GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,344
Erlang
31
GitHub Actions
22
Go
2,115
Maven
5,000+
npm
3,767
NuGet
680
pip
3,454
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,274 advisories
Filter by severity
Stored XSS with custom URLs in PrestaShop module ps_linklist
Moderate
CVE-2020-5273
was published
for
prestashop/ps_linklist
(Composer)
Oct 12, 2021
Cross-site scripting in demos/demo.mysqli.php in getID3
Moderate
CVE-2021-40926
was published
for
james-heinrich/getid3
(Composer)
Oct 4, 2021
Cross-site scripting in application/controllers/dropbox.php in JustWriting
Moderate
CVE-2021-41467
was published
for
hjue/justwriting
(Composer)
Oct 4, 2021
Cross-site Scripting in LaraCMS
Moderate
CVE-2020-20129
was published
for
wanglelecc/laracms
(Composer)
Oct 4, 2021
Cross-site Scripting in GilaCMS
Moderate
CVE-2020-20696
was published
for
gilacms/gila
(Composer)
Sep 30, 2021
Cross-site Scripting in GilaCMS
Moderate
CVE-2020-20695
was published
for
gilacms/gila
(Composer)
Sep 30, 2021
Cross-site Scripting in yourls
Moderate
CVE-2021-3783
was published
for
yourls/yourls
(Composer)
Sep 20, 2021
Cross-site Scripting in yourls
Moderate
CVE-2021-3785
was published
for
yourls/yourls
(Composer)
Sep 20, 2021
Cross-site scripting in ICEcoder
Moderate
CVE-2021-32106
was published
for
icecoder/icecoder
(Composer)
Sep 9, 2021
Cross-site Scripting in LibreNMS
Moderate
CVE-2021-31274
was published
for
librenms/librenms
(Composer)
Sep 9, 2021
Cross-site scripting
Moderate
CVE-2021-32713
was published
for
shopware/shopware
(Composer)
Sep 8, 2021
Cross-site scripting in LavaLite-CMS
Moderate
CVE-2020-23700
was published
for
lavalite/cms
(Composer)
Sep 8, 2021
XSS vulnerability on password reset page
Moderate
CVE-2021-27909
was published
for
mautic/core
(Composer)
Sep 1, 2021
Cross-site Scripting in the femanager TYPO3 extension
Moderate
CVE-2021-36787
was published
for
in2code/femanager
(Composer)
Sep 1, 2021
Cross-site Scripting in the yoast_seo TYPO3 extension
Moderate
CVE-2021-36788
was published
for
yoast-seo-for-typo3/yoast_seo
(Composer)
Sep 1, 2021
Cross Site Scripting in Subrion CMS
Moderate
CVE-2020-22392
was published
for
intelliants/subrion
(Composer)
Sep 1, 2021
Cross-site Scripting in TYPO3 extension
Moderate
CVE-2021-36785
was published
for
miniorange/miniorange-saml
(Composer)
Aug 30, 2021
Cross-site scripting in imgURL
Moderate
CVE-2021-38713
was published
for
helloxz/imgurl
(Composer)
Aug 30, 2021
Cross-site scripting in feehicms
Moderate
CVE-2020-19709
was published
for
feehi/feehicms
(Composer)
Aug 30, 2021
Cross site scripting via HTML attributes in the back end
Moderate
CVE-2021-35955
was published
for
contao/contao
(Composer)
Aug 25, 2021
Cross-Site Scripting via Rich-Text Content
Moderate
CVE-2021-32768
was published
for
typo3/cms
(Composer)
Aug 19, 2021
Cross Site Scripting in LavaLite CMS
Moderate
CVE-2020-23234
was published
for
lavalite/cms
(Composer)
Aug 9, 2021
Cross-Site Scripting in Backend Grid View
Moderate
CVE-2021-32669
was published
for
typo3/cms
(Composer)
Jul 22, 2021
Cross-Site Scripting in Query Generator & Query View
Moderate
CVE-2021-32668
was published
for
typo3/cms
(Composer)
Jul 22, 2021
Cross-Site Scripting in Page Preview
Moderate
CVE-2021-32667
was published
for
typo3/cms
(Composer)
Jul 22, 2021
ProTip!
Advisories are also available from the
GraphQL API