GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
74
GitHub Actions
54
Go
4,134
Maven
5,000+
npm
5,000+
NuGet
1,013
pip
5,000+
Pub
13
RubyGems
1,095
Rust
1,419
Swift
61
Unreviewed advisories
All unreviewed
5,000+
42 advisories
Filter by severity
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
CVE-2026-54002
was published
for
getkirby/cms
(Composer)
Jun 18, 2026
TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
Moderate
CVE-2026-55661
was published
for
@tinacms/mdx
(npm)
Jun 18, 2026
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer.
This issue...
Moderate
Unreviewed
CVE-2026-25688
was published
Jun 9, 2026
md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)
High
CVE-2026-46492
was published
for
md-fileserver
(npm)
May 21, 2026
Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
High
CVE-2026-45314
was published
for
open-webui
(pip)
May 14, 2026
Magento LTS: Reflected XSS - Import -> Data Flow (profiles)
Moderate
CVE-2026-42458
was published
for
openmage/magento-lts
(Composer)
May 6, 2026
n8n Vulnerable to XSS via MCP OAuth client
High
CVE-2026-42235
was published
for
n8n
(npm)
Apr 29, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
High
CVE-2026-40321
was published
for
DotNetNuke.Core
(NuGet)
Apr 10, 2026
The Elementor Website Builder – More Than Just a Page Builder plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2025-14732
was published
Apr 8, 2026
Improper neutralization of alternate XSS syntax vulnerability in The Wikimedia Foundation...
Moderate
Unreviewed
CVE-2026-22711
was published
Apr 7, 2026
YesWiki has Persistent Blind XSS at "/?BazaR&vue=consulter"
High
CVE-2026-34598
was published
for
yeswiki/yeswiki
(Composer)
Apr 1, 2026
Leaf-kit html escaping does not work on characters that are part of extended grapheme cluster
Moderate
CVE-2026-27120
was published
for
github.com/vapor/leaf-kit
(Swift)
Feb 19, 2026
Contao is vulnerable to cross-site scripting in templates
Low
CVE-2025-65961
was published
for
contao/core-bundle
(Composer)
Nov 25, 2025
bagisto has Cross Site Scripting (XSS) in Create New Customer
Moderate
CVE-2025-62414
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has a Cross Site Scripting (XSS) vulnerability in TinyMCE Image Upload (SVG)
Moderate
CVE-2025-62418
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
bagisto has Cross Site Scripting (XSS) issue in TinyMCE Image Upload (HTML)
Moderate
CVE-2025-62415
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
The Ova Advent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
Moderate
Unreviewed
CVE-2025-8561
was published
Oct 15, 2025
Node-SAML SAML Authentication Bypass
Critical
CVE-2025-54369
was published
for
@node-saml/node-saml
(npm)
Jul 25, 2025
Hax CMS Stored Cross-Site Scripting vulnerability
High
CVE-2025-49137
was published
for
elmsln/haxcms
(Composer)
Jun 9, 2025
Gokapi vulnerable to stored XSS via uploading file with malicious file name
Moderate
CVE-2025-48494
was published
for
github.com/forceu/gokapi
(Go)
Jun 3, 2025
Gokapi has stored XSS vulnerability in friendly name for API keys
Moderate
CVE-2025-48495
was published
for
github.com/forceu/gokapi
(Go)
Jun 3, 2025
Vega vulnerable to Cross-site Scripting via RegExp.prototype[@@replace]
Moderate
CVE-2025-27793
was published
for
vega
(npm)
Mar 27, 2025
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2024-8505
was published
Oct 2, 2024
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2024-4459
was published
Jun 6, 2024
The Opal Estate Pro – Property Management and Submission plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2024-3666
was published
May 22, 2024
ProTip!
Advisories are also available from the
GraphQL API