Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,389 advisories

Loading
league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed High
GHSA-f8fg-pg57-v4j8 was published for league/commonmark (Composer) Sep 1, 2026
StarPlatinu Credited to StarPlatinu
Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions. High Unreviewed
CVE-2026-82221 was published Aug 31, 2026
Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions. High Unreviewed
CVE-2026-82224 was published Aug 31, 2026
Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions. High Unreviewed
CVE-2026-81298 was published Aug 31, 2026
Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions. High Unreviewed
CVE-2026-81291 was published Aug 31, 2026
Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions. High Unreviewed
CVE-2026-81764 was published Aug 31, 2026
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions. High Unreviewed
CVE-2026-81768 was published Aug 31, 2026
Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions. High Unreviewed
CVE-2026-81765 was published Aug 31, 2026
ProTip! Advisories are also available from the GraphQL API