GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
965 advisories
Filter by severity
jsoup: Cleaner may expose markup with custom raw-text elements
Moderate
CVE-2026-71497
was published
for
org.jsoup:jsoup
(Maven)
Aug 6, 2026
OmniFaces: Forged combined-resource IDs and related output/push boundaries
High
GHSA-fp43-vj7g-pg92
was published
for
org.omnifaces:omnifaces
(Maven)
Jul 24, 2026
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page
Moderate
CVE-2026-62280
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Jul 24, 2026
GeoNetwork has reflected XSS through client-side template injection
High
CVE-2026-39379
was published
for
org.geonetwork-opensource:geonetwork
(Maven)
Jul 1, 2026
OpenAM SAML2 Cluster Cookie-Hash-Redirect Path has Pre-authentication Reflected XSS via `FSUtils.postToTarget`
Low
CVE-2026-44793
was published
for
org.openidentityplatform.openam:openam-federation-library
(Maven)
Jun 22, 2026
OpenAM has pre-auth Reflected XSS in OAuth2 / OIDC response_mode=form_post via state parameter (FormPostResponse.ftl)
Critical
CVE-2026-44203
was published
for
org.openidentityplatform.openam:openam-oauth2
(Maven)
Jun 22, 2026
Allure Report: Stored XSS via unescaped ANSI helper in status message/trace rendering
Moderate
CVE-2026-55847
was published
for
io.qameta.allure:allure-generator
(Maven)
Jun 19, 2026
Jenkins: Stored XSS vulnerability in node offline cause description
High
CVE-2026-53441
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Jun 10, 2026
Spring Framework Cross-site Scripting via JSP Form Tags
Moderate
CVE-2026-41846
was published
for
org.springframework:spring-webmvc
(Maven)
Jun 9, 2026
Spring Framework Cross-site Scripting via JavaScriptUtils
High
CVE-2026-41845
was published
for
org.springframework:spring-webmvc
(Maven)
Jun 9, 2026
Apache ActiveMQ, Apache ActiveMQ Web have a Cross-site Scripting issue
Moderate
CVE-2026-42253
was published
for
org.apache.activemq:activemq-web
(Maven)
Jun 1, 2026
Jenkins buildgraph-view Plugin does not escape the build URL
Moderate
CVE-2026-48927
was published
for
org.jenkins-ci.plugins:buildgraph-view
(Maven)
May 27, 2026
Alkacon OpenCms is vulnerable to XSS via updateModelGroups.jsp
Moderate
CVE-2023-42345
was published
for
org.opencms:opencms-core
(Maven)
May 8, 2026
Alkacon OpenCms is vulnerable to XSS via cmis-online/type
Moderate
CVE-2023-42343
was published
for
org.opencms:opencms-core
(Maven)
May 8, 2026
Apache Wicket has a Cross-site Scripting issue
Moderate
CVE-2026-42509
was published
for
org.apache.wicket:wicket-parent
(Maven)
May 6, 2026
Shopizer is vulnerable to Cross-site Scripting
Moderate
CVE-2026-36766
was published
for
com.shopizer:shopizer
(Maven)
Apr 30, 2026
Jenkins HTML Publisher Plugin has a XSS vulnerability in the legacy wrapper file
High
CVE-2026-42524
was published
for
org.jenkins-ci.plugins:htmlpublisher
(Maven)
Apr 29, 2026
Jenkins GitHub Plugin has an XSS vulnerability
Critical
CVE-2026-42523
was published
for
org.jenkins-ci.plugins:git
(Maven)
Apr 29, 2026
Apache ActiveMQ Vulnerable to Cross-site Scripting
Moderate
CVE-2026-41043
was published
for
org.apache.activemq:activemq-all
(Maven)
Apr 24, 2026
Silverpeas Core has a reflected cross-site scripting vulnerability
Moderate
CVE-2026-30139
was published
for
org.silverpeas.core:silverpeas-core-war
(Maven)
Apr 22, 2026
Keycloak: Arbitrary code execution via Stored Cross-Site Scripting (XSS) in organization selection login page
Moderate
CVE-2026-37980
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 14, 2026
Apache Storm UI: Stored Cross-Site Scripting (XSS) via Unsanitized Topology Metadata
Moderate
CVE-2026-35565
was published
for
org.apache.storm:storm-webapp
(Maven)
Apr 13, 2026
Emissary has Stored XSS via Navigation Template Link Injection
Moderate
CVE-2026-35571
was published
for
gov.nsa.emissary:emissary
(Maven)
Apr 7, 2026
XWiki Blog Application home page vulnerable to Stored XSS via Post Title
High
CVE-2025-66024
was published
for
org.xwiki.contrib.blog:application-blog-ui
(Maven)
Mar 4, 2026
PMD Designer has Stored XSS in VBHTMLRenderer and YAHTMLRenderer via unescaped violation messages
Moderate
CVE-2026-28338
was published
for
net.sourceforge.pmd:pmd-core
(Maven)
Feb 28, 2026
ProTip!
Advisories are also available from the
GraphQL API