Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,868 advisories

Loading
silverstripe/framework's `Member.Name` is not escaped Moderate
GHSA-r9vp-fp72-xgf7 was published for silverstripe/framework (Composer) May 27, 2024
silverstripe/framework missing ACL on reports Moderate
GHSA-52cx-hpc5-cxwc was published for silverstripe/framework (Composer) May 27, 2024
silverstripe/framework ChangePasswordForm does not check `Member::canLogIn()` Moderate
GHSA-p5h2-vr99-xm99 was published for silverstripe/framework (Composer) May 27, 2024
SilverStripe comments module includes version of jQuery vulnerable to Cross-site Scripting Moderate
GHSA-frm9-7pm9-5rgc was published for silverstripe/comments (Composer) May 27, 2024
Drupal core Cross-site Scripting (XSS) vulnerability Moderate
CVE-2020-13672 was published for drupal/core (Composer) Feb 12, 2022
PHP Server Monitor vulnerable to Cross-site Scripting Moderate
CVE-2024-5312 was published for phpservermon/phpservermon (Composer) May 24, 2024
Mantis Bug Tracker (MantisBT) vulnerable to cross-site scripting Moderate
CVE-2024-34081 was published for mantisbt/mantisbt (Composer) May 13, 2024
atrol unboundeduniverse
dregad
Credited to atrol, unboundeduniverse, and dregad
silverstripe/framework ReadOnly transformation for formfields exploitable Moderate
GHSA-97jm-g33h-f46g was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Cross-site scripting vulnerability in VersionedRequestFilter Moderate
GHSA-mpqj-f4v3-334h was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Missing CSRF protection in login form Moderate
GHSA-vj2j-6g3w-4662 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS in CMS Edit Page Moderate
GHSA-m8v7-x398-pxrf was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Hostname, IP and Protocol Spoofing through HTTP Headers Moderate
GHSA-87pf-7x99-5xc4 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe CSRF vulnerability in GridFieldAddExistingAutocompleter Moderate
GHSA-2hpc-mf4q-j885 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe HtmlEditor embed url sanitisation Moderate
GHSA-qp29-wcc2-vmpc was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Form field validation message XSS vulnerability Moderate
GHSA-j982-5jv7-v43r was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe framework is vulnerable to XSS in install.php Moderate
GHSA-mqf5-275h-gf6r was published for silverstripe/framework (Composer) May 23, 2024
SilverStripe Vulnerability on 'isDev', 'isTest' and 'flush' $_GET validation Moderate
GHSA-g4hp-pfvf-vm5w was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS in dev/build returnURL Parameter Moderate
GHSA-hq4p-5mpr-jj9m was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe External redirection risk in Security?ReturnURL Moderate
GHSA-vp8p-c6xj-xpj7 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS in Director::force_redirect() Moderate
GHSA-jqp8-v74p-g8px was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS In FormAction Moderate
GHSA-4h54-vwx9-3vr3 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS In rewritten hash links Moderate
GHSA-34q6-xqxh-gq39 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS In GridField print Moderate
GHSA-88jp-9jrv-6368 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS in TreeDropdownField and TreeMultiSelectField Moderate
GHSA-r32j-mr8p-hfp8 was published for silverstripe/framework (Composer) May 23, 2024
SilverStripe framework XML Quadratic Blowup Attack Moderate
GHSA-g43w-98wp-m694 was published for silverstripe/framework (Composer) May 23, 2024
ProTip! Advisories are also available from the GraphQL API