Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34,166 advisories

Filter by severity
Loading
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature Moderate
CVE-2026-59817 was published for ghost (npm) Aug 4, 2026
sane100400Credited to sane100400 and P4P3R-HAKP4P3R-HAKP4P3R-HAK
Ghost: Member existence leak via magic link sign-in response Moderate
CVE-2026-53947 was published for ghost (npm) Aug 4, 2026
XSS in Ghost's ActivityPub client High
CVE-2026-53950 was published for @tryghost/activitypub (npm) Aug 4, 2026
bgeesamanCredited to bgeesaman
Ghost: Session Fixation in Ghost Admin Moderate
CVE-2026-70594 was published for ghost (npm) Aug 4, 2026
Ghost: Theme Upload Path Traversal Moderate
CVE-2026-70593 was published for ghost (npm) Aug 4, 2026
Ghost: Database Backup Path Traversal Moderate
CVE-2026-70592 was published for ghost (npm) Aug 4, 2026
Ghost: Server-Side Request Forgery in Image Fetching Moderate
CVE-2026-70591 was published for ghost (npm) Aug 4, 2026
koyokrCredited to koyokr
Ghost: Blind Password Hash Disclosure in Ghost Admin API Moderate
CVE-2026-70590 was published for ghost (npm) Aug 4, 2026
Ghost: Mobiledoc image-size fetch SSRF Moderate
CVE-2026-53946 was published for ghost (npm) Aug 4, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling Moderate
CVE-2026-53945 was published for ghost (npm) Aug 4, 2026
l3tchupktCredited to l3tchupkt
Ghost: Private IP filtering bypass to make server-side requests to internal services Moderate
CVE-2026-53944 was published for ghost (npm) Aug 4, 2026
l3tchupktCredited to l3tchupkt
Ghost: Archived Offers can be Redeemed Moderate
CVE-2026-70589 was published for ghost (npm) Aug 4, 2026
Ghost: File Upload Content-Type Spoofing Moderate
CVE-2026-53948 was published for ghost (npm) Aug 4, 2026
Ghost: Cross-Site Scripting in Universal Import Moderate
CVE-2026-70588 was published for ghost (npm) Aug 4, 2026
legobattmanCredited to legobattman and Classic298Classic298Classic298
Classic298Credited to Classic298
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages High
CVE-2026-70492 was published for open-webui (pip) Aug 4, 2026
maxntvCredited to maxntv and Classic298Classic298Classic298
Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints Moderate
CVE-2026-70491 was published for open-webui (pip) Aug 4, 2026
bogdancherniy11-sudoCredited to bogdancherniy11-sudo and Classic298Classic298Classic298
rexpositoryCredited to rexpository and Classic298Classic298Classic298
Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing Moderate
CVE-2026-70489 was published for open-webui (pip) Aug 4, 2026
Classic298Credited to Classic298
Open WebUI: DNS Rebinding SSRF Bypass Moderate
CVE-2026-54020 was published for open-webui (pip) Aug 4, 2026
rezadutyCredited to rezaduty, Classic298, dhyabi2, geo-chen, and bogdancherniy11-sudoClassic298Classic298
dhyabi2dhyabi2geo-chengeo-chenbogdancherniy11-sudobogdancherniy11-sudo
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata Moderate
CVE-2026-70487 was published for open-webui (pip) Aug 4, 2026
whyiugCredited to whyiug and Classic298Classic298Classic298
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup Moderate
CVE-2026-70488 was published for open-webui (pip) Aug 4, 2026
whyiugCredited to whyiug and Classic298Classic298Classic298
manus-useCredited to manus-use and Classic298Classic298Classic298
tonghuarootCredited to tonghuaroot and Classic298Classic298Classic298
ProTip! Advisories are also available from the GraphQL API