GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
145,439 advisories
Filter by severity
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-14442
was published
Dec 12, 2025
The Magical Posts Display plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-12965
was published
Dec 12, 2025
The Secure Copy Content Protection and Content Locking plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-14159
was published
Dec 12, 2025
The AI Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-14030
was published
Dec 12, 2025
The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-13993
was published
Dec 12, 2025
The Simple Bike Rental plugin for WordPress is vulnerable to unauthorized access of data due to a...
Moderate
Unreviewed
CVE-2025-14065
was published
Dec 12, 2025
The PDF for Contact Form 7 + Drag and Drop Template Builder plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-14074
was published
Dec 12, 2025
The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for...
Moderate
Unreviewed
CVE-2025-12348
was published
Dec 12, 2025
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-12407
was published
Dec 12, 2025
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-12408
was published
Dec 12, 2025
The Bookit WordPress plugin before 2.5.1 has a publicly accessible REST endpoint that allows...
Moderate
Unreviewed
CVE-2025-12841
was published
Dec 12, 2025
The Simple CSV Table plugin for WordPress is vulnerable to Directory Traversal in all versions up...
Moderate
Unreviewed
CVE-2025-12960
was published
Dec 12, 2025
The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to unauthorized access of...
Moderate
Unreviewed
CVE-2025-14356
was published
Dec 12, 2025
The Guest Support plugin for WordPress is vulnerable to User Email Disclosure in versions up to,...
Moderate
Unreviewed
CVE-2025-13660
was published
Dec 12, 2025
The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to Path...
Moderate
Unreviewed
CVE-2025-13891
was published
Dec 12, 2025
The VikRentItems Flexible Rental Management System plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-14049
was published
Dec 12, 2025
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to arbitrary file write...
Moderate
Unreviewed
CVE-2025-12655
was published
Dec 12, 2025
The Mailgun Subscriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-11876
was published
Dec 12, 2025
The BSK PDF Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG...
Moderate
Unreviewed
CVE-2025-4970
was published
Dec 12, 2025
The WP Job Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all...
Moderate
Unreviewed
CVE-2025-14467
was published
Dec 12, 2025
The Ayo Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-14143
was published
Dec 12, 2025
The Kirim.Email WooCommerce Integration plugin for WordPress is vulnerable to Cross-Site Request...
Moderate
Unreviewed
CVE-2025-14165
was published
Dec 12, 2025
The Vimeo SimpleGallery plugin for WordPress is vulnerable to Missing Authorization in all...
Moderate
Unreviewed
CVE-2025-14170
was published
Dec 12, 2025
The Truefy Embed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions...
Moderate
Unreviewed
CVE-2025-14161
was published
Dec 12, 2025
The BMLT WordPress Plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
Moderate
Unreviewed
CVE-2025-14162
was published
Dec 12, 2025
ProTip!
Advisories are also available from the
GraphQL API