GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,768
Erlang
35
GitHub Actions
29
Go
2,332
Maven
5,000+
npm
3,965
NuGet
713
pip
3,750
Pub
12
RubyGems
921
Rust
975
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,768 advisories
Filter by severity
Citizen skin vulnerable to stored XSS through multiple system messages
Moderate
CVE-2025-49575
was published
for
starcitizentools/citizen-skin
(Composer)
Jun 11, 2025
HAX CMS vulnerable to Local File Inclusion via saveOutline API Location Parameter
Moderate
CVE-2025-49138
was published
for
elmsln/haxcms
(Composer)
Jun 9, 2025
MantisBT XSS through weak CSP when using Gravatar plugin
Moderate
CVE-2016-7111
was published
for
mantisbt/mantisbt
(Composer)
May 17, 2022
MantisBT XSS via adm_config_report.php's action parameter
Moderate
CVE-2017-6973
was published
for
mantisbt/mantisbt
(Composer)
May 17, 2022
MantisBT XSS via move_attachments_page.php
Moderate
CVE-2017-7241
was published
for
mantisbt/mantisbt
(Composer)
May 17, 2022
Drupal Admin Audit Trail Allocation of Resources Without Limits or Throttling vulnerability
High
CVE-2025-48448
was published
for
drupal/admin_audit_trail
(Composer)
Jun 11, 2025
Drupal Lightgallery Cross-site Scripting vulnerability
Moderate
CVE-2025-48447
was published
for
drupal/lightgallery
(Composer)
Jun 11, 2025
Drupal Quick Node Block Missing Authorization vulnerability
Moderate
CVE-2025-48444
was published
for
drupal/quick_node_block
(Composer)
Jun 11, 2025
Drupal Commerce Alphabank Redirect Incorrect Authorization vulnerability
High
CVE-2025-48446
was published
for
drupal/commerce_alphabank_redirect
(Composer)
Jun 11, 2025
Drupal Commerce Eurobank (Redirect) Incorrect Authorization vulnerability
High
CVE-2025-48445
was published
for
drupal/commerce_eurobank_redirect
(Composer)
Jun 11, 2025
Drupal Quick Node Block Missing Authorization vulnerability
Moderate
CVE-2025-48013
was published
for
drupal/quick_node_block
(Composer)
Jun 11, 2025
MantisBT XSS through crafted SVG documents in file_download.php
Moderate
CVE-2022-33910
was published
for
mantisbt/mantisbt
(Composer)
Jun 25, 2022
MantisBT vulnerable to XSS through config_option parameter in adm_config_report.php
Moderate
CVE-2017-7309
was published
for
mantisbt/mantisbt
(Composer)
May 17, 2022
MantisBT vulnerable to XSS via unsanitized filter field in manage_user_page.php
Moderate
CVE-2017-12062
was published
for
mantisbt/mantisbt
(Composer)
May 17, 2022
MantisBT vulnerable to XSS via unescaped output in browser_search_plugin.php
Moderate
CVE-2022-28508
was published
for
mantisbt/mantisbt
(Composer)
May 5, 2022
MantisBT vulnerable to XSS due to improper escape in manage_plugin_page.php and manage_plugin_uninstall.php
Moderate
CVE-2022-26144
was published
for
mantisbt/mantisbt
(Composer)
Apr 14, 2022
Hax CMS Stored Cross-Site Scripting vulnerability
High
CVE-2025-49137
was published
for
elmsln/haxcms
(Composer)
Jun 9, 2025
MantisBT Insufficient Session Expiration cookie string not reset after logout
High
CVE-2009-20001
was published
for
mantisbt/mantisbt
(Composer)
Apr 21, 2022
Laravel Translation Manager Vulnerable to Stored Cross-site Scripting
Moderate
CVE-2025-49130
was published
for
barryvdh/laravel-translation-manager
(Composer)
Jun 9, 2025
CodeIgniter Session Fixation Vulnerability
Critical
CVE-2018-12071
was published
for
codeigniter/framework
(Composer)
May 14, 2022
Roundcube Webmail Vulnerable to Authenticated RCE via PHP Object Deserialization
Critical
CVE-2025-49113
was published
for
roundcube/roundcubemail
(Composer)
Jun 2, 2025
Yii 2 Redis may expose AUTH parameters in logs in case of connection failure
Moderate
CVE-2025-48493
was published
for
yiisoft/yii2-redis
(Composer)
Jun 5, 2025
laravel-auth0 SDK Deserialization of Untrusted Data vulnerability
Critical
GHSA-c42h-56wx-h85q
was published
for
auth0/login
(Composer)
Jun 6, 2025
Auth0 Symfony SDK Deserialization of Untrusted Data vulnerability
Critical
GHSA-98j6-67v3-mw34
was published
for
auth0/symfony
(Composer)
Jun 6, 2025
Auth0 Wordpress Plugin vulnerable to Deserialization of Untrusted Data
Critical
GHSA-862m-5253-832r
was published
for
auth0/wordpress
(Composer)
Jun 5, 2025
ProTip!
Advisories are also available from the
GraphQL API