Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

43,658 advisories

Loading
thientd Credited to thientd
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands Low
CVE-2026-59727 was published for astro (npm) Jul 20, 2026
jlgore Credited to jlgore
Mistune: XSS via unescaped class option in Admonition directive Moderate
CVE-2026-59926 was published for mistune (pip) Jul 20, 2026
sergeykochanov Credited to sergeykochanov
Mistune: XSS via percent-encoded javascript URI bypass in safe_url() Moderate
CVE-2026-59923 was published for mistune (pip) Jul 20, 2026
redyank Credited to redyank
The Joomla extension Quix Page Builder Pro is vulnerable to an authenticated stored XSS... Moderate Unreviewed
CVE-2026-60029 was published Jul 20, 2026
Astro: Reflected XSS via unescaped View Transition animation properties Moderate
GHSA-4g3v-8h47-v7g6 was published for astro (npm) Jul 20, 2026
Ryoga-exe Credited to Ryoga-exe
Tornado vulnerable to Header Injection and XSS via reason argument Moderate
CVE-2025-67724 was published for tornado (pip) Jul 20, 2026
Finder16 Credited to Finder16 and Cheshire1225 Cheshire1225 Cheshire1225
Improper neutralization of input during web page generation ('cross-site scripting')... Moderate Unreviewed
CVE-2026-6793 was published Jul 20, 2026
ProTip! Advisories are also available from the GraphQL API