GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
200 advisories
Filter by severity
TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments
High
CVE-2026-47762
was published
for
TinyMCE
(Composer)
Jun 5, 2026
MantisBT: Stored XSS in print_all_bug_page_word.php
High
CVE-2026-62944
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
High
CVE-2026-54087
was published
for
easycorp/easyadmin-bundle
(Composer)
Jul 14, 2026
NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module
High
CVE-2026-54064
was published
for
nukeviet/nukeviet
(Composer)
Jul 13, 2026
NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
High
CVE-2026-49259
was published
for
nukeviet/nukeviet
(Composer)
Jul 13, 2026
NukeViet: Unauthenticated Reflected XSS in Comment Module
High
CVE-2026-48118
was published
for
nukeviet/nukeviet
(Composer)
Jul 13, 2026
TinyMCE Cross-Site Scripting (XSS) vulnerability using through data-mce- prefixed src, href, style attributes
High
CVE-2026-47759
was published
for
TinyMCE
(Composer)
Jun 5, 2026
Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget
High
CVE-2026-55790
was published
for
craftcms/cms
(Composer)
Jul 6, 2026
Mautic has Stored Cross-Site Scripting (XSS) in Projects Component
High
CVE-2026-9809
was published
for
mautic/core
(Composer)
Jul 2, 2026
mediawiki/maps has stored XSS through the overlays parameter in the display_map parser function
High
CVE-2026-52854
was published
for
mediawiki/maps
(Composer)
Jul 2, 2026
TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection
High
CVE-2026-47761
was published
for
TinyMCE
(Composer)
Jun 5, 2026
Concrete CMS has Stored XSS through its height parameter
High
CVE-2026-8203
was published
for
concrete5/concrete5
(Composer)
May 21, 2026
Concrete CMS is vulnerable to Stored XSS via OAuth integration name
High
CVE-2026-8197
was published
for
concrete5/concrete5
(Composer)
May 21, 2026
StarCitizenWiki Extension Embed Video: Stored XSS via malformed src url with $wgEmbedVideoRequireConsent enabled
High
CVE-2026-55692
was published
for
starcitizenwiki/embedvideo
(Composer)
Jun 19, 2026
StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized class passed to template
High
CVE-2026-55691
was published
for
starcitizenwiki/embedvideo
(Composer)
Jun 19, 2026
StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized service name in exception text
High
CVE-2026-55690
was published
for
starcitizenwiki/embedvideo
(Composer)
Jun 19, 2026
Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module
High
CVE-2026-55746
was published
for
cotonti/cotonti
(Composer)
Jun 18, 2026
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
High
CVE-2026-54002
was published
for
getkirby/cms
(Composer)
Jun 18, 2026
Filament: Disabled RichEditor field state can be used for XSS
High
CVE-2026-55409
was published
for
filament/forms
(Composer)
Jun 17, 2026
ipl/web is vulnerable to reflected XSS by malformed search requests
High
CVE-2026-42224
was published
for
ipl/web
(Composer)
Apr 29, 2026
MantisBT Vulnerable to Stored XSS in File Download
High
CVE-2026-44657
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
MantisBT has Stored XSS on Move Attachments Admin Page
High
CVE-2026-44655
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
Duplicate Advisory: phpMyFAQ has stored XSS via | raw Filter in search.twig — html_entity_decode(strip_tags()) Bypass in Search Result Rendering
High
GHSA-478m-mrw4-qf2w
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 15, 2026
•
withdrawn
phpMyFAQ has stored XSS via Utils::parseUrl() in comment rendering
High
CVE-2026-46367
was published
for
phpmyfaq/phpmyfaq
(Composer)
May 6, 2026
Duplicate Advisory: phpMyFAQ: Stored XSS via Utils::parseUrl() in comment rendering
High
GHSA-w42g-jj8w-fj77
was published
for
phpMyFAQ/phpMyFAQ
(Composer)
May 15, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API