Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,780 advisories

Loading
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-4168 was published for showdoc/showdoc (Composer) Jan 6, 2022
invoiceninja is vulnerable to Cross-site Scripting Moderate
CVE-2021-3977 was published for hillelcoren/invoice-ninja (Composer) Jan 6, 2022
elgg is vulnerable to Cross-site Scripting Moderate
CVE-2021-4072 was published for elgg/elgg (Composer) Jan 6, 2022
Unrestricted Upload of File with Dangerous Type in unisharp/laravel-filemanager Moderate
CVE-2021-23814 was published for unisharp/laravel-filemanager (Composer) Jan 6, 2022
streamtw
Cross-Site Request Forgery in Moodle Moderate
CVE-2020-1692 was published for moodle/moodle (Composer) Jan 6, 2022
XSS vulnerability on email template preview page Moderate
CVE-2021-41236 was published for oro/platform (Composer) Jan 6, 2022
Client-Side JavaScript Prototype Pollution in oro/platform Moderate
CVE-2021-43852 was published for oro/platform (Composer) Jan 6, 2022
Cross-site Scripting in pimcore Moderate
CVE-2021-4139 was published for pimcore/pimcore (Composer) Jan 5, 2022
livehelperchat is vulnerable to Cross-site Scripting Moderate
CVE-2021-4132 was published for remdex/livehelperchat (Composer) Jan 5, 2022
Cross-site Scripting in Anchor CMS Moderate
CVE-2021-44116 was published for anchorcms/anchor-cms (Composer) Jan 5, 2022
Cross site scripting in dolibarr Moderate
CVE-2022-22293 was published for dolibarr/dolibarr (Composer) Jan 3, 2022
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-4123 was published for remdex/livehelperchat (Composer) Dec 17, 2021
yetiforcecrm is vulnerable to Cross-site Scripting Moderate
CVE-2021-4121 was published for yetiforce/yetiforce-crm (Composer) Dec 17, 2021
YetiForceCRM is vulnerable to Business Logic Errors in the weight of a product Moderate
CVE-2021-4117 was published for yetiforce/yetiforce-crm (Composer) Dec 16, 2021
yetiforcecrm is vulnerable to Cross-site Scripting Moderate
CVE-2021-4116 was published for yetiforce/yetiforce-crm (Composer) Dec 16, 2021
BookStack is vulnerable to Improper Access Control. Moderate
CVE-2021-4119 was published for ssddanbrown/bookstack (Composer) Dec 16, 2021
Open Redirect in showdoc Moderate
CVE-2021-4000 was published for showdoc/showdoc (Composer) Dec 16, 2021
snipe-it is vulnerable to Improper Access Control Moderate
CVE-2021-4089 was published for snipe/snipe-it (Composer) Dec 16, 2021
Cross-site Scripting in pimcore Moderate
CVE-2021-4084 was published for pimcore/pimcore (Composer) Dec 16, 2021
pimcore is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-4082 was published for pimcore/pimcore (Composer) Dec 16, 2021
pimcore is vulnerable to Cross-site Scripting Moderate
CVE-2021-4081 was published for pimcore/pimcore (Composer) Dec 16, 2021
phpservermon is vulnerable to CRLF Injection Moderate
CVE-2021-4097 was published for phpservermon/phpservermon (Composer) Dec 16, 2021
yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-4092 was published for yetiforce/yetiforce-crm (Composer) Dec 16, 2021
snipe-it is vulnerable to Cross-site Scripting Moderate
CVE-2021-4108 was published for snipe/snipe-it (Composer) Dec 16, 2021
yetiforcecrm is vulnerable to Cross-site Scripting Moderate
CVE-2021-4107 was published for yetiforce/yetiforce-crm (Composer) Dec 16, 2021
ProTip! Advisories are also available from the GraphQL API