GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
375 advisories
Filter by severity
Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
Moderate
CVE-2026-59929
was published
for
mistune
(pip)
Jul 20, 2026
Mistune: XSS via unescaped class option in Admonition directive
Moderate
CVE-2026-59926
was published
for
mistune
(pip)
Jul 20, 2026
Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
Moderate
CVE-2026-59923
was published
for
mistune
(pip)
Jul 20, 2026
Tornado vulnerable to Header Injection and XSS via reason argument
Moderate
CVE-2025-67724
was published
for
tornado
(pip)
Jul 20, 2026
GeoNode: Stored XSS to full account takeover
Moderate
CVE-2024-27091
was published
for
geonode
(pip)
Jul 13, 2026
Open WebUI allows limited stored XSS vila uploaded html file
Moderate
CVE-2025-46571
was published
for
open-webui
(pip)
Jul 7, 2026
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
Moderate
GHSA-75mw-h36v-2jv7
was published
for
dosage
(pip)
Jun 26, 2026
justhtml: to_markdown() code-span blank-line breakout enables XSS
Moderate
GHSA-jf6w-2mvx-633j
was published
for
justhtml
(pip)
Jun 25, 2026
marimo contains a reflected cross-site scripting vulnerability in the notebook page
Moderate
CVE-2026-54386
was published
for
marimo
(pip)
Jun 18, 2026
Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
Moderate
GHSA-gj48-438w-jh9v
was published
for
bleach
(pip)
Jun 16, 2026
malla: Stored XSS via Meshtastic node names in multiple frontend pages
Moderate
CVE-2026-43980
was published
for
malla
(pip)
Jun 3, 2026
Weblate: Stored HTML injection in editor search preview
Moderate
CVE-2026-45106
was published
for
weblate
(pip)
May 15, 2026
Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)
Moderate
CVE-2026-45318
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI has Stored Cross-Site Scripting In Profile Picture
Moderate
CVE-2026-45299
was published
for
open-webui
(pip)
May 14, 2026
Mistune Image Directive CSS Injection Vulnerability
Moderate
CVE-2026-44899
was published
for
mistune
(pip)
May 14, 2026
Mistune TOC Anchor Injection XSS
Moderate
CVE-2026-44898
was published
for
mistune
(pip)
May 14, 2026
local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)
Moderate
CVE-2026-43979
was published
for
local-deep-research
(pip)
May 11, 2026
pgAdmin 4: Stored cross-site scripting (XSS) vulnerability in Browser Tree and Explain Visualizer modules
Moderate
CVE-2026-7814
was published
for
pgadmin4
(pip)
May 11, 2026
Mistune Heading ID Attribute has Injection XSS
Moderate
CVE-2026-44897
was published
for
mistune
(pip)
May 9, 2026
Mistune has XSS via unescaped figclass/figwidth in Figure directive
Moderate
CVE-2026-44896
was published
for
mistune
(pip)
May 8, 2026
Mistune Math Plugin has an XSS Escape Bypass
Moderate
CVE-2026-44708
was published
for
mistune
(pip)
May 8, 2026
Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order
Moderate
CVE-2026-44568
was published
for
open-webui
(pip)
May 8, 2026
Weblate vulnerable to XSS via crafted Markdown
Moderate
CVE-2026-44264
was published
for
weblate
(pip)
May 7, 2026
beets has a Cross-site Scripting vulnerability
Moderate
CVE-2026-42052
was published
for
beets
(pip)
Apr 29, 2026
wlc: print_html outputs API data without HTML escaping
Moderate
CVE-2026-42150
was published
for
wlc
(pip)
Apr 24, 2026
ProTip!
Advisories are also available from the
GraphQL API