GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,300
NuGet
760
pip
4,078
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,868 advisories
Filter by severity
silverstripe/framework's `Member.Name` is not escaped
Moderate
GHSA-r9vp-fp72-xgf7
was published
for
silverstripe/framework
(Composer)
May 27, 2024
silverstripe/framework missing ACL on reports
Moderate
GHSA-52cx-hpc5-cxwc
was published
for
silverstripe/framework
(Composer)
May 27, 2024
silverstripe/framework ChangePasswordForm does not check `Member::canLogIn()`
Moderate
GHSA-p5h2-vr99-xm99
was published
for
silverstripe/framework
(Composer)
May 27, 2024
SilverStripe comments module includes version of jQuery vulnerable to Cross-site Scripting
Moderate
GHSA-frm9-7pm9-5rgc
was published
for
silverstripe/comments
(Composer)
May 27, 2024
Drupal core Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2020-13672
was published
for
drupal/core
(Composer)
Feb 12, 2022
PHP Server Monitor vulnerable to Cross-site Scripting
Moderate
CVE-2024-5312
was published
for
phpservermon/phpservermon
(Composer)
May 24, 2024
Mantis Bug Tracker (MantisBT) vulnerable to cross-site scripting
Moderate
CVE-2024-34081
was published
for
mantisbt/mantisbt
(Composer)
May 13, 2024
silverstripe/framework ReadOnly transformation for formfields exploitable
Moderate
GHSA-97jm-g33h-f46g
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Cross-site scripting vulnerability in VersionedRequestFilter
Moderate
GHSA-mpqj-f4v3-334h
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Missing CSRF protection in login form
Moderate
GHSA-vj2j-6g3w-4662
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe XSS in CMS Edit Page
Moderate
GHSA-m8v7-x398-pxrf
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Hostname, IP and Protocol Spoofing through HTTP Headers
Moderate
GHSA-87pf-7x99-5xc4
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe CSRF vulnerability in GridFieldAddExistingAutocompleter
Moderate
GHSA-2hpc-mf4q-j885
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe HtmlEditor embed url sanitisation
Moderate
GHSA-qp29-wcc2-vmpc
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Form field validation message XSS vulnerability
Moderate
GHSA-j982-5jv7-v43r
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe framework is vulnerable to XSS in install.php
Moderate
GHSA-mqf5-275h-gf6r
was published
for
silverstripe/framework
(Composer)
May 23, 2024
SilverStripe Vulnerability on 'isDev', 'isTest' and 'flush' $_GET validation
Moderate
GHSA-g4hp-pfvf-vm5w
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe XSS in dev/build returnURL Parameter
Moderate
GHSA-hq4p-5mpr-jj9m
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe External redirection risk in Security?ReturnURL
Moderate
GHSA-vp8p-c6xj-xpj7
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe XSS in Director::force_redirect()
Moderate
GHSA-jqp8-v74p-g8px
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe XSS In FormAction
Moderate
GHSA-4h54-vwx9-3vr3
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe XSS In rewritten hash links
Moderate
GHSA-34q6-xqxh-gq39
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe XSS In GridField print
Moderate
GHSA-88jp-9jrv-6368
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe XSS in TreeDropdownField and TreeMultiSelectField
Moderate
GHSA-r32j-mr8p-hfp8
was published
for
silverstripe/framework
(Composer)
May 23, 2024
SilverStripe framework XML Quadratic Blowup Attack
Moderate
GHSA-g43w-98wp-m694
was published
for
silverstripe/framework
(Composer)
May 23, 2024
ProTip!
Advisories are also available from the
GraphQL API