GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,193
Erlang
25
GitHub Actions
39
Go
2,385
Maven
3,027
npm
3,078
NuGet
529
pip
2,897
Pub
5
RubyGems
444
Rust
905
Swift
20
Unreviewed advisories
All unreviewed
5,000+
807 advisories
Filter by severity
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
Moderate
CVE-2026-41201
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 22, 2026
Kimai has Stored XSS via Incomplete HTML Attribute Escaping in Team Member Widget
Moderate
CVE-2026-40479
was published
for
kimai/kimai
(Composer)
Apr 15, 2026
WWBN AVideo has an incomplete fix for CVE-2026-33500: XSS
Moderate
GHSA-m7r8-6q9j-m2hc
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
WWBN AVideo has Stored XSS via Unanchored Duration Regex in Video Encoder Receiver
Moderate
GHSA-8pv3-29pp-pf8f
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
October Rain has Stored XSS via SVG Filter Bypass
Moderate
CVE-2026-25133
was published
for
october/rain
(Composer)
Apr 14, 2026
October CMS has Stored XSS in Event Log Mail Preview
Moderate
CVE-2026-24907
was published
for
october/system
(Composer)
Apr 14, 2026
October CMS has Stored XSS in Backend Editor Markup Classes
Moderate
CVE-2026-24906
was published
for
october/system
(Composer)
Apr 14, 2026
LibreNMS affected by an authenticated Cross-site Scripting vulnerability on the showconfig page
Moderate
CVE-2026-2728
was published
for
librenms/librenms
(Composer)
Apr 13, 2026
rhukster/dom-sanitizer: SVG <style> tag allows CSS injection via unfiltered url() and @import directives
Moderate
CVE-2026-40301
was published
for
rhukster/dom-sanitizer
(Composer)
Apr 10, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
Moderate
CVE-2026-39392
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 8, 2026
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List
Moderate
CVE-2026-39391
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 8, 2026
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting
Moderate
CVE-2026-39390
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 8, 2026
WWBN AVideo has Stored XSS via Malicious EPG XML Program Titles in AVideo EPG Page
Moderate
CVE-2026-39367
was published
for
wwbn/avideo
(Composer)
Apr 8, 2026
yaffa vulnerable to Cross Site Scripting
Moderate
CVE-2025-70844
was published
for
kantorge/yaffa
(Composer)
Apr 7, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the creation/editing module
Moderate
CVE-2026-31313
was published
for
feehi/cms
(Composer)
Apr 6, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Page Sign parameter
Moderate
CVE-2026-31350
was published
for
feehi/cms
(Composer)
Apr 6, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the creation/editing module
Moderate
CVE-2026-31351
was published
for
feehi/cms
(Composer)
Apr 6, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Role Management module
Moderate
CVE-2026-31352
was published
for
feehi/cms
(Composer)
Apr 6, 2026
Feehi CMS has authenticated stored cross-site scripting (XSS) vulnerabilities via the Permissions module
Moderate
CVE-2026-31354
was published
for
feehi/cms
(Composer)
Apr 6, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Category module
Moderate
CVE-2026-31353
was published
for
feehi/cms
(Composer)
Apr 6, 2026
Nodcms contains a cross-site request forgery vulnerability
Moderate
CVE-2016-20054
was published
for
khodakhah/nodcms
(Composer)
Apr 4, 2026
Roundcube Webmail: Insufficient HTML attachment sanitization in preview mode
Moderate
CVE-2026-35539
was published
for
roundcube/roundcubemail
(Composer)
Apr 3, 2026
phpMyFAQ: SVG Sanitizer Bypass via HTML Entity Encoding Leads to Stored XSS and Privilege Escalation
Moderate
CVE-2026-34974
was published
for
thorsten/phpmyfaq
(Composer)
Apr 1, 2026
AVideo has Stored XSS via Unescaped Menu Item Fields in TopMenu Plugin
Moderate
GHSA-gmpc-fxg2-vcmq
was published
for
wwbn/avideo
(Composer)
Apr 1, 2026
phpMyFAQ: Stored XSS via Regex Bypass in Filter::removeAttributes()
Moderate
CVE-2026-34729
was published
for
phpmyfaq/phpmyfaq
(Composer)
Apr 1, 2026
ProTip!
Advisories are also available from the
GraphQL API