Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5 advisories

Loading
ApostropheCMS: Stored XSS via SVG SMIL URI-list scheme-policy bypass Moderate
CVE-2026-84371 was published for sanitize-html (npm) Sep 1, 2026
koyokr Credited to koyokr
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS Moderate
GHSA-55q2-fjhq-7xh7 was published for dompurify (npm) Aug 7, 2026
koyokr Credited to koyokr
Ghost: Server-Side Request Forgery in Image Fetching Moderate
CVE-2026-70591 was published for ghost (npm) Aug 4, 2026
koyokr Credited to koyokr
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier High
CVE-2026-58263 was published for jodit (npm) Jul 31, 2026
koyokr Credited to koyokr
koyokr Credited to koyokr
ProTip! Advisories are also available from the GraphQL API