GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,578
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,524
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
44,501 advisories
Filter by severity
Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF export link in Joomla...
Moderate
Unreviewed
CVE-2026-77989
was published
Aug 27, 2026
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the...
High
Unreviewed
CVE-2026-16809
was published
Aug 27, 2026
LimeSurvey Community Edition 7.0.5 contains an authenticated stored cross-site scripting...
Moderate
Unreviewed
CVE-2026-65930
was published
Aug 27, 2026
LimeSurvey Community Edition 7.0.5+260623 contains an authenticated reflected Cross-Site...
High
Unreviewed
CVE-2026-63360
was published
Aug 27, 2026
LimeSurvey Community Edition 7.0.5 contains a stored cross-site scripting vulnerability in the...
High
Unreviewed
CVE-2026-15973
was published
Aug 26, 2026
FiftyOne renders a dataset field's description as markup. The sidebar field-information component...
High
Unreviewed
CVE-2026-80426
was published
Aug 26, 2026
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Stored...
Moderate
Unreviewed
CVE-2026-5092
was published
Aug 26, 2026
The Reviews and Rating – Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2026-2388
was published
Aug 26, 2026
The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's ...
Moderate
Unreviewed
CVE-2026-6178
was published
Aug 26, 2026
The Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More...
High
Unreviewed
CVE-2026-18331
was published
Aug 26, 2026
The Gutenverse – Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is...
Moderate
Unreviewed
CVE-2026-3002
was published
Aug 26, 2026
The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget...
Moderate
Unreviewed
CVE-2026-19226
was published
Aug 26, 2026
The WP Fastest Cache – WordPress Cache Plugin plugin for WordPress is vulnerable to Stored Cross...
High
Unreviewed
CVE-2026-19760
was published
Aug 26, 2026
OpenSTAManager has HTML Injection in modules/utenti/edit.php
Low
CVE-2026-44701
was published
for
devcode-it/openstamanager
(Composer)
Aug 26, 2026
LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates
High
GHSA-7w8c-qgxg-m7jx
was published
for
librenms/librenms
(Composer)
Aug 26, 2026
SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed
High
CVE-2026-54606
was published
for
suneditor
(npm)
Aug 26, 2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting")...
Moderate
Unreviewed
CVE-2026-55805
was published
Aug 26, 2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting")...
Unknown
Unreviewed
CVE-2026-15917
was published
Aug 26, 2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting")...
Unknown
Unreviewed
CVE-2026-16640
was published
Aug 26, 2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting")...
Unknown
Unreviewed
CVE-2026-16638
was published
Aug 26, 2026
A vulnerability has been found in code-projects Online Shopping System 1.0. Affected by this...
Low
Unreviewed
CVE-2026-79793
was published
Aug 25, 2026
The WP Fastest Cache WordPress plugin before 1.5.1 does not validate the Host header before using...
High
Unreviewed
CVE-2026-74932
was published
Aug 25, 2026
Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the...
Moderate
Unreviewed
CVE-2026-26211
was published
Aug 25, 2026
Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
High
CVE-2026-55596
was published
for
@platejs/media
(npm)
Aug 25, 2026
Ech0 before 4.7.3 contains a stored cross-site scripting vulnerability in the public RSS feed...
Moderate
Unreviewed
CVE-2026-79663
was published
Aug 25, 2026
ProTip!
Advisories are also available from the
GraphQL API