GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,831
Maven
5,000+
npm
4,462
NuGet
775
pip
4,226
Pub
12
RubyGems
972
Rust
1,093
Swift
47
Unreviewed advisories
All unreviewed
5,000+
141 advisories
Filter by severity
svelte is vulnerable to XSS with textarea bind:value
High
GHSA-gw32-9rmw-qwww
was published
for
svelte
(npm)
Jan 16, 2026
Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
High
CVE-2026-22610
was published
for
@angular/compiler
(npm)
Jan 9, 2026
html2pdf.js contains a cross-site scripting vulnerability
High
CVE-2026-22787
was published
for
html2pdf.js
(npm)
Jan 14, 2026
HAXcms Has Stored XSS Vulnerability that May Lead to Account Takeover
High
CVE-2026-22704
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jan 13, 2026
React Router vulnerable to XSS via Open Redirects
High
CVE-2026-22029
was published
for
@remix-run/router
(npm)
Jan 8, 2026
React Router SSR XSS in ScrollRestoration
High
CVE-2026-21884
was published
for
@remix-run/react
(npm)
Jan 8, 2026
React Router has XSS Vulnerability
High
CVE-2025-59057
was published
for
@remix-run/react
(npm)
Jan 8, 2026
`vega-functions` vulnerable to Cross-site Scripting via `setdata` function
High
CVE-2025-66648
was published
for
vega-functions
(npm)
Jan 5, 2026
Vega XSS via expression abusing vlSelectionTuples function array map calls in environments with satisfactory function gadgets in the global scope
High
CVE-2025-65110
was published
for
vega-selections
(npm)
Jan 5, 2026
n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox
High
CVE-2025-61914
was published
for
n8n
(npm)
Dec 26, 2025
Open WebUI Vulnerable to Stored DOM XSS via Note 'Download PDF'
High
CVE-2025-65959
was published
for
open-webui
(npm)
Dec 4, 2025
Angular Stored XSS Vulnerability via SVG Animation, SVG URL and MathML Attributes
High
CVE-2025-66412
was published
for
@angular/compiler
(npm)
Dec 2, 2025
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
High
CVE-2025-64495
was published
for
open-webui
(npm)
Nov 7, 2025
Astro vulnerable to reflected XSS via the server islands feature
High
CVE-2025-64764
was published
for
astro
(npm)
Nov 19, 2025
Vega Cross-Site Scripting (XSS) via expressions abusing toString calls in environments using the VEGA_DEBUG global variable
High
CVE-2025-59840
was published
for
vega
(npm)
Nov 13, 2025
DOMpurify has a nesting-based mXSS
High
CVE-2024-47875
was published
for
dompurify
(npm)
Oct 11, 2024
Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
High
CVE-2025-59837
was published
for
astro
(npm)
Oct 28, 2025
Cross-site Scripting (XSS) in @scullyio/scully
High
CVE-2020-28470
was published
for
@scullyio/ng-lib
(npm)
Apr 13, 2021
Duplicate Advisory: Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
High
GHSA-7rgr-72hp-9wp3
was published
for
flowise
(npm)
Oct 6, 2025
•
withdrawn
Duplicate Advisory: Flowise Stored XSS vulnerability through logs in chatbot
High
GHSA-wq95-wr7m-26h4
was published
for
flowise
(npm)
Oct 6, 2025
•
withdrawn
MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server
High
CVE-2025-58444
was published
for
@modelcontextprotocol/inspector
(npm)
Sep 8, 2025
Mesh Connect JS SDK Vulnerable to Cross Site Scripting via createLink.openLink
High
CVE-2025-59430
was published
for
@meshconnect/web-link-sdk
(npm)
Sep 22, 2025
Webrecorder packages are vulnerable to XSS through 404 error handling logic
High
CVE-2025-58765
was published
for
@webrecorder/archivewebpage
(npm)
Sep 10, 2025
N8N's Chat Trigger component is vulnerable to XSS
High
CVE-2025-56265
was published
for
@n8n/n8n-nodes-langchain
(npm)
Sep 8, 2025
NocoDB Vulnerable to Stored Cross-Site Scripting in Formula.vue
High
CVE-2023-49781
was published
for
nocodb
(npm)
May 13, 2024
ProTip!
Advisories are also available from the
GraphQL API