GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,950
Erlang
39
GitHub Actions
38
Go
2,603
Maven
5,000+
npm
4,250
NuGet
755
pip
4,013
Pub
12
RubyGems
953
Rust
1,048
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,096 advisories
Filter by severity
MCMS reflected cross-site scripting (XSS) vulnerability
Moderate
CVE-2025-60837
was published
for
net.mingsoft:ms-mcms
(Maven)
Oct 23, 2025
Piranha CMS vulnerable to stored cross-site scripting (XSS)
Moderate
CVE-2025-61413
was published
for
Piranha
(NuGet)
Oct 23, 2025
Mattermost Server allows XSS via CSRF
Moderate
CVE-2016-11084
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server: Files may be rendered inline instead of downloaded, allowing script execution
Moderate
CVE-2016-11083
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server is vulnerable to XSS through crafted links
Moderate
CVE-2016-11082
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Liferay Portal and Liferay DXP vulnerable to reflected cross-site scripting (XSS)
Moderate
CVE-2025-62248
was published
for
com.liferay:com.liferay.dynamic.data.mapping.web
(Maven)
Oct 22, 2025
Mattermost Server allows XSS via redirect URL
Moderate
CVE-2016-11079
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server is vulnerable to XSS through lack of link relationship attributes `noreferrer` and `noopener`
Moderate
CVE-2016-11071
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server is vulnerable to XSS via a Legal or Support setting
Moderate
CVE-2016-11073
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Mattermost Server is vulnerable to XSS through customizable theme color-code values
Moderate
CVE-2016-11070
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Potential XSS vulnerability in jQuery
Moderate
CVE-2020-11023
was published
for
components/jquery
(RubyGems)
Apr 29, 2020
Liferay Portal reflected cross-site scripting (XSS) vulnerability in the google_gaget
Moderate
CVE-2025-62249
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
Oct 21, 2025
Mattermost Server vulnerable to Cross-site Scripting through file preview feature
Moderate
CVE-2016-11063
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
code16 Sharp vulnerable to Cross Site Scripting (XSS)
Moderate
CVE-2025-61457
was published
for
code16/sharp
(Composer)
Oct 21, 2025
Magento vulnerable to stored Cross-Site Scripting (XSS)
Moderate
CVE-2025-54266
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
Taguette vulnerable to cross-site scripting via tag name, tag description, document name and document description
Moderate
CVE-2025-62528
was published
for
taguette
(pip)
Oct 20, 2025
Cargo Mediawiki Extension vulnerable to Cross-site Scripting
Moderate
CVE-2025-62671
was published
for
mediawiki/cargo
(Composer)
Oct 18, 2025
Citizen vulnerable to stored XSS in sticky header button messages
Moderate
CVE-2025-62508
was published
for
starcitizentools/citizen-skin
(Composer)
Oct 20, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Moderate
GHSA-8c2g-f8jm-5cr7
was published
for
ibexa/fieldtype-richtext
(Composer)
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Moderate
GHSA-2mx6-fq24-g2mh
was published
for
ibexa/admin-ui
(Composer)
Oct 17, 2025
ezsystems/ezplatform-admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Moderate
GHSA-99c7-c3mw-mxhv
was published
for
ezsystems/ezplatform-admin-ui
(Composer)
Oct 17, 2025
Keycloak error_description injection on error pages that can trigger phishing attacks
Moderate
CVE-2025-10044
was published
for
org.keycloak:keycloak-account-ui
(Maven)
Oct 17, 2025
Duplicate Advisory: Keycloak error_description injection on error pages that can trigger phishing attacks
Moderate
GHSA-xmcw-mv9p-7pq2
was published
for
org.keycloak:keycloak-account-ui
(Maven)
Sep 5, 2025
•
withdrawn
bagisto has Cross Site Scripting (XSS) in Create New Customer
Moderate
CVE-2025-62414
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has a Cross Site Scripting (XSS) vulnerability in TinyMCE Image Upload (SVG)
Moderate
CVE-2025-62418
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
ProTip!
Advisories are also available from the
GraphQL API