GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
33,834 advisories
Filter by severity
Improper neutralization of input during web page generation ('cross-site scripting')...
Moderate
Unreviewed
CVE-2026-8167
was published
Jul 28, 2026
The GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress...
Moderate
Unreviewed
CVE-2026-15730
was published
Jul 28, 2026
ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting...
Moderate
Unreviewed
CVE-2026-44387
was published
Jul 28, 2026
Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS)...
Moderate
Unreviewed
CVE-2026-17528
was published
Jul 28, 2026
Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1...
Moderate
Unreviewed
CVE-2026-65448
was published
Jul 28, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2026-66390
was published
Jul 27, 2026
Pivotick contains a cross-site scripting vulnerability in the sidebar property-list component....
Moderate
Unreviewed
CVE-2026-66825
was published
Jul 27, 2026
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting...
Moderate
Unreviewed
CVE-2026-66031
was published
Jul 27, 2026
The Calendar WordPress plugin before 1.3.18 does not properly escape a user-supplied event field...
Moderate
Unreviewed
CVE-2026-14827
was published
Jul 27, 2026
Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting...
Moderate
Unreviewed
CVE-2026-66030
was published
Jul 27, 2026
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting...
Moderate
Unreviewed
CVE-2026-66029
was published
Jul 27, 2026
The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before...
Moderate
Unreviewed
CVE-2026-14203
was published
Jul 27, 2026
The Sina Extension for Elementor WordPress plugin before 3.10.2 does not escape a value...
Moderate
Unreviewed
CVE-2026-14190
was published
Jul 27, 2026
Simply Schedule Appointments is vulnerable to unauthenticated Stored Cross-Site Scripting in all...
Moderate
Unreviewed
CVE-2026-13400
was published
Jul 27, 2026
The Advanced Ads WordPress plugin before 2.0.23 does not sanitize and escape a shortcode...
Moderate
Unreviewed
CVE-2026-10082
was published
Jul 27, 2026
The Document Gallery WordPress plugin before 5.1.1 does not properly sanitise and escape user...
Moderate
Unreviewed
CVE-2026-12982
was published
Jul 27, 2026
Stored condition values could also execute HTML/JavaScript in administrator summaries.
Moderate
Unreviewed
CVE-2026-63281
was published
Jul 22, 2026
Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values...
Moderate
Unreviewed
CVE-2026-64795
was published
Jul 22, 2026
Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug &...
Moderate
Unreviewed
CVE-2026-66434
was published
Jul 27, 2026
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 versions.
Moderate
Unreviewed
CVE-2026-66448
was published
Jul 27, 2026
Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 versions.
Moderate
Unreviewed
CVE-2026-66433
was published
Jul 27, 2026
Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 versions.
Moderate
Unreviewed
CVE-2026-66445
was published
Jul 27, 2026
Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 versions.
Moderate
Unreviewed
CVE-2026-65563
was published
Jul 27, 2026
Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for WooCommerce – Checkout...
Moderate
Unreviewed
CVE-2026-66475
was published
Jul 27, 2026
Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
Moderate
Unreviewed
CVE-2026-65557
was published
Jul 27, 2026
ProTip!
Advisories are also available from the
GraphQL API