GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
38,274 advisories
Filter by severity
The WP Bootstrap Tabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-11822
was published
Nov 11, 2025
The Magazine Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-11828
was published
Nov 11, 2025
Due to a Reflected Cross-Site Scripting (XSS) vulnerability in SAP Business Connector, an...
Moderate
Unreviewed
CVE-2025-42886
was published
Nov 11, 2025
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that...
High
Unreviewed
CVE-2025-11892
was published
Nov 11, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-53286
was published
Nov 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49390
was published
Nov 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-31029
was published
Nov 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-53245
was published
Nov 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-53239
was published
Nov 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49909
was published
Nov 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-53574
was published
Nov 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-53324
was published
Nov 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-53349
was published
Nov 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-52764
was published
Nov 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49904
was published
Nov 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49905
was published
Nov 6, 2025
Duplicate Advisory: ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values
High
GHSA-vfpf-xmwh-8m65
was published
for
prosemirror_to_html
(RubyGems)
Nov 7, 2025
•
withdrawn
Lack of Input Validation in the web UI might lead to potential exploitation.This issue affects...
Moderate
Unreviewed
CVE-2025-12284
was published
Oct 26, 2025
Cross Site Scripting (XSS) vulnerability stored in SOPlanning v1.53.02, which consist of a stored...
Moderate
Unreviewed
CVE-2025-41001
was published
Nov 10, 2025
Stored Cross Site Scripting (XSS) vulnerability in Smart School 7.0 due to lack of proper...
Moderate
Unreviewed
CVE-2025-41107
was published
Nov 10, 2025
A flaw has been found in qianfox FoxCMS up to 1.2.16. Affected by this vulnerability is the...
Moderate
Unreviewed
CVE-2025-12920
was published
Nov 10, 2025
The Saphali LiqPay for donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-12643
was published
Nov 8, 2025
The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-12837
was published
Nov 8, 2025
The WP2Social Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-12064
was published
Nov 8, 2025
The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to Stored...
Moderate
Unreviewed
CVE-2025-12112
was published
Nov 8, 2025
ProTip!
Advisories are also available from the
GraphQL API