GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,373
Erlang
33
GitHub Actions
22
Go
2,135
Maven
5,000+
npm
3,797
NuGet
687
pip
3,478
Pub
12
RubyGems
896
Rust
897
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,506 advisories
Filter by severity
Leantime affected by Improper Neutralization of HTML Tags
Moderate
GHSA-95j3-435g-vjcp
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Cross-Site Request Forgery (CSRF)
Moderate
GHSA-92xh-6x7v-4rmq
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Stored Cross-Site Scripting (XSS)
Moderate
GHSA-63cr-xg3f-8jvr
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Refelected Cross-Site Scripting (XSS)
Moderate
GHSA-52xf-h226-pfgx
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime has Insufficiently Protected Credentials
Moderate
GHSA-h6w8-27ph-c385
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Stored Cross-Site Scripting (XSS)
Moderate
GHSA-mg4c-884j-pcq9
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime has Host Header Injection Vulnerability
Moderate
GHSA-99r5-84gr-59f6
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Remote code execution in alextselegidis/easyappointments
Moderate
CVE-2024-57601
was published
for
alextselegidis/easyappointments
(Composer)
Feb 13, 2025
Stored XSS in REDAXO
Moderate
CVE-2024-13209
was published
for
redaxo/source
(Composer)
Feb 10, 2025
Connect-CMS Access control vulnerability
Moderate
GHSA-5rjc-jc28-cwgg
was published
for
opensource-workshop/connect-cms
(Composer)
Feb 7, 2025
Pimcore Admin Classic Bundle allows user enumeration
Moderate
CVE-2025-24980
was published
for
pimcore/admin-ui-classic-bundle
(Composer)
Feb 7, 2025
Withdrawn Advisory: Sylius allows unrestricted brute-force attacks on user accounts
Moderate
CVE-2024-57610
was published
for
sylius/sylius
(Composer)
Feb 6, 2025
•
withdrawn
Browsershot Local File Inclusion
Moderate
CVE-2025-1026
was published
for
spatie/browsershot
(Composer)
Feb 5, 2025
PhpSpreadsheet allows bypassing of XSS sanitizer using the javascript protocol and special characters
Moderate
CVE-2025-23210
was published
for
phpoffice/phpspreadsheet
(Composer)
Feb 3, 2025
DevDojo Voyager Arbitrary File Write
Moderate
CVE-2024-55417
was published
for
tcg/voyager
(Composer)
Jan 30, 2025
Twig security issue where escaping was missing when using null coalesce operator
Moderate
CVE-2025-24374
was published
for
twig/twig
(Composer)
Jan 29, 2025
TYPO3-EXT-SA-2025-001: Account Takeover in extension "OpenID Connect Authentication" (oidc)
Moderate
CVE-2025-24856
was published
for
causal/oidc
(Composer)
Jan 28, 2025
pimcore/customer-data-framework vulnerable to SQL Injection
Moderate
CVE-2024-11956
was published
for
pimcore/customer-management-framework-bundle
(Composer)
Jan 28, 2025
Duplicate Advisory: pimcore/customer-data-framework vulnerable to SQL Injection: Hibernate
Moderate
GHSA-8m8m-98c9-vw7q
was published
for
pimcore/customer-data-framework
(Composer)
Jan 28, 2025
•
withdrawn
phpMyAdmin XSS when checking tables
Moderate
CVE-2025-24530
was published
for
phpmyadmin/phpmyadmin
(Composer)
Jan 23, 2025
ps_contactinfo has a potential XSS due to usage of the nofilter tag in template
Moderate
CVE-2025-24027
was published
for
prestashop/ps_contactinfo
(Composer)
Jan 22, 2025
Missing validation of header name and value in codeigniter4/framework
Moderate
CVE-2025-24013
was published
for
codeigniter4/framework
(Composer)
Jan 21, 2025
Cross-Site Scripting (XSS) vulnerability in generateNavigation() function in PhpSpreadsheet
Moderate
CVE-2025-22131
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 21, 2025
Librenms has a reflected XSS on error alert
Moderate
CVE-2025-23201
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
LibreNMS Misc Section Stored Cross-site Scripting vulnerability
Moderate
CVE-2025-23200
was published
for
librenms/librenms
(Composer)
Jan 16, 2025
ProTip!
Advisories are also available from the
GraphQL API