GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
44,004 advisories
Filter by severity
The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
High
Unreviewed
CVE-2026-17506
was published
Aug 5, 2026
Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the...
High
Unreviewed
CVE-2026-71285
was published
Aug 5, 2026
OpenBK7231T's CHANNEL_SetLabel() (src/cmnds/cmd_channels.c) stores channel labels received via...
High
Unreviewed
CVE-2026-71274
was published
Aug 5, 2026
OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter...
Moderate
Unreviewed
CVE-2026-71275
was published
Aug 5, 2026
Ghost: Cross-Site Scripting in Feature Image Captions
Moderate
CVE-2026-70596
was published
for
ghost
(npm)
Aug 5, 2026
299Ko's public contact form (plugin/contact/controllers/ContactController.php, home()) sets raw...
Moderate
Unreviewed
CVE-2026-71249
was published
Aug 5, 2026
InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using...
High
Unreviewed
CVE-2026-71233
was published
Aug 5, 2026
Grocy's API request-body parser (controllers/Api/BaseApiController.php,...
High
Unreviewed
CVE-2026-71236
was published
Aug 5, 2026
The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2026-15452
was published
Aug 5, 2026
The Simple Yearly Archive plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2026-7441
was published
Aug 5, 2026
The SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2026-6972
was published
Aug 5, 2026
The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2026-5108
was published
Aug 5, 2026
The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2026-5116
was published
Aug 5, 2026
The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...
Moderate
Unreviewed
CVE-2026-17532
was published
Aug 5, 2026
The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected...
Moderate
Unreviewed
CVE-2026-17505
was published
Aug 5, 2026
The GeoDirectory WordPress plugin before 2.8.110 does not sanitise and escape a place-category...
Low
Unreviewed
CVE-2025-15677
was published
Aug 5, 2026
The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before...
High
Unreviewed
CVE-2026-16573
was published
Aug 5, 2026
The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2026-8790
was published
Aug 5, 2026
The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored...
High
Unreviewed
CVE-2026-16143
was published
Aug 5, 2026
Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63...
Moderate
Unreviewed
CVE-2026-51144
was published
Aug 5, 2026
XSS in Ghost's ActivityPub client
High
CVE-2026-53950
was published
for
@tryghost/activitypub
(npm)
Aug 4, 2026
SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route"...
Low
Unreviewed
CVE-2026-66300
was published
Aug 4, 2026
Ghost: Cross-Site Scripting in Universal Import
Moderate
CVE-2026-70588
was published
for
ghost
(npm)
Aug 4, 2026
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
High
CVE-2026-70492
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
High
CVE-2026-70486
was published
for
open-webui
(pip)
Aug 4, 2026
ProTip!
Advisories are also available from the
GraphQL API