GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,081
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
505 advisories
Filter by severity
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
High
CVE-2025-64495
was published
for
open-webui
(npm)
Nov 7, 2025
OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization
High
CVE-2025-66021
was published
for
com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer
(Maven)
Nov 25, 2025
Astro vulnerable to reflected XSS via the server islands feature
High
CVE-2025-64764
was published
for
astro
(npm)
Nov 19, 2025
Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values
High
CVE-2025-64501
was published
for
prosemirror_to_html
(RubyGems)
Nov 6, 2025
Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global variable
High
CVE-2025-59840
was published
for
vega
(npm)
Nov 13, 2025
ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values
High
GHSA-4249-gjr8-jpq3
was published
for
prosemirror_to_html
(RubyGems)
Nov 13, 2025
Duplicate Advisory: ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values
High
GHSA-vfpf-xmwh-8m65
was published
for
prosemirror_to_html
(RubyGems)
Nov 7, 2025
•
withdrawn
Magento DOM-based Cross-Site Scripting (XSS) vulnerability
High
CVE-2024-39400
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento Stored Cross-Site Scripting (XSS) vulnerability
High
CVE-2024-39403
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Jenkins Applitools Eyes Plugin vulnerable to XSS through its Build page
High
CVE-2025-53658
was published
for
org.jenkins-ci.plugins:applitools-eyes
(Maven)
Jul 9, 2025
Pimcore Authenticated Stored Cross-Site Scripting (XSS) Via Search Document
High
CVE-2024-11954
was published
for
pimcore/pimcore
(Composer)
Jan 28, 2025
smarty Cross-site Scripting vulnerability in Javascript escaping
High
CVE-2023-28447
was published
for
smarty/smarty
(Composer)
Mar 29, 2023
DOMpurify has a nesting-based mXSS
High
CVE-2024-47875
was published
for
dompurify
(npm)
Oct 11, 2024
Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validation
High
CVE-2025-64112
was published
for
statamic/cms
(Composer)
Oct 30, 2025
Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
High
CVE-2025-59837
was published
for
astro
(npm)
Oct 28, 2025
Magento vulnerable to stored Cross-Site Scripting (XSS)
High
CVE-2025-54264
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
High
CVE-2025-62172
was published
for
homeassistant
(pip)
Oct 14, 2025
Cross-site Scripting (XSS) in @scullyio/scully
High
CVE-2020-28470
was published
for
@scullyio/ng-lib
(npm)
Apr 13, 2021
Bagisto is vulnerable to XSS through Admin Panel's product creation path
High
CVE-2025-60880
was published
for
bagisto/bagisto
(Composer)
Oct 10, 2025
pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
High
CVE-2025-61773
was published
for
pyload-ng
(pip)
Oct 9, 2025
Duplicate Advisory: Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
High
GHSA-7rgr-72hp-9wp3
was published
for
flowise
(npm)
Oct 6, 2025
•
withdrawn
Duplicate Advisory: Flowise Stored XSS vulnerability through logs in chatbot
High
GHSA-wq95-wr7m-26h4
was published
for
flowise
(npm)
Oct 6, 2025
•
withdrawn
MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server
High
CVE-2025-58444
was published
for
@modelcontextprotocol/inspector
(npm)
Sep 8, 2025
Star Citizen EmbedVideo Extension Stored XSS through wikitext caused by usage of non-reserved data attributes
High
CVE-2025-59839
was published
for
starcitizenwiki/embedvideo
(Composer)
Sep 24, 2025
Mesh Connect JS SDK Vulnerable to Cross Site Scripting via createLink.openLink
High
CVE-2025-59430
was published
for
@meshconnect/web-link-sdk
(npm)
Sep 22, 2025
ProTip!
Advisories are also available from the
GraphQL API