GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
428 advisories
Filter by severity
Malicious HTML content contained in the layout specification of a PDF
ticket or badge layout was...
High
Unreviewed
CVE-2026-57532
was published
Jun 25, 2026
Malicious HTML content could be injected into the content of a page in the pretix-pages plugin.
Low
Unreviewed
CVE-2026-57534
was published
Jun 25, 2026
Content injected to PDF rendering contexts could, in many places, include HTML content including ...
Low
Unreviewed
CVE-2026-57535
was published
Jun 25, 2026
Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.
Moderate
Unreviewed
CVE-2025-64637
was published
Jun 26, 2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-50229
was published
Jun 29, 2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A...
Moderate
Unreviewed
CVE-2025-36321
was published
Jun 30, 2026
mediawiki/maps has stored XSS through the overlays parameter in the display_map parser function
High
CVE-2026-52854
was published
for
mediawiki/maps
(Composer)
Jul 2, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-7380
was published
Jul 7, 2026
HTML Injection in ActiveMQ Artemis Web Console
Moderate
CVE-2022-35278
was published
for
org.apache.activemq:artemis-server
(Maven)
Aug 24, 2022
YesWiki Vulnerable to Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php`
Moderate
CVE-2026-52773
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
YesWiki Vulnerable to Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes
Moderate
CVE-2026-52774
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in...
Moderate
Unreviewed
CVE-2026-59838
was published
Jul 15, 2026
plone.app.textfield: Stored XSS by spoofing mime type
Moderate
CVE-2026-54503
was published
for
plone.app.textfield
(pip)
Jul 17, 2026
plone.restapi: Stored XSS by spoofing mime type
Moderate
GHSA-8rqh-vxpr-x77p
was published
for
plone.restapi
(pip)
Jul 17, 2026
AngleSharp HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point Bypass
Moderate
CVE-2026-54570
was published
for
AngleSharp
(NuGet)
Jul 17, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS
Moderate
CVE-2026-52816
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting ...
Critical
Unreviewed
CVE-2024-58353
was published
Jul 24, 2026
Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting...
Critical
Unreviewed
CVE-2024-58355
was published
Jul 24, 2026
A carefully crafted editing request could trigger an XSS vulnerability
on Apache JSPWiki when...
Moderate
Unreviewed
CVE-2026-48910
was published
Jul 30, 2026
Apache Answer vulnerable to Cross-site Scripting
Moderate
CVE-2026-34033
was published
for
github.com/apache/incubator-answer
(Go)
Jun 9, 2026
Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
Moderate
CVE-2026-65841
was published
for
jodit
(npm)
Jul 31, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-34497
was published
Jul 31, 2026
Astro: Reflected XSS via unescaped slot name
High
CVE-2026-50146
was published
for
astro
(npm)
Jun 16, 2026
XSS vulnerability in Markdown handling in Apache Allura.
This issue affects Apache Allura: from...
Moderate
Unreviewed
CVE-2026-73237
was published
Aug 12, 2026
XSS vulnerability in code display in Apache Allura.
This issue affects Apache Allura: before 1...
Moderate
Unreviewed
CVE-2026-73238
was published
Aug 12, 2026
ProTip!
Advisories are also available from the
GraphQL API