Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,999 advisories

Loading
Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options Low
CVE-2026-56393 was published for craftcms/cms (Composer) Mar 3, 2026
mHe4am Credited to mHe4am
Duplicate Advisory: Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options Moderate
GHSA-f95g-vm94-46c3 was published for craftcms/cms (Composer) Jun 21, 2026 withdrawn
Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page Low
CVE-2026-56381 was published for craftcms/cms (Composer) Mar 11, 2026
mHe4am Credited to mHe4am
Duplicate Advisory: Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page Moderate
GHSA-9r7j-7jhg-4f4c was published for craftcms/cms (Composer) Jun 21, 2026 withdrawn
Craft CMS: Stored XSS in the control panel via unescaped draft name Moderate
GHSA-2rp4-x2j7-qmcc was published for craftcms/cms (Composer) Aug 6, 2026
je-lv Credited to je-lv
Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type Low
CVE-2026-56383 was published for craftcms/cms (Composer) Feb 25, 2026
mHe4am Credited to mHe4am
Duplicate Advisory: Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type Moderate
GHSA-5w9j-w5p8-r4p7 was published for craftcms/cms (Composer) Jun 21, 2026 withdrawn
league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes Moderate
CVE-2026-71478 was published for league/commonmark (Composer) Aug 6, 2026
TungNGo02 Credited to TungNGo02
Silverstripe: XSS in breadcrumbs in page list view Moderate
CVE-2026-54717 was published for silverstripe/cms (Composer) Aug 6, 2026
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template Moderate
CVE-2026-71435 was published for statamic/cms (Composer) Aug 6, 2026
ya3raj Credited to ya3raj
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS Low
CVE-2026-52838 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
TYPO3 Cross-Site Scripting in Fluid ViewHelpers Moderate
GHSA-22q7-cg4r-p9mx was published for typo3/cms-fluid (Composer) May 30, 2024
RainSignal Credited to RainSignal
TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments High
CVE-2026-47762 was published for TinyMCE (Composer) Jun 5, 2026
he1d3n Credited to he1d3n and bluvulture bluvulture bluvulture
MantisBT: Stored XSS in print_all_bug_page_word.php High
CVE-2026-62944 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
dracosectech-code Credited to dracosectech-code and dregad dregad dregad
MantisBT: Reflected XSS in admin/install.php via unescaped printf Critical
CVE-2026-52881 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
McCaulay Credited to McCaulay and dregad dregad dregad
MantisBT: Reflected XSS in admin/install.php Critical
CVE-2026-52847 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
McCaulay Credited to McCaulay and dregad dregad dregad
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField High
CVE-2026-54087 was published for easycorp/easyadmin-bundle (Composer) Jul 14, 2026
NukeViet: Multiple Anti-XSS Filter Bypasses Leading to Stored XSS in News Module High
CVE-2026-54064 was published for nukeviet/nukeviet (Composer) Jul 13, 2026
hoaquynhtim99 Credited to hoaquynhtim99 and g03m0n g03m0n g03m0n
NukeViet: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High
CVE-2026-49259 was published for nukeviet/nukeviet (Composer) Jul 13, 2026
0xGunrunner Credited to 0xGunrunner
NukeViet: Unauthenticated Reflected XSS in Comment Module High
CVE-2026-48118 was published for nukeviet/nukeviet (Composer) Jul 13, 2026
hoaquynhtim99 Credited to hoaquynhtim99 and 0xGunrunner 0xGunrunner 0xGunrunner
YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html')) Moderate
CVE-2026-52772 was published for yeswiki/yeswiki (Composer) Jul 9, 2026
offset Credited to offset
Potential XSS vulnerability in jQuery Moderate
CVE-2020-11022 was published for athlon1600/youtube-downloader (RubyGems) Apr 29, 2020
masatokinugawa Credited to masatokinugawa, Churro, Rudloff, sealonohana, and Athlon1600 Churro Churro
Rudloff Rudloff sealonohana sealonohana Athlon1600 Athlon1600
TypiCMS Core has Stored Cross-Site Scripting (XSS) via SVG File Upload Moderate
CVE-2026-27621 was published for typicms/core (Composer) Feb 25, 2026
lukasz-rybak Credited to lukasz-rybak and sdebacker sdebacker sdebacker
mtrill47 Credited to mtrill47 and he1d3n he1d3n he1d3n
ProTip! Advisories are also available from the GraphQL API