GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,630
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,850
Pub
13
RubyGems
1,045
Rust
1,301
Swift
53
Unreviewed advisories
All unreviewed
5,000+
231 advisories
Filter by severity
goldmark vulnerable to Cross-site Scripting (XSS)
Moderate
CVE-2026-5160
was published
for
github.com/yuin/goldmark/renderer/html
(Go)
Apr 17, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering
Moderate
CVE-2026-40302
was published
for
github.com/openziti/zrok
(Go)
Apr 16, 2026
SiYuan has incomplete fix for CVE-2026-33066: XSS
Moderate
CVE-2026-40922
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Apr 14, 2026
Note Mark has Stored XSS via Unrestricted Asset Upload
High
CVE-2026-40262
was published
for
github.com/enchant97/note-mark/backend
(Go)
Apr 13, 2026
Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorer
Moderate
CVE-2026-40179
was published
for
github.com/prometheus/prometheus
(Go)
Apr 13, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications
Moderate
CVE-2026-35600
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
SiYuan: Remote Code Execution in the Electron desktop client via stored XSS in synced table captions
Critical
CVE-2026-39846
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Apr 8, 2026
Hugo: Certain markdown links are not properly escaped
Moderate
CVE-2026-35166
was published
for
github.com/gohugoio/hugo
(Go)
Apr 3, 2026
Casdoor vulnerable to Stored XSS via Application formCss / formSideHtml
Low
CVE-2026-5468
was published
for
github.com/casdoor/casdoor
(Go)
Apr 3, 2026
SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon, unauthenticated)
High
CVE-2026-34605
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Apr 1, 2026
SiYuan Desktop: Stored XSS in imported .sy.zip content leads to arbitrary command execution
High
CVE-2026-34585
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Apr 1, 2026
File Browser vulnerable to Stored Cross-site Scripting via text/template branding injection
Moderate
CVE-2026-34530
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 31, 2026
File Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB file
High
CVE-2026-34529
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 31, 2026
SiYuan: Stored XSS in Attribute View Gallery/Kanban Cover Rendering Allows Arbitrary Command Execution in Desktop Client
Critical
CVE-2026-34448
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 31, 2026
Authelia: Improper Neutralization of Input During Web Page Generation Leads to Potential Cross-site Scripting
Low
CVE-2026-33525
was published
for
github.com/authelia/authelia/v4
(Go)
Mar 24, 2026
mo has a XSS via inline SVG script tags in Markdown rendering
Low
GHSA-vccx-p757-pv6h
was published
for
github.com/k1LoW/mo
(Go)
Mar 18, 2026
SiYuan has Stored XSS to RCE via Unsanitized Bazaar Package Metadata
Moderate
CVE-2026-33067
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 18, 2026
SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering
Moderate
CVE-2026-33066
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 18, 2026
SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183)
Critical
CVE-2026-32940
was published
for
github.com/siyuan-note/siyuan
(Go)
Mar 17, 2026
SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
Moderate
GHSA-v3mg-9v85-fcm7
was published
for
siyuan
(Go)
Mar 16, 2026
SiYuan Vulnerable to Remote Code Execution via Stored XSS in Notebook Name - Mobile Interface
Moderate
CVE-2026-32751
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 16, 2026
SiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS
Moderate
CVE-2026-31809
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 10, 2026
SiYuan has a SVG Sanitizer Bypass via `<animate>` Element — Unauthenticated XSS
Moderate
CVE-2026-31807
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 10, 2026
FileBrowser Quantum: Stored XSS in public share page via unsanitized share metadata (text/template misuse)
High
CVE-2026-30934
was published
for
github.com/gtsteffaniak/filebrowser
(Go)
Mar 9, 2026
Gogs: DOM-based XSS via milestone selection
High
CVE-2026-26276
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
ProTip!
Advisories are also available from the
GraphQL API