GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,193
Erlang
25
GitHub Actions
39
Go
2,385
Maven
3,027
npm
3,078
NuGet
529
pip
2,897
Pub
5
RubyGems
444
Rust
905
Swift
20
Unreviewed advisories
All unreviewed
5,000+
40 advisories
Filter by severity
pretalx vulnerable to stored cross-site scripting in organizer search typeahead
High
GHSA-cjcx-jfp2-f7m2
was published
for
pretalx
(pip)
Apr 18, 2026
JustHTML is vulnerable to XSS via code fence breakout in <pre> content
High
GHSA-5vp3-3cg6-2rq3
was published
for
justhtml
(pip)
Mar 24, 2026
Rucio WebUI Vulnerable to Stored Cross-site Scripting (XSS) through Custom Rule Function
High
CVE-2026-25733
was published
for
rucio-webui
(pip)
Feb 25, 2026
Rucio WebUI has a Reflected Cross-site Scripting Vulnerability
High
CVE-2026-25136
was published
for
rucio-webui
(pip)
Feb 25, 2026
Google Cloud Vertex AI SDK affected by Stored Cross-Site Scripting (XSS)
High
CVE-2026-2472
was published
for
google-cloud-aiplatform
(pip)
Feb 20, 2026
Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL
High
CVE-2026-25640
was published
for
pydantic-ai
(pip)
Feb 6, 2026
MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field
High
CVE-2026-24490
was published
for
mobsf
(pip)
Jan 26, 2026
Label Studio is vulnerable to full account takeover by chaining Stored XSS + IDOR in User Profile via custom_hotkeys field
High
CVE-2026-22033
was published
for
label-studio
(pip)
Jan 12, 2026
NiceGUI apps which use `ui.sub_pages` vulnerable to zero-click XSS
High
CVE-2026-21873
was published
for
nicegui
(pip)
Jan 8, 2026
Open WebUI vulnerable to Stored DOM XSS via prompts when 'Insert Prompt as Rich Text' is enabled resulting in ATO/RCE
High
CVE-2025-64495
was published
for
open-webui
(npm)
Nov 7, 2025
Home Assistant has Stored XSS vulnerability in Energy dashboard from Energy Entity Name
High
CVE-2025-62172
was published
for
homeassistant
(pip)
Oct 14, 2025
pyLoad CNL and captcha handlers allow Code Injection via unsanitized parameters
High
CVE-2025-61773
was published
for
pyload-ng
(pip)
Oct 9, 2025
Cadwyn vulnerable to XSS on the docs page
High
CVE-2025-53528
was published
for
cadwyn
(pip)
Jul 21, 2025
ChangeDetection.io XSS in watch overview
High
CVE-2025-52558
was published
for
changedetection.io
(pip)
Jun 23, 2025
label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
High
CVE-2025-47783
was published
for
label-studio
(pip)
May 15, 2025
Open WebUI stored cross-site scripting (XSS) vulnerability
High
CVE-2024-7990
was published
for
open-webui
(pip)
Mar 20, 2025
Open WebUI Vulnerable to a Session Fixation Attack
High
CVE-2024-7053
was published
for
open-webui
(pip)
Mar 20, 2025
MobSF Stored Cross-Site Scripting (XSS)
High
CVE-2025-24803
was published
for
mobsf
(pip)
Feb 5, 2025
CKAN has an XSS vector in user uploaded images in group/org and user profiles
High
CVE-2025-24372
was published
for
ckan
(pip)
Feb 5, 2025
LLama Factory Remote OS Command Injection Vulnerability
High
CVE-2024-52803
was published
for
llamafactory
(pip)
Nov 21, 2024
HTML Cleaner allows crafted scripts in special contexts like svg or math to pass through
High
CVE-2024-52595
was published
for
lxml-html-clean
(pip)
Nov 19, 2024
HTML injection in Jupyter Notebook and JupyterLab leading to DOM Clobbering
High
CVE-2024-43805
was published
for
jupyterlab
(pip)
Aug 29, 2024
pretix Stored Cross-site Scripting vulnerability
High
CVE-2024-8113
was published
for
pretix
(pip)
Aug 23, 2024
ansibleguy-webui Cross-site Scripting vulnerability
High
CVE-2024-36110
was published
for
ansibleguy-webui
(pip)
May 28, 2024
ProTip!
Advisories are also available from the
GraphQL API