GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,831
Maven
5,000+
npm
4,462
NuGet
775
pip
4,226
Pub
12
RubyGems
972
Rust
1,093
Swift
47
Unreviewed advisories
All unreviewed
5,000+
95 advisories
Filter by severity
jQuery vulnerable to Cross-Site Scripting (XSS)
Moderate
CVE-2011-4969
was published
for
jQuery
(RubyGems)
May 14, 2022
Umbraco CMS has an arbitrary file upload vulnerability
Moderate
CVE-2025-67288
was published
for
Umbraco.Cms
(NuGet)
Dec 22, 2025
Piranha has stored cross-site scripting (XSS) vulnerability
Low
CVE-2025-67291
was published
for
Piranha
(NuGet)
Dec 22, 2025
Piranha has stored cross-site scripting (XSS) vulnerability
Low
CVE-2025-67290
was published
for
Piranha
(NuGet)
Dec 22, 2025
Bootstrap Cross-site Scripting vulnerability
Moderate
CVE-2018-14041
was published
for
bootstrap
(RubyGems)
Sep 13, 2018
XSS in the `of` option of the `.position()` util in jquery-ui
Moderate
CVE-2021-41184
was published
for
jQuery.UI.Combined
(RubyGems)
Oct 26, 2021
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
Moderate
CVE-2025-64094
was published
for
DotNetNuke.Core
(NuGet)
Oct 29, 2025
Piranha CMS vulnerable to stored cross-site scripting (XSS)
Moderate
CVE-2025-61413
was published
for
Piranha
(NuGet)
Oct 23, 2025
Potential XSS vulnerability in jQuery
Moderate
CVE-2020-11023
was published
for
components/jquery
(RubyGems)
Apr 29, 2020
Withdrawn Advisory: Bootstrap Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2024-6531
was published
for
bootstrap
(RubyGems)
Jul 11, 2024
•
withdrawn
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
Moderate
CVE-2025-59821
was published
for
DotNetNuke.Core
(NuGet)
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
Low
CVE-2025-59546
was published
for
DotNetNuke.Core
(NuGet)
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
Critical
CVE-2025-59545
was published
for
DotNetNuke.Core
(NuGet)
Sep 23, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
Moderate
CVE-2025-59539
was published
for
DotNetNuke.Core
(NuGet)
Sep 22, 2025
DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjects
Moderate
CVE-2025-52486
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed
Moderate
CVE-2025-52485
was published
for
DNN.PLATFORM
(NuGet)
Jun 20, 2025
Withdrawn Advisory: Bootstrap Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2024-6484
was published
for
bootstrap
(RubyGems)
Jul 11, 2024
•
withdrawn
FormCms avatar upload feature has a stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-56236
was published
for
FormCMS
(NuGet)
Aug 28, 2025
jQuery UI vulnerable to XSS when refreshing a checkboxradio with an HTML-like initial text label
Moderate
CVE-2022-31160
was published
for
jQuery.UI.Combined
(RubyGems)
Jul 18, 2022
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Moderate
CVE-2025-48377
was published
for
DotNetNuke.Core
(NuGet)
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Moderate
CVE-2025-48378
was published
for
DotNetNuke.Core
(NuGet)
May 23, 2025
Cross-site Scripting in jquery-ui
Moderate
CVE-2010-5312
was published
for
jQuery.UI.Combined
(RubyGems)
Oct 24, 2017
XSS/HTML Injection Vulnerability in Umbraco Preview Badge
Moderate
CVE-2024-10761
was published
for
Umbraco.Cms
(NuGet)
Jan 21, 2025
Duplicate Advisory: Umbraco CMS Cross-site Scripting vulnerability
Low
GHSA-4gmq-m9vp-jrwg
was published
for
Umbraco.Cms.Core
(NuGet)
Nov 4, 2024
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API