Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,781 advisories

Loading
Cross-site Scripting in Netgen Tags Bundle Moderate
CVE-2021-45895 was published for netgen/tagsbundle (Composer) Jan 6, 2022
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-4168 was published for showdoc/showdoc (Composer) Jan 6, 2022
invoiceninja is vulnerable to Cross-site Scripting Moderate
CVE-2021-3977 was published for hillelcoren/invoice-ninja (Composer) Jan 6, 2022
elgg is vulnerable to Cross-site Scripting Moderate
CVE-2021-4072 was published for elgg/elgg (Composer) Jan 6, 2022
Unrestricted Upload of File with Dangerous Type in unisharp/laravel-filemanager Moderate
CVE-2021-23814 was published for unisharp/laravel-filemanager (Composer) Jan 6, 2022
streamtw
Cross-Site Request Forgery in Moodle Moderate
CVE-2020-1692 was published for moodle/moodle (Composer) Jan 6, 2022
XSS vulnerability on email template preview page Moderate
CVE-2021-41236 was published for oro/platform (Composer) Jan 6, 2022
Client-Side JavaScript Prototype Pollution in oro/platform Moderate
CVE-2021-43852 was published for oro/platform (Composer) Jan 6, 2022
Cross-site Scripting in pimcore Moderate
CVE-2021-4139 was published for pimcore/pimcore (Composer) Jan 5, 2022
livehelperchat is vulnerable to Cross-site Scripting Moderate
CVE-2021-4132 was published for remdex/livehelperchat (Composer) Jan 5, 2022
Cross-site Scripting in Anchor CMS Moderate
CVE-2021-44116 was published for anchorcms/anchor-cms (Composer) Jan 5, 2022
Cross site scripting in dolibarr Moderate
CVE-2022-22293 was published for dolibarr/dolibarr (Composer) Jan 3, 2022
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-4123 was published for remdex/livehelperchat (Composer) Dec 17, 2021
yetiforcecrm is vulnerable to Cross-site Scripting Moderate
CVE-2021-4121 was published for yetiforce/yetiforce-crm (Composer) Dec 17, 2021
YetiForceCRM is vulnerable to Business Logic Errors in the weight of a product Moderate
CVE-2021-4117 was published for yetiforce/yetiforce-crm (Composer) Dec 16, 2021
yetiforcecrm is vulnerable to Cross-site Scripting Moderate
CVE-2021-4116 was published for yetiforce/yetiforce-crm (Composer) Dec 16, 2021
BookStack is vulnerable to Improper Access Control. Moderate
CVE-2021-4119 was published for ssddanbrown/bookstack (Composer) Dec 16, 2021
Open Redirect in showdoc Moderate
CVE-2021-4000 was published for showdoc/showdoc (Composer) Dec 16, 2021
snipe-it is vulnerable to Improper Access Control Moderate
CVE-2021-4089 was published for snipe/snipe-it (Composer) Dec 16, 2021
Cross-site Scripting in pimcore Moderate
CVE-2021-4084 was published for pimcore/pimcore (Composer) Dec 16, 2021
pimcore is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-4082 was published for pimcore/pimcore (Composer) Dec 16, 2021
pimcore is vulnerable to Cross-site Scripting Moderate
CVE-2021-4081 was published for pimcore/pimcore (Composer) Dec 16, 2021
phpservermon is vulnerable to CRLF Injection Moderate
CVE-2021-4097 was published for phpservermon/phpservermon (Composer) Dec 16, 2021
yetiforcecrm is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-4092 was published for yetiforce/yetiforce-crm (Composer) Dec 16, 2021
snipe-it is vulnerable to Cross-site Scripting Moderate
CVE-2021-4108 was published for snipe/snipe-it (Composer) Dec 16, 2021
ProTip! Advisories are also available from the GraphQL API