Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,886 advisories

Loading
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-4123 was published for remdex/livehelperchat (Composer) Dec 17, 2021
yetiforcecrm is vulnerable to Cross-site Scripting Moderate
CVE-2021-4121 was published for yetiforce/yetiforce-crm (Composer) Dec 17, 2021
Cross-site Scripting in FacturaScripts Moderate
CVE-2022-1988 was published for facturascripts/facturascripts (Composer) Jun 4, 2022
Cross-site scripting (XSS) vulnerability in CakePHP Moderate
CVE-2006-4067 was published for cakephp/cakephp (Composer) May 1, 2022
ravage84
Credited to ravage84
Cross-site Scripting in Backdrop CMS Moderate
CVE-2022-42095 was published for backdrop/backdrop (Composer) Nov 23, 2022
XSS via uploaded gpx file Moderate
CVE-2022-38147 was published for silverstripe/assets (Composer) Nov 21, 2022
Stored XSS using uppercase characters in HTMLEditor Moderate
CVE-2022-37430 was published for silverstripe/framework (Composer) Nov 21, 2022
Stored XSS in Compare Mode Moderate
CVE-2022-38145 was published for silverstripe/versioned-admin (Composer) Nov 22, 2022
wallabag subject to Improper Authorization via annotations Moderate
CVE-2023-0610 was published for wallabag/wallabag (Composer) Feb 2, 2023
bAuh0lz
Credited to bAuh0lz
Cross-site Scripting in Bootstrap-3-Typeahead Moderate
CVE-2019-10215 was published for bassjobsen/bootstrap-3-typeahead (Composer) May 24, 2022
Froxlor vulnerable to Cross-Site Request Forgery Moderate
CVE-2022-4867 was published for froxlor/froxlor (Composer) Dec 31, 2022
Froxlor Improper Authorization vulnerability Moderate
CVE-2022-4868 was published for froxlor/froxlor (Composer) Dec 31, 2022
livehelperchat is vulnerable to Cross-site Scripting Moderate
CVE-2021-4132 was published for remdex/livehelperchat (Composer) Jan 5, 2022
Wechat-php-sdk is affected by a Cross Site Scripting vulnerability. Moderate
CVE-2021-43678 was published for gaoming13/wechat-php-sdk (Composer) Jan 7, 2022
Cross-site Scripting in pimcore Moderate
CVE-2021-4139 was published for pimcore/pimcore (Composer) Jan 5, 2022
elgg is vulnerable to Cross-site Scripting Moderate
CVE-2021-4072 was published for elgg/elgg (Composer) Jan 6, 2022
invoiceninja is vulnerable to Cross-site Scripting Moderate
CVE-2021-3977 was published for hillelcoren/invoice-ninja (Composer) Jan 6, 2022
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-4168 was published for showdoc/showdoc (Composer) Jan 6, 2022
Open redirect in shopware Moderate
CVE-2022-21651 was published for shopware/shopware (Composer) Jan 6, 2022
Cross-Site Request Forgery in Moodle Moderate
CVE-2020-1692 was published for moodle/moodle (Composer) Jan 6, 2022
XSS vulnerability on email template preview page Moderate
CVE-2021-41236 was published for oro/platform (Composer) Jan 6, 2022
User enumeration in livehelperchat Moderate
CVE-2022-0083 was published for remdex/livehelperchat (Composer) Jan 21, 2022
Client-Side JavaScript Prototype Pollution in oro/platform Moderate
CVE-2021-43852 was published for oro/platform (Composer) Jan 6, 2022
showdoc is vulnerable to Generation of Error Message Containing Sensitive Information Moderate
CVE-2022-0079 was published for showdoc/showdoc (Composer) Jan 6, 2022
Cross-site Scripting in DayByDay CRM Moderate
CVE-2022-22109 was published for bottelet/flarepoint (Composer) Jan 8, 2022
ProTip! Advisories are also available from the GraphQL API