GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,831
Maven
5,000+
npm
4,462
NuGet
775
pip
4,226
Pub
12
RubyGems
972
Rust
1,093
Swift
47
Unreviewed advisories
All unreviewed
5,000+
936 advisories
Filter by severity
PlantUML is vulnerable to Stored XSS due to insufficient sanitization of interactive attributes in GraphViz diagrams
Low
CVE-2026-0858
was published
for
net.sourceforge.plantuml:plantuml
(Maven)
Jan 16, 2026
jQuery vulnerable to Cross-Site Scripting (XSS)
Moderate
CVE-2011-4969
was published
for
jQuery
(RubyGems)
May 14, 2022
OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization
High
CVE-2025-66021
was published
for
com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer
(Maven)
Nov 25, 2025
Vaadin vulnerable to Cross-site Scripting
Moderate
CVE-2025-15022
was published
for
com.vaadin:vaadin
(Maven)
Jan 5, 2026
Duplicate Advisory: Keycloak error_description injection on error pages that can trigger phishing attacks
Moderate
GHSA-xmcw-mv9p-7pq2
was published
for
org.keycloak:keycloak-account-ui
(Maven)
Sep 5, 2025
•
withdrawn
Liferay Portal Vulnerable to Cross-Site Scripting
Moderate
CVE-2025-43731
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 18, 2025
Liferay Portal and Liferay DXP vulnerable to store Cross-site Scripting
Moderate
CVE-2025-43776
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 9, 2025
Liferay Portal Vulnerable to Cross-Site Scripting
Low
CVE-2025-43733
was published
for
com.liferay:com.liferay.layout.taglib
(Maven)
Aug 18, 2025
Liferay Cross-site Scripting vulnerability
Moderate
CVE-2025-3760
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Apr 17, 2025
Liferay Portal has stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-43794
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Sep 15, 2025
Liferay Portal's selection modal is vulnerable to XSS
Moderate
CVE-2025-43787
was published
for
com.liferay:com.liferay.users.admin.web
(Maven)
Sep 12, 2025
Liferay Portal is vulnerable to Reflected XSS attack through get_editor path
Moderate
CVE-2025-43783
was published
for
com.liferay:com.liferay.frontend.editor.ckeditor.web
(Maven)
Sep 10, 2025
Liferay Portal and Liferay DXP vulnerable to Stored Cross-site Scripting
Moderate
CVE-2025-43785
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 10, 2025
Liferay Portal is vulnerable to XSS attack through its search bar portlet
Moderate
CVE-2025-43781
was published
for
com.liferay:com.liferay.portal.search.web
(Maven)
Sep 9, 2025
Liferay Portal is vulnerable to XSS attacks via its remote app title field
Moderate
CVE-2025-43775
was published
for
com.liferay:com.liferay.client.extension.web
(Maven)
Sep 9, 2025
Liferay Portal Reflected Cross-Site Scripting Vulnerability via PortalUtil.escapeRedirect
Moderate
CVE-2025-43760
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 22, 2025
Liferay Portal Vulnerable to Cross-Site Scripting through URLs
Moderate
CVE-2025-43742
was published
for
com.liferay:com.liferay.layout.type.controller.display.page
(Maven)
Aug 20, 2025
Liferay Portal Commerce Shop is vulnerable to Stored XSS through SVG file
Moderate
CVE-2025-43829
was published
for
com.liferay.commerce:com.liferay.commerce.shop.by.diagram.web
(Maven)
Oct 8, 2025
Liferay Portal is vulnerable to XSS through its Commerce Product's Name text field
Moderate
CVE-2025-43821
was published
for
com.liferay.commerce:com.liferay.commerce.product.service
(Maven)
Oct 8, 2025
Liferay Portal has multiple Stored XSS vulnerabilities on its View Order page
Moderate
CVE-2025-43822
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 8, 2025
Liferay Portal is vulnerable to XSS through its Commerce Search Result widget
Moderate
CVE-2025-43823
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 8, 2025
Liferay Profile Widget does not prevent vCard extension spoofing
Moderate
CVE-2025-43824
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 7, 2025
Liferay Portal Vulnerable to XSS in Web Content translation
Moderate
CVE-2025-43826
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Oct 1, 2025
Liferay has a stored cross-site scripting (XSS) vulnerability via a a publication’s “Name” text field
Moderate
CVE-2025-43807
was published
for
com.liferay:com.liferay.change.tracking.service
(Maven)
Sep 22, 2025
Liferay Portal CAPTCHA Bypass for Gogo Shell
Moderate
CVE-2025-4604
was published
for
com.liferay:com.liferay.captcha.impl
(Maven)
Aug 5, 2025
ProTip!
Advisories are also available from the
GraphQL API