Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,025 advisories

Loading
Duplicate Advisory: Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type Moderate
GHSA-5w9j-w5p8-r4p7 was published for craftcms/cms (Composer) Jun 21, 2026 withdrawn
Duplicate Advisory: Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page Moderate
GHSA-9r7j-7jhg-4f4c was published for craftcms/cms (Composer) Jun 21, 2026 withdrawn
symfony/ux-icons: XSS via unsanitized SVG content in local files and Iconify on-demand responses Moderate
CVE-2026-55877 was published for symfony/ux-icons (Composer) Jun 19, 2026
Kocal Credited to Kocal and Amoifr Amoifr Amoifr
StarCitizenWiki Extension Embed Video: Stored XSS via malformed src url with $wgEmbedVideoRequireConsent enabled High
CVE-2026-55692 was published for starcitizenwiki/embedvideo (Composer) Jun 19, 2026
StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized class passed to template High
CVE-2026-55691 was published for starcitizenwiki/embedvideo (Composer) Jun 19, 2026
StarCitizenWiki Extension Embed Video: Stored XSS via unsanitized service name in exception text High
CVE-2026-55690 was published for starcitizenwiki/embedvideo (Composer) Jun 19, 2026
symfony/ux-autocomplete: XSS via unescaped AJAX response data Moderate
CVE-2026-49216 was published for symfony/ux-autocomplete (Composer) Jun 19, 2026
Kocal Credited to Kocal
symfony/ux-live-component: XSS via attacker-controlled child component tag Moderate
CVE-2026-49210 was published for symfony/ux-live-component (Composer) Jun 19, 2026
Amoifr Credited to Amoifr and Kocal Kocal Kocal
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()` High
CVE-2026-54002 was published for getkirby/cms (Composer) Jun 18, 2026
shafiqaimanx Credited to shafiqaimanx
CyberKareem Credited to CyberKareem
Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module High
CVE-2026-55746 was published for cotonti/cotonti (Composer) Jun 18, 2026
Filament: Disabled RichEditor field state can be used for XSS High
CVE-2026-55409 was published for filament/forms (Composer) Jun 17, 2026
mike197312 Credited to mike197312 and danharrin danharrin danharrin
Symfony: HtmlSanitizer UrlAttributeSanitizer Misses URL Attributes Moderate
CVE-2026-48761 was published for symfony/html-sanitizer (Composer) Jun 15, 2026
tob-scott-a Credited to tob-scott-a and nicolas-grekas nicolas-grekas nicolas-grekas
Subrion CMS vulnerable to Cross-site Scripting Low
CVE-2026-12202 was published for intelliants/subrion (Composer) Jun 15, 2026
TYPO3 HTML Sanitizer allows Cross-site Scripting Moderate
CVE-2026-47345 was published for typo3/html-sanitizer (Composer) Jun 12, 2026
TYPO3 CMS has Cross-Site Scripting in Indexed Search Moderate
CVE-2026-47348 was published for typo3/cms-core (Composer) Jun 12, 2026
TYPO3 HTML Sanitizer allows Cross-site Scripting Low
CVE-2026-47344 was published for typo3/html-sanitizer (Composer) Jun 12, 2026
ohader Credited to ohader
Firefly II has Stored XSS in Audit Log Entry view via piggy bank name (ale.twig) Moderate
GHSA-6jq6-x4cx-qvcm was published for grumpydictator/firefly-iii (Composer) Jun 12, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
Twig: XSS in profiler HtmlDumper via unescaped template and profile names Low
CVE-2026-47730 was published for twig/twig (Composer) Jun 5, 2026
nicolas-grekas Credited to nicolas-grekas
Shopper: Multiple data integrity and disclosure issues in admin Livewire components High
CVE-2026-47743 was published for shopper/framework (Composer) Jun 5, 2026
baradika Credited to baradika
TinyMCE Cross-Site Scripting (XSS) vulnerability using media plugin `data-mce-object` injection High
CVE-2026-47761 was published for TinyMCE (Composer) Jun 5, 2026
UncleJ4ck Credited to UncleJ4ck, ange-primiterra, bluvulture, and sbrinkhorst ange-primiterra ange-primiterra
bluvulture bluvulture sbrinkhorst sbrinkhorst
TinyMCE Cross-Site Scripting (XSS) vulnerability through `mce:protected` comments High
CVE-2026-47762 was published for TinyMCE (Composer) Jun 5, 2026
he1d3n Credited to he1d3n and bluvulture bluvulture bluvulture
mtrill47 Credited to mtrill47 and he1d3n he1d3n he1d3n
TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs High
CVE-2026-47760 was published for TinyMCE (Composer) Jun 5, 2026
maple3142 Credited to maple3142
Shopware: Stored XSS via SVG file upload — no SVG sanitization Moderate
CVE-2026-48015 was published for shopware/core (Composer) Jun 4, 2026
Keyvanhardani Credited to Keyvanhardani
ProTip! Advisories are also available from the GraphQL API