GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,662
Maven
5,000+
npm
4,289
NuGet
760
pip
4,069
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
247 advisories
Filter by severity
A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in...
Moderate
Unreviewed
CVE-2025-58412
was published
Nov 19, 2025
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-11267
was published
Nov 18, 2025
The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-11265
was published
Nov 18, 2025
A Stored Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop...
Moderate
Unreviewed
CVE-2025-54348
was published
Nov 14, 2025
The Chart Expert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-12753
was published
Nov 11, 2025
The Slippy Slider – Responsive Touch Navigation Slider plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-11874
was published
Nov 11, 2025
IBM OpenPages 9.1, and 9.0 with Watson is vulnerable to HTML injection. A remote attacker could...
Moderate
Unreviewed
CVE-2025-33110
was published
Nov 6, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-49398
was published
Nov 6, 2025
The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2025-11745
was published
Nov 5, 2025
The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-11987
was published
Nov 5, 2025
OctoPrint vulnerable to XSS in Action Commands Notification and Prompt
Moderate
CVE-2025-64187
was published
for
octoprint
(pip)
Nov 4, 2025
IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker...
Moderate
Unreviewed
CVE-2025-36121
was published
Oct 27, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-62936
was published
Oct 27, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-62897
was published
Oct 27, 2025
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution...
Moderate
Unreviewed
CVE-2025-11823
was published
Oct 25, 2025
The Multi Item Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery...
Moderate
Unreviewed
CVE-2025-11992
was published
Oct 24, 2025
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-58970
was published
Oct 22, 2025
bagisto has Cross Site Scripting (XSS) in Create New Customer
Moderate
CVE-2025-62414
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has a Cross Site Scripting (XSS) vulnerability in TinyMCE Image Upload (SVG)
Moderate
CVE-2025-62418
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has Cross Site Scripting (XSS) issue in TinyMCE Image Upload (HTML)
Moderate
CVE-2025-62415
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-11160
was published
Oct 15, 2025
The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-11161
was published
Oct 15, 2025
HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could...
Moderate
Unreviewed
CVE-2025-31992
was published
Oct 12, 2025
A vulnerability in HCL HCL MyXalytics allows HTML InjectionThis issue affects HCL MyXalytics: 6.6.
Moderate
Unreviewed
CVE-2025-52654
was published
Oct 3, 2025
The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in...
Moderate
Unreviewed
CVE-2025-11241
was published
Oct 3, 2025
ProTip!
Advisories are also available from the
GraphQL API