GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
145,439 advisories
Filter by severity
The Simple Theme Changer plugin for WordPress is vulnerable to Cross-Site Request Forgery in...
Moderate
Unreviewed
CVE-2025-14391
was published
Dec 12, 2025
The Wpik WordPress Basic Ajax Form plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2025-14393
was published
Dec 12, 2025
The Coding Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
Moderate
Unreviewed
CVE-2025-14158
was published
Dec 12, 2025
The WPMasterToolKit plugin for WordPress is vulnerable to PHP Code Injection in all versions up...
Moderate
Unreviewed
CVE-2025-14166
was published
Dec 12, 2025
The Upcoming for Calendly plugin for WordPress is vulnerable to Cross-Site Request Forgery in all...
Moderate
Unreviewed
CVE-2025-14160
was published
Dec 12, 2025
The Resource Library for Logged In Users plugin for WordPress is vulnerable to Cross-Site Request...
Moderate
Unreviewed
CVE-2025-14354
was published
Dec 12, 2025
The Simple Theme Changer plugin for WordPress is vulnerable to unauthorized modification of data...
Moderate
Unreviewed
CVE-2025-14392
was published
Dec 12, 2025
The Construction Light WordPress theme before 1.6.8 does not have authorisation and CSRF when...
Moderate
Unreviewed
CVE-2025-10684
was published
Dec 12, 2025
Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.3.0,...
Moderate
Unreviewed
CVE-2025-53523
was published
Dec 12, 2025
Cross-site request forgery vulnerability exists in GroupSession Free edition prior to ver5.3.0,...
Moderate
Unreviewed
CVE-2025-58576
was published
Dec 12, 2025
Stored cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3.0,...
Moderate
Unreviewed
CVE-2025-54407
was published
Dec 12, 2025
Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.3...
Moderate
Unreviewed
CVE-2025-57883
was published
Dec 12, 2025
In GroupSession, a Circular notice can be created with its memo field non-editable, but the...
Moderate
Unreviewed
CVE-2025-61950
was published
Dec 12, 2025
GroupSession Free edition prior to ver5.3.0, GroupSession byCloud prior to ver5.3.3, and...
Moderate
Unreviewed
CVE-2025-61987
was published
Dec 12, 2025
SQL Injection vulnerability exists in GroupSession Free edition prior to ver5.3.0, GroupSession...
Moderate
Unreviewed
CVE-2025-62192
was published
Dec 12, 2025
Stored cross-site scripting vulnerabilities exist in GroupSession Free edition prior to ver5.7.1,...
Moderate
Unreviewed
CVE-2025-66284
was published
Dec 12, 2025
In GroupSession Free edition prior to ver5.7.1, GroupSession byCloud prior to ver5.7.1, and...
Moderate
Unreviewed
CVE-2025-64781
was published
Dec 12, 2025
Reflected cross-site scripting vulnerability exists in GroupSession Free edition prior to ver5.7...
Moderate
Unreviewed
CVE-2025-65120
was published
Dec 12, 2025
The Like DisLike Voting plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2025-14129
was published
Dec 12, 2025
The Complag plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `...
Moderate
Unreviewed
CVE-2025-14125
was published
Dec 12, 2025
The App Landing Template Blocks for WPBakery (Visual Composer) Page Builder plugin for WordPress...
Moderate
Unreviewed
CVE-2025-14119
was published
Dec 12, 2025
The Category Dropdown List plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-14132
was published
Dec 12, 2025
The Simple AL Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2025-14137
was published
Dec 12, 2025
The WPLG Default Mail From plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-14138
was published
Dec 12, 2025
The Hide Email Address plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-13884
was published
Dec 12, 2025
ProTip!
Advisories are also available from the
GraphQL API