Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,731 advisories

Loading
Cross-site scripting (XSS) from unsanitized uploaded SVG files in Kirby High
CVE-2021-29460 was published for getkirby/cms (Composer) Apr 30, 2021
sreenathr10
Credited to sreenathr10
Cross-Site Scripting in Bootstrap Package Moderate
CVE-2021-21365 was published for bk2k/bootstrap-package (Composer) Apr 29, 2021
ohader
Credited to ohader
Potential XSS injection in the newsletter conditions field Moderate
CVE-2021-21418 was published for prestashop/ps_emailsubscription (Composer) Apr 6, 2021
Cross site-scripting (XSS) moodle Moderate
CVE-2020-25628 was published for moodle/moodle (Composer) Mar 29, 2021
Cross-site Scripting (XSS) in moodle Moderate
CVE-2020-25702 was published for moodle/moodle (Composer) Mar 29, 2021
Cross-site scripting (XSS) and Server side request forgery (SSRF) in moodle Moderate
CVE-2021-20280 was published for moodle/moodle (Composer) Mar 29, 2021
Stored cross-site scripting in PressBooks Moderate
CVE-2021-3271 was published for pressbooks/pressbooks (Composer) Mar 29, 2021
XSS in CreateQueuedJobTask Moderate
CVE-2021-27938 was published for symbiote/silverstripe-queuedjobs (Composer) Mar 24, 2021
Cross-Site Scripting in Content Preview (CType menu) Moderate
CVE-2021-21370 was published for typo3/cms (Composer) Mar 23, 2021
o-ba
Credited to o-ba
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in typo3/cms-form Moderate
CVE-2021-21358 was published for typo3/cms (Composer) Mar 23, 2021
andreaskienast sushiwushi
Credited to andreaskienast and sushiwushi
Cross-Site Scripting in Content Preview Moderate
CVE-2021-21340 was published for typo3/cms (Composer) Mar 23, 2021
sushiwushi andreaskienast
Credited to sushiwushi and andreaskienast
Cross-site scripting in eZ Platform Kernel High
GHSA-mrvj-7q4f-5p42 was published for ezsystems/ezplatform-kernel (Composer) Mar 19, 2021
Cross-site scripting (XSS) Moderate
CVE-2020-17551 was published for impresscms/impresscms (Composer) Mar 12, 2021
Cross-site scripting (XSS) Moderate
CVE-2021-28088 was published for impresscms/impresscms (Composer) Mar 12, 2021
XSS in Adminer Moderate
GHSA-m56g-3g8v-2rxw was published for vrana/adminer (Composer) Feb 11, 2021 withdrawn
emilwareus
Credited to emilwareus
vrana/adminer via XSS in the history parameter in SQL command Moderate
CVE-2020-35572 was published for vrana/adminer (Composer) Feb 11, 2021
XSS in Mautic High
CVE-2021-3142 was published for mautic/core (Composer) Jan 29, 2021
dennisameling
Credited to dennisameling
XSS in Flarum Sticky extension Moderate
CVE-2021-21283 was published for flarum/sticky (Composer) Jan 29, 2021
XSS vulnerability in company name field in Mautic Moderate
CVE-2018-11200 was published for mautic/core (Composer) Jan 19, 2021
joanbono alanhartless
Credited to joanbono and alanhartless
Inline JS XSS vulnerability in Mautic Moderate
CVE-2017-1000488 was published for mautic/core (Composer) Jan 19, 2021
alanhartless
Credited to alanhartless
XSS vulnerability in theme config file in Mautic Moderate
CVE-2018-8071 was published for mautic/core (Composer) Jan 19, 2021
XSS vulnerability in Author URL of themes in Mautic Moderate
CVE-2018-11198 was published for mautic/core (Composer) Jan 19, 2021
joanbono
Credited to joanbono
XSS vulnerability leveraged through referrers could allow un-authorized admin access in Mautic Critical
CVE-2020-35124 was published for mautic/core (Composer) Jan 19, 2021
nvn1729
Credited to nvn1729
Cross-site scripting vulnerability in TinyMCE Moderate
CVE-2024-21911 was published for TinyMCE (Composer) Jan 6, 2021
emilwareus
Credited to emilwareus
Cross-Site Scripting in Fluid view helpers Moderate
CVE-2020-26227 was published for typo3/cms (Composer) Dec 21, 2020
ohader
Credited to ohader
ProTip! Advisories are also available from the GraphQL API