Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,025 advisories

Loading
Sulu: Stored XSS via media download inline-disposition override Moderate
CVE-2026-82396 was published for sulu/sulu (Composer) Sep 2, 2026
0x3xP01t3r Credited to 0x3xP01t3r
Livewire DOM-based cross-site scripting during client-side state handling Moderate
CVE-2026-81887 was published for livewire/livewire (Composer) Sep 2, 2026
Vagebondcur Credited to Vagebondcur and MelvinTh17 MelvinTh17 MelvinTh17
league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed High
GHSA-f8fg-pg57-v4j8 was published for league/commonmark (Composer) Sep 1, 2026
StarPlatinu Credited to StarPlatinu
silverstripe/versioned has XSS in archive admin restore Moderate
CVE-2026-55779 was published for silverstripe/versioned (Composer) Aug 28, 2026
EvidentObscurity Credited to EvidentObscurity, rugk, and elrido rugk rugk
elrido elrido
Snipe-IT has CSS Injection via `header_color` Setting Moderate
CVE-2026-55481 was published for snipe/snipe-it (Composer) Aug 28, 2026
ZeroXJacks Credited to ZeroXJacks
Snipe-IT vulnerable to stored XSS via inline-served attachment Moderate
CVE-2026-55466 was published for snipe/snipe-it (Composer) Aug 28, 2026
callmeks Credited to callmeks
Snipe-IT vulnerable to stored XSS via Markdown custom field Moderate
CVE-2026-55464 was published for snipe/snipe-it (Composer) Aug 28, 2026
iltosec Credited to iltosec
Silverstripe Framework: Possible XSS attack through media embed Moderate
CVE-2026-54720 was published for silverstripe/framework (Composer) Aug 27, 2026
OpenSTAManager has HTML Injection in modules/utenti/edit.php Low
CVE-2026-44701 was published for devcode-it/openstamanager (Composer) Aug 26, 2026
ilmercu Credited to ilmercu
LibreNMS — Stored XSS via SNMP/Syslog Data in Legacy Templates High
GHSA-7w8c-qgxg-m7jx was published for librenms/librenms (Composer) Aug 26, 2026
TristanInSec Credited to TristanInSec
YOURLS has stored XSS in referrer statistics chart via crafted Referer header High
CVE-2026-63135 was published for yourls/yourls (Composer) Aug 21, 2026
sondt99 Credited to sondt99, dgw, ozh, and LeoColomb dgw dgw
ozh ozh LeoColomb LeoColomb
skeletonsec Credited to skeletonsec
Winter: Reflected XSS through the search query parameter in the backend Table widget Moderate
GHSA-hq84-x37p-j6q5 was published for winter/wn-backend-module (Composer) Aug 20, 2026
NRAwwad Credited to NRAwwad
Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles Moderate
GHSA-5cwr-5jxg-pcf6 was published for winter/wn-backend-module (Composer) Aug 20, 2026
NRAwwad Credited to NRAwwad
Winter: Stored XSS through Backend List widget image columns Low
GHSA-7mpf-4465-7fc2 was published for winter/wn-backend-module (Composer) Aug 20, 2026
Laravel Backpack CRUD: Stored XSS in the color column — the `@if($column['escaped'])` branches are inverted Moderate
CVE-2026-54181 was published for backpack/crud (Composer) Aug 20, 2026
therawdev Credited to therawdev and tabacitu tabacitu tabacitu
pxpm Credited to pxpm and tabacitu tabacitu tabacitu
Snipe-IT: Stored DOM XSS via table selected-count IDs Moderate
CVE-2026-61807 was published for snipe/snipe-it (Composer) Aug 19, 2026
LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page High
GHSA-7gww-x7fh-jf9j was published for librenms/librenms (Composer) Aug 18, 2026
k1bana Credited to k1bana
LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users Moderate
GHSA-7cj5-v4pp-v632 was published for librenms/librenms (Composer) Aug 18, 2026
k1bana Credited to k1bana
Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover High
CVE-2026-54347 was published for froxlor/froxlor (Composer) Aug 18, 2026
de3erve Credited to de3erve
LibreNMS: Reflected XSS via Proxmox instance/vmid GET parameters injected into document.title JavaScript assignment Moderate
CVE-2026-45694 was published for librenms/librenms (Composer) Aug 12, 2026
k1bana Credited to k1bana
Winter: Stored XSS through Editor Settings custom styles High
CVE-2026-32258 was published for winter/wn-backend-module (Composer) Aug 12, 2026
skyhex19 Credited to skyhex19
Winter: Stored XSS through Brand Settings custom styles High
CVE-2026-32257 was published for winter/wn-backend-module (Composer) Aug 12, 2026
skyhex19 Credited to skyhex19
ProTip! Advisories are also available from the GraphQL API