Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

375 advisories

Loading
Mistune: XSS via unescaped class option in Admonition directive Moderate
CVE-2026-59926 was published for mistune (pip) Jul 20, 2026
sergeykochanov Credited to sergeykochanov
Mistune: XSS via percent-encoded javascript URI bypass in safe_url() Moderate
CVE-2026-59923 was published for mistune (pip) Jul 20, 2026
redyank Credited to redyank
Tornado vulnerable to Header Injection and XSS via reason argument Moderate
CVE-2025-67724 was published for tornado (pip) Jul 20, 2026
Finder16 Credited to Finder16 and Cheshire1225 Cheshire1225 Cheshire1225
GeoNode: Stored XSS to full account takeover Moderate
CVE-2024-27091 was published for geonode (pip) Jul 13, 2026
ImThatT Credited to ImThatT
Open WebUI allows limited stored XSS vila uploaded html file Moderate
CVE-2025-46571 was published for open-webui (pip) Jul 7, 2026
choket Credited to choket
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers Moderate
GHSA-75mw-h36v-2jv7 was published for dosage (pip) Jun 26, 2026
yueyueL Credited to yueyueL and krotname krotname krotname
justhtml: to_markdown() code-span blank-line breakout enables XSS Moderate
GHSA-jf6w-2mvx-633j was published for justhtml (pip) Jun 25, 2026
seankohjs Credited to seankohjs and yueyueL yueyueL yueyueL
marimo contains a reflected cross-site scripting vulnerability in the notebook page Moderate
CVE-2026-54386 was published for marimo (pip) Jun 18, 2026
Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes Moderate
GHSA-gj48-438w-jh9v was published for bleach (pip) Jun 16, 2026
BangbBros Credited to BangbBros
malla: Stored XSS via Meshtastic node names in multiple frontend pages Moderate
CVE-2026-43980 was published for malla (pip) Jun 3, 2026
tiagoabreu22 Credited to tiagoabreu22
Weblate: Stored HTML injection in editor search preview Moderate
CVE-2026-45106 was published for weblate (pip) May 15, 2026
adrgs Credited to adrgs, aisafe-bot, nijel, and KarenKonou aisafe-bot aisafe-bot
nijel nijel KarenKonou KarenKonou
foodlook Credited to foodlook
Open WebUI has Stored Cross-Site Scripting In Profile Picture Moderate
CVE-2026-45299 was published for open-webui (pip) May 14, 2026
raresvis Credited to raresvis, Gh05t666nero, and Classic298 Gh05t666nero Gh05t666nero
Classic298 Classic298
Mistune Image Directive CSS Injection Vulnerability Moderate
CVE-2026-44899 was published for mistune (pip) May 14, 2026
QiaoNPC Credited to QiaoNPC and Across-Verticals-Malaysia Across-Verticals-Malaysia Across-Verticals-Malaysia
Mistune TOC Anchor Injection XSS Moderate
CVE-2026-44898 was published for mistune (pip) May 14, 2026
QiaoNPC Credited to QiaoNPC and Across-Verticals-Malaysia Across-Verticals-Malaysia Across-Verticals-Malaysia
Firebasky Credited to Firebasky
Mistune Heading ID Attribute has Injection XSS Moderate
CVE-2026-44897 was published for mistune (pip) May 9, 2026
QiaoNPC Credited to QiaoNPC and Across-Verticals-Malaysia Across-Verticals-Malaysia Across-Verticals-Malaysia
Mistune has XSS via unescaped figclass/figwidth in Figure directive Moderate
CVE-2026-44896 was published for mistune (pip) May 8, 2026
sergeykochanov Credited to sergeykochanov
Mistune Math Plugin has an XSS Escape Bypass Moderate
CVE-2026-44708 was published for mistune (pip) May 8, 2026
QiaoNPC Credited to QiaoNPC and Across-Verticals-Malaysia Across-Verticals-Malaysia Across-Verticals-Malaysia
Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order Moderate
CVE-2026-44568 was published for open-webui (pip) May 8, 2026
morimori-dev Credited to morimori-dev and Classic298 Classic298 Classic298
Weblate vulnerable to XSS via crafted Markdown Moderate
CVE-2026-44264 was published for weblate (pip) May 7, 2026
nijel Credited to nijel
beets has a Cross-site Scripting vulnerability Moderate
CVE-2026-42052 was published for beets (pip) Apr 29, 2026
FORIMOC Credited to FORIMOC and nnin-nnin nnin-nnin nnin-nnin
wlc: print_html outputs API data without HTML escaping Moderate
CVE-2026-42150 was published for wlc (pip) Apr 24, 2026
fg0x0 Credited to fg0x0 and nijel nijel nijel
ProTip! Advisories are also available from the GraphQL API