GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
38,271 advisories
Filter by severity
The Flickr Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-12672
was published
Nov 11, 2025
The Featured Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via image...
Moderate
Unreviewed
CVE-2025-12019
was published
Nov 11, 2025
The Five9 Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-11829
was published
Nov 11, 2025
The Nonaki – Drag and Drop Email Template builder and Newsletter plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-12644
was published
Nov 11, 2025
The Ungapped Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-12652
was published
Nov 11, 2025
The Share to Google Classroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-12711
was published
Nov 11, 2025
The Live Photos on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-12651
was published
Nov 11, 2025
The Progress Bar Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-12880
was published
Nov 11, 2025
The My Geo Posts Free plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-11863
was published
Nov 11, 2025
The Include Fussball.de Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-11129
was published
Nov 11, 2025
The WP BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
Moderate
Unreviewed
CVE-2025-11873
was published
Nov 11, 2025
The Simple Donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-11882
was published
Nov 11, 2025
The Woocommerce – Products By Custom Tax plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-11821
was published
Nov 11, 2025
The Precise Columns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-11869
was published
Nov 11, 2025
The Skip to Timestamp plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-11805
was published
Nov 11, 2025
The Paypal Donation Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-11859
was published
Nov 11, 2025
The WP-OAuth plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-12021
was published
Nov 11, 2025
The Twitter Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-11860
was published
Nov 11, 2025
The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-11822
was published
Nov 11, 2025
The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-11828
was published
Nov 11, 2025
Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an...
Moderate
Unreviewed
CVE-2025-42886
was published
Nov 11, 2025
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that...
High
Unreviewed
CVE-2025-11892
was published
Nov 11, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-53286
was published
Nov 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49390
was published
Nov 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-31029
was published
Nov 6, 2025
ProTip!
Advisories are also available from the
GraphQL API