GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
344 advisories
Filter by severity
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS
Low
CVE-2026-52838
was published
for
alextselegidis/easyappointments
(Composer)
Jul 29, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Low
GHSA-5qhf-9phg-95m2
was published
for
loofah
(RubyGems)
Jul 21, 2026
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
Low
GHSA-c2j3-45gr-mqc4
was published
for
dompurify
(npm)
Jul 21, 2026
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Low
CVE-2026-59727
was published
for
astro
(npm)
Jul 20, 2026
FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`
Low
CVE-2026-45710
was published
for
facturascripts/facturascripts
(Composer)
Jul 14, 2026
Kiwi TCMS vulnerable to stored XSS via JavaScript: URI in extra_link field (TestPlan & TestCase)
Low
CVE-2026-55630
was published
for
kiwitcms
(pip)
Jul 6, 2026
SFTPGo has stored XSS via inline parameter on public shares and user file download
Low
CVE-2026-49245
was published
for
github.com/drakkan/sftpgo/v2
(Go)
Jul 2, 2026
Schema.org has cross-site scripting (XSS) via script break-out in toScript() output
Low
GHSA-hwmc-r6mf-jh83
was published
for
spatie/schema-org
(Composer)
Jul 1, 2026
OpenAM SAML2 Cluster Cookie-Hash-Redirect Path has Pre-authentication Reflected XSS via `FSUtils.postToTarget`
Low
CVE-2026-44793
was published
for
org.openidentityplatform.openam:openam-federation-library
(Maven)
Jun 22, 2026
Sveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe
Low
GHSA-h5jc-78hr-3pc9
was published
for
@sveltia/cms
(npm)
Jun 19, 2026
parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist
Low
CVE-2026-53724
was published
for
parse-server
(npm)
Jun 19, 2026
Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
Low
CVE-2026-54326
was published
for
@earendil-works/pi-coding-agent
(npm)
Jun 16, 2026
Cross-site scripting via <NoScript> slot content in Nuxt's head components
Low
GHSA-m3q2-p4fw-w38m
was published
for
nuxt
(npm)
Jun 16, 2026
DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes
Low
CVE-2026-65900
was published
for
dompurify
(npm)
Jun 15, 2026
DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects
Low
CVE-2026-65901
was published
for
dompurify
(npm)
Jun 15, 2026
TYPO3 HTML Sanitizer allows Cross-site Scripting
Low
CVE-2026-47344
was published
for
typo3/html-sanitizer
(Composer)
Jun 12, 2026
Twig: XSS in profiler HtmlDumper via unescaped template and profile names
Low
CVE-2026-47730
was published
for
twig/twig
(Composer)
Jun 5, 2026
Symfony's HtmlSanitizer UrlAttributeSanitizer Omits action/formaction/poster/cite — `javascript`: URI Survives Sanitization (XSS)
Low
CVE-2026-45753
was published
for
symfony/html-sanitizer
(Composer)
May 28, 2026
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering
Low
CVE-2026-45072
was published
for
symfony/symfony
(Composer)
May 27, 2026
Concrete CMS is vulnerable to Stored XSS via page name in the Atomik theme
Low
CVE-2026-8353
was published
for
concrete5/concrete5
(Composer)
May 26, 2026
Concrete CMS is vulnerable to Stored XSS via external-link page cvName
Low
CVE-2026-8139
was published
for
concrete5/concrete5
(Composer)
May 22, 2026
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
Low
CVE-2026-46342
was published
for
@nuxt/nitro-server
(npm)
May 19, 2026
LibreNMS: Cross-Site Scripting in ShowConfigController
Low
CVE-2026-2728
was published
for
librenms/librenms
(Composer)
May 18, 2026
Sveltia CMS: Stored XSS in entry summary rendering via entity-decoded HTML
Low
GHSA-97r8-rf7q-wmjw
was published
for
@sveltia/cms
(npm)
May 18, 2026
ProTip!
Advisories are also available from the
GraphQL API