Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,886 advisories

Loading
alextselegidis/easyappointments vulnerable to Stored Cross-site Scripting Moderate
CVE-2023-2103 was published for alextselegidis/easyappointments (Composer) Apr 15, 2023
Concrete CMS vulnerable to Reflected Cross-site Scripting Moderate
CVE-2022-43692 was published for concrete5/concrete5 (Composer) Nov 15, 2022
tdunlap607
Credited to tdunlap607
phpMyFAQ vulnerable to improper input validation Moderate
CVE-2023-1754 was published for thorsten/phpmyfaq (Composer) Mar 31, 2023
Cross-site scripting vulnerabilities in old version of bundled TinyMCE Moderate
GHSA-wqm8-jx8r-8rcq was published for silverstripe/admin (Composer) Apr 26, 2023
Concrete CMS vulnerable to Improper Authentication Moderate
CVE-2022-43690 was published for concrete5/concrete5 (Composer) Nov 15, 2022
tdunlap607
Credited to tdunlap607
Pimcore Cross-site Scripting (XSS) in Predefined Properties delete Moderate
CVE-2023-2615 was published for pimcore/pimcore (Composer) May 10, 2023
sampritdas8
Credited to sampritdas8
Pimcore Cross-site Scripting (XSS) in name field of Custom Reports Moderate
CVE-2023-2614 was published for pimcore/pimcore (Composer) May 10, 2023
sampritdas8
Credited to sampritdas8
Pimcore Cross-site Scripting (XSS) in Static Routes name field Moderate
CVE-2023-2616 was published for pimcore/pimcore (Composer) May 11, 2023
sampritdas8
Credited to sampritdas8
Ibexa User Settings are accessible on the front-end for anonymous user Moderate
GHSA-r3fg-3r88-6x3f was published for ibexa/user (Composer) May 10, 2023
BenK0lin
Credited to BenK0lin
PocketMine MP vulnerable to uncontrolled resource consumption via mismatched type of 'InventoryTransactionPacket' Moderate
GHSA-42qm-8v8m-m78c was published for pocketmine/pocketmine-mp (Composer) Jun 1, 2023
dktapps
Credited to dktapps
Silverstripe Form Capture vulnerable to stored cross-site-scripting Moderate
CVE-2023-28851 was published for andrewhaine/silverstripe-form-capture (Composer) Apr 3, 2023
tommcclymont jkylekelly
Credited to tommcclymont and jkylekelly
Incorrect Authentication in shopware Moderate
CVE-2022-24748 was published for shopware/core (Composer) Mar 10, 2022
Microweber before v1.2.20 vulnerable to cross-site scripting Moderate
CVE-2022-2353 was published for microweber/microweber (Composer) Jul 10, 2022
Cross-Site Request Forgery in feehi/feehicms Moderate
CVE-2022-4014 was published for feehi/feehicms (Composer) Nov 16, 2022
Incorrect Default Permissions and Improper Access Control in snipe-it Moderate
CVE-2022-0179 was published for snipe/snipe-it (Composer) Jan 21, 2022
Dolibarr vulnerable to Improper Validation of Specified Quantity in Input Moderate
CVE-2022-0414 was published for dolibarr/dolibarr (Composer) Feb 1, 2022
Microweber vulnerable to Improper Validation of Specified Quantity in Input Moderate
CVE-2022-0596 was published for microweber/microweber (Composer) Feb 16, 2022
Improper Access Control in snipe/snipe-it Moderate
CVE-2022-1511 was published for snipe/snipe-it (Composer) Apr 29, 2022
HTTP caching is marking private HTTP headers as public in Shopware Moderate
CVE-2022-24747 was published for shopware/core (Composer) Mar 10, 2022
UlrichThomasGabor
Credited to UlrichThomasGabor
Sensitive Information Exposure in Sylius Moderate
CVE-2022-24742 was published for sylius/sylius (Composer) Mar 14, 2022
Microweber before 1.2.21 allows attacker to bypass IP detection to brute-force password Moderate
CVE-2022-2368 was published for microweber/microweber (Composer) Jul 12, 2022
WooCommerce WordPress plugin before 6.6.0 vulnerable to stored HTML injection Moderate
CVE-2022-2099 was published for woocommerce/woocommerce (Composer) Jul 18, 2022
Cross-site Scripting (XSS) in baserCMS Moderate
CVE-2021-20681 was published for baserproject/basercms (Composer) Jun 8, 2021
Firefly III vulnerable to image-based stored XSS Moderate
CVE-2019-13647 was published for grumpydictator/firefly-iii (Composer) May 24, 2022
reflected XSS in tribalsystems/zenario Moderate
CVE-2021-27673 was published for tribalsystems/zenario (Composer) Jun 8, 2021
ProTip! Advisories are also available from the GraphQL API