Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3 advisories

Loading
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload High
CVE-2026-40321 was published for DotNetNuke.Core (NuGet) Apr 10, 2026
bdukes Credited to bdukes, valadas, and mbadanoiu valadas valadas
mbadanoiu mbadanoiu
October Rain has Environment Variable Exfiltration via INI Parser Interpolation Moderate
CVE-2026-25125 was published for october/rain (Composer) Apr 14, 2026
daftspunk Credited to daftspunk and mbadanoiu mbadanoiu mbadanoiu
October Rain has Stored XSS via SVG Filter Bypass Moderate
CVE-2026-25133 was published for october/rain (Composer) Apr 14, 2026
daftspunk Credited to daftspunk and mbadanoiu mbadanoiu mbadanoiu
ProTip! Advisories are also available from the GraphQL API