Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

44,695 advisories

Loading
rz1027 Credited to rz1027
SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting... Moderate Unreviewed
CVE-2026-75134 was published Sep 2, 2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting")... Moderate Unreviewed
CVE-2026-81201 was published Sep 2, 2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting")... Moderate Unreviewed
CVE-2026-81167 was published Sep 2, 2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting")... Moderate Unreviewed
CVE-2026-81160 was published Sep 2, 2026
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. High Unreviewed
CVE-2026-76782 was published Sep 2, 2026
Vulnerability in Drupal Screenshot. This issue affects Screenshot versions: *.*. High Unreviewed
CVE-2026-76759 was published Sep 2, 2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting")... Moderate Unreviewed
CVE-2026-18986 was published Sep 2, 2026
Sulu: Stored XSS via media download inline-disposition override Moderate
CVE-2026-82396 was published for sulu/sulu (Composer) Sep 2, 2026
0x3xP01t3r Credited to 0x3xP01t3r
Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes Moderate
GHSA-cp6q-959q-f8rh was published for @tiptap/core (npm) Sep 2, 2026
joostgrunwald Credited to joostgrunwald
Livewire DOM-based cross-site scripting during client-side state handling Moderate
CVE-2026-81887 was published for livewire/livewire (Composer) Sep 2, 2026
Vagebondcur Credited to Vagebondcur and MelvinTh17 MelvinTh17 MelvinTh17
Contributor Cross Site Scripting (XSS) in WCFM Marketplace <= 3.8.2 versions. Moderate Unreviewed
CVE-2026-83562 was published Sep 2, 2026
Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions. Moderate Unreviewed
CVE-2026-84781 was published Sep 2, 2026
Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting... Moderate Unreviewed
CVE-2026-84793 was published Sep 2, 2026
Unauthenticated Cross Site Scripting (XSS) in TrustedSite <= 1.2.5 versions. High Unreviewed
CVE-2026-81771 was published Sep 2, 2026
Unauthenticated Cross Site Scripting (XSS) in Estatik <= 4.3.4 versions. High Unreviewed
CVE-2026-81775 was published Sep 2, 2026
ProTip! Advisories are also available from the GraphQL API