Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

37,317 advisories

Loading
Loofah: SVG `href` attribute bypasses local-reference restriction Moderate
GHSA-9wjq-cp2p-hrgf was published for loofah (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility Moderate
CVE-2026-59895 was published for hono (npm) Jul 21, 2026
a-tt-om Credited to a-tt-om and teebow1e teebow1e teebow1e
thientd Credited to thientd
Mistune: XSS via unescaped class option in Admonition directive Moderate
CVE-2026-59926 was published for mistune (pip) Jul 20, 2026
sergeykochanov Credited to sergeykochanov
Mistune: XSS via percent-encoded javascript URI bypass in safe_url() Moderate
CVE-2026-59923 was published for mistune (pip) Jul 20, 2026
redyank Credited to redyank
The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS... Moderate Unreviewed
CVE-2026-60029 was published Jul 20, 2026
Astro: Reflected XSS via unescaped View Transition animation properties Moderate
GHSA-4g3v-8h47-v7g6 was published for astro (npm) Jul 20, 2026
Ryoga-exe Credited to Ryoga-exe
Tornado vulnerable to Header Injection and XSS via reason argument Moderate
CVE-2025-67724 was published for tornado (pip) Jul 20, 2026
Finder16 Credited to Finder16 and Cheshire1225 Cheshire1225 Cheshire1225
Improper neutralization of input during web page generation ('cross-site scripting')... Moderate Unreviewed
CVE-2026-6793 was published Jul 20, 2026
ProTip! Advisories are also available from the GraphQL API