GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
713 advisories
Filter by severity
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
High
GHSA-86j7-9j95-vpqj
was published
for
better-auth
(npm)
Jul 7, 2026
Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
High
CVE-2026-26193
was published
for
open-webui
(pip)
Jul 7, 2026
Open WebUI vulnerable to Stored XSS via iFrame in citations model
High
CVE-2026-26192
was published
for
open-webui
(pip)
Jul 7, 2026
Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
High
CVE-2025-46719
was published
for
open-webui
(pip)
Jul 7, 2026
Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget
High
CVE-2026-55790
was published
for
craftcms/cms
(Composer)
Jul 6, 2026
Mautic has Stored Cross-Site Scripting (XSS) in Projects Component
High
CVE-2026-9809
was published
for
mautic/core
(Composer)
Jul 2, 2026
mediawiki/maps has stored XSS through the overlays parameter in the display_map parser function
High
CVE-2026-52854
was published
for
mediawiki/maps
(Composer)
Jul 2, 2026
wetty vulnerable to DOM XSS via file-download filename
High
CVE-2026-49864
was published
for
wetty
(npm)
Jul 1, 2026
GeoNetwork has reflected XSS through client-side template injection
High
CVE-2026-39379
was published
for
org.geonetwork-opensource:geonetwork
(Maven)
Jul 1, 2026
Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing
High
CVE-2026-48788
was published
for
github.com/umputun/remark42
(Go)
Jun 26, 2026
Angular's deprecated package has a Cross-Site Scripting issue
High
CVE-2026-11998
was published
for
angular
(npm)
Jun 24, 2026
Gogs has Stored XSS in `.ipynb` Preview
High
CVE-2026-52798
was published
for
gogs.io/gogs
(Go)
Jun 22, 2026
appium-mcp: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)
High
GHSA-x975-rgx4-5fh4
was published
for
appium-mcp
(npm)
Jun 19, 2026
StarCitizenWiki Extension Embed Video: Stored XSS via malformed src url with $wgEmbedVideoRequireConsent enabled
High
CVE-2026-55692
was published
for
starcitizenwiki/embedvideo
(Composer)
Jun 19, 2026
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
High
CVE-2026-55660
was published
for
@tinacms/app
(npm)
Jun 19, 2026
StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized class passed to template
High
CVE-2026-55691
was published
for
starcitizenwiki/embedvideo
(Composer)
Jun 19, 2026
StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized service name in exception text
High
CVE-2026-55690
was published
for
starcitizenwiki/embedvideo
(Composer)
Jun 19, 2026
jupyterlab-git extension: Stored XSS leading to RCE
High
CVE-2026-54527
was published
for
@jupyterlab/git
(npm)
Jun 19, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
CVE-2026-54002
was published
for
getkirby/cms
(Composer)
Jun 18, 2026
PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
High
CVE-2026-56840
was published
for
praisonai
(pip)
Jun 18, 2026
Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module
High
CVE-2026-55746
was published
for
cotonti/cotonti
(Composer)
Jun 18, 2026
Filament: Disabled RichEditor field state can be used for XSS
High
CVE-2026-55409
was published
for
filament/forms
(Composer)
Jun 17, 2026
Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer
High
CVE-2026-28737
was published
for
code.gitea.io/gitea
(Go)
Jun 17, 2026
Open WebUI: Stored XSS to Account Takeover via Model Profile Images
High
CVE-2026-54013
was published
for
open-webui
(pip)
Jun 17, 2026
Open WebUI: Stored XSS in Mermaid Markdown Preview
High
CVE-2026-54011
was published
for
open-webui
(pip)
Jun 17, 2026
ProTip!
Advisories are also available from the
GraphQL API