GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,911
Erlang
39
GitHub Actions
38
Go
2,569
Maven
5,000+
npm
4,245
NuGet
754
pip
4,006
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
10,771 advisories
Filter by severity
Taguette vulnerable to cross-site scripting via tag name, tag description, document name and document description
Moderate
CVE-2025-62528
was published
for
taguette
(pip)
Oct 20, 2025
Uptime Kuma Server-side Template Injection (SSTI) in Notification Templates Allows Arbitrary File Read
Moderate
GHSA-vffh-c9pq-4crh
was published
for
uptime-kuma
(npm)
Oct 20, 2025
vite allows server.fs.deny bypass via backslash on Windows
Moderate
CVE-2025-62522
was published
for
vite
(npm)
Oct 20, 2025
Actual Sync-server Gocardless service is logging sensitive data including bearer tokens and account numbers
Moderate
GHSA-xvp7-8vm8-xfxx
was published
for
@actual-app/sync-server
(npm)
Oct 20, 2025
Citizen vulnerable to stored XSS in sticky header button messages
Moderate
CVE-2025-62508
was published
for
starcitizentools/citizen-skin
(Composer)
Oct 20, 2025
Cargo Mediawiki Extension vulnerable to Cross-site Scripting
Moderate
CVE-2025-62671
was published
for
mediawiki/cargo
(Composer)
Oct 18, 2025
ibexa/fieldtype-richtext has an XSS vulnerability via acronym custom tag in Rich Text
Moderate
GHSA-8c2g-f8jm-5cr7
was published
for
ibexa/fieldtype-richtext
(Composer)
Oct 17, 2025
ibexa/admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Moderate
GHSA-2mx6-fq24-g2mh
was published
for
ibexa/admin-ui
(Composer)
Oct 17, 2025
ezsystems/ezplatform-admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Moderate
GHSA-99c7-c3mw-mxhv
was published
for
ezsystems/ezplatform-admin-ui
(Composer)
Oct 17, 2025
ibexa/user login enumerates user accounts
Moderate
GHSA-q3x8-6898-23g3
was published
for
ibexa/user
(Composer)
Oct 17, 2025
Keycloak error_description injection on error pages that can trigger phishing attacks
Moderate
CVE-2025-10044
was published
for
org.keycloak:keycloak-account-ui
(Maven)
Oct 17, 2025
Mammoth is vulnerable to Directory Traversal
Moderate
CVE-2025-11849
was published
for
Mammoth
(Maven)
Oct 17, 2025
bagisto has Cross Site Scripting (XSS) in Create New Customer
Moderate
CVE-2025-62414
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has a Cross Site Scripting (XSS) vulnerability in TinyMCE Image Upload (SVG)
Moderate
CVE-2025-62418
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has Server Side Template Injection (SSTI) in Product Description
Moderate
CVE-2025-62416
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
PrestaShop Checkout Backoffice directory traversal allows arbitrary file disclosure
Moderate
CVE-2025-61923
was published
for
prestashop/ps_checkout
(Composer)
Oct 16, 2025
Strapi core vulnerable to sensitive data exposure via CORS misconfiguration
Moderate
CVE-2025-53092
was published
for
@strapi/core
(npm)
Oct 16, 2025
Strapi Password Hashing Missing Maximum Password Length Validation
Moderate
CVE-2025-25298
was published
for
@strapi/core
(npm)
Oct 16, 2025
Smidge is vulnerable to Path Traversal
Moderate
CVE-2025-11842
was published
for
Smidge
(NuGet)
Oct 16, 2025
bagisto has Cross Site Scripting (XSS) issue in TinyMCE Image Upload (HTML)
Moderate
CVE-2025-62415
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
LibreNMS has a Stored XSS vulnerability in its Alert Transport name field
Moderate
CVE-2025-62411
was published
for
librenms/librenms
(Composer)
Oct 16, 2025
Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
Moderate
CVE-2025-41254
was published
for
org.springframework:spring-websocket
(Maven)
Oct 16, 2025
Strapi is vulnerable to Insufficient Session Expiration
Moderate
CVE-2025-3930
was published
for
@strapi/strapi
(npm)
Oct 16, 2025
Mattermost has a Missing Authorization vulnerability
Moderate
CVE-2025-41410
was published
for
github.com/mattermost/mattermost-server
(Go)
Oct 16, 2025
Mattermost has a Missing Authorization vulnerability
Moderate
CVE-2025-41443
was published
for
github.com/mattermost/mattermost-server
(Go)
Oct 16, 2025
ProTip!
Advisories are also available from the
GraphQL API