Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

186 advisories

Loading
Apache Answer vulnerable to Cross-site Scripting Moderate
CVE-2026-34033 was published for github.com/apache/incubator-answer (Go) Jun 9, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page Moderate
CVE-2026-52807 was published for gogs.io/gogs (Go) Jun 23, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS Moderate
CVE-2026-52816 was published for gogs.io/gogs (Go) Jun 23, 2026
JLGitHub66 Credited to JLGitHub66
Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component Moderate
CVE-2026-55437 was published for github.com/coder/coder/v2 (Go) Jul 6, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer Moderate
GHSA-q76j-gcg9-vxc6 was published for github.com/gohugoio/hugo (Go) Jun 19, 2026
k0ngj1 Credited to k0ngj1
Hugo: XSS via text/html content files Moderate
CVE-2026-50133 was published for github.com/gohugoio/hugo (Go) Jun 16, 2026
jmooring Credited to jmooring
Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display Moderate
CVE-2026-44903 was published for github.com/prometheus/prometheus (Go) May 5, 2026
iiihaiii Credited to iiihaiii and ngocnn97 ngocnn97 ngocnn97
podinfo: cross-site scripting vulnerability in the /echo and /api/echo endpoints Moderate
CVE-2026-43644 was published for github.com/stefanprodan/podinfo (Go) May 14, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl` Moderate
CVE-2026-44429 was published for github.com/modelcontextprotocol/registry (Go) May 8, 2026
JosephDoUrden Credited to JosephDoUrden and rdimitrov rdimitrov rdimitrov
Kyverno policy-reporter-ui has XSS via Stored Property Values in PropertyCard Component Moderate
CVE-2026-44245 was published for github.com/kyverno/policy-reporter-ui (Go) May 6, 2026
r0binak Credited to r0binak
Fiber vulnerable to XSS in AutoFormat Content Negotiation Moderate
CVE-2026-42554 was published for github.com/gofiber/fiber/v2 (Go) May 5, 2026
wodzen Credited to wodzen, gaby, ReneWerner87, and sixcolors gaby gaby
ReneWerner87 ReneWerner87 sixcolors sixcolors
Grafana has a Cross-site Scripting issue Moderate
CVE-2025-41117 was published for github.com/grafana/grafana (Go) Feb 12, 2026
Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers Moderate
GHSA-3v85-fqvh-7rxf was published for github.com/lin-snow/Ech0 (Go) May 7, 2026
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
FileBrowser Vulnerable to Stored XSS via SVG File in Public Share (Missing CSP Header) Moderate
GHSA-mmpx-jh39-wrv6 was published for github.com/gtsteffaniak/filebrowser (Go) May 7, 2026
MuxiLyuLucy Credited to MuxiLyuLucy
Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorer Moderate
CVE-2026-40179 was published for github.com/prometheus/prometheus (Go) Apr 13, 2026
gladiator9797 Credited to gladiator9797
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering Moderate
CVE-2026-40302 was published for github.com/openziti/zrok (Go) Apr 16, 2026
bugbunny-research Credited to bugbunny-research
SiYuan has incomplete fix for CVE-2026-33066: XSS Moderate
CVE-2026-40922 was published for github.com/siyuan-note/siyuan/kernel (Go) Apr 14, 2026
goldmark vulnerable to Cross-site Scripting (XSS) Moderate
CVE-2026-5160 was published for github.com/yuin/goldmark/renderer/html (Go) Apr 17, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications Moderate
CVE-2026-35600 was published for code.vikunja.io/api (Go) Apr 10, 2026
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
Hugo: Certain markdown links are not properly escaped Moderate
CVE-2026-35166 was published for github.com/gohugoio/hugo (Go) Apr 3, 2026
cataliniovita Credited to cataliniovita
File Browser vulnerable to Stored Cross-site Scripting via text/template branding injection Moderate
CVE-2026-34530 was published for github.com/filebrowser/filebrowser/v2 (Go) Mar 31, 2026
tomasvanagas Credited to tomasvanagas and hacdias hacdias hacdias
Hydra has Reflected XSS via error_hint parameter Moderate
CVE-2019-8400 was published for github.com/ory/hydra (Go) May 14, 2022
Apache Answer Cross-site Scripting vulnerability Moderate
CVE-2024-23349 was published for github.com/apache/incubator-answer (Go) Feb 22, 2024
Authentication Bypass by Spoofing in github.com/greenpau/caddy-security Moderate
CVE-2024-21494 was published for github.com/greenpau/caddy-security (Go) Feb 17, 2024
SiYuan has Stored XSS to RCE via Unsanitized Bazaar Package Metadata Moderate
CVE-2026-33067 was published for github.com/siyuan-note/siyuan/kernel (Go) Mar 18, 2026
0xkakash1 Credited to 0xkakash1
ProTip! Advisories are also available from the GraphQL API