GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
5,067 advisories
Filter by severity
ezsystems/ezplatform-admin-ui has an XSS vulnerability in Cancel/Reschedule future publication modal
Moderate
GHSA-99c7-c3mw-mxhv
was published
for
ezsystems/ezplatform-admin-ui
(Composer)
Oct 17, 2025
ibexa/user login enumerates user accounts
Moderate
GHSA-q3x8-6898-23g3
was published
for
ibexa/user
(Composer)
Oct 17, 2025
bagisto has Cross Site Scripting (XSS) in Create New Customer
Moderate
CVE-2025-62414
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has CSV Formula Injection in Create New Product
Critical
CVE-2025-62417
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has a Cross Site Scripting (XSS) vulnerability in TinyMCE Image Upload (SVG)
Moderate
CVE-2025-62418
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has Server Side Template Injection (SSTI) in Product Description
Moderate
CVE-2025-62416
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
LibreNMS alert-rules has a Cross-Site Scripting Vulnerability
Low
CVE-2025-62412
was published
for
librenms/librenms
(Composer)
Oct 16, 2025
PrestaShop Checkout Target PayPal merchant account hijacking from backoffice
Low
CVE-2025-61924
was published
for
prestashop/ps_checkout
(Composer)
Oct 16, 2025
PrestaShop Checkout Backoffice directory traversal allows arbitrary file disclosure
Moderate
CVE-2025-61923
was published
for
prestashop/ps_checkout
(Composer)
Oct 16, 2025
PrestaShop Checkout allows customer account takeover via email
Critical
CVE-2025-61922
was published
for
prestashop/ps_checkout
(Composer)
Oct 16, 2025
bagisto has Cross Site Scripting (XSS) issue in TinyMCE Image Upload (HTML)
Moderate
CVE-2025-62415
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
LibreNMS has a Stored XSS vulnerability in its Alert Transport name field
Moderate
CVE-2025-62411
was published
for
librenms/librenms
(Composer)
Oct 16, 2025
Magento allows incorrect authorization
Moderate
CVE-2025-54265
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
Magento provides incorrect authorization through a security feature bypass
High
CVE-2025-54263
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
Magento vulnerable to stored Cross-Site Scripting (XSS)
High
CVE-2025-54264
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
Magento vulnerable to privilege escalation due to incorrect authorization
Moderate
CVE-2025-54267
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
Magento vulnerable to stored Cross-Site Scripting (XSS)
Moderate
CVE-2025-54266
was published
for
magento/community-edition
(Composer)
Oct 14, 2025
LibreNMS is vulnerable to Reflected-XSS in `report_this` function
Moderate
CVE-2025-62365
was published
for
librenms/librenms
(Composer)
Oct 13, 2025
Bagisto is vulnerable to XSS through Admin Panel's product creation path
High
CVE-2025-60880
was published
for
bagisto/bagisto
(Composer)
Oct 10, 2025
Alt Redirect: Potential Authentication Bypass by Spoofing through query-string stripping logic flaw
Moderate
CVE-2025-60868
was published
for
alt-design/alt-redirect
(Composer)
Oct 10, 2025
drupal-pattern-lab/unified-twig-extensions is vulnerable to XXS
Low
CVE-2025-11570
was published
for
drupal-pattern-lab/unified-twig-extensions
(Composer)
Oct 10, 2025
VaahCMS is vulnerable to XSS through its Avatar Upload endpoint
Moderate
CVE-2025-61183
was published
for
webreinvent/vaahcms
(Composer)
Oct 8, 2025
Melis Platform CMS Unauthenticated File Upload Leading to RCE
Critical
CVE-2025-10353
was published
for
melisplatform/melis-cms-slider
(Composer)
Oct 8, 2025
Melis Platform CMS SQL Injection
Critical
CVE-2025-10351
was published
for
melisplatform/melis-cms
(Composer)
Oct 8, 2025
Melis Platform CMS Unauthenticated Admin Account Creation
Critical
CVE-2025-10352
was published
for
melisplatform/melis-core
(Composer)
Oct 8, 2025
ProTip!
Advisories are also available from the
GraphQL API