Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,870 advisories

Loading
Stored cross-site scripting in Snipe-IT Moderate
CVE-2022-1445 was published for snipe/snipe-it (Composer) Apr 25, 2022
SQL injection in helloxz/imgurl High
CVE-2022-29305 was published for helloxz/imgurl (Composer) May 25, 2022
Cross-site Scripting in Jirafeau Moderate
CVE-2022-30110 was published for mojo42/jirafeau (Composer) May 18, 2022
CSRF token exposure in TYPO3 extension Moderate
CVE-2021-36793 was published for lms/routes (Composer) Sep 2, 2021
Kirby .dev domains and some reverse proxy setups were treated as local Moderate
CVE-2020-26253 was published for getkirby/cms (Composer) Jan 14, 2021
Server-Side Request Forgery (SSRF) in Shopware High
CVE-2022-24871 was published for shopware/core (Composer) Apr 22, 2022
shyim
PHPMailer susceptible to arbitrary code execution High
CVE-2008-5619 was published for phpmailer/phpmailer (Composer) May 14, 2022
jhutchings1
snipe-it vulnerable to cross-site scripting (XSS) Moderate
CVE-2022-3035 was published for snipe/snipe-it (Composer) Aug 30, 2022
exceedone/exment and exceedone/laravel-admin SQL Injection vulnerability High
CVE-2022-37333 was published for exceedone/exment (Composer) Aug 25, 2022
francoisjacquet/rosariosis vulnerable to Cross-Site Scripting (XSS) Moderate
CVE-2022-3072 was published for francoisjacquet/rosariosis (Composer) Sep 2, 2022
Subrion CMS 4.2.1 vulnerable to cross-site scripting in admin panel Moderate
CVE-2022-37059 was published for intelliants/subrion (Composer) Aug 29, 2022
Command injection in czproject/git-php High
CVE-2022-25866 was published for czproject/git-php (Composer) Apr 26, 2022
Cross site scripting in facturascripts Critical
CVE-2022-1457 was published for neorazorx/facturascripts (Composer) Apr 26, 2022
Rank Math SEO plugin vulnerable to Server-Side Request Forgery Critical
CVE-2022-36376 was published for rankmath/seo-by-rank-math (Composer) Sep 10, 2022
Kirby CMS 2.5.12 Cross-site Request Forgery Moderate
CVE-2018-14519 was published for getkirby/cms (Composer) Aug 25, 2022
Froxlor vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2022-3017 was published for froxlor/froxlor (Composer) Aug 29, 2022
baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability Moderate
CVE-2022-39325 was published for baserproject/basercms (Composer) Nov 28, 2022
TYPO3 CMS vulnerable to User Enumeration via Response Timing Moderate
CVE-2022-36105 was published for typo3/cms (Composer) Sep 16, 2022
Vautia
TYPO3 CMS vulnerable to Denial of Service in Page Error Handling Moderate
CVE-2022-36104 was published for typo3/cms (Composer) Sep 16, 2022
rikwillems
Shopware access control list bypassed via crafted specific URLs Moderate
CVE-2022-36102 was published for shopware/shopware (Composer) Sep 16, 2022
exceedone/exment and exceedone/laravel-admin Cross-site Scripting vulnerability Moderate
CVE-2022-38080 was published for exceedone/exment (Composer) Aug 25, 2022
Kirby CMS 2.5.12 Cross-site Scripting Moderate
CVE-2018-14520 was published for getkirby/cms (Composer) Aug 25, 2022
Pagekit CMS cross-site scripting in Markdown text box where articles are edited Moderate
CVE-2022-36573 was published for pagekit/pagekit (Composer) Aug 29, 2022
PHP Code Injection by malicious block or filename in Smarty High
CVE-2022-29221 was published for smarty/smarty (Composer) May 25, 2022
altm4n
ThinkPHP deserialization vulnerability Critical
CVE-2022-38352 was published for topthink/framework (Composer) Sep 16, 2022
ProTip! Advisories are also available from the GraphQL API