GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
3,527 advisories
Filter by severity
Craft CMS: Stored XSS in the control panel via unescaped draft name
Moderate
GHSA-2rp4-x2j7-qmcc
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
jsoup: Cleaner may expose markup with custom raw-text elements
Moderate
CVE-2026-71497
was published
for
org.jsoup:jsoup
(Maven)
Aug 6, 2026
league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes
Moderate
CVE-2026-71478
was published
for
league/commonmark
(Composer)
Aug 6, 2026
Silverstripe: XSS in breadcrumbs in page list view
Moderate
CVE-2026-54717
was published
for
silverstripe/cms
(Composer)
Aug 6, 2026
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template
Moderate
CVE-2026-71435
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Ghost: Cross-Site Scripting in Feature Image Captions
Moderate
CVE-2026-70596
was published
for
ghost
(npm)
Aug 5, 2026
Ghost: Cross-Site Scripting in Universal Import
Moderate
CVE-2026-70588
was published
for
ghost
(npm)
Aug 4, 2026
sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes
Moderate
CVE-2026-53606
was published
for
sanitize-html
(npm)
Jul 31, 2026
Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS
Moderate
CVE-2026-62324
was published
for
jodit
(npm)
Jul 31, 2026
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
Moderate
CVE-2026-62280
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Jul 24, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste
Moderate
GHSA-53g2-mvcc-q9x3
was published
for
action_text-trix
(RubyGems)
Jul 24, 2026
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
Moderate
GHSA-hc76-7mpc-qjqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
React Router: RSCErrorHandler Missing Protocol Validation (XSS)
Moderate
CVE-2026-53667
was published
for
react-router
(npm)
Jul 23, 2026
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Moderate
GHSA-cj75-f6xr-r4g7
was published
for
rails-html-sanitizer
(RubyGems)
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
Moderate
GHSA-9wjq-cp2p-hrgf
was published
for
loofah
(RubyGems)
Jul 21, 2026
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
Moderate
CVE-2026-59895
was published
for
hono
(npm)
Jul 21, 2026
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
Moderate
CVE-2026-59729
was published
for
astro
(npm)
Jul 20, 2026
Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
Moderate
CVE-2026-59929
was published
for
mistune
(pip)
Jul 20, 2026
Mistune: XSS via unescaped class option in Admonition directive
Moderate
CVE-2026-59926
was published
for
mistune
(pip)
Jul 20, 2026
Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
Moderate
CVE-2026-59923
was published
for
mistune
(pip)
Jul 20, 2026
Astro: Reflected XSS via unescaped View Transition animation properties
Moderate
GHSA-4g3v-8h47-v7g6
was published
for
astro
(npm)
Jul 20, 2026
Tornado vulnerable to Header Injection and XSS via reason argument
Moderate
CVE-2025-67724
was published
for
tornado
(pip)
Jul 20, 2026
GeoNode: Stored XSS to full account takeover
Moderate
CVE-2024-27091
was published
for
geonode
(pip)
Jul 13, 2026
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
Moderate
CVE-2026-54163
was published
for
secure_headers
(RubyGems)
Jul 10, 2026
YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html'))
Moderate
CVE-2026-52772
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
ProTip!
Advisories are also available from the
GraphQL API