GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
428 advisories
Filter by severity
OctoPrint has XSS in its Suppressed Command Notifications
Moderate
CVE-2026-35163
was published
for
OctoPrint
(pip)
Jun 23, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS
Moderate
CVE-2026-52816
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Malicious HTML content could be injected into the content rendered by the pretix-digital plugin.
Low
Unreviewed
CVE-2026-13314
was published
Jun 25, 2026
Malicious HTML content could be injected into the page pretix shows when
redirection to an...
Low
Unreviewed
CVE-2026-57533
was published
Jun 25, 2026
Malicious HTML content contained in the layout specification of a PDF
ticket or badge layout was...
High
Unreviewed
CVE-2026-57532
was published
Jun 25, 2026
Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.
Low
Unreviewed
CVE-2026-57534
was published
Jun 25, 2026
Malicious HTML content could be injected into the email address of an
order, which pretix showed...
Moderate
Unreviewed
CVE-2026-13225
was published
Jun 25, 2026
Content injected to PDF rendering contexts could, in many places, include HTML content including ...
Low
Unreviewed
CVE-2026-57535
was published
Jun 25, 2026
Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.
Moderate
Unreviewed
CVE-2025-64637
was published
Jun 26, 2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-50229
was published
Jun 29, 2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A...
Moderate
Unreviewed
CVE-2025-36321
was published
Jun 30, 2026
mediawiki/maps has stored XSS through the overlays parameter in the display_map parser function
High
CVE-2026-52854
was published
for
mediawiki/maps
(Composer)
Jul 2, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-7380
was published
Jul 7, 2026
YesWiki Vulnerable to Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php`
Moderate
CVE-2026-52773
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
YesWiki Vulnerable to Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes
Moderate
CVE-2026-52774
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in...
Moderate
Unreviewed
CVE-2026-59838
was published
Jul 15, 2026
plone.app.textfield: Stored XSS by spoofing mime type
Moderate
CVE-2026-54503
was published
for
plone.app.textfield
(pip)
Jul 17, 2026
plone.restapi: Stored XSS by spoofing mime type
Moderate
GHSA-8rqh-vxpr-x77p
was published
for
plone.restapi
(pip)
Jul 17, 2026
AngleSharp HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point Bypass
Moderate
CVE-2026-54570
was published
for
AngleSharp
(NuGet)
Jul 17, 2026
Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting ...
Critical
Unreviewed
CVE-2024-58353
was published
Jul 24, 2026
Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting...
Critical
Unreviewed
CVE-2024-58355
was published
Jul 24, 2026
A carefully crafted editing request could trigger an XSS vulnerability
on Apache JSPWiki when...
Moderate
Unreviewed
CVE-2026-48910
was published
Jul 30, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-34497
was published
Jul 31, 2026
Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
Moderate
CVE-2026-65841
was published
for
jodit
(npm)
Jul 31, 2026
XSS vulnerability in Markdown handling in Apache Allura.
This issue affects Apache Allura: from...
Moderate
Unreviewed
CVE-2026-73237
was published
Aug 12, 2026
ProTip!
Advisories are also available from the
GraphQL API