Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,763 advisories

Loading
Craft CMS: Stored XSS in the control panel via unescaped draft name Moderate
GHSA-2rp4-x2j7-qmcc was published for craftcms/cms (Composer) Aug 6, 2026
je-lv Credited to je-lv
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF High
CVE-2026-16633 was published for pdfjs-dist (npm) Aug 6, 2026
wlayzz Credited to wlayzz
jsoup: Cleaner may expose markup with custom raw-text elements Moderate
CVE-2026-71497 was published for org.jsoup:jsoup (Maven) Aug 6, 2026
quitbug Credited to quitbug and jhy jhy jhy
league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes Moderate
CVE-2026-71478 was published for league/commonmark (Composer) Aug 6, 2026
TungNGo02 Credited to TungNGo02
Silverstripe: XSS in breadcrumbs in page list view Moderate
CVE-2026-54717 was published for silverstripe/cms (Composer) Aug 6, 2026
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template Moderate
CVE-2026-71435 was published for statamic/cms (Composer) Aug 6, 2026
ya3raj Credited to ya3raj
Ghost: Cross-Site Scripting in Feature Image Captions Moderate
CVE-2026-70596 was published for ghost (npm) Aug 5, 2026
itamarperetz Credited to itamarperetz
XSS in Ghost's ActivityPub client High
CVE-2026-53950 was published for @tryghost/activitypub (npm) Aug 4, 2026
bgeesaman Credited to bgeesaman
Ghost: Cross-Site Scripting in Universal Import Moderate
CVE-2026-70588 was published for ghost (npm) Aug 4, 2026
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages High
CVE-2026-70492 was published for open-webui (pip) Aug 4, 2026
maxntv Credited to maxntv and Classic298 Classic298 Classic298
manus-use Credited to manus-use and Classic298 Classic298 Classic298
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes High
CVE-2026-69151 was published for @angular/compiler (npm) Aug 3, 2026
Hexix23 Credited to Hexix23, alan-agius4, and JeanMeche alan-agius4 alan-agius4
JeanMeche JeanMeche
Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS) High
CVE-2026-69149 was published for @angular/platform-server (npm) Aug 3, 2026
SkyZeroZx Credited to SkyZeroZx and alan-agius4 alan-agius4 alan-agius4
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag High
CVE-2026-53608 was published for @apostrophecms/seo (npm) Jul 31, 2026
H3xV0rT3x Credited to H3xV0rT3x
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier High
CVE-2026-58263 was published for jodit (npm) Jul 31, 2026
koyokr Credited to koyokr
koyokr Credited to koyokr
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS Low
CVE-2026-52838 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
OmniFaces: Forged combined-resource IDs and related output/push boundaries High
GHSA-fp43-vj7g-pg92 was published for org.omnifaces:omnifaces (Maven) Jul 24, 2026
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page Moderate
CVE-2026-62280 was published for org.openidentityplatform.openam:openam-oauth2 (Maven) Jul 24, 2026
geo-chen Credited to geo-chen
Open WebUI: Stored web worker XSS via Pyodide High
CVE-2026-59214 was published for open-webui (pip) Jul 24, 2026
gg0h Credited to gg0h and Classic298 Classic298 Classic298
Trix: Stored XSS via HTMLParser attribute injection on paste Moderate
GHSA-53g2-mvcc-q9x3 was published for action_text-trix (RubyGems) Jul 24, 2026
newbiefromcoma Credited to newbiefromcoma
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797 Moderate
GHSA-hc76-7mpc-qjqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
React Router: RSCErrorHandler Missing Protocol Validation (XSS) Moderate
CVE-2026-53667 was published for react-router (npm) Jul 23, 2026
unknownhad Credited to unknownhad
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) High
GHSA-pppj-hq3g-57pj was published for jupyterlab (pip) Jul 22, 2026
de3erve-hunter Credited to de3erve-hunter, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
ProTip! Advisories are also available from the GraphQL API