GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,700
Maven
5,000+
npm
4,328
NuGet
761
pip
4,100
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,886 advisories
Filter by severity
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-4123
was published
for
remdex/livehelperchat
(Composer)
Dec 17, 2021
yetiforcecrm is vulnerable to Cross-site Scripting
Moderate
CVE-2021-4121
was published
for
yetiforce/yetiforce-crm
(Composer)
Dec 17, 2021
Cross-site Scripting in FacturaScripts
Moderate
CVE-2022-1988
was published
for
facturascripts/facturascripts
(Composer)
Jun 4, 2022
Cross-site scripting (XSS) vulnerability in CakePHP
Moderate
CVE-2006-4067
was published
for
cakephp/cakephp
(Composer)
May 1, 2022
Cross-site Scripting in Backdrop CMS
Moderate
CVE-2022-42095
was published
for
backdrop/backdrop
(Composer)
Nov 23, 2022
XSS via uploaded gpx file
Moderate
CVE-2022-38147
was published
for
silverstripe/assets
(Composer)
Nov 21, 2022
Stored XSS using uppercase characters in HTMLEditor
Moderate
CVE-2022-37430
was published
for
silverstripe/framework
(Composer)
Nov 21, 2022
Stored XSS in Compare Mode
Moderate
CVE-2022-38145
was published
for
silverstripe/versioned-admin
(Composer)
Nov 22, 2022
wallabag subject to Improper Authorization via annotations
Moderate
CVE-2023-0610
was published
for
wallabag/wallabag
(Composer)
Feb 2, 2023
Cross-site Scripting in Bootstrap-3-Typeahead
Moderate
CVE-2019-10215
was published
for
bassjobsen/bootstrap-3-typeahead
(Composer)
May 24, 2022
Froxlor vulnerable to Cross-Site Request Forgery
Moderate
CVE-2022-4867
was published
for
froxlor/froxlor
(Composer)
Dec 31, 2022
Froxlor Improper Authorization vulnerability
Moderate
CVE-2022-4868
was published
for
froxlor/froxlor
(Composer)
Dec 31, 2022
livehelperchat is vulnerable to Cross-site Scripting
Moderate
CVE-2021-4132
was published
for
remdex/livehelperchat
(Composer)
Jan 5, 2022
Wechat-php-sdk is affected by a Cross Site Scripting vulnerability.
Moderate
CVE-2021-43678
was published
for
gaoming13/wechat-php-sdk
(Composer)
Jan 7, 2022
Cross-site Scripting in pimcore
Moderate
CVE-2021-4139
was published
for
pimcore/pimcore
(Composer)
Jan 5, 2022
elgg is vulnerable to Cross-site Scripting
Moderate
CVE-2021-4072
was published
for
elgg/elgg
(Composer)
Jan 6, 2022
invoiceninja is vulnerable to Cross-site Scripting
Moderate
CVE-2021-3977
was published
for
hillelcoren/invoice-ninja
(Composer)
Jan 6, 2022
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-4168
was published
for
showdoc/showdoc
(Composer)
Jan 6, 2022
Open redirect in shopware
Moderate
CVE-2022-21651
was published
for
shopware/shopware
(Composer)
Jan 6, 2022
Cross-Site Request Forgery in Moodle
Moderate
CVE-2020-1692
was published
for
moodle/moodle
(Composer)
Jan 6, 2022
XSS vulnerability on email template preview page
Moderate
CVE-2021-41236
was published
for
oro/platform
(Composer)
Jan 6, 2022
User enumeration in livehelperchat
Moderate
CVE-2022-0083
was published
for
remdex/livehelperchat
(Composer)
Jan 21, 2022
Client-Side JavaScript Prototype Pollution in oro/platform
Moderate
CVE-2021-43852
was published
for
oro/platform
(Composer)
Jan 6, 2022
showdoc is vulnerable to Generation of Error Message Containing Sensitive Information
Moderate
CVE-2022-0079
was published
for
showdoc/showdoc
(Composer)
Jan 6, 2022
Cross-site Scripting in DayByDay CRM
Moderate
CVE-2022-22109
was published
for
bottelet/flarepoint
(Composer)
Jan 8, 2022
ProTip!
Advisories are also available from the
GraphQL API