GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
43,658 advisories
Filter by severity
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress...
Moderate
Unreviewed
CVE-2026-15145
was published
Jul 21, 2026
The WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz &...
Moderate
Unreviewed
CVE-2026-15782
was published
Jul 21, 2026
The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress...
Moderate
Unreviewed
CVE-2026-15156
was published
Jul 21, 2026
HCL DevOps Plan is potentially susceptible to Cross-Site Scripting (XSS) which could allow an...
Low
Unreviewed
CVE-2023-37508
was published
Jul 21, 2026
The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-12900
was published
Jul 21, 2026
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
Moderate
CVE-2026-59729
was published
for
astro
(npm)
Jul 20, 2026
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Low
CVE-2026-59727
was published
for
astro
(npm)
Jul 20, 2026
Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
Moderate
CVE-2026-59929
was published
for
mistune
(pip)
Jul 20, 2026
Mistune: XSS via unescaped class option in Admonition directive
Moderate
CVE-2026-59926
was published
for
mistune
(pip)
Jul 20, 2026
Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
Moderate
CVE-2026-59923
was published
for
mistune
(pip)
Jul 20, 2026
The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads...
Critical
Unreviewed
CVE-2026-60034
was published
Jul 20, 2026
The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS...
Moderate
Unreviewed
CVE-2026-60029
was published
Jul 20, 2026
The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS...
High
Unreviewed
CVE-2026-60028
was published
Jul 20, 2026
Astro: Reflected XSS via unescaped View Transition animation properties
Moderate
GHSA-4g3v-8h47-v7g6
was published
for
astro
(npm)
Jul 20, 2026
Tornado vulnerable to Header Injection and XSS via reason argument
Moderate
CVE-2025-67724
was published
for
tornado
(pip)
Jul 20, 2026
Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in...
Moderate
Unreviewed
CVE-2026-26483
was published
Jul 20, 2026
Improper neutralization of input during web page generation ('cross-site scripting')...
Moderate
Unreviewed
CVE-2026-6793
was published
Jul 20, 2026
Stored Cross-site Scripting (CWE-79) in the client-side report rendering functions (renderPreview...
Moderate
Unreviewed
CVE-2026-59238
was published
Jul 20, 2026
The affected product accepts user-supplied input within a URL parameter without enforcing...
Moderate
Unreviewed
CVE-2026-2445
was published
Jul 20, 2026
The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0...
High
Unreviewed
CVE-2026-9833
was published
Jul 20, 2026
The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled...
High
Unreviewed
CVE-2026-12592
was published
Jul 20, 2026
The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before...
High
Unreviewed
CVE-2026-12970
was published
Jul 20, 2026
The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape...
High
Unreviewed
CVE-2026-10081
was published
Jul 20, 2026
A flaw has been found in itsourcecode Courier Management System up to 1.0. Affected by this...
Low
Unreviewed
CVE-2026-16229
was published
Jul 19, 2026
A vulnerability has been found in code-projects Online Examination System 1.0. This vulnerability...
Low
Unreviewed
CVE-2026-16220
was published
Jul 19, 2026
ProTip!
Advisories are also available from the
GraphQL API