Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,513 advisories

Loading
OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page Moderate
CVE-2026-62280 was published for org.openidentityplatform.openam:openam-oauth2 (Maven) Jul 24, 2026
geo-chen Credited to geo-chen
Trix: Stored XSS via HTMLParser attribute injection on paste Moderate
GHSA-53g2-mvcc-q9x3 was published for action_text-trix (RubyGems) Jul 24, 2026
newbiefromcoma Credited to newbiefromcoma
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797 Moderate
GHSA-hc76-7mpc-qjqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
React Router: RSCErrorHandler Missing Protocol Validation (XSS) Moderate
CVE-2026-53667 was published for react-router (npm) Jul 23, 2026
unknownhad Credited to unknownhad
DOMPurify is vulnerable to mutation-XSS via Re-Contextualization Moderate
CVE-2026-65914 was published for dompurify (npm) Mar 27, 2026
researchatfluidattacks Credited to researchatfluidattacks, caverav, and tachote caverav caverav
tachote tachote
trace37labs Credited to trace37labs and EchoTydes EchoTydes EchoTydes
Wagtail Vulnerable to Cross-site Scripting in TableBlock class attributes Moderate
CVE-2026-28222 was published for wagtail (pip) Mar 3, 2026
GCXWLP Credited to GCXWLP, RealOrangeOne, and gasman RealOrangeOne RealOrangeOne
gasman gasman
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations Moderate
GHSA-cj75-f6xr-r4g7 was published for rails-html-sanitizer (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
Loofah: SVG `href` attribute bypasses local-reference restriction Moderate
GHSA-9wjq-cp2p-hrgf was published for loofah (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
Dosage Vulnerable to Stored Cross-Site Scripting (XSS) in HTML/RSS Output Handlers Moderate
GHSA-75mw-h36v-2jv7 was published for dosage (pip) Jun 26, 2026
yueyueL Credited to yueyueL and krotname krotname krotname
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility Moderate
CVE-2026-59895 was published for hono (npm) Jul 21, 2026
a-tt-om Credited to a-tt-om and teebow1e teebow1e teebow1e
Gogs has DOM-based XSS via Milestone Name on New Issue Page Moderate
CVE-2026-52807 was published for gogs.io/gogs (Go) Jun 23, 2026
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS Moderate
CVE-2026-52816 was published for gogs.io/gogs (Go) Jun 23, 2026
JLGitHub66 Credited to JLGitHub66
thientd Credited to thientd
Mistune: XSS via unescaped class option in Admonition directive Moderate
CVE-2026-59926 was published for mistune (pip) Jul 20, 2026
sergeykochanov Credited to sergeykochanov
Mistune: XSS via percent-encoded javascript URI bypass in safe_url() Moderate
CVE-2026-59923 was published for mistune (pip) Jul 20, 2026
redyank Credited to redyank
n8n has a Stored XSS Vulnerability in its Form Trigger Moderate
CVE-2026-56358 was published for n8n (npm) Mar 27, 2026
tr4ce-ju Credited to tr4ce-ju
NocoDB: Stored Cross-Site Scripting via Secure Attachment Moderate
CVE-2026-53929 was published for nocodb (npm) Jun 17, 2026
bugbunny-research Credited to bugbunny-research
NocoDB: Reflected Cross-Site Scripting via Password Reset Token Moderate
CVE-2026-47376 was published for nocodb (npm) Jun 5, 2026
fg0x0 Credited to fg0x0
NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL Moderate
CVE-2026-46547 was published for nocodb (npm) May 21, 2026
naoyashiga Credited to naoyashiga
Astro: Reflected XSS via unescaped View Transition animation properties Moderate
GHSA-4g3v-8h47-v7g6 was published for astro (npm) Jul 20, 2026
Ryoga-exe Credited to Ryoga-exe
Tornado vulnerable to Header Injection and XSS via reason argument Moderate
CVE-2025-67724 was published for tornado (pip) Jul 20, 2026
Finder16 Credited to Finder16 and Cheshire1225 Cheshire1225 Cheshire1225
sm1ee Credited to sm1ee
ProTip! Advisories are also available from the GraphQL API