Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

713 advisories

Loading
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF High
CVE-2026-16633 was published for pdfjs-dist (npm) Aug 6, 2026
wlayzz Credited to wlayzz
XSS in Ghost's ActivityPub client High
CVE-2026-53950 was published for @tryghost/activitypub (npm) Aug 4, 2026
bgeesaman Credited to bgeesaman
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages High
CVE-2026-70492 was published for open-webui (pip) Aug 4, 2026
maxntv Credited to maxntv and Classic298 Classic298 Classic298
manus-use Credited to manus-use and Classic298 Classic298 Classic298
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes High
CVE-2026-69151 was published for @angular/compiler (npm) Aug 3, 2026
Hexix23 Credited to Hexix23, alan-agius4, and JeanMeche alan-agius4 alan-agius4
JeanMeche JeanMeche
Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS) High
CVE-2026-69149 was published for @angular/platform-server (npm) Aug 3, 2026
SkyZeroZx Credited to SkyZeroZx and alan-agius4 alan-agius4 alan-agius4
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag High
CVE-2026-53608 was published for @apostrophecms/seo (npm) Jul 31, 2026
H3xV0rT3x Credited to H3xV0rT3x
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier High
CVE-2026-58263 was published for jodit (npm) Jul 31, 2026
koyokr Credited to koyokr
OmniFaces: Forged combined-resource IDs and related output/push boundaries High
GHSA-fp43-vj7g-pg92 was published for org.omnifaces:omnifaces (Maven) Jul 24, 2026
Open WebUI: Stored web worker XSS via Pyodide High
CVE-2026-59214 was published for open-webui (pip) Jul 24, 2026
gg0h Credited to gg0h and Classic298 Classic298 Classic298
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) High
GHSA-pppj-hq3g-57pj was published for jupyterlab (pip) Jul 22, 2026
de3erve-hunter Credited to de3erve-hunter, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab High
GHSA-gx64-gj6p-pc4c was published for jupyterlab (pip) Jul 22, 2026
krassowski Credited to krassowski, MUFFANUJ, and dlqqq MUFFANUJ MUFFANUJ
dlqqq dlqqq
n8n: Stored DOM XSS via Resource Locator `cachedResultUrl` High
CVE-2026-65592 was published for n8n (npm) Jul 22, 2026
odgrso Credited to odgrso
n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview High
CVE-2026-65597 was published for n8n (npm) Jul 22, 2026
odgrso Credited to odgrso
Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview High
GHSA-vhcw-f978-xjjg was published for n8n (npm) Jul 22, 2026 withdrawn
Malayke Credited to Malayke
Duplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl` High
GHSA-h5xr-fqvj-253p was published for n8n (npm) Jul 22, 2026 withdrawn
Malayke Credited to Malayke
SVGO removeScripts plugin leaves some executable scripts intact High
GHSA-2p49-hgcm-8545 was published for svgo (npm) Jul 21, 2026
Admu-Dev Credited to Admu-Dev
ViewComponent: around_render HTML-Safety Bypass High
CVE-2026-54498 was published for view_component (RubyGems) Jul 15, 2026
cyberlanc3r Credited to cyberlanc3r
MantisBT: Stored XSS in print_all_bug_page_word.php High
CVE-2026-62944 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
dracosectech-code Credited to dracosectech-code and dregad dregad dregad
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField High
CVE-2026-54087 was published for easycorp/easyadmin-bundle (Composer) Jul 14, 2026
NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module High
CVE-2026-54064 was published for nukeviet/nukeviet (Composer) Jul 13, 2026
hoaquynhtim99 Credited to hoaquynhtim99 and g03m0n g03m0n g03m0n
NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High
CVE-2026-49259 was published for nukeviet/nukeviet (Composer) Jul 13, 2026
0xGunrunner Credited to 0xGunrunner
NukeViet: Unauthenticated Reflected XSS in Comment Module High
CVE-2026-48118 was published for nukeviet/nukeviet (Composer) Jul 13, 2026
hoaquynhtim99 Credited to hoaquynhtim99 and 0xGunrunner 0xGunrunner 0xGunrunner
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers High
CVE-2026-54070 was published for github.com/siyuan-note/siyuan/kernel (Go) Jul 10, 2026
kah-ja Credited to kah-ja
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes High
CVE-2026-49825 was published for lxml_html_clean (pip) Jul 8, 2026
glefait Credited to glefait, frenzymadness, and scoder frenzymadness frenzymadness
scoder scoder
ProTip! Advisories are also available from the GraphQL API