Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

375 advisories

Loading
Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes Moderate
CVE-2026-28222 was published for wagtail (pip) Mar 3, 2026
GCXWLP Credited to GCXWLP, RealOrangeOne, and gasman RealOrangeOne RealOrangeOne
gasman gasman
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers Moderate
GHSA-75mw-h36v-2jv7 was published for dosage (pip) Jun 26, 2026
yueyueL Credited to yueyueL and krotname krotname krotname
Mistune: XSS via unescaped class option in Admonition directive Moderate
CVE-2026-59926 was published for mistune (pip) Jul 20, 2026
sergeykochanov Credited to sergeykochanov
Mistune: XSS via percent-encoded javascript URI bypass in safe_url() Moderate
CVE-2026-59923 was published for mistune (pip) Jul 20, 2026
redyank Credited to redyank
Tornado vulnerable to Header Injection and XSS via reason argument Moderate
CVE-2025-67724 was published for tornado (pip) Jul 20, 2026
Finder16 Credited to Finder16 and Cheshire1225 Cheshire1225 Cheshire1225
Dash apps vulnerable to Cross-site Scripting Moderate
CVE-2024-21485 was published for dash (npm) Feb 2, 2024
graingert Credited to graingert
GeoNode: Stored XSS to full account takeover Moderate
CVE-2024-27091 was published for geonode (pip) Jul 13, 2026
ImThatT Credited to ImThatT
Open WebUI allows limited stored XSS vila uploaded html file Moderate
CVE-2025-46571 was published for open-webui (pip) Jul 7, 2026
choket Credited to choket
justhtml: to_markdown() code-span blank-line breakout enables XSS Moderate
GHSA-jf6w-2mvx-633j was published for justhtml (pip) Jun 25, 2026
seankohjs Credited to seankohjs and yueyueL yueyueL yueyueL
beets has a Cross-site Scripting vulnerability Moderate
CVE-2026-42052 was published for beets (pip) Apr 29, 2026
FORIMOC Credited to FORIMOC and nnin-nnin nnin-nnin nnin-nnin
marimo contains a reflected cross-site scripting vulnerability in the notebook page Moderate
CVE-2026-54386 was published for marimo (pip) Jun 18, 2026
Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes Moderate
GHSA-gj48-438w-jh9v was published for bleach (pip) Jun 16, 2026
BangbBros Credited to BangbBros
Weblate: Stored HTML injection in editor search preview Moderate
CVE-2026-45106 was published for weblate (pip) May 15, 2026
adrgs Credited to adrgs, aisafe-bot, nijel, and KarenKonou aisafe-bot aisafe-bot
nijel nijel KarenKonou KarenKonou
Tendenci CMS contains a stored Cross-site Scripting (XSS) vulnerability in the Forums module Moderate
CVE-2025-70960 was published for tendenci (pip) Feb 3, 2026
Tendenci CMS Contains a Cross-site Scripting Vulnerability in its Jobs Module Moderate
CVE-2025-70959 was published for tendenci (pip) Feb 3, 2026
Cross-site Scripting in wagtail Moderate
CVE-2021-32681 was published for wagtail (pip) Jun 17, 2021
django CMS Cross-Site Scripting (XSS) Moderate
CVE-2024-11319 was published for django-cms (pip) Nov 18, 2024
django CMS Attributes Field Cross-site Scripting Moderate
CVE-2024-11406 was published for djangocms-attributes-field (pip) Nov 20, 2024
Dask Distributed is Vulnerable to Remote Code Execution via Jupyter Proxy and Dashboard Moderate
CVE-2026-23528 was published for distributed (pip) Jan 16, 2026
Firebasky Credited to Firebasky
Mistune has XSS via unescaped figclass/figwidth in Figure directive Moderate
CVE-2026-44896 was published for mistune (pip) May 8, 2026
sergeykochanov Credited to sergeykochanov
Mistune Image Directive CSS Injection Vulnerability Moderate
CVE-2026-44899 was published for mistune (pip) May 14, 2026
QiaoNPC Credited to QiaoNPC and Across-Verticals-Malaysia Across-Verticals-Malaysia Across-Verticals-Malaysia
Mistune TOC Anchor Injection XSS Moderate
CVE-2026-44898 was published for mistune (pip) May 14, 2026
QiaoNPC Credited to QiaoNPC and Across-Verticals-Malaysia Across-Verticals-Malaysia Across-Verticals-Malaysia
ProTip! Advisories are also available from the GraphQL API