GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
431 advisories
Filter by severity
PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction
Moderate
CVE-2026-55696
was published
for
privatebin/privatebin
(Composer)
Aug 28, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-5218
was published
Aug 27, 2026
justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown()...
Moderate
Unreviewed
CVE-2026-5389
was published
Aug 23, 2026
A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000...
Moderate
Unreviewed
CVE-2026-20232
was published
Aug 19, 2026
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows...
Moderate
Unreviewed
CVE-2026-75872
was published
Aug 18, 2026
XSS vulnerability in Markdown handling in Apache Allura.
This issue affects Apache Allura: from...
Moderate
Unreviewed
CVE-2026-73237
was published
Aug 12, 2026
XSS vulnerability in code display in Apache Allura.
This issue affects Apache Allura: before 1...
Moderate
Unreviewed
CVE-2026-73238
was published
Aug 12, 2026
Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization
Moderate
CVE-2026-65841
was published
for
jodit
(npm)
Jul 31, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-34497
was published
Jul 31, 2026
A carefully crafted editing request could trigger an XSS vulnerability
on Apache JSPWiki when...
Moderate
Unreviewed
CVE-2026-48910
was published
Jul 30, 2026
Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerable to cross-site scripting ...
Critical
Unreviewed
CVE-2024-58353
was published
Jul 24, 2026
Cal.com (calcom/cal.diy) versions through 4.7.15 contain a stored cross-site scripting...
Critical
Unreviewed
CVE-2024-58355
was published
Jul 24, 2026
AngleSharp HTML5 Spec Compliance: mXSS via annotation-xml HTML Integration Point Bypass
Moderate
CVE-2026-54570
was published
for
AngleSharp
(NuGet)
Jul 17, 2026
plone.restapi: Stored XSS by spoofing mime type
Moderate
GHSA-8rqh-vxpr-x77p
was published
for
plone.restapi
(pip)
Jul 17, 2026
plone.app.textfield: Stored XSS by spoofing mime type
Moderate
CVE-2026-54503
was published
for
plone.app.textfield
(pip)
Jul 17, 2026
A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in...
Moderate
Unreviewed
CVE-2026-59838
was published
Jul 15, 2026
YesWiki Vulnerable to Reflected XSS via Unescaped `id` Parameter in Bazar Widget HTML Attributes
Moderate
CVE-2026-52774
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
YesWiki Vulnerable to Reflected XSS via Unescaped Archived-Revision `time` Parameter in `handlers/page/show.php`
Moderate
CVE-2026-52773
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-7380
was published
Jul 7, 2026
mediawiki/maps has stored XSS through the overlays parameter in the display_map parser function
High
CVE-2026-52854
was published
for
mediawiki/maps
(Composer)
Jul 2, 2026
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A...
Moderate
Unreviewed
CVE-2025-36321
was published
Jun 30, 2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-50229
was published
Jun 29, 2026
Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.
Moderate
Unreviewed
CVE-2025-64637
was published
Jun 26, 2026
Malicious HTML content could be injected into the content rendered by the pretix-digital plugin.
Low
Unreviewed
CVE-2026-13314
was published
Jun 25, 2026
Malicious HTML content could be injected into the email address of an
order, which pretix showed...
Moderate
Unreviewed
CVE-2026-13225
was published
Jun 25, 2026
ProTip!
Advisories are also available from the
GraphQL API