Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

965 advisories

Loading
jsoup: Cleaner may expose markup with custom raw-text elements Moderate
CVE-2026-71497 was published for org.jsoup:jsoup (Maven) Aug 6, 2026
quitbug Credited to quitbug and jhy jhy jhy
OmniFaces: Forged combined-resource IDs and related output/push boundaries High
GHSA-fp43-vj7g-pg92 was published for org.omnifaces:omnifaces (Maven) Jul 24, 2026
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page Moderate
CVE-2026-62280 was published for org.openidentityplatform.openam:openam-oauth2 (Maven) Jul 24, 2026
geo-chen Credited to geo-chen
GeoNetwork has reflected XSS through client-side template injection High
CVE-2026-39379 was published for org.geonetwork-opensource:geonetwork (Maven) Jul 1, 2026
Timonheu Credited to Timonheu, juanluisrp, and jodygarnett juanluisrp juanluisrp
jodygarnett jodygarnett
OpenAM SAML2 Cluster Cookie-Hash-Redirect Path has Pre-authentication Reflected XSS via `FSUtils.postToTarget` Low
CVE-2026-44793 was published for org.openidentityplatform.openam:openam-federation-library (Maven) Jun 22, 2026
gujjuboy10x00 Credited to gujjuboy10x00
OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl) Critical
CVE-2026-44203 was published for org.openidentityplatform.openam:openam-oauth2 (Maven) Jun 22, 2026
gujjuboy10x00 Credited to gujjuboy10x00 and wodzen wodzen wodzen
Allure Report: Stored XSS via unescaped ANSI helper in status message/trace rendering Moderate
CVE-2026-55847 was published for io.qameta.allure:allure-generator (Maven) Jun 19, 2026
offset Credited to offset and baev baev baev
Jenkins: Stored XSS vulnerability in node offline cause description High
CVE-2026-53441 was published for org.jenkins-ci.main:jenkins-core (Maven) Jun 10, 2026
lohitkolluri Credited to lohitkolluri
Spring Framework Cross-site Scripting via JSP Form Tags Moderate
CVE-2026-41846 was published for org.springframework:spring-webmvc (Maven) Jun 9, 2026
Spring Framework Cross-site Scripting via JavaScriptUtils High
CVE-2026-41845 was published for org.springframework:spring-webmvc (Maven) Jun 9, 2026
Apache ActiveMQ, Apache ActiveMQ Web have a Cross-site Scripting issue Moderate
CVE-2026-42253 was published for org.apache.activemq:activemq-web (Maven) Jun 1, 2026
Jenkins buildgraph-view Plugin does not escape the build URL Moderate
CVE-2026-48927 was published for org.jenkins-ci.plugins:buildgraph-view (Maven) May 27, 2026
Alkacon OpenCms is vulnerable to XSS via updateModelGroups.jsp Moderate
CVE-2023-42345 was published for org.opencms:opencms-core (Maven) May 8, 2026
Alkacon OpenCms is vulnerable to XSS via cmis-online/type Moderate
CVE-2023-42343 was published for org.opencms:opencms-core (Maven) May 8, 2026
Apache Wicket has a Cross-site Scripting issue Moderate
CVE-2026-42509 was published for org.apache.wicket:wicket-parent (Maven) May 6, 2026
Shopizer is vulnerable to Cross-site Scripting Moderate
CVE-2026-36766 was published for com.shopizer:shopizer (Maven) Apr 30, 2026
Jenkins HTML Publisher Plugin has a XSS vulnerability in the legacy wrapper file High
CVE-2026-42524 was published for org.jenkins-ci.plugins:htmlpublisher (Maven) Apr 29, 2026
Jenkins GitHub Plugin has an XSS vulnerability Critical
CVE-2026-42523 was published for org.jenkins-ci.plugins:git (Maven) Apr 29, 2026
Apache ActiveMQ Vulnerable to Cross-site Scripting Moderate
CVE-2026-41043 was published for org.apache.activemq:activemq-all (Maven) Apr 24, 2026
Silverpeas Core has a reflected cross-site scripting vulnerability Moderate
CVE-2026-30139 was published for org.silverpeas.core:silverpeas-core-war (Maven) Apr 22, 2026
Keycloak: Arbitrary code execution via Stored Cross-Site Scripting (XSS) in organization selection login page Moderate
CVE-2026-37980 was published for org.keycloak:keycloak-services (Maven) Apr 14, 2026
Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata Moderate
CVE-2026-35565 was published for org.apache.storm:storm-webapp (Maven) Apr 13, 2026
Emissary has Stored XSS via Navigation Template Link Injection Moderate
CVE-2026-35571 was published for gov.nsa.emissary:emissary (Maven) Apr 7, 2026
BrennanTM Credited to BrennanTM
XWiki Blog Application home page vulnerable to Stored XSS via Post Title High
CVE-2025-66024 was published for org.xwiki.contrib.blog:application-blog-ui (Maven) Mar 4, 2026
lukasz-rybak Credited to lukasz-rybak and sealbenb sealbenb sealbenb
PMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation messages Moderate
CVE-2026-28338 was published for net.sourceforge.pmd:pmd-core (Maven) Feb 28, 2026
smaranchand Credited to smaranchand
ProTip! Advisories are also available from the GraphQL API