Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,781 advisories

Loading
Cross site scripting via HTML attributes in the back end Moderate
CVE-2021-35955 was published for contao/contao (Composer) Aug 25, 2021
m-vo
CKEditor 4 vulnerabilities in versions <4.16.1 Moderate
GHSA-cfcv-q4qq-2ph4 was published for pimcore/pimcore (Composer) Aug 23, 2021
PHP file inclusion via insert tags Moderate
CVE-2021-37626 was published for contao/contao (Composer) Aug 23, 2021
ausi
Cross-Site Scripting via Rich-Text Content Moderate
CVE-2021-32768 was published for typo3/cms (Composer) Aug 19, 2021
sushiwushi ohader
einpraegsam
Improper Access Control in Dolibarr Moderate
CVE-2021-25954 was published for dolibarr/dolibarr (Composer) Aug 11, 2021
Cross Site Scripting in LavaLite CMS Moderate
CVE-2020-23234 was published for lavalite/cms (Composer) Aug 9, 2021
No Restriction of Excessive Authentication Attempts in Firefly III Moderate
CVE-2021-3663 was published for grumpydictator/firefly-iii (Composer) Aug 9, 2021
Incorrect Authorization in TYPO3 extension Moderate
CVE-2020-25025 was published for localizationteam/l10nmgr (Composer) Jul 26, 2021
Missing Authorization in TYPO3 extension Moderate
CVE-2020-12700 was published for directmailteam/direct-mail (Composer) Jul 26, 2021
Missing Authorization in TYPO3 extension Moderate
CVE-2020-12698 was published for directmailteam/direct-mail (Composer) Jul 26, 2021
Information Disclosure in User Authentication Moderate
CVE-2021-32767 was published for typo3/cms (Composer) Jul 26, 2021
tdunlap607
Cross-Site Scripting in Backend Grid View Moderate
CVE-2021-32669 was published for typo3/cms (Composer) Jul 22, 2021
o-ba
Cross-Site Scripting in Query Generator & Query View Moderate
CVE-2021-32668 was published for typo3/cms (Composer) Jul 22, 2021
sushiwushi
Cross-Site Scripting in Page Preview Moderate
CVE-2021-32667 was published for typo3/cms (Composer) Jul 22, 2021
o-ba
Cross-site Scripting in Froala WYSIWYG Editor Moderate
CVE-2021-28114 was published for froala/wysiwyg-editor (Composer) Jul 19, 2021
Craft CMS Cross-site Scripting Vulnerability Moderate
CVE-2021-27902 was published for craftcms/cms (Composer) Jul 2, 2021
XSS Injection in Media Collection Title was possible Moderate
CVE-2021-32737 was published for sulu/sulu (Composer) Jul 2, 2021
Cross site scripting in the system log Moderate
CVE-2021-35210 was published for contao/contao (Composer) Jul 1, 2021
Missing Authentication for Critical Function Moderate
CVE-2021-32709 was published for shopware/platform (Composer) Jun 29, 2021
List of order ids, number, items total and token value exposed for unauthorized uses via new API Moderate
CVE-2021-32720 was published for sylius/sylius (Composer) Jun 29, 2021
nickvanderzwet
non-admin users can create integration role with administrator role Moderate
GHSA-243q-g9j3-qf6r was published for shopware/core (Composer) Jun 28, 2021
Internal hidden fields are visible on to many associations in admin api Moderate
GHSA-gpmh-g94g-qrhr was published for shopware/core (Composer) Jun 28, 2021
Canceling of orders not related to the logged-in user Moderate
GHSA-wq3r-jwrq-xg6w was published for shopware/core (Composer) Jun 28, 2021
Cross-site Scripting in yii2cmf Moderate
CVE-2018-10704 was published for yidashi/yii2cmf (Composer) Jun 22, 2021
Session Fixation in Subrion CMS Moderate
CVE-2020-12467 was published for intelliants/subrion (Composer) Jun 22, 2021
ProTip! Advisories are also available from the GraphQL API