GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,706
Erlang
34
GitHub Actions
28
Go
2,292
Maven
5,000+
npm
3,942
NuGet
708
pip
3,711
Pub
12
RubyGems
919
Rust
959
Swift
38
Unreviewed advisories
All unreviewed
5,000+
273 advisories
Filter by severity
TYPO3 Unverified Password Change for Backend Users
Low
CVE-2025-47938
was published
for
typo3/cms-core
(Composer)
May 20, 2025
TYPO3 Allows Information Disclosure via DBAL Restriction Handling
Low
CVE-2025-47937
was published
for
typo3/cms-core
(Composer)
May 20, 2025
TYPO3 CMS Webhooks Server Side Request Forgery
Low
CVE-2025-47936
was published
for
typo3/cms-webhooks
(Composer)
May 20, 2025
LibreNMS stored Cross-site Scripting vulnerability in poller group name
Low
CVE-2025-47931
was published
for
librenms/librenms
(Composer)
May 19, 2025
Kirby vulnerable to path traversal in the router for PHP's built-in server
Low
CVE-2025-30207
was published
for
getkirby/cms
(Composer)
May 13, 2025
October CMS Allows Unprotected SVG Rename in Media Manager
Low
CVE-2024-51991
was published
for
october/october
(Composer)
May 5, 2025
Yeswiki Vulnerable to Authenticated Reflected Cross-site Scripting
Low
CVE-2025-46350
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
YesWiki Stored XSS Vulnerability in Comments
Low
CVE-2025-46346
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
Drupal Formatter Suite Vulnerable to Cross-Site Scripting (XSS) via Link Element Attributes
Low
CVE-2025-31697
was published
for
drupal/formatter_suite
(Composer)
Apr 1, 2025
Drupal RapiDoc OAS Field Formatter Cross-Site Scripting (XSS) vulnerability
Low
CVE-2025-31696
was published
for
drupal/rapidoc_elements_field_formatter
(Composer)
Apr 1, 2025
Drupal Link field display mode formatter Cross-Site Scripting (XSS) vulnerability
Low
CVE-2025-31695
was published
for
drupal/link_field_display_mode_formatter
(Composer)
Apr 1, 2025
Drupal Configuration Split Cross-Site Request Forgery (CSRF) vulnerability
Low
CVE-2025-31688
was published
for
drupal/config_split
(Composer)
Apr 1, 2025
Drupal SpamSpan Cross-Site Scripting (XSS) vulnerability
Low
CVE-2025-31687
was published
for
drupal/spamspan
(Composer)
Apr 1, 2025
Drupal OAuth2 Client Cross-Site Request Forgery (CSRF)
Low
CVE-2025-31684
was published
for
drupal/oauth2_client
(Composer)
Apr 1, 2025
Drupal Matomo Analytics Cross-Site Request Forgery (CSRF) vulnerability
Low
CVE-2025-31680
was published
for
drupal/matomo
(Composer)
Apr 1, 2025
Drupal Core Cross-Site Scripting (XSS) Vulnerability
Low
CVE-2025-31675
was published
for
drupal/core
(Composer)
Apr 1, 2025
Moodle has a CSRF risk in Brickfield tool's analysis request action
Low
CVE-2025-3638
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle's mod_data edit/delete pages pass CSRF token in GET parameter
Low
CVE-2025-3637
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has a CSRF risk in user tours manager that allows tour duplication
Low
CVE-2025-3635
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Duplicate Advisory: Contao allows admin an account to upload SVG file containing malicious JavaScript
Low
CVE-2024-45965
was published
for
contao/contao
(Composer)
Oct 2, 2024
•
withdrawn
concrete5 vulnerable to Cross-site Scripting
Low
CVE-2015-3989
was published
for
concrete5/concrete5
(Composer)
May 17, 2022
WEC Map (wec_map) extension for TYPO3 allows Cross-site Scripting
Low
CVE-2014-6296
was published
for
jbartels/wec-map
(Composer)
May 17, 2022
Joomla! Cross-site Scripting vulnerability
Low
CVE-2013-5583
was published
for
joomla/joomla-cms
(Composer)
May 17, 2022
Static Info Tables (static_info_tables) extension TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2013-5323
was published
for
sjbr/static-info-tables
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API