GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
3,527 advisories
Filter by severity
Duplicate Advisory: Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options
Moderate
GHSA-f95g-vm94-46c3
was published
for
craftcms/cms
(Composer)
Jun 21, 2026
•
withdrawn
Duplicate Advisory: Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page
Moderate
GHSA-9r7j-7jhg-4f4c
was published
for
craftcms/cms
(Composer)
Jun 21, 2026
•
withdrawn
Craft CMS: Stored XSS in the control panel via unescaped draft name
Moderate
GHSA-2rp4-x2j7-qmcc
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
jsoup: Cleaner may expose markup with custom raw-text elements
Moderate
CVE-2026-71497
was published
for
org.jsoup:jsoup
(Maven)
Aug 6, 2026
Duplicate Advisory: Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type
Moderate
GHSA-5w9j-w5p8-r4p7
was published
for
craftcms/cms
(Composer)
Jun 21, 2026
•
withdrawn
league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes
Moderate
CVE-2026-71478
was published
for
league/commonmark
(Composer)
Aug 6, 2026
Silverstripe: XSS in breadcrumbs in page list view
Moderate
CVE-2026-54717
was published
for
silverstripe/cms
(Composer)
Aug 6, 2026
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template
Moderate
CVE-2026-71435
was published
for
statamic/cms
(Composer)
Aug 6, 2026
Ghost: Cross-Site Scripting in Feature Image Captions
Moderate
CVE-2026-70596
was published
for
ghost
(npm)
Aug 5, 2026
Ghost: Cross-Site Scripting in Universal Import
Moderate
CVE-2026-70588
was published
for
ghost
(npm)
Aug 4, 2026
sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes
Moderate
CVE-2026-53606
was published
for
sanitize-html
(npm)
Jul 31, 2026
Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS
Moderate
CVE-2026-62324
was published
for
jodit
(npm)
Jul 31, 2026
Apache Answer vulnerable to Cross-site Scripting
Moderate
CVE-2026-34033
was published
for
github.com/apache/incubator-answer
(Go)
Jun 9, 2026
Spring Framework Cross-site Scripting via JSP Form Tags
Moderate
CVE-2026-41846
was published
for
org.springframework:spring-webmvc
(Maven)
Jun 9, 2026
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
Moderate
CVE-2026-62280
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Jul 24, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste
Moderate
GHSA-53g2-mvcc-q9x3
was published
for
action_text-trix
(RubyGems)
Jul 24, 2026
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797
Moderate
GHSA-hc76-7mpc-qjqh
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
React Router: RSCErrorHandler Missing Protocol Validation (XSS)
Moderate
CVE-2026-53667
was published
for
react-router
(npm)
Jul 23, 2026
DOMPurify is vulnerable to mutation-XSS via Re-Contextualization
Moderate
CVE-2026-65914
was published
for
dompurify
(npm)
Mar 27, 2026
DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)
Moderate
CVE-2026-65898
was published
for
dompurify
(npm)
Jun 18, 2026
Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes
Moderate
CVE-2026-28222
was published
for
wagtail
(pip)
Mar 3, 2026
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Moderate
GHSA-cj75-f6xr-r4g7
was published
for
rails-html-sanitizer
(RubyGems)
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
Moderate
GHSA-9wjq-cp2p-hrgf
was published
for
loofah
(RubyGems)
Jul 21, 2026
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
Moderate
GHSA-75mw-h36v-2jv7
was published
for
dosage
(pip)
Jun 26, 2026
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
Moderate
CVE-2026-59895
was published
for
hono
(npm)
Jul 21, 2026
ProTip!
Advisories are also available from the
GraphQL API