Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,885 advisories

Loading
TYPO3 Open Redirection vulnerability on the backend Moderate
CVE-2010-3661 was published for typo3/cms-backend (Composer) Apr 21, 2022
TYPO3 is vulnerable to Cross-Site Scripting (XSS) on the backend Moderate
CVE-2010-3660 was published for typo3/cms-backend (Composer) Apr 21, 2022
TYPO3 vulnerable to Cross-Site Scripting in the textarea view helper Moderate
CVE-2010-3672 was published for typo3/cms-fluid (Composer) Apr 21, 2022
Reflected XSS in SilverStripe Moderate
CVE-2019-19325 was published for silverstripe/framework (Composer) Feb 24, 2020
SilverStripe GraphQL Server permission checker not inherited by query subclass. Moderate
CVE-2021-28661 was published for silverstripe/graphql (Composer) Oct 12, 2021
Symfony Path Disclosure Moderate
CVE-2018-19789 was published for symfony/form (Composer) May 14, 2022
Symfony Access Control Vulnerability Moderate
CVE-2012-6432 was published for symfony/symfony (Composer) May 17, 2022
Symfony Allows URI Restrictions Bypass Via Double-Encoded String Moderate
CVE-2012-6431 was published for symfony/http-foundation (Composer) May 17, 2022
Ability to switch customer email address on account detail page and stay verified Moderate
CVE-2020-15245 was published for sylius/sylius (Composer) Oct 19, 2020
decemvre
Credited to decemvre
Exceptions displayed in non-debug configurations in Symfony Moderate
CVE-2020-5274 was published for symfony/error-handler (Composer) Mar 30, 2020
yceruto jderusse
LukaSikic
Credited to yceruto, jderusse, and LukaSikic
TYPO3 Flow Cross-site scripting (XSS) vulnerability Moderate
CVE-2013-7082 was published for neos/flow (Composer) May 17, 2022
Moderate severity vulnerability that affects league/commonmark Moderate
CVE-2019-10010 was published for league/commonmark (Composer) Sep 17, 2019
PHP League CommonMark vulnerable to Cross-Site Scripting (XSS) Moderate
CVE-2018-20583 was published for league/commonmark (Composer) May 14, 2022
jhutchings1
Credited to jhutchings1
File reference keys leads to incorrect hashes on HMAC algorithms Moderate
CVE-2021-41106 was published for lcobucci/jwt (Composer) Sep 29, 2021
arokettu
Credited to arokettu
Missing Authorization in Drupal Moderate
CVE-2017-6923 was published for drupal/core (Composer) Oct 10, 2019
Cross-site Scripting in Drupal Core Moderate
CVE-2020-13668 was published for drupal/core (Composer) Feb 12, 2022
tdunlap607
Credited to tdunlap607
DOMPDF Information Disclosure Moderate
CVE-2014-5011 was published for dompdf/dompdf (Composer) May 17, 2022
Cross-site Scripting in Contao Moderate
CVE-2018-10125 was published for contao/contao (Composer) Feb 10, 2022
phpMyFAQ vulnerable to stored XSS on attachments filename Moderate
CVE-2024-24574 was published for phpmyfaq/phpmyfaq (Composer) Feb 5, 2024
nikkoenggaliano
Credited to nikkoenggaliano
Craft CMS Audit Plugin Cross Site Scripting vulnerability Moderate
CVE-2023-36259 was published for superbig/craft-audit (Composer) Jan 30, 2024
phpMyFAQ sharing FAQ functionality can easily be abused for phishing purposes Moderate
CVE-2024-22208 was published for phpmyfaq/phpmyfaq (Composer) Feb 5, 2024
PinkDraconian
Credited to PinkDraconian
phpMyFAQ User Removal Page Allows Spoofing Of User Details Moderate
CVE-2024-22202 was published for phpmyfaq/phpmyfaq (Composer) Feb 5, 2024
PinkDraconian
Credited to PinkDraconian
Yii Framework Cross-site Scripting Vulnerability Moderate
CVE-2015-3397 was published for yiisoft/yii2 (Composer) May 17, 2022
Ckeditor XSS Vulnerability Moderate
CVE-2018-17960 was published for ckeditor (Composer) Nov 21, 2018
Typo3 Open Redirect In Frontend Rendering Moderate
CVE-2014-9508 was published for typo3/cms (Composer) May 17, 2022
ProTip! Advisories are also available from the GraphQL API