GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
186 advisories
Filter by severity
Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component
Moderate
CVE-2026-55437
was published
for
github.com/coder/coder/v2
(Go)
Jul 6, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS
Moderate
CVE-2026-52816
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Gogs has DOM-based XSS via Milestone Name on New Issue Page
Moderate
CVE-2026-52807
was published
for
gogs.io/gogs
(Go)
Jun 23, 2026
Hugo: XSS via unescaped code-fence language in default code block renderer
Moderate
GHSA-q76j-gcg9-vxc6
was published
for
github.com/gohugoio/hugo
(Go)
Jun 19, 2026
Hugo: XSS via text/html content files
Moderate
CVE-2026-50133
was published
for
github.com/gohugoio/hugo
(Go)
Jun 16, 2026
Apache Answer vulnerable to Cross-site Scripting
Moderate
CVE-2026-34033
was published
for
github.com/apache/incubator-answer
(Go)
Jun 9, 2026
podinfo: cross-site scripting vulnerability in the /echo and /api/echo endpoints
Moderate
CVE-2026-43644
was published
for
github.com/stefanprodan/podinfo
(Go)
May 14, 2026
MCP Registry vulnerable to stored XSS in catalogue UI via attribute-quote breakout in publisher-controlled `websiteUrl`
Moderate
CVE-2026-44429
was published
for
github.com/modelcontextprotocol/registry
(Go)
May 8, 2026
Ech0's RSS feed renders unescaped tag names and raw-HTML markdown, stored XSS against subscribers
Moderate
GHSA-3v85-fqvh-7rxf
was published
for
github.com/lin-snow/Ech0
(Go)
May 7, 2026
FileBrowser Vulnerable to Stored XSS via SVG File in Public Share (Missing CSP Header)
Moderate
GHSA-mmpx-jh39-wrv6
was published
for
github.com/gtsteffaniak/filebrowser
(Go)
May 7, 2026
Kyverno policy-reporter-ui has XSS via Stored Property Values in PropertyCard Component
Moderate
CVE-2026-44245
was published
for
github.com/kyverno/policy-reporter-ui
(Go)
May 6, 2026
Prometheus vulnerable to stored XSS via crafted histogram bucket label values in the old web UI heatmap display
Moderate
CVE-2026-44903
was published
for
github.com/prometheus/prometheus
(Go)
May 5, 2026
Fiber vulnerable to XSS in AutoFormat Content Negotiation
Moderate
CVE-2026-42554
was published
for
github.com/gofiber/fiber/v2
(Go)
May 5, 2026
goldmark vulnerable to Cross-site Scripting (XSS)
Moderate
CVE-2026-5160
was published
for
github.com/yuin/goldmark/renderer/html
(Go)
Apr 17, 2026
zrok: Reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering
Moderate
CVE-2026-40302
was published
for
github.com/openziti/zrok
(Go)
Apr 16, 2026
SiYuan has incomplete fix for CVE-2026-33066: XSS
Moderate
CVE-2026-40922
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Apr 14, 2026
Prometheus has Stored XSS via metric names and label values in Prometheus web UI tooltips and metrics explorer
Moderate
CVE-2026-40179
was published
for
github.com/prometheus/prometheus
(Go)
Apr 13, 2026
Vikunja has HTML Injection via Task Titles in Overdue Email Notifications
Moderate
CVE-2026-35600
was published
for
code.vikunja.io/api
(Go)
Apr 10, 2026
Hugo: Certain markdown links are not properly escaped
Moderate
CVE-2026-35166
was published
for
github.com/gohugoio/hugo
(Go)
Apr 3, 2026
File Browser vulnerable to Stored Cross-site Scripting via text/template branding injection
Moderate
CVE-2026-34530
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Mar 31, 2026
SiYuan has Stored XSS to RCE via Unsanitized Bazaar Package Metadata
Moderate
CVE-2026-33067
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 18, 2026
SiYuan has Stored XSS to RCE via Unsanitized Bazaar README Rendering
Moderate
CVE-2026-33066
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 18, 2026
SiYuan Vulnerable to Remote Code Execution via Malicious Bazaar Package — Marketplace XSS
Moderate
GHSA-v3mg-9v85-fcm7
was published
for
siyuan
(Go)
Mar 16, 2026
SiYuan Vulnerable to Remote Code Execution via Stored XSS in Notebook Name - Mobile Interface
Moderate
CVE-2026-32751
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 16, 2026
SiYuan has a SVG Sanitizer Bypass via Whitespace in `javascript:` URI — Unauthenticated XSS
Moderate
CVE-2026-31809
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 10, 2026
ProTip!
Advisories are also available from the
GraphQL API