Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

37,043 advisories

Loading
Multiple cross-site scripting (XSS) vulnerabilities in SmartCMS v.2. Moderate Unreviewed
CVE-2014-9557 was published May 13, 2022
Reflected Cross site scripting (XSS) in kairosdb Moderate
CVE-2019-19040 was published for org.kairosdb:kairosdb (Maven) Nov 3, 2022
Apache Sling App CMS vulnerable to Cross-site Scripting Moderate
CVE-2022-43670 was published for org.apache.sling:org.apache.sling.cms (Maven) Nov 2, 2022
Tribal Systems Zenario CMS vulnerable to Cross-site Scripting Moderate
CVE-2020-36608 was published for tribalsystems/zenario (Composer) Nov 3, 2022
Cross-site Scripting in Joplin Moderate
CVE-2020-9038 was published for joplin (npm) Oct 13, 2020
XSS in HtmlSanitizer Low
CVE-2020-26293 was published for HtmlSanitizer (NuGet) Jan 4, 2021
Reflected Cross-site Scripting in ACS Commons High
CVE-2021-21028 was published for com.adobe.acs:acs-aem-commons (Maven) Feb 2, 2021
Inline JS XSS vulnerability in Mautic Moderate
CVE-2017-1000488 was published for mautic/core (Composer) Jan 19, 2021
alanhartless
Cross-site Scripting in dompurify Moderate
CVE-2020-26870 was published for dompurify (npm) Dec 18, 2020
Cross-site scripting (XSS) in Apache Velocity Tools Moderate
CVE-2020-13959 was published for org.apache.velocity.tools:velocity-tools-parent (Maven) Mar 12, 2021
Cross Site Scripting (XSS) in XWiki Moderate
CVE-2021-3137 was published for org.xwiki.commons:xwiki-commons (Maven) Jan 29, 2021
XSS in Flarum Sticky extension Moderate
CVE-2021-21283 was published for flarum/sticky (Composer) Jan 29, 2021
Cross-site Scripting in vis-timeline Moderate
CVE-2020-28487 was published for vis-timeline (npm) Apr 13, 2021
ProTip! Advisories are also available from the GraphQL API