Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

300 advisories

Loading
Moodle vulnerable to Cross-site Scripting Low
CVE-2010-1614 was published for moodle/moodle (Composer) May 13, 2022
Moodle vulnerable to Cross-site Scripting Low
CVE-2010-1619 was published for moodle/moodle (Composer) May 13, 2022
phpMyAdmin Vulnerable to Cross-Site Scripting Low
CVE-2011-1940 was published for phpmyadmin/phpmyadmin (Composer) May 17, 2022
Piwik (now Matomo) Vulnerable to Cross-Site Scripting (XSS) Low
CVE-2013-1844 was published for matomo/matomo (Composer) May 13, 2022
Moodle doesn't properly check role Low
CVE-2010-1617 was published for moodle/moodle (Composer) May 13, 2022
Commerce extension for TYPO3 vulnerable to Cross-site Scripting Low
CVE-2009-4963 was published for commerceteam/commerce (Composer) May 2, 2022
MantisBT Cross-site Scripting vulnerability Low
CVE-2010-2574 was published for mantisbt/mantisbt (Composer) May 14, 2022
Joomla! vulnerable to Cross-site Scripting Low
CVE-2011-4332 was published for joomla/joomla-cms (Composer) May 17, 2022
phpMyAdmin vulnerable to Cross-site Scripting Low
CVE-2011-4634 was published for phpmyadmin/phpmyadmin (Composer) May 17, 2022
phpMyAdmin Cross-site Scripting vulnerability Low
CVE-2011-4782 was published for phpmyadmin/phpmyadmin (Composer) May 17, 2022
Symphony CMS vulnerable to Cross-site Scripting Low
CVE-2011-4340 was published for symphonycms/symphony-2 (Composer) May 17, 2022
Moodle vulnerable to Cross-Site Scripting Low
CVE-2011-4299 was published for moodle/moodle (Composer) May 13, 2022
Moodle vulnerable to Cross-site Scripting Low
CVE-2011-4282 was published for moodle/moodle (Composer) May 13, 2022
powermail extension for TYPO3 has Cross-site Scripting vulnerability Low
CVE-2012-5889 was published for in2code/powermail (Composer) May 17, 2022
Basic SEO Features (seo_basics) extension TYPO3 vulnerable to Cross-site Scripting Low
CVE-2012-5888 was published for b13/seo_basics (Composer) May 17, 2022
PHPUnit extension for TYPO3 vulnerable to Cross-site Scripting Low
CVE-2013-4744 was published for oliverklee/phpunit (Composer) May 13, 2022
Static Methods since 2007 (div2007) extension for TYPO3 vulnerable to Cross-site Scripting Low
CVE-2013-5100 was published for jambagecom/div2007 (Composer) May 17, 2022
Static Info Tables (static_info_tables) extension TYPO3 vulnerable to Cross-site Scripting Low
CVE-2013-5323 was published for sjbr/static-info-tables (Composer) May 17, 2022
Joomla! Cross-site Scripting vulnerability Low
CVE-2013-5583 was published for joomla/joomla-cms (Composer) May 17, 2022
WEC Map (wec_map) extension for TYPO3 allows Cross-site Scripting Low
CVE-2014-6296 was published for jbartels/wec-map (Composer) May 17, 2022
concrete5 vulnerable to Cross-site Scripting Low
CVE-2015-3989 was published for concrete5/concrete5 (Composer) May 17, 2022
Typo3 XSS Vulnerabilities Low
CVE-2014-3943 was published for typo3/cms (Composer) May 14, 2022
Duplicate Advisory: Contao allows admin an account to upload SVG file containing malicious JavaScript Low
CVE-2024-45965 was published for contao/contao (Composer) Oct 2, 2024 withdrawn
zoglo
Credited to zoglo
Moodle has a CSRF risk in user tours manager that allows tour duplication Low
CVE-2025-3635 was published for moodle/moodle (Composer) Apr 25, 2025
Moodle's mod_data edit/delete pages pass CSRF token in GET parameter Low
CVE-2025-3637 was published for moodle/moodle (Composer) Apr 25, 2025
ProTip! Advisories are also available from the GraphQL API