GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,270
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,517
Pub
12
RubyGems
998
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
143 advisories
Filter by severity
jsPDF has HTML Injection in New Window paths
Critical
CVE-2026-31938
was published
for
jspdf
(npm)
Mar 17, 2026
SiYuan has a SanitizeSVG bypass via data:text/xml in getDynamicIcon (incomplete fix for CVE-2026-29183)
Critical
CVE-2026-32940
was published
for
github.com/siyuan-note/siyuan
(Go)
Mar 17, 2026
ZITADEL has 1-Click Account Takeover via XSS in /saml-post Endpoint
Critical
CVE-2026-29191
was published
for
github.com/zitadel/zitadel
(Go)
Mar 4, 2026
SiYuan: Unauthenticated Reflected XSS via SVG Injection in /api/icon/getDynamicIcon Endpoint
Critical
CVE-2026-29183
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 4, 2026
Rust has Critical Stored XSS in Preview Modal, leading to Administrative Account Takeover
Critical
CVE-2026-27822
was published
for
rustfs
(Rust)
Feb 25, 2026
Bugsink is vulnerable to Stored XSS via Pygments fallback in stacktrace rendering
Critical
CVE-2026-27614
was published
for
bugsink
(pip)
Feb 25, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
Critical
CVE-2026-24838
was published
for
DotNetNuke.Core
(NuGet)
Jan 28, 2026
Saltcorn's Reflected XSS and Command Injection vulnerabilities can be chained for 1-click-RCE
Critical
GHSA-cr3w-cw5w-h3fj
was published
for
@saltcorn/server
(npm)
Jan 26, 2026
Malicious website can execute commands on the local system through XSS in the OpenCode web UI
Critical
CVE-2026-22813
was published
for
opencode-ai
(npm)
Jan 13, 2026
Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
Critical
CVE-2025-50538
was published
for
flowise
(npm)
Oct 3, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
Critical
CVE-2025-59545
was published
for
DotNetNuke.Core
(NuGet)
Sep 23, 2025
pyLoad vulnerable to XSS through insecure CAPTCHA
Critical
CVE-2025-53890
was published
for
pyload-ng
(pip)
Jul 15, 2025
XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax
Critical
CVE-2025-53835
was published
for
org.xwiki.rendering:xwiki-rendering-syntax-xhtml
(Maven)
Jul 14, 2025
Magneto contains stored XSS vulnerability
Critical
CVE-2025-47110
was published
for
magento/community-edition
(Composer)
Jun 10, 2025
Argo CD allows cross-site scripting on repositories page
Critical
CVE-2025-47933
was published
for
github.com/argoproj/argo-cd
(Go)
May 28, 2025
org.xwiki.contrib.markdown:syntax-markdown-commonmark12 vulnerable to XSS via Markdown content
Critical
CVE-2025-46558
was published
for
org.xwiki.contrib.markdown:syntax-markdown-commonmark12
(Maven)
Apr 30, 2025
pgAdmin 4 Vulnerable to Cross-Site Scripting (XSS) via Query Result Rendering
Critical
CVE-2025-2946
was published
for
pgadmin4
(pip)
Apr 3, 2025
Beego allows Reflected/Stored XSS in Beego's RenderForm() Function Due to Unescaped User Input
Critical
CVE-2025-30223
was published
for
github.com/beego/beego
(Go)
Mar 31, 2025
Parsed HTML anchor links in Markdown provided to parseMarkdown can result in XSS in @nuxtjs/mdc
Critical
CVE-2025-24981
was published
for
@nuxtjs/mdc
(npm)
Feb 6, 2025
happy-dom allows for server side code to be executed by a <script> tag
Critical
CVE-2024-51757
was published
for
happy-dom
(npm)
Nov 6, 2024
Osmedeus Web Server Vulnerable to Stored XSS, Leading to RCE
Critical
CVE-2024-51735
was published
for
github.com/j3ssie/osmedeus
(Go)
Nov 5, 2024
XWiki Platform allows XSS through XClass name in string properties
Critical
CVE-2024-43400
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Aug 19, 2024
Gitea Cross-site Scripting Vulnerability
Critical
CVE-2024-6886
was published
for
code.gitea.io/gitea
(Go)
Aug 6, 2024
NextChat has full-read SSRF and XSS vulnerability in /api/cors endpoint
Critical
CVE-2023-49785
was published
for
nextchat
(npm)
Aug 5, 2024
XWiki Platform vulnerable to Cross-Site Scripting (XSS) through conflict resolution
Critical
CVE-2024-41947
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Jul 31, 2024
ProTip!
Advisories are also available from the
GraphQL API