GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
745 advisories
Filter by severity
TeleJSON: DOM XSS via unsanitised constructor name in `new Function()`
Low
GHSA-ccgf-5rwj-j3hv
was published
for
telejson
(npm)
Apr 2, 2026
dbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configuration
High
CVE-2026-34725
was published
for
dbgate-web
(npm)
Apr 1, 2026
@payloadcms/next has Stored XSS in Admin Panel
High
CVE-2026-34748
was published
for
@payloadcms/next
(npm)
Apr 1, 2026
Nuxt OG Image is vulnerable to reflected XSS via query parameter injection into HTML attributes
Moderate
CVE-2026-34405
was published
for
nuxt-og-image
(npm)
Mar 31, 2026
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
Low
GHSA-53p3-c7vp-4mcc
was published
for
action_text-trix
(RubyGems)
Mar 29, 2026
DOMPurify is vulnerable to mutation-XSS via Re-Contextualization
Moderate
GHSA-h8r8-wccr-v5f2
was published
for
dompurify
(npm)
Mar 27, 2026
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
High
CVE-2026-33941
was published
for
handlebars
(npm)
Mar 27, 2026
n8n has XSS in its Credential Management Flow
Moderate
GHSA-364x-8g5j-x2pr
was published
for
n8n
(npm)
Mar 27, 2026
n8n has XSS in Chat Trigger Node through Custom CSS
Moderate
GHSA-3c7f-5hgj-h279
was published
for
n8n
(npm)
Mar 27, 2026
n8n: Authenticated XSS and Open Redirect via Form Node
Moderate
GHSA-w673-8fjw-457c
was published
for
n8n
(npm)
Mar 27, 2026
n8n has a Stored XSS Vulnerability in its Form Trigger
Moderate
GHSA-q4fm-pjq6-m63g
was published
for
n8n
(npm)
Mar 27, 2026
Express XSS Sanitizer: allowedTags/allowedAttributes bypass leads to permissive sanitization (XSS risk)
High
CVE-2026-33979
was published
for
express-xss-sanitizer
(npm)
Mar 27, 2026
Handlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
Moderate
CVE-2026-33916
was published
for
handlebars
(npm)
Mar 26, 2026
n8n Vulnerable to XSS via Binary Data Inline HTML Rendering
Moderate
CVE-2026-33749
was published
for
n8n
(npm)
Mar 26, 2026
Seafile Server has multiple stored XSS vulnerabilities
Moderate
CVE-2026-30587
was published
for
@seafile/sdoc-editor
(npm)
Mar 25, 2026
@grackle-ai/server has Missing Content-Security-Policy and X-Frame-Options Headers
Moderate
GHSA-3mjm-x6gw-2x42
was published
for
@grackle-ai/server
(npm)
Mar 25, 2026
@grackle-ai/server: Unescaped Error String in renderPairingPage() HTML Template
Low
GHSA-7q9x-8g6p-3x75
was published
for
@grackle-ai/server
(npm)
Mar 25, 2026
PDFME has XSS via Unsanitized i18n Label Injection into innerHTML in multiVariableText propPanel
Moderate
GHSA-xgx4-2wgv-4jhm
was published
for
@pdfme/schemas
(npm)
Mar 20, 2026
oRPC has Stored XSS in OpenAPI Reference Plugin via unescaped JSON.stringify
High
CVE-2026-33331
was published
for
@orpc/openapi
(npm)
Mar 20, 2026
SVG Injection via Unsanitized Options in @dicebear/core and @dicebear/initials
Moderate
CVE-2026-33311
was published
for
@dicebear/core
(npm)
Mar 19, 2026
NotChatbot WebChat has a stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2026-30048
was published
for
@developer.notchatbot/webchat
(npm)
Mar 18, 2026
Cross-Site Scripting (XSS) via SVG Schema innerHTML Injection in @pdfme/schemas
Moderate
GHSA-87v3-4cfp-cm76
was published
for
@pdfme/schemas
(npm)
Mar 18, 2026
Cross-Site Scripting (XSS) via Select Schema Option Value Injection in @pdfme/schemas
Moderate
GHSA-qq9g-96v4-m3cj
was published
for
@pdfme/schemas
(npm)
Mar 18, 2026
jsPDF has HTML Injection in New Window paths
Critical
CVE-2026-31938
was published
for
jspdf
(npm)
Mar 17, 2026
Parse Server has a stored XSS filter bypass via Content-Type MIME parameter and missing XML extension blocklist entries
High
CVE-2026-32728
was published
for
parse-server
(npm)
Mar 16, 2026
ProTip!
Advisories are also available from the
GraphQL API