GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,411
Erlang
33
GitHub Actions
22
Go
2,146
Maven
5,000+
npm
3,808
NuGet
687
pip
3,481
Pub
12
RubyGems
897
Rust
899
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,519 advisories
Filter by severity
Formwork has a cross-site scripting (XSS) vulnerability in Site title
Moderate
GHSA-vf6x-59hh-332f
was published
for
getformwork/formwork
(Composer)
Mar 1, 2025
Silverstripe Flash Clipboard Reflected XSS
Moderate
CVE-2019-12205
was published
for
silverstripe/admin
(Composer)
May 24, 2022
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24437
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24435
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24436
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24427
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento stored Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-24428
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24424
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Business Logic Error vulnerability
Moderate
CVE-2025-24425
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Incorrect Authorization vulnerability
Moderate
CVE-2025-24421
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Information Exposure vulnerability
Moderate
CVE-2025-24408
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Mautic allows Relative Path Traversal in assets file upload
Moderate
CVE-2022-25773
was published
for
mautic/core
(Composer)
Feb 26, 2025
Carbon has an arbitrary file include via unvalidated input passed to Carbon::setLocale
Moderate
CVE-2025-22145
was published
for
nesbot/carbon
(Composer)
Jan 8, 2025
MediaWiki UnlinkedWikibase Cross-site Scripting vulnerability
Moderate
CVE-2024-34500
was published
for
samwilson/unlinked-wikibase
(Composer)
May 5, 2024
Moodle's feedback response viewing and deletions did not respect Separate Groups mode
Moderate
CVE-2025-26526
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle's non-searchable tags can still be discovered on the tag search page and in the tags block
Moderate
CVE-2025-26527
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Leantime affected by Improper Neutralization of HTML Tags
Moderate
GHSA-95j3-435g-vjcp
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Cross-Site Request Forgery (CSRF)
Moderate
GHSA-92xh-6x7v-4rmq
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Stored Cross-Site Scripting (XSS)
Moderate
GHSA-63cr-xg3f-8jvr
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Refelected Cross-Site Scripting (XSS)
Moderate
GHSA-52xf-h226-pfgx
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime has Insufficiently Protected Credentials
Moderate
GHSA-h6w8-27ph-c385
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Stored Cross-Site Scripting (XSS)
Moderate
GHSA-mg4c-884j-pcq9
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime has Host Header Injection Vulnerability
Moderate
GHSA-99r5-84gr-59f6
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Mautic has insufficient authentication in upgrade flow
Moderate
CVE-2022-25770
was published
for
mautic/core
(Composer)
Sep 18, 2024
The Preview plugin in CKEditor allows Cross-site scripting (XSS)
Moderate
CVE-2014-5191
was published
for
ckeditor/ckeditor
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API