Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

515 advisories

Loading
DOMPurify is vulnerable to mutation-XSS via Re-Contextualization Moderate
GHSA-h8r8-wccr-v5f2 was published for dompurify (npm) Mar 27, 2026
researchatfluidattacks Credited to researchatfluidattacks and caverav caverav caverav
n8n has XSS in its Credential Management Flow Moderate
GHSA-364x-8g5j-x2pr was published for n8n (npm) Mar 27, 2026
yohannslm Credited to yohannslm
n8n has XSS in Chat Trigger Node through Custom CSS Moderate
GHSA-3c7f-5hgj-h279 was published for n8n (npm) Mar 27, 2026
JorianWoltjer Credited to JorianWoltjer
n8n: Authenticated XSS and Open Redirect via Form Node Moderate
GHSA-w673-8fjw-457c was published for n8n (npm) Mar 27, 2026
tCu0n9 Credited to tCu0n9
n8n has a Stored XSS Vulnerability in its Form Trigger Moderate
GHSA-q4fm-pjq6-m63g was published for n8n (npm) Mar 27, 2026
tr4ce-ju Credited to tr4ce-ju
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection Moderate
CVE-2026-33916 was published for handlebars (npm) Mar 26, 2026
ByamB4 Credited to ByamB4
n8n Vulnerable to XSS via Binary Data Inline HTML Rendering Moderate
CVE-2026-33749 was published for n8n (npm) Mar 26, 2026
simonkoeck Credited to simonkoeck
@grackle-ai/server has Missing Content-Security-Policy and X-Frame-Options Headers Moderate
GHSA-3mjm-x6gw-2x42 was published for @grackle-ai/server (npm) Mar 25, 2026
PDFME has XSS via Unsanitized i18n Label Injection into innerHTML in multiVariableText propPanel Moderate
GHSA-xgx4-2wgv-4jhm was published for @pdfme/schemas (npm) Mar 20, 2026
offset Credited to offset
SVG Injection via Unsanitized Options in @dicebear/core and @dicebear/initials Moderate
CVE-2026-33311 was published for @dicebear/core (npm) Mar 19, 2026
offset Credited to offset
NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability Moderate
CVE-2026-30048 was published for @developer.notchatbot/webchat (npm) Mar 18, 2026
Cross-Site Scripting (XSS) via SVG Schema innerHTML Injection in @pdfme/schemas Moderate
GHSA-87v3-4cfp-cm76 was published for @pdfme/schemas (npm) Mar 18, 2026
deprrous Credited to deprrous
Cross-Site Scripting (XSS) via Select Schema Option Value Injection in @pdfme/schemas Moderate
GHSA-qq9g-96v4-m3cj was published for @pdfme/schemas (npm) Mar 18, 2026
deprrous Credited to deprrous
Vulnogram contains a stored cross-site scripting vulnerability in comment hypertext handling Moderate
CVE-2026-32774 was published for vulnogram (npm) Mar 16, 2026
Trix has a Stored XSS vulnerability through serialized attributes Moderate
GHSA-qmpg-8xg6-ph5q was published for action_text-trix (RubyGems) Mar 12, 2026
simonkoeck Credited to simonkoeck
Parse Server vulnerable to stored XSS via file upload of HTML-renderable file types Moderate
CVE-2026-31868 was published for parse-server (npm) Mar 11, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support package Moderate
CVE-2026-28343 was published for @ckeditor/ckeditor5-html-support (npm) Mar 4, 2026
mhassan1 Credited to mhassan1
OpenClaw has Canvas route hardening for mixed-trust deployments Moderate
GHSA-cjv3-m589-v3rx was published for openclaw (npm) Mar 3, 2026
NucleiAv Credited to NucleiAv
OpenClaw has stored XSS in exported session HTML viewer via markdown/raw-HTML rendering Moderate
GHSA-r294-2894-92j3 was published for openclaw (npm) Mar 3, 2026
allsmog Credited to allsmog
NocoDB Vulnerable to Stored Cross-Site Scripting via Rich Text Cells Moderate
CVE-2026-28401 was published for nocodb (npm) Mar 3, 2026
p- Credited to p-
NocoDB Vulnerable to Stored Cross-site Scripting via Comments Moderate
CVE-2026-28397 was published for nocodb (npm) Mar 3, 2026
p- Credited to p-
NocoDB Vulnerable to Stored Cross-Site Scripting via Comments and Rich Text Cells Moderate
CVE-2026-28398 was published for nocodb (npm) Mar 3, 2026
bugbunny-research Credited to bugbunny-research
DOMPurify contains a Cross-site Scripting vulnerability Moderate
CVE-2025-15599 was published for dompurify (npm) Mar 3, 2026
DOMPurify contains a Cross-site Scripting vulnerability Moderate
CVE-2026-0540 was published for dompurify (npm) Mar 3, 2026
swils23 Credited to swils23 and cure53 cure53 cure53
ProTip! Advisories are also available from the GraphQL API