Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,883 advisories

Loading
exceedone/exment and exceedone/laravel-admin Cross-site Scripting vulnerability Moderate
CVE-2022-38080 was published for exceedone/exment (Composer) Aug 25, 2022
Kirby CMS 2.5.12 Cross-site Scripting Moderate
CVE-2018-14520 was published for getkirby/cms (Composer) Aug 25, 2022
Shopware access control list bypassed via crafted specific URLs Moderate
CVE-2022-36102 was published for shopware/shopware (Composer) Sep 16, 2022
TYPO3 CMS vulnerable to User Enumeration via Response Timing Moderate
CVE-2022-36105 was published for typo3/cms (Composer) Sep 16, 2022
Vautia
Credited to Vautia
TYPO3 CMS vulnerable to Denial of Service in Page Error Handling Moderate
CVE-2022-36104 was published for typo3/cms (Composer) Sep 16, 2022
rikwillems
Credited to rikwillems
baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability Moderate
CVE-2022-39325 was published for baserproject/basercms (Composer) Nov 28, 2022
Froxlor vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2022-3017 was published for froxlor/froxlor (Composer) Aug 29, 2022
Kirby CMS 2.5.12 Cross-site Request Forgery Moderate
CVE-2018-14519 was published for getkirby/cms (Composer) Aug 25, 2022
francoisjacquet/rosariosis vulnerable to Cross-Site Scripting (XSS) Moderate
CVE-2022-3072 was published for francoisjacquet/rosariosis (Composer) Sep 2, 2022
Subrion CMS 4.2.1 vulnerable to cross-site scripting in admin panel Moderate
CVE-2022-37059 was published for intelliants/subrion (Composer) Aug 29, 2022
snipe-it vulnerable to cross-site scripting (XSS) Moderate
CVE-2022-3035 was published for snipe/snipe-it (Composer) Aug 30, 2022
Kirby .dev domains and some reverse proxy setups were treated as local Moderate
CVE-2020-26253 was published for getkirby/cms (Composer) Jan 14, 2021
Cross-site Scripting in Jirafeau Moderate
CVE-2022-30110 was published for mojo42/jirafeau (Composer) May 18, 2022
CSRF token exposure in TYPO3 extension Moderate
CVE-2021-36793 was published for lms/routes (Composer) Sep 2, 2021
Stored cross-site scripting in Snipe-IT Moderate
CVE-2022-1445 was published for snipe/snipe-it (Composer) Apr 25, 2022
Cross-site Scripting in Microweber Moderate
CVE-2022-1439 was published for microweber/microweber (Composer) Apr 23, 2022
Cross-site Scripting in snipe-it Moderate
CVE-2022-1380 was published for snipe/snipe-it (Composer) Apr 17, 2022
Cross-site Scripting in Pimcore Moderate
CVE-2022-1351 was published for pimcore/pimcore (Composer) Apr 15, 2022
HTML Injection in Froxlor Moderate
CVE-2020-29653 was published for froxlor/froxlor (Composer) Apr 14, 2022
Open redirect in wwbn/avideo Moderate
CVE-2022-27463 was published for wwbn/avideo (Composer) Apr 6, 2022
Cross-site Scripting in craftcms/cms Moderate
CVE-2022-28378 was published for craftcms/cms (Composer) Apr 4, 2022
Incorrect Access Control in ImpressCMS Moderate
CVE-2021-26598 was published for impresscms/impresscms (Composer) Mar 29, 2022
Cross-site Scripting in teampass Moderate
CVE-2022-26980 was published for nilsteampassnet/teampass (Composer) Mar 29, 2022
Cross-Site Request Forgery in Anchor CMS Moderate
CVE-2022-25576 was published for anchorcms/anchor-cms (Composer) Mar 26, 2022
Cross-site Scripting in Fork CMS Moderate
CVE-2022-0145 was published for forkcms/forkcms (Composer) Mar 25, 2022
ProTip! Advisories are also available from the GraphQL API