Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

211 advisories

Loading
Timing attack in eZ Platform Ibexa Low
CVE-2022-48366 was published for ezsystems/ezplatform-kernel (Composer) Mar 12, 2023
Shopware user session is not logged out if the password is reset via password recovery Low
CVE-2022-24744 was published for shopware/core (Composer) Mar 10, 2022
tdunlap607
Discoverability of user password hash in Statamic CMS Low
CVE-2022-24784 was published for statamic/cms (Composer) Mar 29, 2022
Codeigniter4's Secure or HttpOnly flag set in Config\Cookie is not reflected in Cookies issued Low
CVE-2022-39284 was published for codeigniter4/framework (Composer) Oct 6, 2022
Magento 2 Community Edition vulnerable to Improper Authorization Low
CVE-2020-24404 was published for magento/community-edition (Composer) May 24, 2022
Byobu user preference to prevent private discussions being started are not respected Low
CVE-2022-35921 was published for fof/byobu (Composer) Aug 6, 2022
phpMyAdmin cross-site scripting vulnerability in crafted view name Low
CVE-2014-5274 was published for phpmyadmin/phpmyadmin (Composer) May 14, 2022
phpMyAdmin cross-site scripting Vulnerability in Table or Column Names Low
CVE-2014-4986 was published for phpmyadmin/phpmyadmin (Composer) May 17, 2022
phpMyAdmin cross-site scripting Vulnerability via ENUM value Low
CVE-2014-7217 was published for phpmyadmin/phpmyadmin (Composer) May 17, 2022
TYPO3 Cross-site scripting (XSS) vulnerability in the Extbase Framework Low
CVE-2013-7078 was published for typo3/cms-core (Composer) May 17, 2022
TYPO3 Cross-Site Scripting (XSS) vulnerabilities in Content Editing Wizards component Low
CVE-2013-7074 was published for typo3/cms (Composer) May 17, 2022
phpMyAdmin Cross-site scripting (XSS) vulnerability via pageNumber value Low
CVE-2013-5002 was published for phpmyadmin/phpmyadmin (Composer) May 17, 2022
phpMyAdmin multiple cross-site scripting vulnerabilities Low
CVE-2012-5339 was published for phpmyadmin/phpmyadmin (Composer) May 17, 2022
phpMyAdmin Multiple Cross-site Scripting Vulnerabilities in the Database Structure page Low
CVE-2012-4345 was published for phpmyadmin/phpmyadmin (Composer) May 17, 2022
phpMyAdmin Multiple XSS Vulnerabilities Low
CVE-2012-4579 was published for phpmyadmin/phpmyadmin (Composer) May 17, 2022
Typo3 Backend XSS Vulnerabilities Low
CVE-2012-1606 was published for typo3/cms (Composer) May 17, 2022
Insufficient user authorization in Moodle Low
CVE-2022-0333 was published for moodle/moodle (Composer) Jan 28, 2022
snipe-it is vulnerable to Cross-site Scripting Low
CVE-2021-3938 was published for snipe/snipe-it (Composer) Nov 15, 2021
pterodactyl/panel CSRF allowing an external page to trigger a user logout event Low
CVE-2021-41176 was published for pterodactyl/panel (Composer) Oct 25, 2021
HDVinnie
Twig Sandbox Information Disclosure Low
CVE-2019-9942 was published for twig/twig (Composer) Mar 26, 2022
phpMyAdmin cookie-attribute injection Low
CVE-2016-5702 was published for phpmyadmin/phpmyadmin (Composer) May 17, 2022
Download route allows filename change in eZpublish kernel Low
GHSA-946c-f9w6-2c25 was published for ezsystems/ezpublish-kernel (Composer) Nov 3, 2023
Ibexa DXP Download route allows filename change Low
GHSA-g95c-xc83-8353 was published for ibexa/core (Composer) Nov 3, 2023
Information Disclosure due to Out-of-scope Site Resolution Low
CVE-2023-38499 was published for typo3/cms-core (Composer) Jul 25, 2023
fe-hicking ohader
bnf
Winter CMS stored XSS through privileged upload of SVG file Low
CVE-2023-37269 was published for wintercms/winter (Composer) Jul 7, 2023
abhishekmorla
ProTip! Advisories are also available from the GraphQL API