Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,272 advisories

Loading
SQL Injection in moodle Moderate
CVE-2020-25700 was published for moodle/moodle (Composer) Mar 29, 2021
Cross-site scripting (XSS) and Server side request forgery (SSRF) in moodle Moderate
CVE-2021-20280 was published for moodle/moodle (Composer) Mar 29, 2021
SQL injection in vhs (aka VHS: Fluid ViewHelpers) Critical
CVE-2021-28381 was published for fluidtypo3/vhs (Composer) Mar 29, 2021
Unauthenticated remote code execution in Ignition Critical
CVE-2021-3129 was published for facade/ignition (Composer) Mar 29, 2021
Stored cross-site scripting in PressBooks Moderate
CVE-2021-3271 was published for pressbooks/pressbooks (Composer) Mar 29, 2021
Path Traversal within joomla/archive zip class Moderate
CVE-2021-26028 was published for joomla/archive (Composer) Mar 24, 2021
XSS in CreateQueuedJobTask Moderate
CVE-2021-27938 was published for symbiote/silverstripe-queuedjobs (Composer) Mar 24, 2021
Cross-Site Scripting in Content Preview (CType menu) Moderate
CVE-2021-21370 was published for typo3/cms (Composer) Mar 23, 2021
o-ba
Denial of Service in Page Error Handling Moderate
CVE-2021-21359 was published for typo3/cms (Composer) Mar 23, 2021
derhansen
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in typo3/cms-form Moderate
CVE-2021-21358 was published for typo3/cms (Composer) Mar 23, 2021
andreaskienast sushiwushi
Broken Access Control in Form Framework High
CVE-2021-21357 was published for typo3/cms (Composer) Mar 23, 2021
sushiwushi waldhacker1
Unrestricted File Upload in Form Framework High
CVE-2021-21355 was published for typo3/cms (Composer) Mar 23, 2021
smichaelsen ohader
marclindemann vertexvaar sushiwushi waldhacker1
Cross-Site Scripting in Content Preview Moderate
CVE-2021-21340 was published for typo3/cms (Composer) Mar 23, 2021
sushiwushi andreaskienast
Cleartext storage of session identifier Moderate
CVE-2021-21339 was published for typo3/cms (Composer) Mar 23, 2021
ohader
Open Redirection in Login Handling Moderate
CVE-2021-21338 was published for typo3/cms (Composer) Mar 23, 2021
einpraegsam derhansen
Cross-site scripting in eZ Platform Kernel High
GHSA-mrvj-7q4f-5p42 was published for ezsystems/ezplatform-kernel (Composer) Mar 19, 2021
Authenticated remote code execution Moderate
GHSA-pjj4-jjgc-h3r8 was published for shopware/platform (Composer) Mar 12, 2021
Potential Session Hijacking Low
GHSA-h9q8-5gv2-v6mg was published for shopware/platform (Composer) Mar 12, 2021
Cross-site scripting (XSS) Moderate
CVE-2020-17551 was published for impresscms/impresscms (Composer) Mar 12, 2021
Cross-site scripting (XSS) Moderate
CVE-2021-28088 was published for impresscms/impresscms (Composer) Mar 12, 2021
/user/sessions endpoint allows detecting valid accounts High
GHSA-gmrf-99gw-vvwj was published for ezsystems/ezpublish-kernel (Composer) Mar 11, 2021
/user/sessions endpoint allows detecting valid accounts High
GHSA-7vwg-39h8-8qp8 was published for ezsystems/ezplatform-rest (Composer) Mar 11, 2021
Potential Host Header Poisoning on misconfigured servers Low
CVE-2021-21265 was published for october/backend (Composer) Mar 10, 2021
Sandbox escape through template_object in smarty High
CVE-2021-26119 was published for smarty/smarty (Composer) Mar 2, 2021
stevenseeley
PHP Code Injection by malicious function name in smarty Critical
CVE-2021-26120 was published for smarty/smarty (Composer) Feb 26, 2021
stevenseeley
ProTip! Advisories are also available from the GraphQL API