Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,883 advisories

Loading
Kirby vulnerable to Cross-site scripting (XSS) in the link field "Custom" type Moderate
CVE-2024-27087 was published for getkirby/cms (Composer) Feb 26, 2024
PlyNatwara
Credited to PlyNatwara
Kirby vulnerable to self cross-site scripting (self-XSS) in the URL field Moderate
CVE-2024-26481 was published for getkirby/cms (Composer) Feb 26, 2024
PlyNatwara
Credited to PlyNatwara
Prevent user enumeration using Guard or the new Authenticator-based Security Moderate
CVE-2021-21424 was published for lexik/jwt-authentication-bundle (Composer) May 13, 2021
jamesisaac mbrodala
chalasr
Credited to jamesisaac, mbrodala, and chalasr
XSS injection in the Grid component of Sylius Moderate
CVE-2019-12186 was published for sylius/grid (Composer) Apr 15, 2020
Enhavo Cross-site Scripting vulnerability Moderate
CVE-2024-25874 was published for enhavo/enhavo-app (Composer) Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management Moderate
CVE-2024-26128 was published for baserproject/basercms (Composer) Feb 22, 2024
baserCMS OS command injection vulnerability in Installer Moderate
CVE-2023-51450 was published for baserproject/basercms (Composer) Feb 22, 2024
Path Traversal in TYPO3 Core Moderate
GHSA-gj48-w74w-8gvm was published for typo3/cms (Composer) Feb 22, 2024
Path disclosure in JavaScript variable Moderate
CVE-2024-26129 was published for prestashop/prestashop (Composer) Feb 21, 2024
hugo-fasone matks
Credited to hugo-fasone and matks
Path Traversal in TYPO3 File Abstraction Layer Storages Moderate
CVE-2023-30451 was published for typo3/cms-core (Composer) Feb 13, 2024
ohader bnf
Credited to ohader and bnf
Joomla! Open Redirect vulnerability Moderate
CVE-2008-4104 was published for joomla/framework (Composer) May 2, 2022
Moodle vulnerable to symlink attack Moderate
CVE-2008-5153 was published for moodle/moodle (Composer) May 17, 2022
phpMyAdmin Cross-site Scripting In MySQL Table Name Moderate
CVE-2009-3696 was published for phpmyadmin/phpmyadmin (Composer) May 2, 2022
Cross-site scripting (XSS) vulnerability in Grav Moderate
CVE-2023-31506 was published for getgrav/grav (Composer) Feb 9, 2024
Symfony Cross-site Scripting (XSS) vulnerability Moderate
CVE-2019-10909 was published for drupal/core (Composer) Nov 12, 2019
TYPO3 vulnerable to Improper Access Control of Resources Referenced by t3:// URI Scheme Moderate
CVE-2024-25120 was published for typo3/cms-core (Composer) Feb 13, 2024
sushiwushi bnf
Credited to sushiwushi and bnf
TYPO3 Install Tool vulnerable to Information Disclosure of Encryption Key Moderate
CVE-2024-25119 was published for typo3/cms-core (Composer) Feb 13, 2024
bnf
Credited to bnf
TYPO3 Backend Forms vulnerable to Information Disclosure of Hashed Passwords Moderate
CVE-2024-25118 was published for typo3/cms-core (Composer) Feb 13, 2024
lolli42 ohader
Credited to lolli42 and ohader
Duplicate Advisory: TYPO3 Arbitrary File Read via Directory Traversal Moderate
GHSA-3gjc-mp82-fj4q was published for typo3/cms-core (Composer) Dec 25, 2023 withdrawn
yuan1994 tpAdmin vulnerable to Server-Side Request Forgery Moderate
CVE-2023-1971 was published for yuan1994/tpadmin (Composer) Apr 10, 2023
Drupal core Denial of Service vulnerability Moderate
GHSA-6ccv-8fgf-cjpw was published for drupal/core (Composer) Feb 12, 2024
Moodle Improper Access Control vulnerability Moderate
CVE-2024-1439 was published for moodle/moodle (Composer) Feb 12, 2024
Moodle does not properly validate module instance id Moderate
CVE-2006-4936 was published for moodle/moodle (Composer) May 1, 2022
Bypass of sitemp access restrictions Moderate
CVE-2019-8133 was published for magento/community-edition (Composer) Nov 12, 2019
Magento Cross-site Scripting (XSS) Moderate
CVE-2019-8153 was published for magento/community-edition (Composer) May 24, 2022
ProTip! Advisories are also available from the GraphQL API