Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,854 advisories

Loading
Improper sanitize of SVG files during content upload ('Cross-site Scripting') in sylius/sylius Moderate
CVE-2022-24749 was published for Sylius/Sylius (Composer) Mar 14, 2022
Ocramius
Credited to Ocramius
Cross-site Scripting in microweber Moderate
CVE-2022-0929 was published for microweber/microweber (Composer) Mar 13, 2022
Cross-site Scripting in ShowDoc Moderate
CVE-2022-0946 was published for showdoc/showdoc (Composer) Mar 15, 2022
Cross-site Scripting in microweber Moderate
CVE-2022-0926 was published for microweber/microweber (Composer) Mar 13, 2022
Cross-site Scripting in microweber Moderate
CVE-2022-0928 was published for microweber/microweber (Composer) Mar 12, 2022
Cross-site Scripting in ShowDoc Moderate
CVE-2022-0962 was published for showdoc/showdoc (Composer) Mar 15, 2022
Unrestricted Upload of File with Dangerous Type in microweber Moderate
CVE-2022-0912 was published for microweber/microweber (Composer) Mar 12, 2022
Cross-site Scripting in ShowDoc Moderate
CVE-2022-0880 was published for showdoc/showdoc (Composer) Mar 13, 2022
Unrestricted Upload of File with Dangerous Type in Microweber Moderate
CVE-2022-0921 was published for microweber/microweber (Composer) Mar 12, 2022
Unrestricted file upload leads to stored cross-site scripting in Microweber Moderate
CVE-2022-0906 was published for microweber/microweber (Composer) Mar 11, 2022
Cross-site Scripting in moodle Moderate
CVE-2021-43558 was published for moodle/moodle (Composer) Nov 23, 2021
Improper Authorization in grumpydictator/firefly-iii Moderate
CVE-2023-0298 was published for grumpydictator/firefly-iii (Composer) Jan 14, 2023
Shopware vulnerable to Improper Input Validation of Clearance sale in cart Moderate
CVE-2023-22730 was published for shopware/core (Composer) Jan 17, 2023
JoshuaBehrens aragon999
Credited to JoshuaBehrens and aragon999
pimcore is vulnerable to cross-site scripting via "title field " in data objects Moderate
CVE-2023-0323 was published for pimcore/pimcore (Composer) Jan 20, 2023
phpMyFAQ Stored Cross-site Scripting vulnerability Moderate
CVE-2023-0313 was published for thorsten/phpmyfaq (Composer) Jan 16, 2023
phpMyFAQ Reflected Cross-site Scripting vulnerability Moderate
CVE-2023-0314 was published for thorsten/phpmyfaq (Composer) Jan 16, 2023
thorsten/phpmyfaq is vulnerable to cross-site scripting (XSS) Moderate
CVE-2023-0312 was published for thorsten/phpmyfaq (Composer) Jan 16, 2023
Froxlor is vulnerable to path traversal Moderate
CVE-2023-0316 was published for froxlor/froxlor (Composer) Jan 16, 2023
Flarum notifications can leak restricted content Moderate
CVE-2023-22488 was published for flarum/core (Composer) Jan 10, 2023
clarkwinkelmann
Credited to clarkwinkelmann
phpMyFAQ Stored Cross-site Scripting vulnerability Moderate
CVE-2023-0306 was published for thorsten/phpmyfaq (Composer) Jan 16, 2023
phpMyFAQ has Weak Password Requirements Moderate
CVE-2023-0307 was published for thorsten/phpmyfaq (Composer) Jan 16, 2023
phpMyFAQ Stored Cross-site Scripting vulnerability Moderate
CVE-2023-0308 was published for thorsten/phpmyfaq (Composer) Jan 16, 2023
phpMyFAQ Stored Cross-site Scripting vulnerability Moderate
CVE-2023-0309 was published for thorsten/phpmyfaq (Composer) Jan 16, 2023
phpMyFAQ Stored Cross-site Scripting vulnerability Moderate
CVE-2023-0310 was published for thorsten/phpmyfaq (Composer) Jan 16, 2023
CakePHP vulnerable to Cross-site Scripting in some development error pages Moderate
GHSA-xwhj-pqcg-8rcr was published for cakephp/cakephp (Composer) Jan 20, 2023
ProTip! Advisories are also available from the GraphQL API