Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,780 advisories

Loading
CKEditor 4 vulnerabilities in versions <4.16.1 Moderate
GHSA-cfcv-q4qq-2ph4 was published for pimcore/pimcore (Composer) Aug 23, 2021
PHP file inclusion via insert tags Moderate
CVE-2021-37626 was published for contao/contao (Composer) Aug 23, 2021
ausi
Cross-Site Scripting via Rich-Text Content Moderate
CVE-2021-32768 was published for typo3/cms (Composer) Aug 19, 2021
sushiwushi ohader
einpraegsam
Improper Access Control in Dolibarr Moderate
CVE-2021-25954 was published for dolibarr/dolibarr (Composer) Aug 11, 2021
Cross Site Scripting in LavaLite CMS Moderate
CVE-2020-23234 was published for lavalite/cms (Composer) Aug 9, 2021
No Restriction of Excessive Authentication Attempts in Firefly III Moderate
CVE-2021-3663 was published for grumpydictator/firefly-iii (Composer) Aug 9, 2021
Incorrect Authorization in TYPO3 extension Moderate
CVE-2020-25025 was published for localizationteam/l10nmgr (Composer) Jul 26, 2021
Missing Authorization in TYPO3 extension Moderate
CVE-2020-12700 was published for directmailteam/direct-mail (Composer) Jul 26, 2021
Missing Authorization in TYPO3 extension Moderate
CVE-2020-12698 was published for directmailteam/direct-mail (Composer) Jul 26, 2021
Information Disclosure in User Authentication Moderate
CVE-2021-32767 was published for typo3/cms (Composer) Jul 26, 2021
tdunlap607
Cross-Site Scripting in Backend Grid View Moderate
CVE-2021-32669 was published for typo3/cms (Composer) Jul 22, 2021
o-ba
Cross-Site Scripting in Query Generator & Query View Moderate
CVE-2021-32668 was published for typo3/cms (Composer) Jul 22, 2021
sushiwushi
Cross-Site Scripting in Page Preview Moderate
CVE-2021-32667 was published for typo3/cms (Composer) Jul 22, 2021
o-ba
Cross-site Scripting in Froala WYSIWYG Editor Moderate
CVE-2021-28114 was published for froala/wysiwyg-editor (Composer) Jul 19, 2021
Craft CMS Cross-site Scripting Vulnerability Moderate
CVE-2021-27902 was published for craftcms/cms (Composer) Jul 2, 2021
XSS Injection in Media Collection Title was possible Moderate
CVE-2021-32737 was published for sulu/sulu (Composer) Jul 2, 2021
Cross site scripting in the system log Moderate
CVE-2021-35210 was published for contao/contao (Composer) Jul 1, 2021
Missing Authentication for Critical Function Moderate
CVE-2021-32709 was published for shopware/platform (Composer) Jun 29, 2021
List of order ids, number, items total and token value exposed for unauthorized uses via new API Moderate
CVE-2021-32720 was published for sylius/sylius (Composer) Jun 29, 2021
nickvanderzwet
non-admin users can create integration role with administrator role Moderate
GHSA-243q-g9j3-qf6r was published for shopware/core (Composer) Jun 28, 2021
Internal hidden fields are visible on to many associations in admin api Moderate
GHSA-gpmh-g94g-qrhr was published for shopware/core (Composer) Jun 28, 2021
Canceling of orders not related to the logged-in user Moderate
GHSA-wq3r-jwrq-xg6w was published for shopware/core (Composer) Jun 28, 2021
Cross-site Scripting in yii2cmf Moderate
CVE-2018-10704 was published for yidashi/yii2cmf (Composer) Jun 22, 2021
Session Fixation in Subrion CMS Moderate
CVE-2020-12467 was published for intelliants/subrion (Composer) Jun 22, 2021
Cross-site scripting in PageKit Moderate
CVE-2021-32245 was published for pagekit/pagekit (Composer) Jun 22, 2021
ProTip! Advisories are also available from the GraphQL API