GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,714
Erlang
34
GitHub Actions
28
Go
2,301
Maven
5,000+
npm
3,942
NuGet
711
pip
3,711
Pub
12
RubyGems
920
Rust
960
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,714 advisories
Filter by severity
Drupal Matomo Analytics Cross-Site Request Forgery (CSRF) vulnerability
Low
CVE-2025-31680
was published
for
drupal/matomo
(Composer)
Apr 1, 2025
Drupal Ignition Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-31679
was published
for
drupal/ignition
(Composer)
Apr 1, 2025
Drupal Open Social Missing Authorization vulnerability
High
CVE-2025-31686
was published
for
goalgorilla/open_social
(Composer)
Apr 1, 2025
Drupal OAuth2 Client Cross-Site Request Forgery (CSRF)
Low
CVE-2025-31684
was published
for
drupal/oauth2_client
(Composer)
Apr 1, 2025
Drupal Cache Utility Cross-Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2025-31690
was published
for
drupal/cache_utility
(Composer)
Apr 1, 2025
Drupal Open Social Missing Authorization vulnerability
Moderate
CVE-2025-31685
was published
for
goalgorilla/open_social
(Composer)
Apr 1, 2025
Drupal Authenticator Login Missing Authorization vulnerability
High
CVE-2025-31681
was published
for
drupal/alogin
(Composer)
Apr 1, 2025
Drupal Google Tag Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-31682
was published
for
drupal/google_tag
(Composer)
Apr 1, 2025
Drupal SpamSpan Cross-Site Scripting (XSS) vulnerability
Low
CVE-2025-31687
was published
for
drupal/spamspan
(Composer)
Apr 1, 2025
Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability
Moderate
CVE-2025-31674
was published
for
drupal/core
(Composer)
Apr 1, 2025
Drupal AI Missing Authorization vulnerability
Moderate
CVE-2025-31678
was published
for
drupal/ai
(Composer)
Apr 1, 2025
Drupal Core Vulnerable to Forceful Browsing
Moderate
CVE-2025-31673
was published
for
drupal/core
(Composer)
Apr 1, 2025
Drupal AI Cross-Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2025-31677
was published
for
drupal/ai
(Composer)
Apr 1, 2025
Drupal Core Cross-Site Scripting (XSS) Vulnerability
Low
CVE-2025-31675
was published
for
drupal/core
(Composer)
Apr 1, 2025
ConcreteCMS Cross-Site Scripting (XSS) via HTML Block Text Field
Moderate
CVE-2025-2967
was published
for
concrete5/concrete5
(Composer)
Mar 31, 2025
ShopXO Vulnerable to Server-Side Request Forgery (SSRF) via Image Upload
Moderate
CVE-2025-28092
was published
for
shopxo/shopxo
(Composer)
Mar 29, 2025
ShopXO Vulnerable to Server-Side Request Forgery (SSRF) and Cross-Site Scripting (XSS)
Moderate
CVE-2025-28094
was published
for
shopxo/shopxo
(Composer)
Mar 29, 2025
ShopXO Vulnerable to Server-Side Request Forgery (SSRF) via Email Settings
Moderate
CVE-2025-28093
was published
for
shopxo/shopxo
(Composer)
Mar 29, 2025
Duplicate Advisory: Leantime affected by Improper Neutralization of HTML Tags
Moderate
GHSA-jf6p-4hgv-v6qh
was published
for
leantime/leantime
(Composer)
Mar 28, 2025
•
withdrawn
wp-svg-upload WordPress plugin vulnerable to Stored Cross-site Scripting
Moderate
CVE-2024-11847
was published
for
digimix/wp-svg-upload
(Composer)
Mar 26, 2025
Pixelfed may allow unauthorized actor to view private posts and private users
Moderate
CVE-2025-30741
was published
for
pixelfed/pixelfed
(Composer)
Mar 25, 2025
API Platform Core does not call GraphQl securityAfterResolver
Moderate
CVE-2025-23204
was published
for
api-platform/core
(Composer)
Mar 24, 2025
yiisoft Yii2 Deserialization of Untrusted Data
Moderate
CVE-2025-2689
was published
for
yiisoft/yii2-dev
(Composer)
Mar 24, 2025
Sylius PayPal Plugin has an Order Manipulation Vulnerability after PayPal Checkout
Moderate
CVE-2025-30152
was published
for
sylius/paypal-plugin
(Composer)
Mar 19, 2025
Clickstorm SEO Allows Cross-Site Scripting (XSS)
Moderate
CVE-2025-30081
was published
for
clickstorm/cs-seo
(Composer)
Mar 19, 2025
ProTip!
Advisories are also available from the
GraphQL API