Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,879 advisories

Loading
laracom Cross-site Scripting Moderate
CVE-2019-15489 was published for jsdecena/laracom (Composer) May 24, 2022
OpenCart Cross-site Scripting Moderate
CVE-2020-13980 was published for opencart/opencart (Composer) May 24, 2022
Cross-site Scripting in phpmyadmin Moderate
CVE-2022-23808 was published for phpmyadmin/phpmyadmin (Composer) Jan 28, 2022
Unrestricted Upload of File with Dangerous Type in unisharp/laravel-filemanager Moderate
CVE-2021-23814 was published for unisharp/laravel-filemanager (Composer) Jan 6, 2022
streamtw
Credited to streamtw
Improper Authentication in phpmyadmin Moderate
CVE-2022-23807 was published for phpmyadmin/phpmyadmin (Composer) Jan 28, 2022
PHP file inclusion via insert tags Moderate
CVE-2021-37626 was published for contao/contao (Composer) Aug 23, 2021
ausi
Credited to ausi
Contao Insert tag injection in forms Moderate
CVE-2020-25768 was published for contao/contao (Composer) Sep 24, 2020
Information disclosure in the Contao backend Moderate
CVE-2019-19712 was published for contao/contao (Composer) Dec 17, 2019
Insert tag injection in the Contao login module Moderate
CVE-2019-19714 was published for contao/contao (Composer) Dec 17, 2019
Moodle may display roles to users who don't have access to them Moderate
CVE-2023-1402 was published for moodle/moodle (Composer) Mar 23, 2023
Moodle vulnerable to SQL Injection Moderate
CVE-2023-35132 was published for moodle/moodle (Composer) Jun 22, 2023
Moodle vulnerable to Cross-site Scripting Moderate
CVE-2023-35131 was published for moodle/moodle (Composer) Jun 22, 2023
Moodle External Control of File Name or Path vulnerability Moderate
CVE-2023-30943 was published for moodle/moodle (Composer) May 2, 2023
Moodle arbitrary file read vulnerability Moderate
CVE-2023-28330 was published for moodle/moodle (Composer) Mar 23, 2023
Moodle vulnerable to Cross-site Scripting Moderate
CVE-2023-28331 was published for moodle/moodle (Composer) Mar 23, 2023
Moodle vulnerable to Cross-site Scripting when algebra filter enabled but not functional Moderate
CVE-2023-28332 was published for moodle/moodle (Composer) Mar 23, 2023
Moodle may allow teachers to access the names of users they could not otherwise access Moderate
CVE-2023-28336 was published for moodle/moodle (Composer) Mar 23, 2023
Reportico affected by Incorrect Access Control Moderate
CVE-2023-48865 was published for reportico-web/reportico (Composer) Apr 12, 2024
Contao: Remember-me tokens will not be cleared after a password change Moderate
CVE-2024-30262 was published for contao/core-bundle (Composer) Apr 9, 2024
bytehead
Credited to bytehead
Contao: Insufficient BBCode sanitizer Moderate
CVE-2024-28234 was published for contao/comments-bundle (Composer) Apr 9, 2024
m-vo
Credited to m-vo
Contao: Cross site scripting in the file manager Moderate
CVE-2024-28190 was published for contao/core-bundle (Composer) Apr 9, 2024
Shopware Improper Session Handling in store-api account logout Moderate
CVE-2024-31447 was published for shopware/core (Composer) Apr 8, 2024
mdanilowicz
Credited to mdanilowicz
phpMyFAQ stored Cross-site Scripting at user email Moderate
CVE-2024-27300 was published for phpmyfaq/phpmyfaq (Composer) Mar 25, 2024
kevinnivekkevin
Credited to kevinnivekkevin
OpenID Connect Authentication (oidc) Typo3 extension Authentication Bypass Moderate
CVE-2024-30173 was published for causal/oidc (Composer) Apr 2, 2024
MediaWiki makeCollapsible allows applying event handler to any CSS selector Moderate
CVE-2020-10960 was published for mediawiki/core (Composer) May 24, 2022
anonymous4ACL24
Credited to anonymous4ACL24
ProTip! Advisories are also available from the GraphQL API