Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,800 advisories

Loading
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text Moderate
GHSA-8c2g-f8jm-5cr7 was published for ibexa/fieldtype-richtext (Composer) Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal Moderate
GHSA-2mx6-fq24-g2mh was published for ibexa/admin-ui (Composer) Oct 17, 2025
ezsystems/ezplatform-admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal Moderate
GHSA-99c7-c3mw-mxhv was published for ezsystems/ezplatform-admin-ui (Composer) Oct 17, 2025
ibexa/user login enumerates user accounts Moderate
GHSA-q3x8-6898-23g3 was published for ibexa/user (Composer) Oct 17, 2025
bagisto has Cross Site Scripting (XSS) in Create New Customer Moderate
CVE-2025-62414 was published for bagisto/bagisto (Composer) Oct 16, 2025
kiwi865
Credited to kiwi865
bagisto has a Cross Site Scripting (XSS) vulnerability in TinyMCE Image Upload (SVG) Moderate
CVE-2025-62418 was published for bagisto/bagisto (Composer) Oct 16, 2025
kiwi865
Credited to kiwi865
bagisto has Server Side Template Injection (SSTI) in Product Description Moderate
CVE-2025-62416 was published for bagisto/bagisto (Composer) Oct 16, 2025
kiwi865
Credited to kiwi865
bagisto has Cross Site Scripting (XSS) issue in TinyMCE Image Upload (HTML) Moderate
CVE-2025-62415 was published for bagisto/bagisto (Composer) Oct 16, 2025
kiwi865
Credited to kiwi865
Mautic allows Relative Path Traversal in assets file upload Moderate
CVE-2022-25773 was published for mautic/core (Composer) Feb 26, 2025
patrykgruszka majkelstick
escopecz
Credited to patrykgruszka, majkelstick, and escopecz
PrestaShop Checkout Backoffice directory traversal allows arbitrary file disclosure Moderate
CVE-2025-61923 was published for prestashop/ps_checkout (Composer) Oct 16, 2025
iNem0o
Credited to iNem0o
LibreNMS has a Stored XSS vulnerability in its Alert Transport name field Moderate
CVE-2025-62411 was published for librenms/librenms (Composer) Oct 16, 2025
at4111
Credited to at4111
Alt Redirect: Potential Authentication Bypass by Spoofing through query-string stripping logic flaw Moderate
CVE-2025-60868 was published for alt-design/alt-redirect (Composer) Oct 10, 2025
Alt-Ben
Credited to Alt-Ben
LibreNMS is vulnerable to Reflected-XSS in `report_this` function Moderate
CVE-2025-62365 was published for librenms/librenms (Composer) Oct 13, 2025
GatekeeperBuster
Credited to GatekeeperBuster
Kimai API returns timesheet entries a user should not be authorized to view Moderate
CVE-2024-29200 was published for kimai/kimai (Composer) Mar 29, 2024
AstroGD
Credited to AstroGD
Withdrawn Advisory: Bootstrap Cross-Site Scripting (XSS) vulnerability Moderate
CVE-2024-6531 was published for bootstrap (RubyGems) Jul 11, 2024 withdrawn
alexeyNeklesa-idt metametadata
eoftedal
Credited to alexeyNeklesa-idt, metametadata, and eoftedal
Open Web Analytics Server is vulnerable to SQL Injection Moderate
CVE-2025-59397 was published for open-web-analytics/open-web-analytics (Composer) Sep 15, 2025
VaahCMS is vulnerable to XSS through its Avatar Upload endpoint Moderate
CVE-2025-61183 was published for webreinvent/vaahcms (Composer) Oct 8, 2025
Joomla! CMS vulnerable to XSS via the input filter Moderate
CVE-2025-54476 was published for joomla/filter (Composer) Sep 30, 2025
MediaWiki Cargo Extension Cross-site Scripting vulnerability Moderate
CVE-2024-23173 was published for mediawiki/cargo (Composer) Jan 12, 2024
kamalinux
Credited to kamalinux
Snipe-IT allows XSS Moderate
CVE-2025-59712 was published for snipe/snipe-it (Composer) Sep 19, 2025
Snipe-IT allows unsafe deserialization Moderate
CVE-2025-59713 was published for snipe/snipe-it (Composer) Sep 19, 2025
Subrion CMS: Authenticated administrators are able to gain escalated access through Run SQL Query tool Moderate
CVE-2025-56556 was published for intelliants/subrion (Composer) Sep 11, 2025
Withdrawn Advisory: Bootstrap Cross-Site Scripting (XSS) vulnerability Moderate
CVE-2024-6484 was published for bootstrap (RubyGems) Jul 11, 2024 withdrawn
metametadata
Credited to metametadata
YesWiki Cross Site Scripting vulnerability Moderate
CVE-2025-52277 was published for yeswiki/yeswiki (Composer) Sep 9, 2025
TYPO3 CMS uses insufficient entropy when generating passwords Moderate
CVE-2025-59015 was published for typo3/cms-core (Composer) Sep 9, 2025
ProTip! Advisories are also available from the GraphQL API