Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

446 advisories

Loading
Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in serialized function bodies Low
CVE-2026-97711 was published for serialize-javascript (npm) Sep 30, 2026
Shop manager Content Injection in Astra WordPress Theme <= 4.13.12 versions. Low Unreviewed
CVE-2026-27085 was published Sep 30, 2026
Laravel: XSS in Debug Page Information Low
CVE-2026-102279 was published for laravel/framework (Composer) Sep 29, 2026
Rikuxx0 Credited to Rikuxx0
Mediawiki EmbedVideo Extension has stored XSS via malformed src url with $wgEmbedVideoRequireConsent disabled High
CVE-2026-57440 was published for starcitizenwiki/embedvideo (Composer) Sep 25, 2026
Home Assistant: XSS in Statistics Graph Card Critical
CVE-2026-91130 was published for homeassistant (pip) Sep 22, 2026
pwnpanda Credited to pwnpanda
Apache Spark History Server allows stored cross-site scripting through unescaped application names Moderate
CVE-2026-32773 was published for org.apache.spark:spark-core_2.12 (Maven) Sep 2, 2026
oscerd Credited to oscerd
EvidentObscurity Credited to EvidentObscurity, rugk, and elrido rugk rugk
elrido elrido
HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows... Moderate Unreviewed
CVE-2026-75872 was published Aug 18, 2026
CrownKingClown Credited to CrownKingClown
ProTip! Advisories are also available from the GraphQL API