GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,746
Erlang
35
GitHub Actions
29
Go
2,319
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
920
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,707 advisories
Filter by severity
XSS vulnerability in translations
Moderate
GHSA-rrgw-3hg3-9x8c
was published
for
oro/platform
(Composer)
Jan 12, 2022
TYPO3 HTML Sanitizer Bypasses Cross-Site Scripting Protection
Moderate
GHSA-gqqf-g5r7-84vf
was published
for
typo3/cms-core
(Composer)
Sep 15, 2022
XSS in richtext custom tag attributes in ezsystems/ezplatform-richtext
Moderate
GHSA-9jp8-cwwx-p64q
was published
for
ezsystems/ezplatform-admin-ui
(Composer)
Dec 1, 2021
non-admin users can create integration role with administrator role
Moderate
GHSA-243q-g9j3-qf6r
was published
for
shopware/core
(Composer)
Jun 28, 2021
CKEditor 4 vulnerabilities in versions <4.16.1
Moderate
GHSA-cfcv-q4qq-2ph4
was published
for
pimcore/pimcore
(Composer)
Aug 23, 2021
Authenticated Stored XSS in Administration
Moderate
GHSA-f6p7-8xfw-fjqq
was published
for
shopware/shopware
(Composer)
May 21, 2021
Internal hidden fields are visible on to many associations in admin api
Moderate
GHSA-gpmh-g94g-qrhr
was published
for
shopware/core
(Composer)
Jun 28, 2021
Canceling of orders not related to the logged-in user
Moderate
GHSA-wq3r-jwrq-xg6w
was published
for
shopware/core
(Composer)
Jun 28, 2021
Information leakage in Error Handler
Moderate
GHSA-9vxv-wpv4-f52p
was published
for
shopware/shopware
(Composer)
May 21, 2021
CSV Injection vulnerability with exported contact lists in Mautic
Moderate
CVE-2018-8092
was published
for
mautic/core
(Composer)
Jan 19, 2021
Authenticated XML External Entity Processing
Moderate
GHSA-8xv9-qcr9-ww9j
was published
for
shopware/core
(Composer)
Oct 19, 2020
Path Traversal within joomla/archive zip class
Moderate
CVE-2021-26028
was published
for
joomla/archive
(Composer)
Mar 24, 2021
Users can edit the tags of any discussion
Moderate
GHSA-32wx-4gxx-h48f
was published
for
flarum/tags
(Composer)
Jan 29, 2021
XSS vulnerability in company name field in Mautic
Moderate
CVE-2018-11200
was published
for
mautic/core
(Composer)
Jan 19, 2021
Cross-Site Scripting in Grav
Moderate
GHSA-cvmr-6428-87w9
was published
for
getgrav/grav
(Composer)
Dec 10, 2020
Reflected XSS with parameters in PostComment
Moderate
CVE-2020-26225
was published
for
prestashop/productcomments
(Composer)
Nov 16, 2020
Exposure of .env if project root is configured as web root in shopware/production
Moderate
GHSA-3pcr-4982-548m
was published
for
shopware/production
(Composer)
Apr 13, 2021
Authenticated remote code execution
Moderate
GHSA-pjj4-jjgc-h3r8
was published
for
shopware/platform
(Composer)
Mar 12, 2021
XSS vulnerability when listing users on add & modify server pages.
Moderate
GHSA-5822-pw57-vv37
was published
for
pterodactyl/panel
(Composer)
Oct 8, 2020
Reset Password / Login vulnerability in Sulu
Moderate
CVE-2020-15132
was published
for
sulu/sulu
(Composer)
Aug 5, 2020
Incorrect access control in typo3_forum
Moderate
CVE-2020-15513
was published
for
mittwald/typo3_forum
(Composer)
Jul 29, 2020
Potentially sensitive data exposure in Symfony Web Socket Bundle
Moderate
GHSA-wwgf-3xp7-cxj4
was published
for
gos/web-socket-bundle
(Composer)
Jul 7, 2020
Cross-Site Scripting in SVG Sanitizer
Moderate
CVE-2020-11070
was published
for
t3g/svg-sanitizer
(Composer)
May 13, 2020
Local file disclosure in PHPMailer
Moderate
CVE-2017-5223
was published
for
phpmailer/phpmailer
(Composer)
Mar 5, 2020
Sanitizer bypass in svg-sanitizer
Moderate
CVE-2019-10772
was published
for
enshrined/svg-sanitize
(Composer)
Feb 27, 2020
ProTip!
Advisories are also available from the
GraphQL API