GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
713 advisories
Filter by severity
n8n: Same-Origin XSS in Respond to Webhook Node
High
CVE-2026-54301
was published
for
n8n
(npm)
Jun 16, 2026
Astro: Reflected XSS via unescaped slot name
High
CVE-2026-50146
was published
for
astro
(npm)
Jun 16, 2026
@angular/platform-server: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSR
High
CVE-2026-50556
was published
for
@angular/platform-server
(npm)
Jun 15, 2026
@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
High
CVE-2026-50555
was published
for
@angular/platform-server
(npm)
Jun 15, 2026
Angular Client Hydration DOM Clobbering & Response-Cache Poisoning
High
CVE-2026-54267
was published
for
@angular/core
(npm)
Jun 15, 2026
Litestar has HTML Injection Through its CSRF Token
High
CVE-2026-48060
was published
for
litestar
(pip)
Jun 10, 2026
Jenkins: Stored XSS vulnerability in node offline cause description
High
CVE-2026-53441
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
Spring Framework Cross-site Scripting via JavaScriptUtils
High
CVE-2026-41845
was published
for
org.springframework:spring-webmvc
(Maven)
Jun 9, 2026
Shopper: Multiple data integrity and disclosure issues in admin Livewire components
High
CVE-2026-47743
was published
for
shopper/framework
(Composer)
Jun 5, 2026
TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection
High
CVE-2026-47761
was published
for
TinyMCE
(Composer)
Jun 5, 2026
TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments
High
CVE-2026-47762
was published
for
TinyMCE
(Composer)
Jun 5, 2026
TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes
High
CVE-2026-47759
was published
for
TinyMCE
(Composer)
Jun 5, 2026
TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs
High
CVE-2026-47760
was published
for
TinyMCE
(Composer)
Jun 5, 2026
NocoDB: Stored Cross-Site Scripting via Form View Redirect URL
High
CVE-2026-47387
was published
for
nocodb
(npm)
Jun 5, 2026
NocoDB: Stored Cross-Site Scripting via Row Comments
High
CVE-2026-47383
was published
for
nocodb
(npm)
Jun 5, 2026
WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass)
High
CVE-2026-49279
was published
for
wwbn/avideo
(Composer)
Jun 4, 2026
React Router vulnerable to XSS in unstable RSC redirect handling via javascript: redirect targets
High
CVE-2026-33245
was published
for
react-router
(npm)
Jun 3, 2026
DOMPurify XSS via selectedcontent re-clone
High
CVE-2026-47423
was published
for
dompurify
(npm)
Jun 1, 2026
HaxCMS has a stored Cross-Site Scripting (XSS) bypass in its saveNode endpoint
High
CVE-2026-48527
was published
for
@haxtheweb/haxcms-nodejs
(npm)
May 29, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend
High
CVE-2026-45368
was published
for
getkirby/cms
(Composer)
May 27, 2026
Kirby CMS vulnerable to cross-site scripting (XSS) from list field content in the site frontend
High
CVE-2026-44175
was published
for
getkirby/cms
(Composer)
May 26, 2026
Typebot has Stored XSS via Rating Block Custom Icon that Bypasses isUnsafe Sandbox in Builder Preview
High
CVE-2026-28445
was published
for
@typebot.io/js
(npm)
May 26, 2026
Concrete CMS has Stored XSS through its height parameter
High
CVE-2026-8203
was published
for
concrete5/concrete5
(Composer)
May 21, 2026
Concrete CMS is vulnerable to Stored XSS via OAuth integration name
High
CVE-2026-8197
was published
for
concrete5/concrete5
(Composer)
May 21, 2026
ProTip!
Advisories are also available from the
GraphQL API