GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,274
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,419
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
210 advisories
Filter by severity
Winter CMS Local File Inclusion through Server Side Template Injection
Low
CVE-2023-52085
was published
for
winter/wn-backend-module
(Composer)
Jan 2, 2024
Winter CMS Stored XSS through Backend ColorPicker FormWidget
Low
CVE-2023-52084
was published
for
winter/wn-backend-module
(Composer)
Dec 28, 2023
Winter CMS Stored XSS through privileged upload of Media Manager file followed by renaming
Low
CVE-2023-52083
was published
for
winter/wn-system-module
(Composer)
Dec 28, 2023
Authenticated Blind SSRF in automad/automad
Low
CVE-2023-7037
was published
for
automad/automad
(Composer)
Dec 21, 2023
Withdrawn Advisory: Stored Cross-site scripting affecting automad/automad
Low
CVE-2023-7035
was published
for
automad/automad
(Composer)
Dec 21, 2023
•
withdrawn
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
Low
CVE-2023-50708
was published
for
yiisoft/yii2-authclient
(Composer)
Dec 18, 2023
Microweber missing standardized error handling mechanism
Low
CVE-2023-6599
was published
for
microweber/microweber
(Composer)
Dec 8, 2023
Concrete CMS Cross-site Scripting vulnerability
Low
CVE-2023-48649
was published
for
concrete5/concrete5
(Composer)
Nov 17, 2023
Information Disclosure in typo3/cms-install tool
Low
CVE-2023-47126
was published
for
typo3/cms-install
(Composer)
Nov 14, 2023
Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Low
CVE-2023-5551
was published
for
moodle/moodle
(Composer)
Nov 9, 2023
Magnesium-PHP Injection vulnerability
Low
CVE-2017-20187
was published
for
floriangaerber/magnesium
(Composer)
Nov 5, 2023
Ibexa ezplatform-kernel download route allows filename change
Low
GHSA-gv2c-5g79-h73c
was published
for
ezsystems/ezplatform-kernel
(Composer)
Nov 3, 2023
Ibexa DXP Download route allows filename change
Low
GHSA-g95c-xc83-8353
was published
for
ibexa/core
(Composer)
Nov 3, 2023
Download route allows filename change in eZpublish kernel
Low
GHSA-946c-f9w6-2c25
was published
for
ezsystems/ezpublish-kernel
(Composer)
Nov 3, 2023
Economizzer Insecure Direct Object Reference vulnerability
Low
CVE-2023-38872
was published
for
gugoan/economizzer
(Composer)
Sep 28, 2023
Froxlor vulnerable to business logic errors
Low
CVE-2023-4304
was published
for
froxlor/froxlor
(Composer)
Aug 11, 2023
Silverstripe Framework: Members with no password can be created and bypass custom login forms
Low
CVE-2023-32302
was published
for
silverstripe/framework
(Composer)
Jul 31, 2023
Information Disclosure due to Out-of-scope Site Resolution
Low
CVE-2023-38499
was published
for
typo3/cms-core
(Composer)
Jul 25, 2023
Winter CMS stored XSS through privileged upload of SVG file
Low
CVE-2023-37269
was published
for
wintercms/winter
(Composer)
Jul 7, 2023
Admidio Improper Access Control vulnerability
Low
CVE-2023-3303
was published
for
admidio/admidio
(Composer)
Jun 23, 2023
CraftCMS stored XSS in Quick Post widget error message
Low
CVE-2023-33194
was published
for
craftcms/cms
(Composer)
May 26, 2023
Stored cross site scripting in RSS displayer
Low
CVE-2023-28820
was published
for
concrete5/concrete5
(Composer)
Apr 28, 2023
Concrete CMS (previously concrete5) is vulnerable to stored XSS in uploaded file and folder names
Low
CVE-2023-28819
was published
for
concrete5/concrete5
(Composer)
Apr 28, 2023
AzuraCast/AzuraCast vulnerable to cross-site scripting
Low
CVE-2023-2191
was published
for
azuracast/azuracast
(Composer)
Apr 20, 2023
Timing attack in eZ Platform Ibexa
Low
CVE-2022-48366
was published
for
ezsystems/ezplatform-kernel
(Composer)
Mar 12, 2023
ProTip!
Advisories are also available from the
GraphQL API