GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
47 advisories
Filter by severity
@astrojs/rss: XML Injection via Unescaped RSS Feed Fields
Moderate
CVE-2026-59728
was published
for
@astrojs/rss
(npm)
Jul 20, 2026
guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator
Moderate
CVE-2026-53723
was published
for
guzzlehttp/guzzle-services
(Composer)
Jun 11, 2026
samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions
High
CVE-2026-46490
was published
for
samlify
(npm)
May 21, 2026
veraPDF has potential XSLT injection vulnerability when using policy files
High
CVE-2024-28109
was published
for
org.verapdf:core
(Maven)
May 20, 2024
fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes
High
CVE-2026-44665
was published
for
fast-xml-builder
(npm)
May 8, 2026
fast-xml-builder Comment Value regex can be bypassed
Moderate
CVE-2026-44664
was published
for
fast-xml-builder
(npm)
May 8, 2026
fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters
Moderate
CVE-2026-41650
was published
for
fast-xml-parser
(npm)
Apr 22, 2026
xmldom has XML injection through unvalidated DocumentType serialization
High
CVE-2026-41674
was published
for
@xmldom/xmldom
(npm)
Apr 22, 2026
xmldom has XML node injection through unvalidated processing instruction serialization
High
CVE-2026-41675
was published
for
@xmldom/xmldom
(npm)
Apr 22, 2026
xmldom has XML node injection through unvalidated comment serialization
High
CVE-2026-41672
was published
for
@xmldom/xmldom
(npm)
Apr 22, 2026
Kirby has XML injection in its XML creator toolkit
Moderate
CVE-2026-32870
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
High
CVE-2026-34601
was published
for
@xmldom/xmldom
(npm)
Apr 1, 2026
fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
Moderate
CVE-2025-66034
was published
for
fonttools
(pip)
Dec 1, 2025
Magento has an XML Injection vulnerability
Critical
CVE-2021-36028
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento XML Injection vulnerability in the Widgets Module
Critical
CVE-2021-36033
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento XML Injection vulnerability in the Widgets Update Layout
High
CVE-2021-36022
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento XML Injection vulnerability in the 'City' field
High
CVE-2021-36020
was published
for
magento/community-edition
(Composer)
May 24, 2022
MinIO Java Client XML Tag Value Substitution Vulnerability
High
CVE-2025-59952
was published
for
io.minio:minio
(Maven)
Sep 29, 2025
XXE in PHPSpreadsheet due to encoding issue
High
CVE-2018-19277
was published
for
phpoffice/phpexcel
(Composer)
Nov 20, 2019
Magento Open Source allows XML Injection
Low
CVE-2023-38207
was published
for
magento/community-edition
(Composer)
Aug 9, 2023
Magento Open Source allows XML Injection
Moderate
CVE-2023-29289
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows XML Injection
High
CVE-2023-22247
was published
for
magento/community-edition
(Composer)
Mar 27, 2023
Apache Ivy External Entity Reference vulnerability
High
CVE-2022-46751
was published
for
org.apache.ivy:ivy
(Maven)
Aug 21, 2023
Magento XPath Injection
Critical
CVE-2021-21025
was published
for
magento/community-edition
(Composer)
May 24, 2022
Modoboa is vulnerable to an XML External Entity Injection (XXE)
High
CVE-2019-19702
was published
for
modoboa-dmarc
(pip)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API