GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
47 advisories
Filter by severity
@astrojs/rss: XML Injection via Unescaped RSS Feed Fields
Moderate
CVE-2026-59728
was published
for
@astrojs/rss
(npm)
Jul 20, 2026
guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator
Moderate
CVE-2026-53723
was published
for
guzzlehttp/guzzle-services
(Composer)
Jun 11, 2026
samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions
High
CVE-2026-46490
was published
for
samlify
(npm)
May 21, 2026
fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes
High
CVE-2026-44665
was published
for
fast-xml-builder
(npm)
May 8, 2026
fast-xml-builder Comment Value regex can be bypassed
Moderate
CVE-2026-44664
was published
for
fast-xml-builder
(npm)
May 8, 2026
Kirby has XML injection in its XML creator toolkit
Moderate
CVE-2026-32870
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
xmldom has XML injection through unvalidated DocumentType serialization
High
CVE-2026-41674
was published
for
@xmldom/xmldom
(npm)
Apr 22, 2026
xmldom has XML node injection through unvalidated processing instruction serialization
High
CVE-2026-41675
was published
for
@xmldom/xmldom
(npm)
Apr 22, 2026
xmldom has XML node injection through unvalidated comment serialization
High
CVE-2026-41672
was published
for
@xmldom/xmldom
(npm)
Apr 22, 2026
fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters
Moderate
CVE-2026-41650
was published
for
fast-xml-parser
(npm)
Apr 22, 2026
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
High
CVE-2026-34601
was published
for
@xmldom/xmldom
(npm)
Apr 1, 2026
fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
Moderate
CVE-2025-66034
was published
for
fonttools
(pip)
Dec 1, 2025
MinIO Java Client XML Tag Value Substitution Vulnerability
High
CVE-2025-59952
was published
for
io.minio:minio
(Maven)
Sep 29, 2025
robrichards/xmlseclibs XPath injection
High
GHSA-2g98-f9jv-w8c5
was published
for
robrichards/xmlseclibs
(Composer)
May 20, 2024
veraPDF has potential XSLT injection vulnerability when using policy files
High
CVE-2024-28109
was published
for
org.verapdf:core
(Maven)
May 20, 2024
codehaus-plexus vulnerable to XML injection
Moderate
CVE-2022-4245
was published
for
org.codehaus.plexus:plexus-utils
(Maven)
Sep 25, 2023
ReportLab vulnerable to remote code execution via paraparser
Critical
CVE-2019-19450
was published
for
reportlab
(pip)
Sep 20, 2023
Apache Ivy External Entity Reference vulnerability
High
CVE-2022-46751
was published
for
org.apache.ivy:ivy
(Maven)
Aug 21, 2023
Magento Open Source allows XML Injection
Low
CVE-2023-38207
was published
for
magento/community-edition
(Composer)
Aug 9, 2023
Magento Open Source allows XML Injection
Moderate
CVE-2023-29289
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows XML Injection
High
CVE-2023-22247
was published
for
magento/community-edition
(Composer)
Mar 27, 2023
Withdrawn: ConcreteCMS vulnerable to Xpath injection attacks
High
CVE-2022-46464
was published
for
concrete5/concrete5
(Composer)
Dec 6, 2022
•
withdrawn
Magento XML Injection vulnerability in the Widgets Module
Critical
CVE-2022-34253
was published
for
magento/community-edition
(Composer)
Aug 17, 2022
Magento XML Injection vulnerability in the 'City' field
High
CVE-2021-36020
was published
for
magento/community-edition
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API