GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,758
Maven
5,000+
npm
4,364
NuGet
766
pip
4,132
Pub
12
RubyGems
961
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
39,018 advisories
Filter by severity
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-14385
was published
Dec 17, 2025
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress...
Moderate
Unreviewed
CVE-2025-13977
was published
Dec 17, 2025
A security vulnerability has been detected in xiweicheng TMS up to 2.28.0. This affects the...
Moderate
Unreviewed
CVE-2025-14801
was published
Dec 17, 2025
An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a...
High
Unreviewed
CVE-2025-14701
was published
Dec 17, 2025
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management...
Moderate
Unreviewed
CVE-2025-65592
was published
Dec 16, 2025
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality...
Moderate
Unreviewed
CVE-2025-65590
was published
Dec 16, 2025
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality.
Moderate
Unreviewed
CVE-2025-65591
was published
Dec 16, 2025
Libredesk has Improper Neutralization of HTML Tags in a Web Page
High
GHSA-wh6m-h6f4-rjf4
was published
for
github.com/abhinavxd/libredesk
(Go)
Dec 16, 2025
Parse Server has a Cross-Site Scripting (XSS) vulnerability via Unescaped Mustache Template Variables
Moderate
CVE-2025-68115
was published
for
parse-server
(npm)
Dec 16, 2025
WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows...
Moderate
Unreviewed
CVE-2023-53903
was published
Dec 16, 2025
Spip 4.1.10 contains a file upload vulnerability that allows attackers to upload malicious SVG...
Low
Unreviewed
CVE-2023-53900
was published
Dec 16, 2025
nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality.
Moderate
Unreviewed
CVE-2025-65589
was published
Dec 16, 2025
Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow...
Moderate
Unreviewed
CVE-2023-53897
was published
Dec 16, 2025
Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated...
Moderate
Unreviewed
CVE-2023-53898
was published
Dec 16, 2025
A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1...
Moderate
Unreviewed
CVE-2025-29231
was published
Dec 16, 2025
In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
Moderate
Unreviewed
CVE-2025-68166
was published
Dec 16, 2025
In JetBrains TeamCity before 2025.11 stored XSS was possible on agentpushInstall page
Low
Unreviewed
CVE-2025-68163
was published
Dec 16, 2025
In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup
Moderate
Unreviewed
CVE-2025-68165
was published
Dec 16, 2025
In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
Moderate
Unreviewed
CVE-2025-68268
was published
Dec 16, 2025
The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
Moderate
Unreviewed
CVE-2025-11220
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-68080
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-67986
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-68076
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-68078
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-68070
was published
Dec 16, 2025
ProTip!
Advisories are also available from the
GraphQL API