Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,895 advisories

Loading
Admidio vulnerable to reflected XSS in msg_window.php via Square Bracket to HTML Tag Conversion Moderate
CVE-2026-41661 was published for admidio/admidio (Composer) Apr 29, 2026
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
ipl/web is vulnerable to reflected XSS by malformed search requests High
CVE-2026-42224 was published for ipl/web (Composer) Apr 29, 2026
PhpSpreadsheet has XSS via number format code with @ text placeholder bypasses htmlspecialchars in HTML writer Moderate
CVE-2026-40296 was published for phpoffice/phpspreadsheet (Composer) Apr 28, 2026
Keyvanhardani Credited to Keyvanhardani
PhpSpreadsheet has XSS via NumberFormat @ Text Substitution in HTML Writer Moderate
CVE-2026-35453 was published for phpoffice/phpspreadsheet (Composer) Apr 28, 2026
marduc812 Credited to marduc812
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS Moderate
CVE-2026-41201 was published for ci4-cms-erp/ci4ms (Composer) Apr 22, 2026
bugmithlegend Credited to bugmithlegend and DexterHK DexterHK DexterHK
October CMS: Reflected XSS via DataTable Form Widget Low
CVE-2026-27937 was published for october/system (Composer) Apr 21, 2026
daftspunk Credited to daftspunk
Kimai has Stored XSS via Incomplete HTML Attribute Escaping in Team Member Widget Moderate
CVE-2026-40479 was published for kimai/kimai (Composer) Apr 15, 2026
WWBN AVideo has an incomplete fix for CVE-2026-33500: XSS Moderate
CVE-2026-41063 was published for wwbn/avideo (Composer) Apr 14, 2026
WWBN AVideo has Stored XSS via Unanchored Duration Regex in Video Encoder Receiver Moderate
CVE-2026-41061 was published for wwbn/avideo (Composer) Apr 14, 2026
offset Credited to offset
October Rain has Stored XSS via SVG Filter Bypass Moderate
CVE-2026-25133 was published for october/rain (Composer) Apr 14, 2026
daftspunk Credited to daftspunk
October CMS has Stored XSS in Event Log Mail Preview Moderate
CVE-2026-24907 was published for october/system (Composer) Apr 14, 2026
Neosprings Credited to Neosprings and daftspunk daftspunk daftspunk
October CMS has Stored XSS in Backend Editor Markup Classes Moderate
CVE-2026-24906 was published for october/system (Composer) Apr 14, 2026
Neosprings Credited to Neosprings and daftspunk daftspunk daftspunk
LibreNMS affected by an authenticated Cross-site Scripting vulnerability on the showconfig page Moderate
CVE-2026-2728 was published for librenms/librenms (Composer) Apr 13, 2026
rhukster/dom-sanitizer: SVG <style> tag allows CSS injection via unfiltered url() and @import directives Moderate
CVE-2026-40301 was published for rhukster/dom-sanitizer (Composer) Apr 10, 2026
morimori-dev Credited to morimori-dev
REDAXO has reflected XSS backend packages API via function parameter (CSRF token required) Low
GHSA-xq4j-g85q-wf97 was published for redaxo/source (Composer) Apr 10, 2026
NumberOreo1 Credited to NumberOreo1
REDAXO has reflected XSS in backend Metainfo API via type parameter (CSRF token required) Low
GHSA-m662-8jrj-cw6v was published for redaxo/source (Composer) Apr 10, 2026
NumberOreo1 Credited to NumberOreo1
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization Moderate
CVE-2026-39392 was published for ci4-cms-erp/ci4ms (Composer) Apr 8, 2026
offset Credited to offset
CI4MS has stored XSS via Unescaped Blacklist Note in Admin User List Moderate
CVE-2026-39391 was published for ci4-cms-erp/ci4ms (Composer) Apr 8, 2026
offset Credited to offset
CI4MS has stored XSS via srcdoc attribute bypass in Google Maps iframe setting Moderate
CVE-2026-39390 was published for ci4-cms-erp/ci4ms (Composer) Apr 8, 2026
offset Credited to offset
WWBN AVideo has Stored XSS via Malicious EPG XML Program Titles in AVideo EPG Page Moderate
CVE-2026-39367 was published for wwbn/avideo (Composer) Apr 8, 2026
offset Credited to offset
yaffa vulnerable to Cross Site Scripting Moderate
CVE-2025-70844 was published for kantorge/yaffa (Composer) Apr 7, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the creation/editing module Moderate
CVE-2026-31313 was published for feehi/cms (Composer) Apr 6, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Page Sign parameter Moderate
CVE-2026-31350 was published for feehi/cms (Composer) Apr 6, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the creation/editing module Moderate
CVE-2026-31351 was published for feehi/cms (Composer) Apr 6, 2026
Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Role Management module Moderate
CVE-2026-31352 was published for feehi/cms (Composer) Apr 6, 2026
ProTip! Advisories are also available from the GraphQL API