GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,675
Maven
5,000+
npm
4,297
NuGet
760
pip
4,077
Pub
12
RubyGems
957
Rust
1,058
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,866 advisories
Filter by severity
Sylius Resource Bundle Cross-Site Request Forgery vulnerability
Moderate
GHSA-65v7-wg35-2qpm
was published
for
sylius/resource-bundle
(Composer)
May 29, 2024
stormpath/sdk uses Insecure Random Number Generator
Moderate
GHSA-q8fc-v85f-78pw
was published
for
stormpath/sdk
(Composer)
May 29, 2024
ScnSocialAuth Cross-site Scripting vulnerability in login redirect param
Moderate
GHSA-g6f5-4w43-2x63
was published
for
socalnick/scn-social-auth
(Composer)
May 29, 2024
SimpleSAMLphp Information Disclosure vulnerability
Moderate
GHSA-ppm4-r2vc-pg74
was published
for
simplesamlphp/simplesamlphp
(Composer)
May 28, 2024
SimpleSAMLphp Reflected Cross-site Scripting vulnerability
Moderate
GHSA-vpr3-cw3h-prw8
was published
for
simplesamlphp/simplesamlphp
(Composer)
May 28, 2024
SimpleSAMLphp exposes credentials in session storage
Moderate
GHSA-7wh8-jrq7-p27f
was published
for
simplesamlphp/simplesamlphp
(Composer)
May 28, 2024
SimpleSAMLphp Link Injection vulnerability
Moderate
GHSA-v858-922f-fj9v
was published
for
simplesamlphp/simplesamlphp
(Composer)
May 28, 2024
Silverstripe Missing security check on dev/build/defaults
Moderate
GHSA-x5w2-wcr8-9q45
was published
for
silverstripe/framework
(Composer)
May 23, 2024
silverstripe/userforms file upload exposure on UserForms module
Moderate
GHSA-55pp-293f-3365
was published
for
silverstripe/userforms
(Composer)
May 28, 2024
Formwork Cross-site Scripting (XSS) from Page title field
Moderate
CVE-2023-24230
was published
for
getformwork/formwork
(Composer)
Feb 10, 2023
silverstripe/framework may disclose database credentials during connection failure
Moderate
GHSA-m2hh-2m46-x6j5
was published
for
silverstripe/framework
(Composer)
May 28, 2024
silverstripe/framework vulnerable to member disclosure in login form
Moderate
GHSA-crr3-h4m8-7f56
was published
for
silverstripe/framework
(Composer)
May 27, 2024
silverstripe/framework uploaded PHP script execution in assets
Moderate
GHSA-f43j-8hq4-2xj9
was published
for
silverstripe/framework
(Composer)
May 27, 2024
silverstripe/framework's install.php script discloses sensitive data by pre-populating DB credential forms
Moderate
GHSA-r3pr-fh25-wrfc
was published
for
silverstripe/framework
(Composer)
May 27, 2024
silverstripe/framework Privilege Escalation Risk in Member Edit form
Moderate
GHSA-xpff-c35g-j3cr
was published
for
silverstripe/framework
(Composer)
May 27, 2024
silverstripe/framework's URL parameters `isDev` and `isTest` unguarded
Moderate
GHSA-55qg-6c4m-mw6g
was published
for
silverstripe/framework
(Composer)
May 27, 2024
silverstripe/framework users inadvertently passing sensitive data to LoginAttempt
Moderate
GHSA-ph62-fv59-vf9h
was published
for
silverstripe/framework
(Composer)
May 27, 2024
silverstripe/framework has Cross-site Scripting vulnerability in page history comparison
Moderate
GHSA-c4c3-j73v-634r
was published
for
silverstripe/framework
(Composer)
May 27, 2024
silverstripe/framework has Cross-site Scripting vulnerability in RedirectorPage
Moderate
GHSA-pp7q-6j3f-74vj
was published
for
silverstripe/framework
(Composer)
May 27, 2024
silverstripe/framework has Cross-site Scripting vulnerability in CMSSecurity BackURL
Moderate
GHSA-r85g-7jpv-8xrx
was published
for
silverstripe/framework
(Composer)
May 27, 2024
silverstripe/framework has Cross-site Scripting vulnerability in page name
Moderate
GHSA-hhvj-mcrx-3vcf
was published
for
silverstripe/framework
(Composer)
May 27, 2024
silverstripe/framework member disclosure in login form
Moderate
GHSA-g84q-cq55-xwgp
was published
for
silverstripe/framework
(Composer)
May 27, 2024
silverstripe/framework vulnerable to Cross-site Scripting In `OptionsetField` and `CheckboxSetField`
Moderate
GHSA-468j-6jrc-2rjx
was published
for
silverstripe/framework
(Composer)
May 27, 2024
silverstripe/framework's `Member.Name` is not escaped
Moderate
GHSA-r9vp-fp72-xgf7
was published
for
silverstripe/framework
(Composer)
May 27, 2024
silverstripe/framework missing ACL on reports
Moderate
GHSA-52cx-hpc5-cxwc
was published
for
silverstripe/framework
(Composer)
May 27, 2024
ProTip!
Advisories are also available from the
GraphQL API