GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
573 advisories
Filter by severity
Ghost: Cross-Site Scripting in Feature Image Captions
Moderate
CVE-2026-70596
was published
for
ghost
(npm)
Aug 5, 2026
Ghost: Cross-Site Scripting in Universal Import
Moderate
CVE-2026-70588
was published
for
ghost
(npm)
Aug 4, 2026
sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes
Moderate
CVE-2026-53606
was published
for
sanitize-html
(npm)
Jul 31, 2026
Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS
Moderate
CVE-2026-62324
was published
for
jodit
(npm)
Jul 31, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste
Moderate
GHSA-53g2-mvcc-q9x3
was published
for
action_text-trix
(RubyGems)
Jul 24, 2026
React Router: RSCErrorHandler Missing Protocol Validation (XSS)
Moderate
CVE-2026-53667
was published
for
react-router
(npm)
Jul 23, 2026
DOMPurify is vulnerable to mutation-XSS via Re-Contextualization
Moderate
CVE-2026-65914
was published
for
dompurify
(npm)
Mar 27, 2026
DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)
Moderate
CVE-2026-65898
was published
for
dompurify
(npm)
Jun 18, 2026
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
Moderate
CVE-2026-59895
was published
for
hono
(npm)
Jul 21, 2026
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
Moderate
CVE-2026-59729
was published
for
astro
(npm)
Jul 20, 2026
n8n has a Stored XSS Vulnerability in its Form Trigger
Moderate
CVE-2026-56358
was published
for
n8n
(npm)
Mar 27, 2026
NocoDB: Stored Cross-Site Scripting via Secure Attachment
Moderate
CVE-2026-53929
was published
for
nocodb
(npm)
Jun 17, 2026
NocoDB: Reflected Cross-Site Scripting via Password Reset Token
Moderate
CVE-2026-47376
was published
for
nocodb
(npm)
Jun 5, 2026
NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL
Moderate
CVE-2026-46547
was published
for
nocodb
(npm)
May 21, 2026
Astro: Reflected XSS via unescaped View Transition animation properties
Moderate
GHSA-4g3v-8h47-v7g6
was published
for
astro
(npm)
Jul 20, 2026
n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
Moderate
CVE-2026-54303
was published
for
n8n
(npm)
Jun 16, 2026
Dash apps vulnerable to Cross-site Scripting
Moderate
CVE-2024-21485
was published
for
dash
(npm)
Feb 2, 2024
Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization
Moderate
CVE-2026-44311
was published
for
fabric
(npm)
Jun 12, 2026
Astro: XSS via Unescaped Attribute Names in Spread Props
Moderate
CVE-2026-54298
was published
for
astro
(npm)
Jun 16, 2026
@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS)
Moderate
CVE-2026-54265
was published
for
@angular/compiler
(npm)
Jun 15, 2026
Angular: Template and Attribute Namespace Sanitization Bypass (XSS)
Moderate
CVE-2026-50557
was published
for
@angular/compiler
(npm)
Jun 15, 2026
@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)
Moderate
CVE-2026-52725
was published
for
@angular/core
(npm)
Jun 15, 2026
LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS
Moderate
CVE-2026-44644
was published
for
liquidjs
(npm)
May 27, 2026
Potential XSS vulnerability in jQuery
Moderate
CVE-2020-11022
was published
for
athlon1600/youtube-downloader
(RubyGems)
Apr 29, 2020
@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString
Moderate
CVE-2026-50290
was published
for
@asymmetric-effort/specifyjs
(npm)
Jul 2, 2026
ProTip!
Advisories are also available from the
GraphQL API