GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,752
Maven
5,000+
npm
4,357
NuGet
765
pip
4,121
Pub
12
RubyGems
961
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
38,963 advisories
Filter by severity
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2025-68078
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2025-68079
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2025-68077
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2025-68080
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2025-68070
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2025-67986
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2025-68076
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2025-67983
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2025-67951
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Unknown
Unreviewed
CVE-2025-67912
was published
Dec 16, 2025
Lucee 5.4.2.17 contains a reflected cross-site scripting vulnerability that allows authenticated...
Moderate
Unreviewed
CVE-2023-53880
was published
Dec 15, 2025
JLex GuestBook 1.6.4 contains a reflected cross-site scripting vulnerability in the 'q' URL...
Moderate
Unreviewed
CVE-2023-53882
was published
Dec 15, 2025
Zomplog 3.9 contains a cross-site scripting vulnerability that allows authenticated users to...
Moderate
Unreviewed
CVE-2023-53887
was published
Dec 15, 2025
Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows...
Moderate
Unreviewed
CVE-2023-53884
was published
Dec 15, 2025
Perch CMS 3.2 contains a stored cross-site scripting vulnerability that allows authenticated...
Moderate
Unreviewed
CVE-2023-53890
was published
Dec 15, 2025
A vulnerability was determined in vion707 DMadmin up to 3403cafdb42537a648c30bf8cbc8148ec60437d1....
Moderate
Unreviewed
CVE-2025-14722
was published
Dec 15, 2025
Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated...
Moderate
Unreviewed
CVE-2023-53891
was published
Dec 15, 2025
Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter...
Moderate
Unreviewed
CVE-2023-53870
was published
Dec 15, 2025
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-14387
was published
Dec 15, 2025
The FluentAuth – The Ultimate Authorization & Security Plugin for WordPress plugin for WordPress...
Moderate
Unreviewed
CVE-2025-13728
was published
Dec 15, 2025
The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login...
Moderate
Unreviewed
CVE-2025-13610
was published
Dec 15, 2025
The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User...
Moderate
Unreviewed
CVE-2025-13367
was published
Dec 15, 2025
The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-13608
was published
Dec 15, 2025
Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79)...
Moderate
Unreviewed
CVE-2025-37732
was published
Dec 15, 2025
The Lightweight Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-13740
was published
Dec 15, 2025
ProTip!
Advisories are also available from the
GraphQL API