Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

363 advisories

Loading
Ghost : Stored XSS via SVG Files in Content Imports Moderate
CVE-2026-105644 was published for ghost (npm) Oct 7, 2026
manus-pi Credited to manus-pi
Ghost: Stored XSS via SVG Uploads Bypassing Sanitization High
CVE-2026-105649 was published for ghost (npm) Oct 7, 2026
5255fgh Credited to 5255fgh and nhattanhh nhattanhh nhattanhh
Payload: Bypassed sanitization of user uploaded SVGs High
CVE-2026-105862 was published for payload (npm) Oct 7, 2026
Zerotistic Credited to Zerotistic and The4v1 The4v1 The4v1
Payload: Uploaded XML files could execute same-origin JavaScript High
CVE-2026-105868 was published for payload (npm) Oct 7, 2026
Zerotistic Credited to Zerotistic
Ghost: Stored XSS via Bookmark Card Images High
CVE-2026-105651 was published for ghost (npm) Oct 7, 2026
sondt99 Credited to sondt99 and 5255fgh 5255fgh 5255fgh
Ghost: Stored XSS via File Uploads on Local Storage High
CVE-2026-105679 was published for ghost (npm) Oct 7, 2026
evertrustai Credited to evertrustai, Enis-Atilgan, doanmanhducz, iamharshitgupta, and 5255fgh Enis-Atilgan Enis-Atilgan
doanmanhducz doanmanhducz iamharshitgupta iamharshitgupta 5255fgh 5255fgh
N0fl0w Credited to N0fl0w and acrobat acrobat acrobat
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain Critical
GHSA-v2f8-6655-7grj was published for vibe-trading-ai (pip) Oct 2, 2026
lemi9090 Credited to lemi9090
Chamilo LMS CStudio upload flow allows unauthenticated remote code execution Critical
CVE-2026-45140 was published for chamilo/chamilo-lms (Composer) Sep 17, 2026
h4knet Credited to h4knet
elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE) High
CVE-2026-81891 was published for Studio-42/elFinder (Composer) Sep 2, 2026
jdh5202 Credited to jdh5202
reachy_mini Allows Unrestricted Upload of File with Dangerous Type Moderate
CVE-2026-55419 was published for reachy-mini (pip) Aug 25, 2026
nnfrog Credited to nnfrog and yuvalmo-jfrog yuvalmo-jfrog yuvalmo-jfrog
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution High
GHSA-ghvf-qf6h-g8x5 was published for @nocobase/server (npm) Aug 20, 2026
lukehebe Credited to lukehebe
pxpm Credited to pxpm and tabacitu tabacitu tabacitu
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules Critical
CVE-2026-63223 was published for codeigniter4/framework (Composer) Aug 7, 2026
wnsgurd90-keke Credited to wnsgurd90-keke
Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types Moderate
CVE-2026-71434 was published for statamic/cms (Composer) Aug 6, 2026
ya3raj Credited to ya3raj
Ghost: File Upload Content-Type Spoofing Moderate
CVE-2026-53948 was published for ghost (npm) Aug 4, 2026
Gitea: Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) Moderate
CVE-2026-58428 was published for code.gitea.io/gitea (Go) Jul 21, 2026
bl4cksku11 Credited to bl4cksku11
hackkim Credited to hackkim
FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE Critical
GHSA-hgjx-r89m-m7v4 was published for facturascripts/facturascripts (Composer) Jul 14, 2026
aslein1413-sys Credited to aslein1413-sys
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField High
CVE-2026-54087 was published for easycorp/easyadmin-bundle (Composer) Jul 14, 2026
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode Critical
CVE-2026-50006 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file) High
GHSA-qv4m-m73m-8hj7 was published for notrinos/notrinos-erp (Composer) Jul 10, 2026
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCE Critical
CVE-2026-53649 was published for github.com/BishopFox/joro (Go) Jul 8, 2026
stover-BF Credited to stover-BF
ProTip! Advisories are also available from the GraphQL API