Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

179 advisories

Loading
Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts Moderate
GHSA-957r-qf9p-67xw was published for craftcms/cms (Composer) Aug 6, 2026
je-lv Credited to je-lv
Ghost: Private IP filtering bypass to make server-side requests to internal services Moderate
CVE-2026-53944 was published for ghost (npm) Aug 4, 2026
l3tchupkt Credited to l3tchupkt
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE Critical
CVE-2026-70470 was published for flowise (npm) Aug 4, 2026
fg0x0 Credited to fg0x0
leoelsolh Credited to leoelsolh
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass Moderate
CVE-2026-52888 was published for @nocobase/plugin-collection-sql (npm) Jul 28, 2026
lucquach Credited to lucquach
manus-use Credited to manus-use
MoonFuji Credited to MoonFuji
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist High
GHSA-2f96-g7mh-g2hx was published for GitPython (pip) Jul 21, 2026
hackkim Credited to hackkim and abhiprd2000 abhiprd2000 abhiprd2000
SVGO removeScripts plugin leaves some executable scripts intact High
GHSA-2p49-hgcm-8545 was published for svgo (npm) Jul 21, 2026
Admu-Dev Credited to Admu-Dev
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements. Low
GHSA-c2j3-45gr-mqc4 was published for dompurify (npm) Jul 21, 2026
Rikuxx0 Credited to Rikuxx0
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references Low
GHSA-8whx-365g-h9vv was published for loofah (RubyGems) Jul 21, 2026
connorshea Credited to connorshea
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers High
CVE-2026-54070 was published for github.com/siyuan-note/siyuan/kernel (Go) Jul 10, 2026
kah-ja Credited to kah-ja
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes High
CVE-2026-49825 was published for lxml_html_clean (pip) Jul 8, 2026
glefait Credited to glefait, frenzymadness, and scoder frenzymadness frenzymadness
scoder scoder
OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks High
GHSA-j472-gf56-x589 was published for openclaw (npm) Jul 2, 2026
YLChen-007 Credited to YLChen-007
ProTip! Advisories are also available from the GraphQL API