Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,999 advisories

Loading
Craft CMS: Stored XSS in the control panel via unescaped draft name Moderate
GHSA-2rp4-x2j7-qmcc was published for craftcms/cms (Composer) Aug 6, 2026
je-lv Credited to je-lv
league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes Moderate
CVE-2026-71478 was published for league/commonmark (Composer) Aug 6, 2026
TungNGo02 Credited to TungNGo02
Silverstripe: XSS in breadcrumbs in page list view Moderate
CVE-2026-54717 was published for silverstripe/cms (Composer) Aug 6, 2026
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template Moderate
CVE-2026-71435 was published for statamic/cms (Composer) Aug 6, 2026
ya3raj Credited to ya3raj
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS Low
CVE-2026-52838 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
MantisBT: Stored XSS in print_all_bug_page_word.php High
CVE-2026-62944 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
dracosectech-code Credited to dracosectech-code and dregad dregad dregad
MantisBT: Reflected XSS in admin/install.php via unescaped printf Critical
CVE-2026-52881 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
McCaulay Credited to McCaulay and dregad dregad dregad
MantisBT: Reflected XSS in admin/install.php Critical
CVE-2026-52847 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
McCaulay Credited to McCaulay and dregad dregad dregad
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField High
CVE-2026-54087 was published for easycorp/easyadmin-bundle (Composer) Jul 14, 2026
NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module High
CVE-2026-54064 was published for nukeviet/nukeviet (Composer) Jul 13, 2026
hoaquynhtim99 Credited to hoaquynhtim99 and g03m0n g03m0n g03m0n
NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High
CVE-2026-49259 was published for nukeviet/nukeviet (Composer) Jul 13, 2026
0xGunrunner Credited to 0xGunrunner
NukeViet: Unauthenticated Reflected XSS in Comment Module High
CVE-2026-48118 was published for nukeviet/nukeviet (Composer) Jul 13, 2026
hoaquynhtim99 Credited to hoaquynhtim99 and 0xGunrunner 0xGunrunner 0xGunrunner
YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html')) Moderate
CVE-2026-52772 was published for yeswiki/yeswiki (Composer) Jul 9, 2026
offset Credited to offset
Craft CMS: Stored XSS via Structure entry title in table view Moderate
CVE-2026-55793 was published for craftcms/cms (Composer) Jul 6, 2026
Crypto-Cat Credited to Crypto-Cat
Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget High
CVE-2026-55790 was published for craftcms/cms (Composer) Jul 6, 2026
Crypto-Cat Credited to Crypto-Cat
Mautic has Stored Cross-Site Scripting (XSS) in Project Option Selector Moderate
CVE-2026-9811 was published for mautic/core (Composer) Jul 2, 2026
pavelkohout396 Credited to pavelkohout396, escopecz, patrykgruszka, and LeuchtfeuerDigitalMarketing escopecz escopecz
patrykgruszka patrykgruszka LeuchtfeuerDigitalMarketing LeuchtfeuerDigitalMarketing
Mautic has Stored Cross-Site Scripting (XSS) in Projects Component High
CVE-2026-9809 was published for mautic/core (Composer) Jul 2, 2026
34selen Credited to 34selen, escopecz, patrykgruszka, and LeuchtfeuerDigitalMarketing escopecz escopecz
patrykgruszka patrykgruszka LeuchtfeuerDigitalMarketing LeuchtfeuerDigitalMarketing
mediawiki/maps has stored XSS through the overlays parameter in the display_map parser function High
CVE-2026-52854 was published for mediawiki/maps (Composer) Jul 2, 2026
SomeMWDev Credited to SomeMWDev, NGoedix, h1david96, and archyxsec NGoedix NGoedix
h1david96 h1david96 archyxsec archyxsec
Schema.org has cross-site scripting (XSS) via script break-out in toScript() output Low
GHSA-hwmc-r6mf-jh83 was published for spatie/schema-org (Composer) Jul 1, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components Moderate
GHSA-2wwr-9x6f-88gp was published for easycorp/easyadmin-bundle (Composer) Jul 1, 2026
Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS Moderate
CVE-2026-48167 was published for filament/infolists (Composer) Jun 23, 2026
wsparks-vc Credited to wsparks-vc and danharrin danharrin danharrin
Slim has Reflected XSS in the HtmlErrorRenderer Moderate
CVE-2026-48157 was published for slim/slim (Composer) Jun 23, 2026
0xEr3n Credited to 0xEr3n
tonghuaroot Credited to tonghuaroot
Duplicate Advisory: Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options Moderate
GHSA-f95g-vm94-46c3 was published for craftcms/cms (Composer) Jun 21, 2026 withdrawn
ProTip! Advisories are also available from the GraphQL API