Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

200 advisories

Loading
Trix: Stored XSS via HTMLParser attribute injection on paste Moderate
CVE-2026-73428 was published for action_text-trix (RubyGems) Jul 24, 2026
newbiefromcoma Credited to newbiefromcoma
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations Moderate
CVE-2026-73648 was published for rails-html-sanitizer (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
MoonFuji Credited to MoonFuji
Loofah: SVG `href` attribute bypasses local-reference restriction Moderate
CVE-2026-73490 was published for loofah (RubyGems) Jul 21, 2026
flavorjones Credited to flavorjones
ViewComponent: around_render HTML-Safety Bypass High
CVE-2026-54498 was published for view_component (RubyGems) Jul 15, 2026
cyberlanc3r Credited to cyberlanc3r
Secure Headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input Moderate
CVE-2026-54163 was published for secure_headers (RubyGems) Jul 10, 2026
tonghuaroot Credited to tonghuaroot
CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters Moderate
CVE-2026-44587 was published for carrierwave (RubyGems) May 27, 2026
snoopysecurity Credited to snoopysecurity and bilerden bilerden bilerden
Sidekiq-cron is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL Moderate
CVE-2025-67202 was published for sidekiq-cron (RubyGems) May 7, 2026
OpenC3 COSMOS is Vulnerable to Self-XSS Through the Command Sender Moderate
CVE-2026-42086 was published for openc3 (RubyGems) Apr 22, 2026
ctrlsill Credited to ctrlsill
Decidim has a cross-site scripting (XSS) in user name Critical
CVE-2026-23891 was published for decidim-core (RubyGems) Apr 13, 2026
cyberschnaps Credited to cyberschnaps
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController) Low
CVE-2026-73427 was published for action_text-trix (RubyGems) Mar 29, 2026
Loofah has improper detection of disallowed URIs via `allowed_uri?` Low
GHSA-2j22-pr5w-6gq8 was published for loofah (RubyGems) Mar 26, 2026
Rails Active Support has a possible XSS vulnerability in SafeBuffer#% Moderate
CVE-2026-33170 was published for activesupport (RubyGems) Mar 23, 2026
ch4n3-yoon Credited to ch4n3-yoon
Rails has a possible XSS vulnerability in its Action View tag helpers Low
CVE-2026-33168 was published for actionview (RubyGems) Mar 23, 2026
Rails has a possible XSS vulnerability in its Action Pack debug exceptions Low
CVE-2026-33167 was published for actionpack (RubyGems) Mar 23, 2026
Avo has a XSS vulnerability on `return_to` param Moderate
CVE-2026-33209 was published for avo (RubyGems) Mar 18, 2026
timwis Credited to timwis
Improper detection of disallowed URIs by Loofah `allowed_uri?` Low
GHSA-46fp-8f5p-pf2m was published for loofah (RubyGems) Mar 18, 2026
Trix has a Stored XSS vulnerability through serialized attributes Moderate
CVE-2026-73426 was published for action_text-trix (RubyGems) Mar 12, 2026
Stored XSS in Rack::Directory via javascript: filenames rendered into anchor href Moderate
CVE-2026-25500 was published for rack (RubyGems) Feb 17, 2026
thesmartshadow Credited to thesmartshadow, jeremyevans, and ioquatix jeremyevans jeremyevans
ioquatix ioquatix
Phlex XSS protection bypass via attribute splatting, dynamic tags, and href values High
GHSA-w67g-2h6v-vjgq was published for phlex (RubyGems) Feb 6, 2026
Trix has a stored XSS vulnerability through its attachment attribute Moderate
GHSA-g9jg-w8vm-g96v was published for action_text-trix (RubyGems) Dec 31, 2025
Duplicate Advisory: ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values High
GHSA-4249-gjr8-jpq3 was published for prosemirror_to_html (RubyGems) Nov 13, 2025 withdrawn
Duplicate Advisory: ProsemirrorToHtml has a Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values High
GHSA-vfpf-xmwh-8m65 was published for prosemirror_to_html (RubyGems) Nov 7, 2025 withdrawn
Cross-Site Scripting (XSS) vulnerability through unescaped HTML attribute values High
CVE-2025-64501 was published for prosemirror_to_html (RubyGems) Nov 6, 2025
polypixeldev Credited to polypixeldev, Luke-Oldenburg, Spone, and 9021007 Luke-Oldenburg Luke-Oldenburg
Spone Spone 9021007 9021007
Publify Vulnerable To Cross-Site Scripting (XSS) Via Redirects Requiring User Interaction Low
CVE-2024-39311 was published for publify_core (RubyGems) Mar 28, 2025
PinkDraconian Credited to PinkDraconian
ProTip! Advisories are also available from the GraphQL API