GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
4,389 advisories
Filter by severity
The Broken Link Checker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
High
Unreviewed
CVE-2026-75528
was published
Sep 2, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2026-82883
was published
Sep 2, 2026
league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed
High
GHSA-f8fg-pg57-v4j8
was published
for
league/commonmark
(Composer)
Sep 1, 2026
LibreNMS before 26.3.1 contains a stored cross-site scripting vulnerability in legacy PHP...
High
Unreviewed
CVE-2026-84192
was published
Sep 1, 2026
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
High
Unreviewed
CVE-2026-19914
was published
Sep 1, 2026
The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
High
Unreviewed
CVE-2026-19573
was published
Sep 1, 2026
The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is...
High
Unreviewed
CVE-2026-19796
was published
Sep 1, 2026
Unauthenticated Cross Site Scripting (XSS) in RegistrationMagic <= 6.0.9.8 versions.
High
Unreviewed
CVE-2026-82221
was published
Aug 31, 2026
Unauthenticated Cross Site Scripting (XSS) in SliceWP <= 1.2.10 versions.
High
Unreviewed
CVE-2026-82224
was published
Aug 31, 2026
Unauthenticated Cross Site Scripting (XSS) in WordPress Social Login and Register <= 7.8.2 versions.
High
Unreviewed
CVE-2026-82229
was published
Aug 31, 2026
Unauthenticated Cross Site Scripting (XSS) in Email Subscribers & Newsletters <= 5.9.33 versions.
High
Unreviewed
CVE-2026-81290
was published
Aug 31, 2026
Unauthenticated Cross Site Scripting (XSS) in LeadConnector <= 4.0.5 versions.
High
Unreviewed
CVE-2026-81298
was published
Aug 31, 2026
Unauthenticated Cross Site Scripting (XSS) in Uncode <= 2.12.7 versions.
High
Unreviewed
CVE-2026-81291
was published
Aug 31, 2026
Unauthenticated Cross Site Scripting (XSS) in Email Essentials <= 6.0.6 versions.
High
Unreviewed
CVE-2026-81764
was published
Aug 31, 2026
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
High
Unreviewed
CVE-2026-81768
was published
Aug 31, 2026
Unauthenticated Cross Site Scripting (XSS) in Tailored Tools <= 3.0.2 versions.
High
Unreviewed
CVE-2026-81765
was published
Aug 31, 2026
Joomla Extension - joomshaper.com - Stored Cross-Site Scripting (XSS) in MegaMenu Layout...
High
Unreviewed
CVE-2026-78077
was published
Aug 31, 2026
Readest is an open-source e-book reader built on Tauri. In versions prior to 0.11.16, EPUB...
High
Unreviewed
CVE-2026-82642
was published
Aug 30, 2026
The Groundhogg — CRM, Newsletters, and Marketing Automation WordPress plugin before 4.5.13 does...
High
Unreviewed
CVE-2026-81660
was published
Aug 30, 2026
The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise or escape several parameters...
High
Unreviewed
CVE-2026-14307
was published
Aug 30, 2026
The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 does not sanitise and escape...
High
Unreviewed
CVE-2026-76585
was published
Aug 30, 2026
The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site...
High
Unreviewed
CVE-2026-6176
was published
Aug 28, 2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2026-81760
was published
Aug 28, 2026
The WP Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to...
High
Unreviewed
CVE-2026-5934
was published
Aug 28, 2026
Joomla Extension - digital-peak.com - Authenticated, privileged stored XSS in DP Calendar 7.0.0 -...
High
Unreviewed
CVE-2026-78071
was published
Aug 28, 2026
ProTip!
Advisories are also available from the
GraphQL API