GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
375 advisories
Filter by severity
Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes
Moderate
CVE-2026-28222
was published
for
wagtail
(pip)
Mar 3, 2026
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers
Moderate
GHSA-75mw-h36v-2jv7
was published
for
dosage
(pip)
Jun 26, 2026
Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
Moderate
CVE-2026-59929
was published
for
mistune
(pip)
Jul 20, 2026
Mistune: XSS via unescaped class option in Admonition directive
Moderate
CVE-2026-59926
was published
for
mistune
(pip)
Jul 20, 2026
Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
Moderate
CVE-2026-59923
was published
for
mistune
(pip)
Jul 20, 2026
Mezzanine CMS has a Stored Cross-Site Scripting (XSS) vulnerability in the displayable_links_js function
Moderate
CVE-2025-6050
was published
for
Mezzanine
(pip)
Jun 17, 2025
Tornado vulnerable to Header Injection and XSS via reason argument
Moderate
CVE-2025-67724
was published
for
tornado
(pip)
Jul 20, 2026
Dash apps vulnerable to Cross-site Scripting
Moderate
CVE-2024-21485
was published
for
dash
(npm)
Feb 2, 2024
GeoNode: Stored XSS to full account takeover
Moderate
CVE-2024-27091
was published
for
geonode
(pip)
Jul 13, 2026
Open WebUI allows limited stored XSS vila uploaded html file
Moderate
CVE-2025-46571
was published
for
open-webui
(pip)
Jul 7, 2026
justhtml: to_markdown() code-span blank-line breakout enables XSS
Moderate
GHSA-jf6w-2mvx-633j
was published
for
justhtml
(pip)
Jun 25, 2026
beets has a Cross-site Scripting vulnerability
Moderate
CVE-2026-42052
was published
for
beets
(pip)
Apr 29, 2026
marimo contains a reflected cross-site scripting vulnerability in the notebook page
Moderate
CVE-2026-54386
was published
for
marimo
(pip)
Jun 18, 2026
Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
Moderate
GHSA-gj48-438w-jh9v
was published
for
bleach
(pip)
Jun 16, 2026
Weblate: Stored HTML injection in editor search preview
Moderate
CVE-2026-45106
was published
for
weblate
(pip)
May 15, 2026
Tendenci CMS contains a stored Cross-site Scripting (XSS) vulnerability in the Forums module
Moderate
CVE-2025-70960
was published
for
tendenci
(pip)
Feb 3, 2026
Tendenci CMS Contains a Cross-site Scripting Vulnerability in its Jobs Module
Moderate
CVE-2025-70959
was published
for
tendenci
(pip)
Feb 3, 2026
Cross-site Scripting in wagtail
Moderate
CVE-2021-32681
was published
for
wagtail
(pip)
Jun 17, 2021
django CMS Cross-Site Scripting (XSS)
Moderate
CVE-2024-11319
was published
for
django-cms
(pip)
Nov 18, 2024
django CMS Attributes Field Cross-site Scripting
Moderate
CVE-2024-11406
was published
for
djangocms-attributes-field
(pip)
Nov 20, 2024
Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard
Moderate
CVE-2026-23528
was published
for
distributed
(pip)
Jan 16, 2026
local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)
Moderate
CVE-2026-43979
was published
for
local-deep-research
(pip)
May 11, 2026
Mistune has XSS via unescaped figclass/figwidth in Figure directive
Moderate
CVE-2026-44896
was published
for
mistune
(pip)
May 8, 2026
Mistune Image Directive CSS Injection Vulnerability
Moderate
CVE-2026-44899
was published
for
mistune
(pip)
May 14, 2026
Mistune TOC Anchor Injection XSS
Moderate
CVE-2026-44898
was published
for
mistune
(pip)
May 14, 2026
ProTip!
Advisories are also available from the
GraphQL API