Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,682 advisories

Loading
Cross site-scripting (XSS) moodle Moderate
CVE-2020-25628 was published for moodle/moodle (Composer) Mar 29, 2021
Moodle allowed some users without permission to view other users' full names Moderate
CVE-2021-20281 was published for moodle/moodle (Composer) Mar 29, 2021
Mautic vulnerable to secret data exfiltration via symfony parameters Moderate
CVE-2021-27908 was published for mautic/core (Composer) Apr 6, 2021
Gregy fedys
Potential XSS injection in the newsletter conditions field Moderate
CVE-2021-21418 was published for prestashop/ps_emailsubscription (Composer) Apr 6, 2021
Exposure of .env if project root is configured as web root in shopware/production Moderate
GHSA-3pcr-4982-548m was published for shopware/production (Composer) Apr 13, 2021
Cross-Site Scripting in Bootstrap Package Moderate
CVE-2021-21365 was published for bk2k/bootstrap-package (Composer) Apr 29, 2021
ohader
Bypass of fix for CVE-2020-26231, Twig sandbox escape Moderate
CVE-2021-21264 was published for october/cms (Composer) May 4, 2021
OS Command injection in Bolt Moderate
CVE-2020-28925 was published for bolt/bolt (Composer) May 6, 2021
Cross-site scripting in phpoffice/phpspreadsheet Moderate
CVE-2020-7776 was published for phpoffice/phpexcel (Composer) May 6, 2021
Cross-site scripting in ThinkAdmin Moderate
CVE-2020-29315 was published for zoujingli/thinkadmin (Composer) May 6, 2021
AnonyICSE26
Cross-site Scripting in OpenCart Moderate
CVE-2020-10596 was published for opencart/opencart (Composer) May 6, 2021
Cross-Site Request Forgery in MAGMI Moderate
CVE-2020-5776 was published for dweeves/magmi (Composer) May 6, 2021
Reflected cross-site scripting in francoisjacquet/rosariosis Moderate
CVE-2020-13278 was published for francoisjacquet/rosariosis (Composer) May 6, 2021
Prevent user enumeration using Guard or the new Authenticator-based Security Moderate
CVE-2021-21424 was published for lexik/jwt-authentication-bundle (Composer) May 13, 2021
jamesisaac mbrodala
chalasr
Authenticated Stored XSS in Administration Moderate
GHSA-f6p7-8xfw-fjqq was published for shopware/shopware (Composer) May 21, 2021
Information leakage in Error Handler Moderate
GHSA-9vxv-wpv4-f52p was published for shopware/shopware (Composer) May 21, 2021
Server-Side Request Forgery in yoast_seo Moderate
CVE-2021-31779 was published for yoast-seo-for-typo3/yoast_seo (Composer) May 21, 2021
Denial of service in direct_mail Moderate
CVE-2020-12697 was published for directmailteam/direct-mail (Composer) May 24, 2021
Open redirect in direct_mail Moderate
CVE-2020-12699 was published for directmailteam/direct-mail (Composer) May 24, 2021
Cross-site Scripting (XSS) in baserCMS Moderate
CVE-2021-20681 was published for baserproject/basercms (Composer) Jun 8, 2021
Cross-site Scripting (XSS) in baserCMS Moderate
CVE-2021-20683 was published for baserproject/basercms (Composer) Jun 8, 2021
reflected XSS in tribalsystems/zenario Moderate
CVE-2021-27673 was published for tribalsystems/zenario (Composer) Jun 8, 2021
Cross-site scripting in media2click Moderate
CVE-2021-31778 was published for amazing/media2click (Composer) Jun 8, 2021
SQL Injection in tribalsystems/zenario Moderate
CVE-2021-27672 was published for tribalsystems/zenario (Composer) Jun 8, 2021
Predictable CSRF tokens in centreon/centreon Moderate
CVE-2021-28055 was published for centreon/centreon (Composer) Jun 8, 2021
ProTip! Advisories are also available from the GraphQL API