Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.

150,381 advisories

Loading
Contributor Cross Site Scripting (XSS) in Appointment Hour Booking <= 1.5.86 versions. Moderate Unreviewed
CVE-2026-65514 was published Jul 23, 2026
Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions. Moderate Unreviewed
CVE-2026-65524 was published Jul 23, 2026
Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions. Moderate Unreviewed
CVE-2026-65525 was published Jul 23, 2026
Unauthenticated Broken Access Control in Event post <= 6.0.1 versions. Moderate Unreviewed
CVE-2026-65486 was published Jul 23, 2026
Unauthenticated Broken Access Control in PeproDev Ultimate Invoice <= 2.2.6 versions. Moderate Unreviewed
CVE-2026-65499 was published Jul 23, 2026
Unauthenticated Cross Site Request Forgery (CSRF) in WP Activity Log <= 5.6.4 versions. Moderate Unreviewed
CVE-2026-65512 was published Jul 23, 2026
Author Cross Site Scripting (XSS) in Photo Gallery <= 2.7.7.29 versions. Moderate Unreviewed
CVE-2026-65519 was published Jul 23, 2026
Custom role Server Side Request Forgery (SSRF) in JetBooking <= 4.1.2 versions. Moderate Unreviewed
CVE-2026-65466 was published Jul 23, 2026
Contributor Server Side Request Forgery (SSRF) in JetEngine <= 3.8.11 versions. Moderate Unreviewed
CVE-2026-65467 was published Jul 23, 2026
Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions. Moderate Unreviewed
CVE-2026-65464 was published Jul 23, 2026
Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions. Moderate Unreviewed
CVE-2026-65468 was published Jul 23, 2026
Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions. Moderate Unreviewed
CVE-2026-65463 was published Jul 23, 2026
Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.1.1 versions. Moderate Unreviewed
CVE-2026-65465 was published Jul 23, 2026
Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions. Moderate Unreviewed
CVE-2026-65469 was published Jul 23, 2026
Contributor Cross Site Scripting (XSS) in Fluent Support <= 2.3.0 versions. Moderate Unreviewed
CVE-2026-65470 was published Jul 23, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')... Moderate Unreviewed
CVE-2026-65475 was published Jul 23, 2026
Author Cross Site Scripting (XSS) in HashThemes Demo Importer <= 1.4.2 versions. Moderate Unreviewed
CVE-2026-65483 was published Jul 23, 2026
Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions. Moderate Unreviewed
CVE-2026-65472 was published Jul 23, 2026
Subscriber Broken Access Control in Reviewer <= 3.14.2 versions. Moderate Unreviewed
CVE-2026-65479 was published Jul 23, 2026
Contributor Broken Access Control in Style Kits <= 2.6.5 versions. Moderate Unreviewed
CVE-2026-65484 was published Jul 23, 2026
Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions. Moderate Unreviewed
CVE-2026-65480 was published Jul 23, 2026
ProTip! Advisories are also available from the GraphQL API