GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,227
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,502
Pub
12
RubyGems
995
Rust
1,187
Swift
51
Unreviewed advisories
All unreviewed
5,000+
40,881 advisories
Filter by severity
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This...
Moderate
Unreviewed
CVE-2026-1276
was published
Mar 19, 2026
IBM QRadar SIEM 7.5.0 through 7.5.0 Update Package 14 is vulnerable to cross-site scripting. This...
Moderate
Unreviewed
CVE-2025-15051
was published
Mar 19, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk
Moderate
CVE-2026-33230
was published
for
nltk
(pip)
Mar 18, 2026
JustHTML has a Sanitizer Bypass (in Markdown)
Moderate
GHSA-3rcm-vjrc-p45j
was published
for
justhtml
(pip)
Mar 18, 2026
JustHTML Affected by Mutation XSS via Literal Text Serialization in Raw Text Elements (style/script)
Moderate
GHSA-qvc2-mg72-jjhx
was published
for
justhtml
(pip)
Mar 18, 2026
mo has a XSS via inline SVG script tags in Markdown rendering
Low
GHSA-vccx-p757-pv6h
was published
for
github.com/k1LoW/mo
(Go)
Mar 18, 2026
Filament Unvalidated Range and Values summarizer values can be used for XSS
High
CVE-2026-33080
was published
for
filament/tables
(Composer)
Mar 18, 2026
Statamic has Stored XSS via SVG Sanitization Bypass
High
CVE-2026-33172
was published
for
statamic/cms
(Composer)
Mar 18, 2026
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup...
High
Unreviewed
CVE-2026-3090
was published
Mar 18, 2026
The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom field...
Moderate
Unreviewed
CVE-2026-2512
was published
Mar 18, 2026
Avo has a XSS vulnerability on `return_to` param
Moderate
CVE-2026-33209
was published
for
avo
(RubyGems)
Mar 18, 2026
Improper detection of disallowed URIs by Loofah `allowed_uri?`
Low
GHSA-46fp-8f5p-pf2m
was published
for
loofah
(RubyGems)
Mar 18, 2026
Stored XSS in PySpector HTML Report Generation leads to Javascript Code Execution
Moderate
CVE-2026-33140
was published
for
pyspector
(pip)
Mar 18, 2026
Cross-Site Scripting (XSS) via SVG Schema innerHTML Injection in @pdfme/schemas
Moderate
GHSA-87v3-4cfp-cm76
was published
for
@pdfme/schemas
(npm)
Mar 18, 2026
Cross-Site Scripting (XSS) via Select Schema Option Value Injection in @pdfme/schemas
Moderate
GHSA-qq9g-96v4-m3cj
was published
for
@pdfme/schemas
(npm)
Mar 18, 2026
SiYuan has Stored XSS to RCE via Unsanitized Bazaar Package Metadata
Moderate
CVE-2026-33067
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 18, 2026
SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering
Moderate
CVE-2026-33066
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 18, 2026
Improper neutralization of input during web page generation ('cross-site scripting')...
High
Unreviewed
CVE-2026-3278
was published
Mar 18, 2026
Craft CMS Vulnerable to Stored XSS in Revision Context Menu
Moderate
CVE-2026-33051
was published
for
craftcms/cms
(Composer)
Mar 18, 2026
beefree.io SDK is vulnerable to Stored XSS in Social Media icon URL parameter in email builder...
Moderate
Unreviewed
CVE-2025-12518
was published
Mar 18, 2026
The Writeprint Stylometry plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...
Moderate
Unreviewed
CVE-2026-3512
was published
Mar 18, 2026
A stored cross‑site scripting (XSS) vulnerability in the Link Aggregation configuration interface...
High
Unreviewed
CVE-2026-22322
was published
Mar 18, 2026
The Get Use APIs WordPress plugin before 2.0.10 executes imported JSON, which could allow users...
Moderate
Unreviewed
CVE-2025-15363
was published
Mar 18, 2026
The [CR]Paid Link Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...
Moderate
Unreviewed
CVE-2026-1780
was published
Mar 18, 2026
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2026-4268
was published
Mar 18, 2026
ProTip!
Advisories are also available from the
GraphQL API