-29177
was published
for
craftcms/commerce
(Composer)
Mar 10, 2026
Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options
Low
GHSA-4mgv-366x-qxvx
was published
for
craftcms/cms
(Composer)
Mar 3, 2026
funadmin: XSS through Value argument in Backend Interface component
Low
CVE-2026-2897
was published
for
funadmin/funadmin
(Composer)
Feb 22, 2026
Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type
Low
GHSA-6j87-m5qx-9fqp
was published
for
craftcms/cms
(Composer)
Feb 25, 2026
Freeform Craft Plugin CP UI (builder/integrations) has Stored Cross-Site Scripting (XSS) issue
Low
CVE-2026-26188
was published
for
solspace/craft-freeform
(Composer)
Jan 22, 2026
Craft CMS Vulnerable to Stored XSS in Entry Types Name
Low
CVE-2026-25491
was published
for
craftcms/cms
(Composer)
Feb 9, 2026
Winter CMS has Stored Cross-site Scripting (XSS) in Asset Manager
Low
CVE-2026-22254
was published
for
winter/wn-cms-module
(Composer)
Feb 4, 2026
Microweber Cross-site Scripting vulnerability
Low
CVE-2025-70792
was published
for
microweber/microweber
(Composer)
Feb 5, 2026
Microweber has a Cross-site Scripting vulnerability
Low
CVE-2025-70791
was published
for
microweber/microweber
(Composer)
Feb 5, 2026
solspace/craft-freeform Vulnerable to XSS in `PhpSpreadsheet` HTML Writer Due to Unsanitized Styling Data
Low
GHSA-44jg-mv3h-wj6g
was published
for
solspace/craft-freeform
(Composer)
Jan 15, 2026
Pterodactyl has a Reflected XSS vulnerability in “Create New Database Host”
Low
GHSA-mgr9-6c2j-jxrq
was published
for
pterodactyl/panel
(Composer)
Dec 30, 2025
yungifez Skuul School Management System vulnerable to XSS via SVG
Low
CVE-2025-13784
was published
for
yungifez/skuul
(Composer)
Nov 30, 2025
Contao is vulnerable to cross-site scripting in templates
Low
CVE-2025-65961
was published
for
contao/core-bundle
(Composer)
Nov 25, 2025
PrivateBin vulnerable to malicious filename use for self-XSS / HTML injection locally for users
Low
CVE-2025-64711
was published
for
privatebin/privatebin
(Composer)
Nov 14, 2025
phppgadmin vulnerable to Cross-site Scripting
Low
CVE-2025-60796
was published
for
phppgadmin/phppgadmin
(Composer)
Nov 20, 2025
Drupal Simple multi step form allows Cross-Site Scripting
Low
CVE-2025-12761
was published
for
drupal/simple_multistep
(Composer)
Nov 18, 2025
Drupal Umami Analytics allows Cross-Site Scripting (XSS)
Low
CVE-2025-10931
was published
for
drupal/umami_analytics
(Composer)
Oct 30, 2025
TastyIgniter vulnerable to Cross-Site Scripting
Low
CVE-2025-61417
was published
for
tastyigniter/tastyigniter
(Composer)
Oct 20, 2025
LibreNMS alert-rules has a Cross-Site Scripting Vulnerability
Low
CVE-2025-62412
was published
for
librenms/librenms
(Composer)
Oct 16, 2025
drupal-pattern-lab/unified-twig-extensions is vulnerable to XXS
Low
CVE-2025-11570
was published
for
drupal-pattern-lab/unified-twig-extensions
(Composer)
Oct 10, 2025
ProTip!
Advisories are also available from the
GraphQL API