Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3,915 advisories

Loading
Contributor Arbitrary File Upload in Creator LMS <= 1.2.21 versions. Critical Unreviewed
CVE-2026-62129 was published Oct 10, 2026
Subscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions. Critical Unreviewed
CVE-2026-62024 was published Oct 10, 2026
Unauthenticated Arbitrary File Upload in Tailored Tools <= 3.0.3 versions. Critical Unreviewed
CVE-2026-62025 was published Oct 10, 2026
Ghost : Stored XSS via SVG Files in Content Imports Moderate
CVE-2026-105644 was published for ghost (npm) Oct 7, 2026
manus-pi Credited to manus-pi
Ghost: Stored XSS via SVG Uploads Bypassing Sanitization High
CVE-2026-105649 was published for ghost (npm) Oct 7, 2026
5255fgh Credited to 5255fgh and nhattanhh nhattanhh nhattanhh
Payload: Bypassed sanitization of user uploaded SVGs High
CVE-2026-105862 was published for payload (npm) Oct 7, 2026
Zerotistic Credited to Zerotistic and The4v1 The4v1 The4v1
Payload: Uploaded XML files could execute same-origin JavaScript High
CVE-2026-105868 was published for payload (npm) Oct 7, 2026
Zerotistic Credited to Zerotistic
Ghost: Stored XSS via Bookmark Card Images High
CVE-2026-105651 was published for ghost (npm) Oct 7, 2026
sondt99 Credited to sondt99 and 5255fgh 5255fgh 5255fgh
Ghost: Stored XSS via File Uploads on Local Storage High
CVE-2026-105679 was published for ghost (npm) Oct 7, 2026
evertrustai Credited to evertrustai, Enis-Atilgan, doanmanhducz, iamharshitgupta, and 5255fgh Enis-Atilgan Enis-Atilgan
doanmanhducz doanmanhducz iamharshitgupta iamharshitgupta 5255fgh 5255fgh
N0fl0w Credited to N0fl0w and acrobat acrobat acrobat
Subscriber Arbitrary File Upload in WP Duplicate <= 1.1.11 versions. Critical Unreviewed
CVE-2026-39755 was published Oct 6, 2026
ProTip! Advisories are also available from the GraphQL API