Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,886 advisories

Loading
Grav CMS Cross-site scripting (XSS) vulnerability Moderate
CVE-2018-5233 was published for getgrav/grav (Composer) May 14, 2022
Drupal cross-site scripting vulnerability Moderate
CVE-2017-6927 was published for drupal/core (Composer) May 14, 2022
Drupal external link injection vulnerability Moderate
CVE-2017-6932 was published for drupal/core (Composer) May 14, 2022
Drupal cross site scripting vulnerability Moderate
CVE-2017-6929 was published for drupal/core (Composer) May 14, 2022
Tiki Wiki CMS XSS Vulnerability Moderate
CVE-2018-7302 was published for tikiwiki/tiki-manager (Composer) May 14, 2022
phpMyAdmin Cross-site scripting (XSS) vulnerability in central columns feature Moderate
CVE-2018-7260 was published for phpmyadmin/phpmyadmin (Composer) May 14, 2022
Dolibarr ERP and CRM contain XSS Vulnerability Moderate
CVE-2017-1000509 was published for dolibarr/dolibarr (Composer) May 14, 2022
Cross site scripting in Croogo Moderate
CVE-2017-1000510 was published for croogo/croogo (Composer) May 14, 2022
Ocramius
Credited to Ocramius
Canvs Canvas XSS Vulnerability Moderate
CVE-2017-1000507 was published for austintoddj/canvas (Composer) May 14, 2022
Mautic Cross Site Scripting (XSS) vulnerability Moderate
CVE-2017-1000506 was published for mautic/core (Composer) May 14, 2022
SimpleSAMLphp Open redirection protection bypass Moderate
CVE-2018-6520 was published for simplesamlphp/simplesamlphp (Composer) May 14, 2022
SilverStripe CSV Excel Macro Injection Moderate
CVE-2017-18049 was published for silverstripe/framework (Composer) May 14, 2022
Moodle XSS Vulnerability Moderate
CVE-2018-1045 was published for moodle/moodle (Composer) May 14, 2022
Moodle Privilege escalation in quiz web services Moderate
CVE-2018-1044 was published for moodle/moodle (Composer) May 14, 2022
Magento Cross-Site Request Forgery (CSRF) Moderate
CVE-2018-5301 was published for magento/community-edition (Composer) May 14, 2022
Shopware XSS Vulnerability Moderate
CVE-2017-15374 was published for shopware/shopware (Composer) May 14, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability Moderate
CVE-2018-5366 was published for wpglobus/wpglobus (Composer) May 14, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability Moderate
CVE-2018-5367 was published for wpglobus/wpglobus (Composer) May 14, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability Moderate
CVE-2018-5365 was published for wpglobus/wpglobus (Composer) May 14, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability Moderate
CVE-2018-5364 was published for wpglobus/wpglobus (Composer) May 14, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability Moderate
CVE-2018-5363 was published for wpglobus/wpglobus (Composer) May 14, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability Moderate
CVE-2018-5362 was published for wpglobus/wpglobus (Composer) May 14, 2022
eZ Publish Cross-site Scripting (XSS) vulnerability Moderate
CVE-2017-1000431 was published for ezsystems/ezpublish-legacy (Composer) May 14, 2022
QuickApps CMS Cross-site Scripting Moderate
CVE-2017-1000495 was published for quickapps/cms (Composer) May 14, 2022
Stored XSS in LavaLite 5.2.4 Moderate
CVE-2017-1000467 was published for lavalite/cms (Composer) May 14, 2022
ProTip! Advisories are also available from the GraphQL API