Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,886 advisories

Loading
bookstack is vulnerable to Improper Access Control Moderate
CVE-2021-4194 was published for ssddanbrown/bookstack (Composer) Jan 8, 2022
Subrion CMS Cross-site Scripting (XSS) vulnerability in the `contact us` plugin Moderate
CVE-2021-41948 was published for intelliants/subrion (Composer) Apr 30, 2022
attritionorg
Credited to attritionorg
Pagekit CMS cross-site scripting in Markdown text box where articles are edited Moderate
CVE-2022-36573 was published for pagekit/pagekit (Composer) Aug 29, 2022
exceedone/exment and exceedone/laravel-admin Cross-site Scripting vulnerability Moderate
CVE-2022-38080 was published for exceedone/exment (Composer) Aug 25, 2022
Kirby CMS 2.5.12 Cross-site Scripting Moderate
CVE-2018-14520 was published for getkirby/cms (Composer) Aug 25, 2022
Shopware access control list bypassed via crafted specific URLs Moderate
CVE-2022-36102 was published for shopware/shopware (Composer) Sep 16, 2022
TYPO3 CMS vulnerable to User Enumeration via Response Timing Moderate
CVE-2022-36105 was published for typo3/cms (Composer) Sep 16, 2022
Vautia
Credited to Vautia
TYPO3 CMS vulnerable to Denial of Service in Page Error Handling Moderate
CVE-2022-36104 was published for typo3/cms (Composer) Sep 16, 2022
rikwillems
Credited to rikwillems
baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability Moderate
CVE-2022-39325 was published for baserproject/basercms (Composer) Nov 28, 2022
Froxlor vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2022-3017 was published for froxlor/froxlor (Composer) Aug 29, 2022
Kirby CMS 2.5.12 Cross-site Request Forgery Moderate
CVE-2018-14519 was published for getkirby/cms (Composer) Aug 25, 2022
francoisjacquet/rosariosis vulnerable to Cross-Site Scripting (XSS) Moderate
CVE-2022-3072 was published for francoisjacquet/rosariosis (Composer) Sep 2, 2022
Subrion CMS 4.2.1 vulnerable to cross-site scripting in admin panel Moderate
CVE-2022-37059 was published for intelliants/subrion (Composer) Aug 29, 2022
snipe-it vulnerable to cross-site scripting (XSS) Moderate
CVE-2022-3035 was published for snipe/snipe-it (Composer) Aug 30, 2022
Kirby .dev domains and some reverse proxy setups were treated as local Moderate
CVE-2020-26253 was published for getkirby/cms (Composer) Jan 14, 2021
Cross-site Scripting in Jirafeau Moderate
CVE-2022-30110 was published for mojo42/jirafeau (Composer) May 18, 2022
CSRF token exposure in TYPO3 extension Moderate
CVE-2021-36793 was published for lms/routes (Composer) Sep 2, 2021
Stored cross-site scripting in Snipe-IT Moderate
CVE-2022-1445 was published for snipe/snipe-it (Composer) Apr 25, 2022
Cross-site Scripting in Microweber Moderate
CVE-2022-1439 was published for microweber/microweber (Composer) Apr 23, 2022
Cross-site Scripting in snipe-it Moderate
CVE-2022-1380 was published for snipe/snipe-it (Composer) Apr 17, 2022
Cross-site Scripting in Pimcore Moderate
CVE-2022-1351 was published for pimcore/pimcore (Composer) Apr 15, 2022
HTML Injection in Froxlor Moderate
CVE-2020-29653 was published for froxlor/froxlor (Composer) Apr 14, 2022
Open redirect in wwbn/avideo Moderate
CVE-2022-27463 was published for wwbn/avideo (Composer) Apr 6, 2022
Cross-site Scripting in craftcms/cms Moderate
CVE-2022-28378 was published for craftcms/cms (Composer) Apr 4, 2022
Incorrect Access Control in ImpressCMS Moderate
CVE-2021-26598 was published for impresscms/impresscms (Composer) Mar 29, 2022
ProTip! Advisories are also available from the GraphQL API