Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,886 advisories

Loading
Cross-site Scripting in librenms Moderate
CVE-2022-0576 was published for librenms/librenms (Composer) Feb 15, 2022
Cross-Site Request Forgery microweber Moderate
CVE-2022-0638 was published for microweber/microweber (Composer) Feb 18, 2022
Generation of Error Message Containing Sensitive Information in Snipe-IT Moderate
CVE-2022-0622 was published for snipe/snipe-it (Composer) Feb 18, 2022
Craft CMS vulnerable to Cross-site Scripting via entry revisions and drafts Moderate
CVE-2022-37251 was published for craftcms/cms (Composer) Sep 17, 2022
brandonkelly
Credited to brandonkelly
Cross-site Scripting in microweber Moderate
CVE-2022-0723 was published for microweber/microweber (Composer) Feb 27, 2022
Cross-site Scripting in Cipi Moderate
CVE-2022-26332 was published for andreapollastri/cipi (Composer) Mar 2, 2022
Incorrect authorization in Drupal core Moderate
CVE-2022-25270 was published for drupal/core (Composer) Feb 18, 2022
Cross-site Scripting in microweber Moderate
CVE-2022-0678 was published for microweber/microweber (Composer) Feb 20, 2022
Business Logic Errors in microweber Moderate
CVE-2022-0689 was published for microweber/microweber (Composer) Feb 20, 2022
Logic error in dolibarr/dolibarr Moderate
CVE-2022-0746 was published for dolibarr/dolibarr (Composer) Feb 26, 2022
Missing server signature validation in OctoberCMS Moderate
CVE-2022-23655 was published for october/system (Composer) Feb 24, 2022
Path traversal in pimcore Moderate
CVE-2022-0665 was published for pimcore/pimcore (Composer) Feb 23, 2022
Cross-Site Request Forgery (CSRF) Protection Bypass Vulnerability in CodeIgniter4 Moderate
CVE-2022-24712 was published for codeigniter4/framework (Composer) Mar 1, 2022
Cross site scripting in getgrav/grav Moderate
CVE-2022-0743 was published for getgrav/grav (Composer) Mar 2, 2022
Cross site scripting in francoisjacquet/rosariosis Moderate
CVE-2021-44566 was published for francoisjacquet/rosariosis (Composer) Feb 25, 2022
Cross site scripting in francoisjacquet/rosariosis Moderate
CVE-2021-44565 was published for francoisjacquet/rosariosis (Composer) Feb 25, 2022
Cross-site Scripting in GeniXCMS Moderate
CVE-2022-24563 was published for genix/cms (Composer) Mar 4, 2022
Cross-site Scripting in Subrion CMS Moderate
CVE-2020-18324 was published for intelliants/subrion (Composer) Mar 5, 2022
Cross-site Scripting in BookStack Moderate
CVE-2022-0877 was published for ssddanbrown/bookstack (Composer) Mar 9, 2022
Shopware guest session is shared between customers Moderate
CVE-2022-24745 was published for shopware/platform (Composer) Mar 10, 2022
Cross-site Scripting in microweber Moderate
CVE-2022-0763 was published for microweber/microweber (Composer) Feb 27, 2022
Cross site scripting in LibreNMS Moderate
CVE-2022-0772 was published for librenms/librenms (Composer) Feb 28, 2022
Cross-site Scripting in intelliants/subrion Moderate
CVE-2020-18325 was published for intelliants/subrion (Composer) Mar 5, 2022
Cross-site Scripting in Pimcore Moderate
CVE-2022-0832 was published for pimcore/pimcore (Composer) Mar 5, 2022
Cross-site Scripting in Pimcore Moderate
CVE-2022-0831 was published for pimcore/pimcore (Composer) Mar 5, 2022
ProTip! Advisories are also available from the GraphQL API