Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

213 advisories

Loading
SunEditor Embed Plugin has DOM XSS via External Script Element After Iframe Embed High
CVE-2026-54606 was published for suneditor (npm) Aug 26, 2026
Adyej999 Credited to Adyej999
Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript High
CVE-2026-55596 was published for @platejs/media (npm) Aug 25, 2026
DavidCarliez Credited to DavidCarliez
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors High
CVE-2026-61824 was published for defuddle (npm) Aug 21, 2026
Mr-DJ Credited to Mr-DJ
Etherpad has stored XSS in HTML export via unescaped attribute-pool values High
CVE-2026-55090 was published for ep_etherpad-lite (npm) Aug 17, 2026
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF High
CVE-2026-16633 was published for pdfjs-dist (npm) Aug 6, 2026
wlayzz Credited to wlayzz
XSS in Ghost's ActivityPub client High
CVE-2026-53950 was published for @tryghost/activitypub (npm) Aug 4, 2026
bgeesaman Credited to bgeesaman
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes High
CVE-2026-69151 was published for @angular/compiler (npm) Aug 3, 2026
Hexix23 Credited to Hexix23, alan-agius4, and JeanMeche alan-agius4 alan-agius4
JeanMeche JeanMeche
Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS) High
CVE-2026-69149 was published for @angular/platform-server (npm) Aug 3, 2026
SkyZeroZx Credited to SkyZeroZx and alan-agius4 alan-agius4 alan-agius4
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag High
CVE-2026-53608 was published for @apostrophecms/seo (npm) Jul 31, 2026
H3xV0rT3x Credited to H3xV0rT3x
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier High
CVE-2026-58263 was published for jodit (npm) Jul 31, 2026
koyokr Credited to koyokr
n8n: Stored DOM XSS via Resource Locator `cachedResultUrl` High
CVE-2026-65592 was published for n8n (npm) Jul 22, 2026
odgrso Credited to odgrso
n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview High
CVE-2026-65597 was published for n8n (npm) Jul 22, 2026
odgrso Credited to odgrso
Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview High
GHSA-vhcw-f978-xjjg was published for n8n (npm) Jul 22, 2026 withdrawn
Malayke Credited to Malayke
Duplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl` High
GHSA-h5xr-fqvj-253p was published for n8n (npm) Jul 22, 2026 withdrawn
Malayke Credited to Malayke
SVGO removeScripts plugin leaves some executable scripts intact High
CVE-2026-73650 was published for svgo (npm) Jul 21, 2026
Admu-Dev Credited to Admu-Dev
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp High
GHSA-86j7-9j95-vpqj was published for better-auth (npm) Jul 7, 2026
hillalee Credited to hillalee
wetty vulnerable to DOM XSS via file-download filename High
CVE-2026-49864 was published for wetty (npm) Jul 1, 2026
Dredsen Credited to Dredsen
Angular's deprecated package has a Cross-Site Scripting issue High
CVE-2026-11998 was published for angular (npm) Jun 24, 2026
spectacularpigeoncow Credited to spectacularpigeoncow
appium-mcp: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI) High
GHSA-x975-rgx4-5fh4 was published for appium-mcp (npm) Jun 19, 2026
EQSTLab Credited to EQSTLab
kulesy Credited to kulesy, sondt99, and dungNHVhust sondt99 sondt99
dungNHVhust dungNHVhust
jupyterlab-git extension: Stored XSS leading to RCE High
CVE-2026-54527 was published for @jupyterlab/git (npm) Jun 19, 2026
krassowski Credited to krassowski and jtpio jtpio jtpio
n8n: Stored XSS in Chat Trigger Node High
CVE-2026-54302 was published for n8n (npm) Jun 16, 2026
sm1ee Credited to sm1ee
n8n: Same-Origin XSS in Respond to Webhook Node High
CVE-2026-54301 was published for n8n (npm) Jun 16, 2026
supperhellokitty20 Credited to supperhellokitty20
Astro: Reflected XSS via unescaped slot name High
CVE-2026-50146 was published for astro (npm) Jun 16, 2026
floudeciel Credited to floudeciel and cookesan cookesan cookesan
SkyZeroZx Credited to SkyZeroZx, alan-agius4, and josephperrott alan-agius4 alan-agius4
josephperrott josephperrott
ProTip! Advisories are also available from the GraphQL API