GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
209 advisories
Filter by severity
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
High
CVE-2026-16633
was published
for
pdfjs-dist
(npm)
Aug 6, 2026
XSS in Ghost's ActivityPub client
High
CVE-2026-53950
was published
for
@tryghost/activitypub
(npm)
Aug 4, 2026
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes
High
CVE-2026-69151
was published
for
@angular/compiler
(npm)
Aug 3, 2026
Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)
High
CVE-2026-69149
was published
for
@angular/platform-server
(npm)
Aug 3, 2026
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag
High
CVE-2026-53608
was published
for
@apostrophecms/seo
(npm)
Jul 31, 2026
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier
High
CVE-2026-58263
was published
for
jodit
(npm)
Jul 31, 2026
n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
High
CVE-2026-65592
was published
for
n8n
(npm)
Jul 22, 2026
n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
High
CVE-2026-65597
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
High
GHSA-vhcw-f978-xjjg
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
Duplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
High
GHSA-h5xr-fqvj-253p
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
SVGO removeScripts plugin leaves some executable scripts intact
High
GHSA-2p49-hgcm-8545
was published
for
svgo
(npm)
Jul 21, 2026
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp
High
GHSA-86j7-9j95-vpqj
was published
for
better-auth
(npm)
Jul 7, 2026
wetty vulnerable to DOM XSS via file-download filename
High
CVE-2026-49864
was published
for
wetty
(npm)
Jul 1, 2026
Angular's deprecated package has a Cross-Site Scripting issue
High
CVE-2026-11998
was published
for
angular
(npm)
Jun 24, 2026
appium-mcp: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI)
High
GHSA-x975-rgx4-5fh4
was published
for
appium-mcp
(npm)
Jun 19, 2026
TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
High
CVE-2026-55660
was published
for
@tinacms/app
(npm)
Jun 19, 2026
jupyterlab-git extension: Stored XSS leading to RCE
High
CVE-2026-54527
was published
for
@jupyterlab/git
(npm)
Jun 19, 2026
n8n: Same-Origin XSS in Respond to Webhook Node
High
CVE-2026-54301
was published
for
n8n
(npm)
Jun 16, 2026
Astro: Reflected XSS via unescaped slot name
High
CVE-2026-50146
was published
for
astro
(npm)
Jun 16, 2026
@angular/platform-server: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSR
High
CVE-2026-50556
was published
for
@angular/platform-server
(npm)
Jun 15, 2026
@angular/platform-server: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
High
CVE-2026-50555
was published
for
@angular/platform-server
(npm)
Jun 15, 2026
Angular Client Hydration DOM Clobbering & Response-Cache Poisoning
High
CVE-2026-54267
was published
for
@angular/core
(npm)
Jun 15, 2026
TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection
High
CVE-2026-47761
was published
for
TinyMCE
(Composer)
Jun 5, 2026
TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments
High
CVE-2026-47762
was published
for
TinyMCE
(Composer)
Jun 5, 2026
ProTip!
Advisories are also available from the
GraphQL API