Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,092 advisories

Loading
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature Moderate
CVE-2026-59817 was published for ghost (npm) Aug 4, 2026
sane100400 Credited to sane100400 and P4P3R-HAK P4P3R-HAK P4P3R-HAK
Ghost: Member existence leak via magic link sign-in response Moderate
CVE-2026-53947 was published for ghost (npm) Aug 4, 2026
XSS in Ghost's ActivityPub client High
CVE-2026-53950 was published for @tryghost/activitypub (npm) Aug 4, 2026
bgeesaman Credited to bgeesaman
Ghost: Session Fixation in Ghost Admin Moderate
CVE-2026-70594 was published for ghost (npm) Aug 4, 2026
Ghost: Theme Upload Path Traversal Moderate
CVE-2026-70593 was published for ghost (npm) Aug 4, 2026
Ghost: Database Backup Path Traversal Moderate
CVE-2026-70592 was published for ghost (npm) Aug 4, 2026
Ghost: Server-Side Request Forgery in Image Fetching Moderate
CVE-2026-70591 was published for ghost (npm) Aug 4, 2026
koyokr Credited to koyokr
Ghost: Blind Password Hash Disclosure in Ghost Admin API Moderate
CVE-2026-70590 was published for ghost (npm) Aug 4, 2026
Ghost: Mobiledoc image-size fetch SSRF Moderate
CVE-2026-53946 was published for ghost (npm) Aug 4, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling Moderate
CVE-2026-53945 was published for ghost (npm) Aug 4, 2026
l3tchupkt Credited to l3tchupkt
Ghost: Private IP filtering bypass to make server-side requests to internal services Moderate
CVE-2026-53944 was published for ghost (npm) Aug 4, 2026
l3tchupkt Credited to l3tchupkt
Ghost: Archived Offers can be Redeemed Moderate
CVE-2026-70589 was published for ghost (npm) Aug 4, 2026
Ghost: File Upload Content-Type Spoofing Moderate
CVE-2026-53948 was published for ghost (npm) Aug 4, 2026
Ghost: Cross-Site Scripting in Universal Import Moderate
CVE-2026-70588 was published for ghost (npm) Aug 4, 2026
DeathsPirate Credited to DeathsPirate
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability Critical
CVE-2026-70477 was published for flowise (npm) Aug 4, 2026
zdi-disclosures Credited to zdi-disclosures
berkdedekarginoglu Credited to berkdedekarginoglu
offset Credited to offset
Flowise: Missing Authorization on Execution Update Endpoint High
CVE-2026-70475 was published for flowise (npm) Aug 4, 2026
Dimpyj1604 Credited to Dimpyj1604
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak High
CVE-2026-70474 was published for flowise (npm) Aug 4, 2026
hett-patell Credited to hett-patell
Flowise: Incomplete Credential Redaction Exposes Secrets via API Moderate
GHSA-rwrp-9823-p2xq was published for flowise (npm) Aug 4, 2026
truongvip1 Credited to truongvip1
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store High
CVE-2026-70472 was published for flowise (npm) Aug 4, 2026
Kazamayc Credited to Kazamayc
amwhoi Credited to amwhoi
Mirr2 Credited to Mirr2
ProTip! Advisories are also available from the GraphQL API