Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,527 advisories

Loading
Duplicate Advisory: Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options Moderate
GHSA-f95g-vm94-46c3 was published for craftcms/cms (Composer) Jun 21, 2026 withdrawn
Duplicate Advisory: Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page Moderate
GHSA-9r7j-7jhg-4f4c was published for craftcms/cms (Composer) Jun 21, 2026 withdrawn
Craft CMS: Stored XSS in the control panel via unescaped draft name Moderate
GHSA-2rp4-x2j7-qmcc was published for craftcms/cms (Composer) Aug 6, 2026
je-lv Credited to je-lv
jsoup: Cleaner may expose markup with custom raw-text elements Moderate
CVE-2026-71497 was published for org.jsoup:jsoup (Maven) Aug 6, 2026
quitbug Credited to quitbug and jhy jhy jhy
Duplicate Advisory: Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type Moderate
GHSA-5w9j-w5p8-r4p7 was published for craftcms/cms (Composer) Jun 21, 2026 withdrawn
league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes Moderate
CVE-2026-71478 was published for league/commonmark (Composer) Aug 6, 2026
TungNGo02 Credited to TungNGo02
Silverstripe: XSS in breadcrumbs in page list view Moderate
CVE-2026-54717 was published for silverstripe/cms (Composer) Aug 6, 2026
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template Moderate
CVE-2026-71435 was published for statamic/cms (Composer) Aug 6, 2026
ya3raj Credited to ya3raj
Ghost: Cross-Site Scripting in Feature Image Captions Moderate
CVE-2026-70596 was published for ghost (npm) Aug 5, 2026
itamarperetz Credited to itamarperetz
Ghost: Cross-Site Scripting in Universal Import Moderate
CVE-2026-70588 was published for ghost (npm) Aug 4, 2026
koyokr Credited to koyokr
Apache Answer vulnerable to Cross-site Scripting Moderate
CVE-2026-34033 was published for github.com/apache/incubator-answer (Go) Jun 9, 2026
Spring Framework Cross-site Scripting via JSP Form Tags Moderate
CVE-2026-41846 was published for org.springframework:spring-webmvc (Maven) Jun 9, 2026
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page Moderate
CVE-2026-62280 was published for org.openidentityplatform.openam:openam-oauth2 (Maven) Jul 24, 2026
geo-chen Credited to geo-chen
Trix: Stored XSS via HTMLParser attribute injection on paste Moderate
GHSA-53g2-mvcc-q9x3 was published for action_text-trix (RubyGems) Jul 24, 2026
newbiefromcoma Credited to newbiefromcoma
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797 Moderate
GHSA-hc76-7mpc-qjqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
React Router: RSCErrorHandler Missing Protocol Validation (XSS) Moderate
CVE-2026-53667 was published for react-router (npm) Jul 23, 2026
unknownhad Credited to unknownhad
DOMPurify is vulnerable to mutation-XSS via Re-Contextualization Moderate
CVE-2026-65914 was published for dompurify (npm) Mar 27, 2026
researchatfluidattacks Credited to researchatfluidattacks, caverav, and tachote caverav caverav
tachote tachote
trace37labs Credited to trace37labs and EchoTydes EchoTydes EchoTydes
Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes Moderate
CVE-2026-28222 was published for wagtail (pip) Mar 3, 2026
GCXWLP Credited to GCXWLP, RealOrangeOne, and gasman RealOrangeOne RealOrangeOne
gasman gasman
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations Moderate
GHSA-cj75-f6xr-r4g7 was published for rails-html-sanitizer (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
Loofah: SVG `href` attribute bypasses local-reference restriction Moderate
GHSA-9wjq-cp2p-hrgf was published for loofah (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers Moderate
GHSA-75mw-h36v-2jv7 was published for dosage (pip) Jun 26, 2026
yueyueL Credited to yueyueL and krotname krotname krotname
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility Moderate
CVE-2026-59895 was published for hono (npm) Jul 21, 2026
a-tt-om Credited to a-tt-om and teebow1e teebow1e teebow1e
ProTip! Advisories are also available from the GraphQL API