GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,630
Maven
5,000+
npm
5,000+
NuGet
928
pip
4,850
Pub
13
RubyGems
1,045
Rust
1,301
Swift
53
Unreviewed advisories
All unreviewed
5,000+
1,895 advisories
Filter by severity
CI4MS: Backup Management Full Account Takeover for All Roles & Privilege Escalation via Stored DOM Blind XSS
Moderate
CVE-2026-41201
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 22, 2026
CI4MS: Company Information Public-Facing Page Full Platform Compromise & Full Account Takeover for All Roles & Privilege-Escalation via System Settings Company Information Stored DOM XSS
Critical
CVE-2026-35035
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 6, 2026
Admidio vulnerable to reflected XSS in msg_window.php via Square Bracket to HTML Tag Conversion
Moderate
CVE-2026-41661
was published
for
admidio/admidio
(Composer)
Apr 29, 2026
ipl/web is vulnerable to reflected XSS by malformed search requests
High
CVE-2026-42224
was published
for
ipl/web
(Composer)
Apr 29, 2026
PhpSpreadsheet has XSS via number format code with @ text placeholder bypasses htmlspecialchars in HTML writer
Moderate
CVE-2026-40296
was published
for
phpoffice/phpspreadsheet
(Composer)
Apr 28, 2026
PhpSpreadsheet has XSS via NumberFormat @ Text Substitution in HTML Writer
Moderate
CVE-2026-35453
was published
for
phpoffice/phpspreadsheet
(Composer)
Apr 28, 2026
October Rain has Stored XSS via SVG Filter Bypass
Moderate
CVE-2026-25133
was published
for
october/rain
(Composer)
Apr 14, 2026
CI4MS: Backup Management Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM Blind XSS
Critical
CVE-2026-34563
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 1, 2026
ci4-cms-erp/ci4ms: System Settings (Mail Settings) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
CVE-2026-27599
was published
for
ci4-cms-erp/ci4ms
(Composer)
Mar 30, 2026
CI4MS: System Settings (Social Media Management) Full Platform Compromise & Full Account Takeover for All-Roles & Privilege-Escalation via Stored DOM XSS
Critical
CVE-2026-34561
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 1, 2026
LibreNMS affected by an authenticated Cross-site Scripting vulnerability on the showconfig page
Moderate
CVE-2026-2728
was published
for
librenms/librenms
(Composer)
Apr 13, 2026
Kimai has Stored XSS via Incomplete HTML Attribute Escaping in Team Member Widget
Moderate
CVE-2026-40479
was published
for
kimai/kimai
(Composer)
Apr 15, 2026
October CMS: Reflected XSS via DataTable Form Widget
Low
CVE-2026-27937
was published
for
october/system
(Composer)
Apr 21, 2026
October CMS has Stored XSS in Backend Editor Markup Classes
Moderate
CVE-2026-24906
was published
for
october/system
(Composer)
Apr 14, 2026
October CMS has Stored XSS in Event Log Mail Preview
Moderate
CVE-2026-24907
was published
for
october/system
(Composer)
Apr 14, 2026
rhukster/dom-sanitizer: SVG <style> tag allows CSS injection via unfiltered url() and @import directives
Moderate
CVE-2026-40301
was published
for
rhukster/dom-sanitizer
(Composer)
Apr 10, 2026
WWBN AVideo has an incomplete fix for CVE-2026-33500: XSS
Moderate
CVE-2026-41063
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
WWBN AVideo has Stored XSS via Unanchored Duration Regex in Video Encoder Receiver
Moderate
CVE-2026-41061
was published
for
wwbn/avideo
(Composer)
Apr 14, 2026
Nodcms contains a cross-site request forgery vulnerability
Moderate
CVE-2016-20054
was published
for
khodakhah/nodcms
(Composer)
Apr 4, 2026
Potential XSS vulnerability in jQuery
Moderate
CVE-2020-11022
was published
for
athlon1600/youtube-downloader
(RubyGems)
Apr 29, 2020
REDAXO has reflected XSS backend packages API via function parameter (CSRF token required)
Low
GHSA-xq4j-g85q-wf97
was published
for
redaxo/source
(Composer)
Apr 10, 2026
REDAXO has reflected XSS in backend Metainfo API via type parameter (CSRF token required)
Low
GHSA-m662-8jrj-cw6v
was published
for
redaxo/source
(Composer)
Apr 10, 2026
YesWiki has Persistent Blind XSS at "/?BazaR&vue=consulter"
High
CVE-2026-34598
was published
for
yeswiki/yeswiki
(Composer)
Apr 1, 2026
yaffa vulnerable to Cross Site Scripting
Moderate
CVE-2025-70844
was published
for
kantorge/yaffa
(Composer)
Apr 7, 2026
CI4MS has stored XSS in Pages Content Due to Missing html_purify Sanitization
Moderate
CVE-2026-39392
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 8, 2026
ProTip!
Advisories are also available from the
GraphQL API