GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
45,334 advisories
Filter by severity
md-editor-v3: XSS via fenced-code language rendering bypass
Moderate
CVE-2026-84992
was published
for
md-editor-v3
(npm)
Sep 18, 2026
Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)
Moderate
GHSA-9rcc-pmj8-ffhr
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
Semantic MediaWiki affected by reflected XSS in `Special:Ask` via a forged cursor pagination token
Moderate
CVE-2026-77616
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
Semantic MediaWiki has a query debug output XSS (`DebugFormatter`)
Moderate
CVE-2026-77610
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
Semantic MediaWiki affected by Special:Ask table `sep` parameter reflected XSS
Moderate
CVE-2026-77607
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
Semantic MediaWiki has reflected XSS in `Special:SearchByProperty` (`property` and `value` parameters)
Moderate
CVE-2026-77608
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
Semantic MediaWiki has reflected XSS in Special:Ask plain table headers
Moderate
CVE-2026-77606
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
Semantic MediaWiki vulnerable to stored XSS through wikitext via improper use of non-reserved data attributes
High
CVE-2025-61682
was published
for
mediawiki/semantic-media-wiki
(Composer)
Sep 18, 2026
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML...
Critical
Unreviewed
CVE-2026-93659
was published
Sep 18, 2026
A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file...
Moderate
Unreviewed
CVE-2026-93505
was published
Sep 18, 2026
Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote...
Moderate
Unreviewed
CVE-2026-79294
was published
Sep 18, 2026
Opencast: Stored XSS in Paella player via WebVTT/DFXP caption cue text
High
CVE-2026-77615
was published
for
org.opencastproject:opencast-engage-paella-player-7
(Maven)
Sep 18, 2026
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup...
High
Unreviewed
CVE-2026-87915
was published
Sep 18, 2026
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2026-90884
was published
Sep 18, 2026
The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress...
High
Unreviewed
CVE-2026-18405
was published
Sep 18, 2026
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup...
Moderate
Unreviewed
CVE-2026-15797
was published
Sep 18, 2026
The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross...
High
Unreviewed
CVE-2026-83561
was published
Sep 18, 2026
The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting in...
Moderate
Unreviewed
CVE-2025-13533
was published
Sep 18, 2026
The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-92554
was published
Sep 18, 2026
The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ...
Moderate
Unreviewed
CVE-2026-92622
was published
Sep 18, 2026
The Qi Addons For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting...
Moderate
Unreviewed
CVE-2026-92249
was published
Sep 18, 2026
The Newsletter – Send awesome emails from WordPress plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2026-90981
was published
Sep 18, 2026
An improper neutralization of input during web page generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2026-13623
was published
Sep 18, 2026
An improper neutralization of input during web page generation ('cross-site scripting')...
Moderate
Unreviewed
CVE-2026-40534
was published
Sep 18, 2026
HCL BigFix Service Management is affected by Cross-Site Scripting (XSS) vulnerability, which...
High
Unreviewed
CVE-2026-67103
was published
Sep 18, 2026
ProTip!
Advisories are also available from the
GraphQL API