Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

344 advisories

Loading
Easy!Appointments disable_booking_message rendered as raw HTML on public booking page — Stored XSS Low
CVE-2026-52838 was published for alextselegidis/easyappointments (Composer) Jul 29, 2026
ashrexon Credited to ashrexon
MoonFuji Credited to MoonFuji
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements. Low
GHSA-c2j3-45gr-mqc4 was published for dompurify (npm) Jul 21, 2026
Rikuxx0 Credited to Rikuxx0
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands Low
CVE-2026-59727 was published for astro (npm) Jul 20, 2026
jlgore Credited to jlgore
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
SFTPGo has stored XSS via inline parameter on public shares and user file download Low
CVE-2026-49245 was published for github.com/drakkan/sftpgo/v2 (Go) Jul 2, 2026
Schema.org has cross-site scripting (XSS) via script break-out in toScript() output Low
GHSA-hwmc-r6mf-jh83 was published for spatie/schema-org (Composer) Jul 1, 2026
OpenAM SAML2 Cluster Cookie-Hash-Redirect Path has Pre-authentication Reflected XSS via `FSUtils.postToTarget` Low
CVE-2026-44793 was published for org.openidentityplatform.openam:openam-federation-library (Maven) Jun 22, 2026
gujjuboy10x00 Credited to gujjuboy10x00
Sveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe Low
GHSA-h5jc-78hr-3pc9 was published for @sveltia/cms (npm) Jun 19, 2026
blacksolo1 Credited to blacksolo1
parse-server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist Low
CVE-2026-53724 was published for parse-server (npm) Jun 19, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass Low
CVE-2026-54326 was published for @earendil-works/pi-coding-agent (npm) Jun 16, 2026
urianpaul94 Credited to urianpaul94
Cross-site scripting via <NoScript> slot content in Nuxt's head components Low
GHSA-m3q2-p4fw-w38m was published for nuxt (npm) Jun 16, 2026
alcls01111 Credited to alcls01111
IamLeandrooooo Credited to IamLeandrooooo
TYPO3 HTML Sanitizer allows Cross-site Scripting Low
CVE-2026-47344 was published for typo3/html-sanitizer (Composer) Jun 12, 2026
ohader Credited to ohader
Twig: XSS in profiler HtmlDumper via unescaped template and profile names Low
CVE-2026-47730 was published for twig/twig (Composer) Jun 5, 2026
nicolas-grekas Credited to nicolas-grekas
nicolas-grekas Credited to nicolas-grekas
Symfony Vulnerable to stored XSS in WebProfiler CodeExtension::fileExcerpt() — Unescaped Non-PHP File Rendering Low
CVE-2026-45072 was published for symfony/symfony (Composer) May 27, 2026
Blitz has a Cross-site Scripting issue Low
CVE-2026-9520 was published for blitz (npm) May 26, 2026
Concrete CMS is vulnerable to Stored XSS via page name in the Atomik theme Low
CVE-2026-8353 was published for concrete5/concrete5 (Composer) May 26, 2026
Concrete CMS is vulnerable to Stored XSS via external-link page cvName Low
CVE-2026-8139 was published for concrete5/concrete5 (Composer) May 22, 2026
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning Low
CVE-2026-46342 was published for @nuxt/nitro-server (npm) May 19, 2026
fancymalware Credited to fancymalware
LibreNMS: Cross-Site Scripting in ShowConfigController Low
CVE-2026-2728 was published for librenms/librenms (Composer) May 18, 2026
YuriNek0 Credited to YuriNek0
Sveltia CMS: Stored XSS in entry summary rendering via entity-decoded HTML Low
GHSA-97r8-rf7q-wmjw was published for @sveltia/cms (npm) May 18, 2026
blacksolo1 Credited to blacksolo1
ProTip! Advisories are also available from the GraphQL API