GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
47
Go
3,340
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,549
Pub
12
RubyGems
1,012
Rust
1,202
Swift
51
Unreviewed advisories
All unreviewed
5,000+
585 advisories
Filter by severity
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
High
CVE-2026-33941
was published
for
handlebars
(npm)
Mar 27, 2026
Express XSS Sanitizer: allowedTags/allowedAttributes bypass leads to permissive sanitization (XSS risk)
High
CVE-2026-33979
was published
for
express-xss-sanitizer
(npm)
Mar 27, 2026
LibreNMS is Vulnerable to Remote Code Execution by Arbitrary File Write
High
GHSA-pr3g-phhr-h8fh
was published
for
librenms/librenms
(Composer)
Mar 26, 2026
MantisBT has Stored HTML Injection/XSS when displaying Tags in Timeline
High
CVE-2026-33548
was published
for
mantisbt/mantisbt
(Composer)
Mar 25, 2026
MantisBT Vulnerable to Stored HTML Injection in Tag Delete Confirmation
High
CVE-2026-33517
was published
for
mantisbt/mantisbt
(Composer)
Mar 25, 2026
PrestaShop has multiple stored XSS vulnerabilities via unprotected Template variables
High
CVE-2026-33673
was published
for
prestashop/prestashop
(Composer)
Mar 25, 2026
JustHTML is vulnerable to XSS via code fence breakout in <pre> content
High
GHSA-5vp3-3cg6-2rq3
was published
for
justhtml
(pip)
Mar 24, 2026
Connect CMS has Stored Cross-site Scripting (XSS) in the File Field of its Form Plugin
High
CVE-2026-32278
was published
for
opensource-workshop/connect-cms
(Composer)
Mar 23, 2026
Connect-CMS has DOM-based Cross-Site Scripting (XSS) in the Cabinet Plugin List View
High
CVE-2026-32277
was published
for
opensource-workshop/connect-cms
(Composer)
Mar 23, 2026
oRPC has Stored XSS in OpenAPI Reference Plugin via unescaped JSON.stringify
High
CVE-2026-33331
was published
for
@orpc/openapi
(npm)
Mar 20, 2026
AVideo Affected by Stored XSS via Unescaped Video Title in CDN downloadButtons.php
High
CVE-2026-33295
was published
for
wwbn/avideo
(Composer)
Mar 19, 2026
Filament Unvalidated Range and Values summarizer values can be used for XSS
High
CVE-2026-33080
was published
for
filament/tables
(Composer)
Mar 18, 2026
Statamic has Stored XSS via SVG Sanitization Bypass
High
CVE-2026-33172
was published
for
statamic/cms
(Composer)
Mar 18, 2026
Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries
High
CVE-2026-32728
was published
for
parse-server
(npm)
Mar 16, 2026
Angular vulnerable to XSS in i18n attribute bindings
High
CVE-2026-32635
was published
for
@angular/compiler
(npm)
Mar 13, 2026
OneUptime: Stored XSS via Mermaid Diagram Rendering (securityLevel: "loose")
High
CVE-2026-32308
was published
for
oneuptime
(npm)
Mar 13, 2026
Parse Server vulnerable to stored cross-site scripting (XSS) via SVG file upload
High
CVE-2026-30948
was published
for
parse-server
(npm)
Mar 11, 2026
Craft Commerce has multiple Stored XSS in Commerce Inventory Page, Leading to Session Hijacking
High
CVE-2026-29175
was published
for
craftcms/commerce
(Composer)
Mar 10, 2026
FileBrowser Quantum: Stored XSS in public share page via unsanitized share metadata (text/template misuse)
High
CVE-2026-30934
was published
for
github.com/gtsteffaniak/filebrowser
(Go)
Mar 9, 2026
Gogs: DOM-based XSS via milestone selection
High
CVE-2026-26276
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
Gogs: Stored XSS via data URI in issue comments
High
CVE-2026-26022
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
Gokapi has Stored XSS in SVG Hotlinks
High
CVE-2026-28683
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
ZITADEL: Stored XSS via Default URI Redirect Leads to Account Takeover
High
CVE-2026-29192
was published
for
github.com/zitadel/zitadel
(Go)
Mar 4, 2026
XWiki Blog Application home page vulnerable to Stored XSS via Post Title
High
CVE-2025-66024
was published
for
org.xwiki.contrib.blog:application-blog-ui
(Maven)
Mar 4, 2026
Statamic vulnerable to privilege escalation via stored cross-site scripting
High
CVE-2026-28426
was published
for
statamic/cms
(Composer)
Mar 1, 2026
ProTip!
Advisories are also available from the
GraphQL API