Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,883 advisories

Loading
Cross-Site Scripting in Query Generator & Query View Moderate
CVE-2021-32668 was published for typo3/cms (Composer) Jul 22, 2021
sushiwushi
Credited to sushiwushi
Cross-Site Scripting in Page Preview Moderate
CVE-2021-32667 was published for typo3/cms (Composer) Jul 22, 2021
o-ba
Credited to o-ba
Information Disclosure in User Authentication Moderate
CVE-2021-32767 was published for typo3/cms (Composer) Jul 26, 2021
tdunlap607
Credited to tdunlap607
CSV Injection in symfony/serializer Moderate
CVE-2021-41270 was published for symfony/serializer (Composer) Nov 24, 2021
jakeBarwell jderusse
Credited to jakeBarwell and jderusse
Cookie persistence after password changes in symfony/security-bundle Moderate
CVE-2021-41268 was published for symfony/security-bundle (Composer) Nov 24, 2021
thibaut-decherit wouterj
Credited to thibaut-decherit and wouterj
Webcache Poisoning in symfony/http-kernel Moderate
CVE-2021-41267 was published for symfony/http-kernel (Composer) Nov 24, 2021
jderusse shyim
Credited to jderusse and shyim
Authentication granted to all firewalls instead of just one Moderate
CVE-2021-32693 was published for symfony/security-http (Composer) Jun 21, 2021
gndk mynameisbogdan
pwarchol Warxcell wouterj adrienlamotte
Credited to gndk, mynameisbogdan, pwarchol, Warxcell, wouterj, and adrienlamotte
Cross-Site Scripting in TYPO3 CMS Link Handling Moderate
CVE-2020-11065 was published for typo3/cms (Composer) May 13, 2020
josefglatz ohader
Credited to josefglatz and ohader
Cross-Site Scripting in TYPO3 CMS Form Engine Moderate
CVE-2020-11064 was published for typo3/cms (Composer) May 13, 2020
liayn Weissheiten
Credited to liayn and Weissheiten
Lack of access control on upoaded files Moderate
CVE-2019-12245 was published for silverstripe/assets (Composer) Nov 12, 2019
Mautic vulnerable to secret data exfiltration via symfony parameters Moderate
CVE-2021-27908 was published for mautic/core (Composer) Apr 6, 2021
Gregy fedys
Credited to Gregy and fedys
Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS) Moderate
CVE-2018-9861 was published for ckeditor-dev (Composer) May 14, 2022
Laravel Framework XSS in Blade templating engine Moderate
CVE-2021-43808 was published for illuminate/view (Composer) Dec 8, 2021
chinpei215
Credited to chinpei215
Improper Input Validation in guzzlehttp/psr7 Moderate
CVE-2022-24775 was published for guzzlehttp/psr7 (Composer) Mar 25, 2022
TimWolla GrahamCampbell
Credited to TimWolla and GrahamCampbell
Laravel Sensitive Data Exposure Moderate
CVE-2017-14775 was published for illuminate/auth (Composer) May 17, 2022
G-Rath
Credited to G-Rath
Cross-site Scripting in enshrined/svg-sanitize Moderate
CVE-2022-23638 was published for enshrined/svg-sanitize (Composer) Feb 14, 2022
zcorpan ohader
Credited to zcorpan and ohader
Cross site scripting via HTML attributes in the back end Moderate
CVE-2021-35955 was published for contao/contao (Composer) Aug 25, 2021
m-vo
Credited to m-vo
ADOdb Cross-site scripting vulnerability in old test script Moderate
CVE-2016-4855 was published for adodb/adodb-php (Composer) May 17, 2022
Moodle Improper Access Control Moderate
CVE-2016-3733 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Credited to MarkLee131
PHPMailer Local file inclusion Moderate
CVE-2006-5734 was published for phpmailer/phpmailer (Composer) Feb 2, 2024
Magento 2 Community Edition Information Disclosure Moderate
CVE-2019-7929 was published for magento/community-edition (Composer) May 24, 2022
Magento 2 Community Edition XSS Vulnerability Moderate
CVE-2019-7927 was published for magento/community-edition (Composer) May 24, 2022
Magento 2 Community Edition XSS Vulnerability Moderate
CVE-2019-7926 was published for magento/community-edition (Composer) May 24, 2022
Magento 2 Community Edition XSS Vulnerability Moderate
CVE-2019-8147 was published for magento/community-edition (Composer) May 24, 2022
Magento Cross-Site Scripting via Attribute Set Name Moderate
CVE-2019-8145 was published for magento/community-edition (Composer) Nov 12, 2019
ProTip! Advisories are also available from the GraphQL API