GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,479 advisories
Filter by severity
Grav Cross-site Scripting vulnerability
Low
CVE-2024-35498
was published
for
getgrav/grav
(Composer)
Jan 6, 2025
REDAXO CMS Cross-site Scripting vulnerability
Low
CVE-2024-46209
was published
for
redaxo/source
(Composer)
Jan 6, 2025
PHP-Textile has persistent XSS vulnerability in image link handling
High
GHSA-95m2-chm4-mq7m
was published
for
netcarver/textile
(Composer)
Jan 7, 2025
Extension:TabberNeue vulnerable to Cross-site Scripting
High
CVE-2025-21612
was published
for
starcitizentools/tabber-neue
(Composer)
Jan 6, 2025
PhpSpreadsheet has a Cross-Site Scripting (XSS) vulnerability in custom properties
Moderate
CVE-2024-56410
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet allows bypass XSS sanitizer using the javascript protocol and special characters
Moderate
CVE-2024-56412
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet has a Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page header
Moderate
CVE-2024-56411
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in Currency.php file
High
CVE-2024-56409
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in `Convert-Online.php` file
High
CVE-2024-56408
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in the Accounting.php file
High
CVE-2024-56366
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in the constructor of the Downloader class
High
CVE-2024-56365
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
phpMyFAQ Vulnerable to Stored HTML Injection at FAQ
Moderate
CVE-2024-56199
was published
for
phpmyfaq/phpmyfaq
(Composer)
Jan 2, 2025
LGSL has a reflected XSS at /lgsl_files/lgsl_list.php
Moderate
CVE-2024-56517
was published
for
tltneon/lgsl
(Composer)
Dec 30, 2024
Dcat-Admin Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2024-54775
was published
for
dcat/laravel-admin
(Composer)
Dec 28, 2024
Dcat Admin Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2024-54774
was published
for
dcat/laravel-admin
(Composer)
Dec 28, 2024
TCPDF missing character escape on error messages
Moderate
CVE-2024-56527
was published
for
tecnickcom/tcpdf
(Composer)
Dec 27, 2024
TCPDF lacks SVG sanitization
Moderate
CVE-2024-56519
was published
for
tecnickcom/tcpdf
(Composer)
Dec 27, 2024
lgsl Stored Cross-Site Scripting vulnerability
High
CVE-2024-56361
was published
for
tltneon/lgsl
(Composer)
Dec 26, 2024
Cross-site Scripting vulnerability in SimpleXLSXEx::readThemeColors, SimpleXLSXEx::getColorValue and SimpleXLSX::toHTMLEx
Moderate
CVE-2024-56364
was published
for
shuchkin/simplexlsx
(Composer)
Dec 23, 2024
LibreNMS vulnerable to Stored Cross-site Scripting via File Upload
Low
CVE-2024-47528
was published
for
librenms/librenms
(Composer)
Oct 1, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
Moderate
CVE-2023-44379
was published
for
baserproject/basercms
(Composer)
Feb 22, 2024
Firefly III allows webhooks HTML Injection.
Moderate
CVE-2024-22075
was published
for
grumpydictator/firefly-iii
(Composer)
Jan 5, 2024
Concrete CMS vulnerable to Stored Cross-site Scripting
Low
CVE-2024-4353
was published
for
concrete5/concrete5
(Composer)
Aug 1, 2024
Concrete CMS Stored XSS in Layout Preset Name
Moderate
CVE-2023-48650
was published
for
concrete5/concrete5
(Composer)
Feb 29, 2024
Concrete CMS Stored XSS
Low
CVE-2023-49337
was published
for
concrete5/concrete5
(Composer)
Feb 29, 2024
ProTip!
Advisories are also available from the
GraphQL API