GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
34 advisories
Filter by severity
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
High
CVE-2026-54070
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jul 10, 2026
Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing
High
CVE-2026-48788
was published
for
github.com/umputun/remark42
(Go)
Jun 26, 2026
Gogs has Stored XSS in `.ipynb` Preview
High
CVE-2026-52798
was published
for
gogs.io/gogs
(Go)
Jun 22, 2026
Gitea: Stored XSS via glTF `extensionsRequired` in Gitea 3D File Viewer
High
CVE-2026-28737
was published
for
code.gitea.io/gitea
(Go)
Jun 17, 2026
Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
High
CVE-2026-45738
was published
for
github.com/argoproj/argo-cd
(Go)
May 19, 2026
Arcane Backend: Unauthenticated reflected XSS via SVG color parameter enables admin account takeover
High
CVE-2026-45627
was published
for
github.com/getarcaneapp/arcane/backend
(Go)
May 18, 2026
Note Mark has Stored XSS via Unrestricted Asset Upload
High
CVE-2026-40262
was published
for
github.com/enchant97/note-mark/backend
(Go)
Apr 13, 2026
SiYuan vulnerable to reflected XSS via SVG namespace prefix bypass in SanitizeSVG (getDynamicIcon, unauthenticated)
High
CVE-2026-34605
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Apr 1, 2026
SiYuan Desktop: Stored XSS in imported .sy.zip content leads to arbitrary command execution
High
CVE-2026-34585
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Apr 1, 2026
File Browser is vulnerable to Stored Cross-site Scripting via crafted EPUB file
High
CVE-2026-34529
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 31, 2026
FileBrowser Quantum: Stored XSS in public share page via unsanitized share metadata (text/template misuse)
High
CVE-2026-30934
was published
for
github.com/gtsteffaniak/filebrowser
(Go)
Mar 9, 2026
Gogs: DOM-based XSS via milestone selection
High
CVE-2026-26276
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
Gogs: Stored XSS via data URI in issue comments
High
CVE-2026-26022
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
Gokapi has Stored XSS in SVG Hotlinks
High
CVE-2026-28683
was published
for
github.com/forceu/gokapi
(Go)
Mar 5, 2026
ZITADEL: Stored XSS via Default URI Redirect Leads to Account Takeover
High
CVE-2026-29192
was published
for
github.com/zitadel/zitadel
(Go)
Mar 4, 2026
Vikunja: Stored XSS via Unsanitized SVG Attachment Upload Leads to Token Exposure
High
CVE-2026-27616
was published
for
code.vikunja.io/api
(Go)
Feb 25, 2026
New API has Potential XSS in its MarkdownRenderer component
High
CVE-2026-25802
was published
for
github.com/QuantumNous/new-api
(Go)
Feb 23, 2026
Vikunja Vulnerable to XSS Via Task Preview
High
CVE-2026-25935
was published
for
code.vikunja.io/api
(Go)
Feb 11, 2026
Gogs vulnerable to Stored XSS via Mermaid diagrams
High
GHSA-26gq-grmh-6xm6
was published
for
gogs.io/gogs
(Go)
Feb 6, 2026
Mattermost Confluence plugin doesn't properly escape user-controlled display names in HTML template rendering
High
CVE-2025-13523
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Feb 6, 2026
Argo Workflows affected by stored XSS in the artifact directory listing
High
CVE-2026-23960
was published
for
github.com/argoproj/argo-workflows
(Go)
Jan 21, 2026
Libredesk has Improper Neutralization of HTML Tags in a Web Page
High
CVE-2025-68927
was published
for
github.com/abhinavxd/libredesk
(Go)
Dec 16, 2025
ZITADEL Vulnerable to Account Takeover via DOM-Based XSS in Zitadel V2 Login
High
CVE-2025-67495
was published
for
github.com/zitadel/zitadel
(Go)
Dec 8, 2025
listmonk: CSRF to XSS Chain can Lead to Admin Account Takeover
High
CVE-2025-58430
was published
for
github.com/knadh/listmonk
(Go)
Sep 9, 2025
Grafana is vulnerable to XSS attacks through open redirects and path traversal
High
CVE-2025-6023
was published
for
github.com/grafana/grafana
(Go)
Jul 18, 2025
ProTip!
Advisories are also available from the
GraphQL API