GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,950
Erlang
39
GitHub Actions
38
Go
2,603
Maven
5,000+
npm
4,250
NuGet
755
pip
4,013
Pub
12
RubyGems
953
Rust
1,048
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
29,825 advisories
Filter by severity
The The7 — Website and eCommerce Builder for WordPress theme for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-11897
was published
Oct 25, 2025
The Fast Velocity Minify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-12034
was published
Oct 25, 2025
The SpendeOnline.org plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-11875
was published
Oct 25, 2025
The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-10580
was published
Oct 25, 2025
The Testimonial Carousel For Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-8666
was published
Oct 25, 2025
The Listeo theme for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ...
Moderate
Unreviewed
CVE-2025-8413
was published
Oct 25, 2025
The Gutenberg Blocks – PublishPress Blocks plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2025-8588
was published
Oct 25, 2025
The Open Source Genesis Framework theme for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-10737
was published
Oct 25, 2025
Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability...
Moderate
Unreviewed
CVE-2025-60936
was published
Oct 24, 2025
SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try...
Moderate
Unreviewed
CVE-2025-5350
was published
Oct 24, 2025
The VNPAY Payment gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-12017
was published
Oct 24, 2025
The Simple Excel Pricelist for WooCommerce plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2025-12096
was published
Oct 24, 2025
The qnotsquiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-12016
was published
Oct 24, 2025
The Time Clock – A WordPress Employee & Volunteer Time Clock Plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2025-10701
was published
Oct 24, 2025
Pleasanter contains a stored cross-site scripting vulnerability in Preview for Attachments, which...
Moderate
Unreviewed
CVE-2025-58070
was published
Oct 24, 2025
The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation...
Moderate
Unreviewed
CVE-2025-9158
was published
Oct 24, 2025
Pleasanter contains a stored cross-site scripting vulnerability in Body, Description and Comments...
Moderate
Unreviewed
CVE-2025-61931
was published
Oct 24, 2025
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-7730
was published
Oct 24, 2025
Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to...
Moderate
Unreviewed
CVE-2025-60859
was published
Oct 23, 2025
Cross site scripting (XSS) vulnerability in 17gz International Student service system 1.0 allows...
Moderate
Unreviewed
CVE-2025-57240
was published
Oct 23, 2025
The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2025-8427
was published
Oct 23, 2025
Vilar VS-IPC1002 IP cameras are vulnerable to Reflected XSS (Cross-site Scripting) attacks,...
Moderate
Unreviewed
CVE-2025-53701
was published
Oct 23, 2025
Cross site scripting (XSS) vulnerability in KeeneticOS before 4.3 at "Wireless ISP" page allows...
Moderate
Unreviewed
CVE-2025-56008
was published
Oct 23, 2025
Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an...
Moderate
Unreviewed
CVE-2025-1679
was published
Oct 23, 2025
QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form)....
Moderate
Unreviewed
CVE-2025-9980
was published
Oct 23, 2025
ProTip!
Advisories are also available from the
GraphQL API