Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

713 advisories

Loading
n8n: Stored XSS in Chat Trigger Node High
CVE-2026-54302 was published for n8n (npm) Jun 16, 2026
sm1ee Credited to sm1ee
n8n: Same-Origin XSS in Respond to Webhook Node High
CVE-2026-54301 was published for n8n (npm) Jun 16, 2026
supperhellokitty20 Credited to supperhellokitty20
Astro: Reflected XSS via unescaped slot name High
CVE-2026-50146 was published for astro (npm) Jun 16, 2026
floudeciel Credited to floudeciel
SkyZeroZx Credited to SkyZeroZx, alan-agius4, and josephperrott alan-agius4 alan-agius4
josephperrott josephperrott
@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High
CVE-2026-50555 was published for @angular/platform-server (npm) Jun 15, 2026
SkyZeroZx Credited to SkyZeroZx, alan-agius4, and josephperrott alan-agius4 alan-agius4
josephperrott josephperrott
Angular Client Hydration DOM Clobbering & Response-Cache Poisoning High
CVE-2026-54267 was published for @angular/core (npm) Jun 15, 2026
SkyZeroZx Credited to SkyZeroZx, AndrewKushnir, alan-agius4, josephperrott, and JeanMeche AndrewKushnir AndrewKushnir
alan-agius4 alan-agius4 josephperrott josephperrott JeanMeche JeanMeche
Litestar has HTML Injection Through its CSRF Token High
CVE-2026-48060 was published for litestar (pip) Jun 10, 2026
Blinky-Keys Credited to Blinky-Keys
Jenkins: Stored XSS vulnerability in node offline cause description High
CVE-2026-53441 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
lohitkolluri Credited to lohitkolluri
Spring Framework Cross-site Scripting via JavaScriptUtils High
CVE-2026-41845 was published for org.springframework:spring-webmvc (Maven) Jun 9, 2026
Shopper: Multiple data integrity and disclosure issues in admin Livewire components High
CVE-2026-47743 was published for shopper/framework (Composer) Jun 5, 2026
baradika Credited to baradika
TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection High
CVE-2026-47761 was published for TinyMCE (Composer) Jun 5, 2026
UncleJ4ck Credited to UncleJ4ck, ange-primiterra, bluvulture, and sbrinkhorst ange-primiterra ange-primiterra
bluvulture bluvulture sbrinkhorst sbrinkhorst
TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments High
CVE-2026-47762 was published for TinyMCE (Composer) Jun 5, 2026
he1d3n Credited to he1d3n and bluvulture bluvulture bluvulture
mtrill47 Credited to mtrill47 and he1d3n he1d3n he1d3n
TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs High
CVE-2026-47760 was published for TinyMCE (Composer) Jun 5, 2026
maple3142 Credited to maple3142
NocoDB: Stored Cross-Site Scripting via Form View Redirect URL High
CVE-2026-47387 was published for nocodb (npm) Jun 5, 2026
kah-ja Credited to kah-ja
NocoDB: Stored Cross-Site Scripting via Row Comments High
CVE-2026-47383 was published for nocodb (npm) Jun 5, 2026
DavidCarliez Credited to DavidCarliez and Mouhebbenelwafi Mouhebbenelwafi Mouhebbenelwafi
oduoke567 Credited to oduoke567
React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets High
CVE-2026-33245 was published for react-router (npm) Jun 3, 2026
xaccefy Credited to xaccefy
DOMPurify XSS via selectedcontent re-clone High
CVE-2026-47423 was published for dompurify (npm) Jun 1, 2026
KabirAcharya Credited to KabirAcharya
HaxCMS has a stored Cross-Site Scripting (XSS) bypass in its saveNode endpoint High
CVE-2026-48527 was published for @haxtheweb/haxcms-nodejs (npm) May 29, 2026
kn1ph Credited to kn1ph
offset Credited to offset
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend High
CVE-2026-44175 was published for getkirby/cms (Composer) May 26, 2026
offset Credited to offset
Typebot has Stored XSS via Rating Block Custom Icon that Bypasses isUnsafe Sandbox in Builder Preview High
CVE-2026-28445 was published for @typebot.io/js (npm) May 26, 2026
bugbunny-research Credited to bugbunny-research
Concrete CMS has Stored XSS through its height parameter High
CVE-2026-8203 was published for concrete5/concrete5 (Composer) May 21, 2026
Concrete CMS is vulnerable to Stored XSS via OAuth integration name High
CVE-2026-8197 was published for concrete5/concrete5 (Composer) May 21, 2026
ProTip! Advisories are also available from the GraphQL API