GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,781 advisories
Filter by severity
Cross-Site Request Forgery (CSRF) in livehelperchat
Moderate
CVE-2022-0226
was published
for
remdex/livehelperchat
(Composer)
Jan 26, 2022
Cross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat
Moderate
CVE-2022-0245
was published
for
livehelperchat/livehelperchat
(Composer)
Jan 21, 2022
livehelperchat is vulnerable to Cross-site Scripting
Moderate
CVE-2022-0253
was published
for
remdex/livehelperchat
(Composer)
Jan 21, 2022
Missing Authorization in DayByDay CRM
Moderate
CVE-2022-22107
was published
for
bottelet/flarepoint
(Composer)
Jan 8, 2022
Missing Authorization in DayByDay CRM
Moderate
CVE-2022-22108
was published
for
bottelet/flarepoint
(Composer)
Jan 8, 2022
Cross-site Scripting in DayByDay CRM
Moderate
CVE-2022-22109
was published
for
bottelet/flarepoint
(Composer)
Jan 8, 2022
showdoc is vulnerable to Generation of Error Message Containing Sensitive Information
Moderate
CVE-2022-0079
was published
for
showdoc/showdoc
(Composer)
Jan 6, 2022
Client-Side JavaScript Prototype Pollution in oro/platform
Moderate
CVE-2021-43852
was published
for
oro/platform
(Composer)
Jan 6, 2022
XSS vulnerability on email template preview page
Moderate
CVE-2021-41236
was published
for
oro/platform
(Composer)
Jan 6, 2022
Cross-Site Request Forgery in Moodle
Moderate
CVE-2020-1692
was published
for
moodle/moodle
(Composer)
Jan 6, 2022
User enumeration in livehelperchat
Moderate
CVE-2022-0083
was published
for
remdex/livehelperchat
(Composer)
Jan 21, 2022
Open redirect in shopware
Moderate
CVE-2022-21651
was published
for
shopware/shopware
(Composer)
Jan 6, 2022
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-4168
was published
for
showdoc/showdoc
(Composer)
Jan 6, 2022
invoiceninja is vulnerable to Cross-site Scripting
Moderate
CVE-2021-3977
was published
for
hillelcoren/invoice-ninja
(Composer)
Jan 6, 2022
elgg is vulnerable to Cross-site Scripting
Moderate
CVE-2021-4072
was published
for
elgg/elgg
(Composer)
Jan 6, 2022
Cross-site Scripting in pimcore
Moderate
CVE-2021-4139
was published
for
pimcore/pimcore
(Composer)
Jan 5, 2022
Wechat-php-sdk is affected by a Cross Site Scripting vulnerability.
Moderate
CVE-2021-43678
was published
for
gaoming13/wechat-php-sdk
(Composer)
Jan 7, 2022
livehelperchat is vulnerable to Cross-site Scripting
Moderate
CVE-2021-4132
was published
for
remdex/livehelperchat
(Composer)
Jan 5, 2022
Froxlor Improper Authorization vulnerability
Moderate
CVE-2022-4868
was published
for
froxlor/froxlor
(Composer)
Dec 31, 2022
Froxlor vulnerable to Cross-Site Request Forgery
Moderate
CVE-2022-4867
was published
for
froxlor/froxlor
(Composer)
Dec 31, 2022
Smarty Cross-site Scripting vulnerability in pages that use smarty_function_mailto
Moderate
CVE-2018-25047
was published
for
smarty/smarty
(Composer)
Sep 16, 2022
Cross-site Scripting in Bootstrap-3-Typeahead
Moderate
CVE-2019-10215
was published
for
bassjobsen/bootstrap-3-typeahead
(Composer)
May 24, 2022
wallabag subject to Improper Authorization via annotations
Moderate
CVE-2023-0610
was published
for
wallabag/wallabag
(Composer)
Feb 2, 2023
Stored XSS using uppercase characters in HTMLEditor
Moderate
CVE-2022-37430
was published
for
silverstripe/framework
(Composer)
Nov 21, 2022
Stored XSS in Compare Mode
Moderate
CVE-2022-38145
was published
for
silverstripe/versioned-admin
(Composer)
Nov 22, 2022
ProTip!
Advisories are also available from the
GraphQL API