GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
306 advisories
Filter by severity
Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised...
High
Unreviewed
CVE-2025-39663
was published
Oct 30, 2025
A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability...
Critical
Unreviewed
CVE-2025-53883
was published
Oct 30, 2025
IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker...
Moderate
Unreviewed
CVE-2025-36121
was published
Oct 27, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-62936
was published
Oct 27, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-62897
was published
Oct 27, 2025
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution...
Moderate
Unreviewed
CVE-2025-11823
was published
Oct 25, 2025
The Multi Item Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery...
Moderate
Unreviewed
CVE-2025-11992
was published
Oct 24, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-58970
was published
Oct 22, 2025
bagisto has Cross Site Scripting (XSS) in Create New Customer
Moderate
CVE-2025-62414
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has a Cross Site Scripting (XSS) vulnerability in TinyMCE Image Upload (SVG)
Moderate
CVE-2025-62418
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has Cross Site Scripting (XSS) issue in TinyMCE Image Upload (HTML)
Moderate
CVE-2025-62415
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-11161
was published
Oct 15, 2025
The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-11160
was published
Oct 15, 2025
HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could...
Moderate
Unreviewed
CVE-2025-31992
was published
Oct 12, 2025
The Cookie Notice & Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
High
Unreviewed
CVE-2025-10496
was published
Oct 9, 2025
A vulnerability in HCL HCL MyXalytics allows HTML InjectionThis issue affects HCL MyXalytics: 6.6.
Moderate
Unreviewed
CVE-2025-52654
was published
Oct 3, 2025
The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in...
Moderate
Unreviewed
CVE-2025-11241
was published
Oct 3, 2025
The Eulerpool Research Systems plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-10128
was published
Sep 30, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-60100
was published
Sep 26, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-59573
was published
Sep 22, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-57928
was published
Sep 22, 2025
The Memberlite Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-10125
was published
Sep 17, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover
High
CVE-2025-58430
was published
for
github.com/knadh/listmonk
(Go)
Sep 9, 2025
A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco...
Moderate
Unreviewed
CVE-2025-20342
was published
Aug 27, 2025
The WordPress Automatic Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery...
Moderate
Unreviewed
CVE-2025-6247
was published
Aug 26, 2025
ProTip!
Advisories are also available from the
GraphQL API