GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,585
Maven
5,000+
npm
5,000+
NuGet
923
pip
4,817
Pub
13
RubyGems
1,043
Rust
1,251
Swift
53
Unreviewed advisories
All unreviewed
5,000+
41,938 advisories
Filter by severity
A critical XSS vulnerability affected hackage-server and
hackage.haskell.org. HTML and...
Critical
Unreviewed
CVE-2026-40470
was published
Apr 23, 2026
In hackage-server, user-controlled metadata from .cabal files are rendered into HTML
href...
Critical
Unreviewed
CVE-2026-40472
was published
Apr 23, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2026-28040
was published
Apr 23, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-62110
was published
Apr 23, 2026
The reCaptcha by WebDesignBy WordPress plugin before 2.0 does not sanitize or escape the Site Key...
Low
Unreviewed
CVE-2026-4512
was published
Apr 23, 2026
The WP Store Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2026-3361
was published
Apr 23, 2026
The Gutentor – Gutenberg Blocks – Page Builder for Gutenberg Editor plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-2951
was published
Apr 23, 2026
The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2026-1923
was published
Apr 23, 2026
IBM Guardium Data Protection 12.1 is vulnerable to cross-site scripting. This vulnerability...
Moderate
Unreviewed
CVE-2026-4919
was published
Apr 23, 2026
IBM Guardium Data Protection 12.1 is vulnerable to stored cross-site scripting. This...
Moderate
Unreviewed
CVE-2026-4918
was published
Apr 23, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender
Moderate
GHSA-ffq5-qpvf-xq7x
was published
for
openc3
(RubyGems)
Apr 22, 2026
An authenticated attacker can persist crafted values in multiple field types and trigger client...
Moderate
Unreviewed
CVE-2026-3837
was published
Apr 22, 2026
An authenticated attacker can store a crafted tag value in _user_tags and trigger JavaScript...
Moderate
Unreviewed
CVE-2026-3673
was published
Apr 22, 2026
The WM JqMath plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'style'...
Moderate
Unreviewed
CVE-2026-3998
was published
Apr 22, 2026
The Coachific Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2026-4005
was published
Apr 22, 2026
The Power Charts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2026-4011
was published
Apr 22, 2026
The Quick Interest Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
High
Unreviewed
CVE-2026-5694
was published
Apr 22, 2026
The WP Circliful plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id'...
Moderate
Unreviewed
CVE-2026-3659
was published
Apr 22, 2026
The Accessibly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the REST API...
High
Unreviewed
CVE-2026-3643
was published
Apr 22, 2026
The VI: Include Post By plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Moderate
Unreviewed
CVE-2026-5717
was published
Apr 22, 2026
The List View Google Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2026-2396
was published
Apr 22, 2026
The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable...
High
Unreviewed
CVE-2026-2834
was published
Apr 22, 2026
justhtml has sanitization bypass in custom policies and programmatic DOM
Moderate
GHSA-vrx2-77f2-ww34
was published
for
justhtml
(pip)
Apr 22, 2026
locize Client SDK: Cross-origin DOM XSS & Handler Hijack Through Missing e.origin Validation in InContext Editor
High
GHSA-w937-fg2h-xhq2
was published
for
locize
(npm)
Apr 22, 2026
i18next-http-middleware: HTTP response splitting and DoS via unsanitised Content-Language header
High
CVE-2026-41683
was published
for
i18next-http-middleware
(npm)
Apr 22, 2026
ProTip!
Advisories are also available from the
GraphQL API