GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,754
Maven
5,000+
npm
4,359
NuGet
765
pip
4,126
Pub
12
RubyGems
961
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
33,850 advisories
Filter by severity
Parse Server has a Cross-Site Scripting (XSS) vulnerability via Unescaped Mustache Template Variables
Moderate
CVE-2025-68115
was published
for
parse-server
(npm)
Dec 16, 2025
WebsiteBaker 2.13.3 contains a stored cross-site scripting vulnerability that allows...
Moderate
Unreviewed
CVE-2023-53903
was published
Dec 16, 2025
Rukovoditel 3.4.1 contains multiple stored cross-site scripting vulnerabilities that allow...
Moderate
Unreviewed
CVE-2023-53897
was published
Dec 16, 2025
Rukovoditel 3.4.1 contains a stored cross-site scripting vulnerabilities that allow authenticated...
Moderate
Unreviewed
CVE-2023-53898
was published
Dec 16, 2025
A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1...
Moderate
Unreviewed
CVE-2025-29231
was published
Dec 16, 2025
In JetBrains TeamCity before 2025.11 reflected XSS was possible on VCS Root setup
Moderate
Unreviewed
CVE-2025-68165
was published
Dec 16, 2025
In JetBrains TeamCity before 2025.11.1 reflected XSS was possible on the storage settings page
Moderate
Unreviewed
CVE-2025-68268
was published
Dec 16, 2025
In JetBrains TeamCity before 2025.11 a DOM-based XSS was possible on the OAuth connections tab
Moderate
Unreviewed
CVE-2025-68166
was published
Dec 16, 2025
The Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
Moderate
Unreviewed
CVE-2025-11220
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-67986
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-68076
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-68079
was published
Dec 16, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-67951
was published
Dec 16, 2025
Lucee 5.4.2.17 contains a reflected cross-site scripting vulnerability that allows authenticated...
Moderate
Unreviewed
CVE-2023-53880
was published
Dec 15, 2025
JLex GuestBook 1.6.4 contains a reflected cross-site scripting vulnerability in the 'q' URL...
Moderate
Unreviewed
CVE-2023-53882
was published
Dec 15, 2025
Zomplog 3.9 contains a cross-site scripting vulnerability that allows authenticated users to...
Moderate
Unreviewed
CVE-2023-53887
was published
Dec 15, 2025
Webedition CMS v2.9.8.8 contains a stored cross-site scripting vulnerability that allows...
Moderate
Unreviewed
CVE-2023-53884
was published
Dec 15, 2025
Perch CMS 3.2 contains a stored cross-site scripting vulnerability that allows authenticated...
Moderate
Unreviewed
CVE-2023-53890
was published
Dec 15, 2025
A vulnerability was determined in vion707 DMadmin up to 3403cafdb42537a648c30bf8cbc8148ec60437d1....
Moderate
Unreviewed
CVE-2025-14722
was published
Dec 15, 2025
Blackcat CMS 1.4 contains a stored cross-site scripting vulnerability that allows authenticated...
Moderate
Unreviewed
CVE-2023-53891
was published
Dec 15, 2025
Jorani 1.0.3 contains a reflected cross-site scripting vulnerability in the language parameter...
Moderate
Unreviewed
CVE-2023-53870
was published
Dec 15, 2025
A HTML Injection vulnerability in the comment section of the project page in MicroStudio 24.01.29...
Moderate
Unreviewed
CVE-2025-51962
was published
Dec 15, 2025
A reflected cross-site scripting (XSS) vulnerability in the component /index.php/cuzh4 of PHP...
Moderate
Unreviewed
CVE-2023-36337
was published
Dec 15, 2025
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-14387
was published
Dec 15, 2025
grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page...
Moderate
Unreviewed
CVE-2025-66843
was published
Dec 15, 2025
ProTip!
Advisories are also available from the
GraphQL API