GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
37,317 advisories
Filter by severity
Loofah: SVG `href` attribute bypasses local-reference restriction
Moderate
GHSA-9wjq-cp2p-hrgf
was published
for
loofah
(RubyGems)
Jul 21, 2026
Cross Site Scripting vulnerability in aiflowy <= 2.1.2 allows a remote attacker to obtain...
Moderate
Unreviewed
CVE-2026-52475
was published
Jul 21, 2026
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
Moderate
CVE-2026-59895
was published
for
hono
(npm)
Jul 21, 2026
SolarWinds Serv-U was found to be affected by a stored cross-site scripting vulnerability that...
Moderate
Unreviewed
CVE-2026-28315
was published
Jul 21, 2026
Grav contains a stored cross-site scripting vulnerability in shortcode-core attribute handlers...
Moderate
Unreviewed
CVE-2026-64628
was published
Jul 21, 2026
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress...
Moderate
Unreviewed
CVE-2026-15145
was published
Jul 21, 2026
The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz &...
Moderate
Unreviewed
CVE-2026-15782
was published
Jul 21, 2026
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress...
Moderate
Unreviewed
CVE-2026-15156
was published
Jul 21, 2026
Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote...
Moderate
Unreviewed
CVE-2026-51025
was published
Jul 21, 2026
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-12900
was published
Jul 21, 2026
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
Moderate
CVE-2026-59729
was published
for
astro
(npm)
Jul 20, 2026
Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
Moderate
CVE-2026-59929
was published
for
mistune
(pip)
Jul 20, 2026
Mistune: XSS via unescaped class option in Admonition directive
Moderate
CVE-2026-59926
was published
for
mistune
(pip)
Jul 20, 2026
Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
Moderate
CVE-2026-59923
was published
for
mistune
(pip)
Jul 20, 2026
The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS...
Moderate
Unreviewed
CVE-2026-60029
was published
Jul 20, 2026
Astro: Reflected XSS via unescaped View Transition animation properties
Moderate
GHSA-4g3v-8h47-v7g6
was published
for
astro
(npm)
Jul 20, 2026
Tornado vulnerable to Header Injection and XSS via reason argument
Moderate
CVE-2025-67724
was published
for
tornado
(pip)
Jul 20, 2026
Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-26483
was published
Jul 20, 2026
Improper neutralization of input during web page generation ('cross-site scripting')...
Moderate
Unreviewed
CVE-2026-6793
was published
Jul 20, 2026
Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview...
Moderate
Unreviewed
CVE-2026-59238
was published
Jul 20, 2026
The affected product accepts user-supplied input within a URL parameter without enforcing...
Moderate
Unreviewed
CVE-2026-2445
was published
Jul 20, 2026
The Flow Payment plugin for WordPress (flow.cl) version 3.0.8 is vulnerable to reflected cross...
Moderate
Unreviewed
CVE-2026-57857
was published
Jul 18, 2026
A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and...
Moderate
Unreviewed
CVE-2026-51081
was published
Jul 17, 2026
The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form...
Moderate
Unreviewed
CVE-2026-10525
was published
Jul 17, 2026
The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for...
Moderate
Unreviewed
CVE-2026-15759
was published
Jul 17, 2026
ProTip!
Advisories are also available from the
GraphQL API