GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
55
GitHub Actions
50
Go
3,722
Maven
5,000+
npm
5,000+
NuGet
935
pip
4,946
Pub
13
RubyGems
1,055
Rust
1,338
Swift
54
Unreviewed advisories
All unreviewed
5,000+
11 advisories
Filter by severity
Keycloak: Information disclosure of disabled user attributes via administrative endpoint
Low
CVE-2026-3911
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 11, 2026
XWiki exposes passwords and emails stored in fields not named password/email in xml.vm
High
CVE-2025-54125
was published
for
org.xwiki.platform:xwiki-platform-legacy-oldcore
(Maven)
Aug 5, 2025
XWiki leaks password hashes and other accessible password properties
High
CVE-2025-54124
was published
for
org.xwiki.platform:xwiki-platform-legacy-oldcore
(Maven)
Aug 5, 2025
org.xwiki.platform:xwiki-platform-notifications-ui leaks data of notification filters of users
Moderate
CVE-2024-46979
was published
for
org.xwiki.platform:xwiki-platform-notifications-ui
(Maven)
Sep 18, 2024
XWiki Platform document history including authors of any page exposed to unauthorized actors
Moderate
CVE-2024-45591
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Sep 10, 2024
XWiki Platform may show email addresses in clear in REST results
High
CVE-2023-35151
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Jun 20, 2023
Unauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm
Low
CVE-2023-29203
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Apr 12, 2023
Exposure of Private Personal Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-rest-server
Moderate
CVE-2022-41936
was published
for
org.xwiki.platform:xwiki-platform-rest-server
(Maven)
Nov 21, 2022
XWiki Platform Web Templates vulnerable to Missing Authorization, Exposure of Private Personal Information to Unauthorized Actor
High
CVE-2022-36091
was published
for
org.xwiki.platform:xwiki-platform-web
(Maven)
Sep 16, 2022
Unauthenticated user can list hidden document from multiple velocity templates in XWiki
Moderate
CVE-2022-24820
was published
for
org.xwiki.platform:xwiki-platform-web
(Maven)
Apr 8, 2022
Unauthenticated user can retrieve the list of users through uorgsuggest.vm
Moderate
CVE-2022-24819
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Apr 8, 2022
ProTip!
Advisories are also available from the
GraphQL API