Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,344 advisories

Loading
Potential XSS injection in the newsletter conditions field Moderate
CVE-2021-21418 was published for prestashop/ps_emailsubscription (Composer) Apr 6, 2021
Exposure of .env if project root is configured as web root in shopware/production Moderate
GHSA-3pcr-4982-548m was published for shopware/production (Composer) Apr 13, 2021
Cross-Site Scripting in Bootstrap Package Moderate
CVE-2021-21365 was published for bk2k/bootstrap-package (Composer) Apr 29, 2021
ohader
Bypass of fix for CVE-2020-26231, Twig sandbox escape Moderate
CVE-2021-21264 was published for october/cms (Composer) May 4, 2021
OS Command injection in Bolt Moderate
CVE-2020-28925 was published for bolt/bolt (Composer) May 6, 2021
Cross-site scripting in phpoffice/phpspreadsheet Moderate
CVE-2020-7776 was published for phpoffice/phpspreadsheet (Composer) May 6, 2021
"Cross-site scripting in ThinkAdmin" Moderate
CVE-2020-29315 was published for zoujingli/thinkadmin (Composer) May 6, 2021
Cross-site Scripting in OpenCart Moderate
CVE-2020-10596 was published for opencart/opencart (Composer) May 6, 2021
Cross-Site Request Forgery in MAGMI Moderate
CVE-2020-5776 was published for dweeves/magmi (Composer) May 6, 2021
Reflected cross-site scripting in francoisjacquet/rosariosis Moderate
CVE-2020-13278 was published for francoisjacquet/rosariosis (Composer) May 6, 2021
Prevent user enumeration using Guard or the new Authenticator-based Security Moderate
CVE-2021-21424 was published for lexik/jwt-authentication-bundle (Composer) May 13, 2021
jamesisaac mbrodala
chalasr
Authenticated Stored XSS in Administration Moderate
GHSA-f6p7-8xfw-fjqq was published for shopware/shopware (Composer) May 21, 2021
Information leakage in Error Handler Moderate
GHSA-9vxv-wpv4-f52p was published for shopware/shopware (Composer) May 21, 2021
Server-Side Request Forgery in yoast_seo Moderate
CVE-2021-31779 was published for yoast-seo-for-typo3/yoast_seo (Composer) May 21, 2021
Denial of service in direct_mail Moderate
CVE-2020-12697 was published for directmailteam/direct-mail (Composer) May 24, 2021
Open redirect in direct_mail Moderate
CVE-2020-12699 was published for directmailteam/direct-mail (Composer) May 24, 2021
Cross-site Scripting (XSS) in baserCMS Moderate
CVE-2021-20681 was published for baserproject/basercms (Composer) Jun 8, 2021
Cross-site Scripting (XSS) in baserCMS Moderate
CVE-2021-20683 was published for baserproject/basercms (Composer) Jun 8, 2021
reflected XSS in tribalsystems/zenario Moderate
CVE-2021-27673 was published for tribalsystems/zenario (Composer) Jun 8, 2021
Cross-site scripting in media2click Moderate
CVE-2021-31778 was published for amazing/media2click (Composer) Jun 8, 2021
SQL Injection in tribalsystems/zenario Moderate
CVE-2021-27672 was published for tribalsystems/zenario (Composer) Jun 8, 2021
Predictable CSRF tokens in centreon/centreon Moderate
CVE-2021-28055 was published for centreon/centreon (Composer) Jun 8, 2021
Cross-site scripting in Centreon Moderate
CVE-2021-27676 was published for centreon/centreon (Composer) Jun 8, 2021
Authentication bypass in SilverStripe GraphQL Moderate
CVE-2020-26136 was published for silverstripe/graphql (Composer) Jun 10, 2021
G-Rath
Authentication granted to all firewalls instead of just one Moderate
CVE-2021-32693 was published for symfony/security-http (Composer) Jun 21, 2021
gndk mynameisbogdan
pwarchol Warxcell wouterj adrienlamotte
ProTip! Advisories are also available from the GraphQL API