GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
344 advisories
Filter by severity
Mattermost doesn't escape some variables that could contain malicious content during error page composition
Low
CVE-2026-3495
was published
for
github.com/mattermost/mattermost-server
(Go)
May 18, 2026
Astro: Server island encrypted parameters vulnerable to cross-component replay
Low
CVE-2026-45028
was published
for
astro
(npm)
May 13, 2026
absinthe_plug Has a Cross-site Scripting vulnerability
Low
CVE-2026-42794
was published
for
absinthe_plug
(Erlang)
May 8, 2026
FacturaScripts vulnerable to Reflected Cross-Site Scripting (XSS) via Cookie Manipulation
Low
CVE-2026-27964
was published
for
facturascripts/facturascripts
(Composer)
May 7, 2026
Bagisto affected by Cross-site Scripting
Low
CVE-2026-6745
was published
for
bagisto/bagisto
(Composer)
Apr 21, 2026
October CMS: Reflected XSS via DataTable Form Widget
Low
CVE-2026-27937
was published
for
october/system
(Composer)
Apr 21, 2026
Multiple security fixes in justhtml
Low
GHSA-4p64-v8f5-r2gx
was published
for
justhtml
(pip)
Apr 14, 2026
DbGate has cross site scripting via the SVG Icon String Handler component
Low
CVE-2026-6216
was published
for
dbgate-web
(npm)
Apr 13, 2026
unhead: Streaming SSR `streamKey` injected into inline script without identifier validation
Low
GHSA-x7mm-9vvv-64w8
was published
for
unhead
(npm)
Apr 10, 2026
REDAXO has reflected XSS backend packages API via function parameter (CSRF token required)
Low
GHSA-xq4j-g85q-wf97
was published
for
redaxo/source
(Composer)
Apr 10, 2026
REDAXO has reflected XSS in backend Metainfo API via type parameter (CSRF token required)
Low
GHSA-m662-8jrj-cw6v
was published
for
redaxo/source
(Composer)
Apr 10, 2026
justhtml: Mutation XSS with custom foreign-namespace sanitization policies
Low
GHSA-r758-8hxw-4845
was published
for
justhtml
(pip)
Apr 8, 2026
Casdoor vulnerable to Stored XSS via Application formCss / formSideHtml
Low
CVE-2026-5468
was published
for
github.com/casdoor/casdoor
(Go)
Apr 3, 2026
TeleJSON: DOM XSS via unsanitised constructor name in `new Function()`
Low
CVE-2026-47099
was published
for
telejson
(npm)
Apr 2, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
CVE-2026-5370
was published
for
krayin/laravel-crm
(Composer)
Apr 2, 2026
Graby has stored XSS via iframe srcdoc Attribute in htmLawed Sanitization Config
Low
GHSA-3h6j-9x8m-rg3g
was published
for
j0k3r/graby
(Composer)
Mar 31, 2026
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
Low
GHSA-53p3-c7vp-4mcc
was published
for
action_text-trix
(RubyGems)
Mar 29, 2026
Home Assistant has stored XSS in history-graphs
Low
CVE-2026-33045
was published
for
homeassistant
(pip)
Mar 27, 2026
Home Assistant has stored XSS in Map-card through malicious device name
Low
CVE-2026-33044
was published
for
homeassistant
(pip)
Mar 27, 2026
Loofah has improper detection of disallowed URIs via `allowed_uri?`
Low
GHSA-2j22-pr5w-6gq8
was published
for
loofah
(RubyGems)
Mar 26, 2026
@grackle-ai/server: Unescaped Error String in renderPairingPage() HTML Template
Low
GHSA-7q9x-8g6p-3x75
was published
for
@grackle-ai/server
(npm)
Mar 25, 2026
Authelia: Improper Neutralization of Input During Web Page Generation Leads to Potential Cross-site Scripting
Low
CVE-2026-33525
was published
for
github.com/authelia/authelia/v4
(Go)
Mar 24, 2026
Rails has a possible XSS vulnerability in its Action View tag helpers
Low
CVE-2026-33168
was published
for
actionview
(RubyGems)
Mar 23, 2026
Rails has a possible XSS vulnerability in its Action Pack debug exceptions
Low
CVE-2026-33167
was published
for
actionpack
(RubyGems)
Mar 23, 2026
mo has a XSS via inline SVG script tags in Markdown rendering
Low
GHSA-vccx-p757-pv6h
was published
for
github.com/k1LoW/mo
(Go)
Mar 18, 2026
ProTip!
Advisories are also available from the
GraphQL API