GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
713 advisories
Filter by severity
Budibase: Unrestricted Upload of File with Dangerous Type
High
CVE-2026-46426
was published
for
budibase
(npm)
May 19, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
High
CVE-2026-45738
was published
for
github.com/argoproj/argo-cd
(Go)
May 19, 2026
HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack
High
CVE-2026-46511
was published
for
@haxtheweb/haxcms-nodejs
(npm)
May 19, 2026
Stored XSS via <iframe> in HAX CMS allows access to sensitive client-side data and account takeover
High
CVE-2026-46396
was published
for
@haxtheweb/haxcms-nodejs
(npm)
May 19, 2026
CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule
High
CVE-2026-45270
was published
for
ci4-cms-erp/ci4ms
(Composer)
May 18, 2026
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover
High
CVE-2026-45627
was published
for
github.com/getarcaneapp/arcane/backend
(Go)
May 18, 2026
Duplicate Advisory: phpMyFAQ: Stored XSS via Utils::parseUrl() in comment rendering
High
GHSA-w42g-jj8w-fj77
was published
for
phpMyFAQ/phpMyFAQ
(Composer)
May 15, 2026
•
withdrawn
Duplicate Advisory: phpMyFAQ has stored XSS via | raw Filter in search.twig — html_entity_decode(strip_tags()) Bypass in Search Result Rendering
High
GHSA-478m-mrw4-qf2w
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 15, 2026
•
withdrawn
NukeViet CMS: Stored Cross-Site Scripting (XSS) via insufficient server-side input sanitization in Request class
High
CVE-2026-41147
was published
for
nukeviet/nukeviet
(Composer)
May 15, 2026
Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order
High
CVE-2026-45665
was published
for
open-webui
(npm)
May 14, 2026
Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
High
GHSA-3wgj-c2hg-vm6q
was published
for
open-webui
(pip)
May 14, 2026
pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal
High
CVE-2026-45348
was published
for
pyload-ng
(pip)
May 14, 2026
Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
High
CVE-2026-45315
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI has stored XSS via the HTML renedering view
High
CVE-2026-45303
was published
for
open-webui
(pip)
May 14, 2026
ethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override
High
CVE-2026-44541
was published
for
ethyca-fides
(pip)
May 14, 2026
Apostrophe has stored XSS via javascript: URL in Image Widget Link
High
CVE-2026-45011
was published
for
apostrophe
(npm)
May 14, 2026
MantisBT Vulnerable to Stored XSS in File Download
High
CVE-2026-44657
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT has Stored XSS on Move Attachments Admin Page
High
CVE-2026-44655
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT is Vulnerable to Stored XSS in Saved-Filter Owner Column
High
CVE-2026-40607
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT has a Content Security Policy bypass via attachments
High
CVE-2026-40597
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT is Vulnerable to XSS leading to account takeover via updating a user's font family preference
High
CVE-2026-40596
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT is Vulnerable to Stored HTML Injection/XSS in Clone Issue Form
High
CVE-2026-34463
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
Open WebUI has stored XSS in Excel file preview
High
CVE-2026-44549
was published
for
open-webui
(pip)
May 8, 2026
open-webui Vulnerable to Stored XSS via Model Description
High
CVE-2026-44721
was published
for
open-webui
(npm)
May 8, 2026
netbox-data-flows has stored XSS in ObjectAlias names rendered inside DataFlow tables
High
GHSA-v7qw-hx66-4w9x
was published
for
netbox-data-flows
(pip)
May 7, 2026
ProTip!
Advisories are also available from the
GraphQL API