GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,360
Erlang
33
GitHub Actions
22
Go
2,127
Maven
5,000+
npm
3,793
NuGet
683
pip
3,471
Pub
12
RubyGems
894
Rust
894
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,361 advisories
Filter by severity
phpMyFAQ Stored Cross-site Scripting vulnerability
Moderate
CVE-2023-0309
was published
for
thorsten/phpmyfaq
(Composer)
Jan 16, 2023
phpMyFAQ Improper Authentication vulnerability
Critical
CVE-2023-0311
was published
for
thorsten/phpmyfaq
(Composer)
Jan 16, 2023
phpMyFAQ Stored Cross-site Scripting vulnerability
Moderate
CVE-2023-0310
was published
for
thorsten/phpmyfaq
(Composer)
Jan 16, 2023
CakePHP vulnerable to Cross-site Scripting in some development error pages
Moderate
GHSA-xwhj-pqcg-8rcr
was published
for
cakephp/cakephp
(Composer)
Jan 20, 2023
CakePHP vulnerable to Remote File Inclusion through View template name manipulation
Moderate
GHSA-p76f-wr22-4rv6
was published
for
cakephp/cakephp
(Composer)
Jan 20, 2023
CakePHP allows direct access of prefixed controller actions
Moderate
GHSA-6hg4-vp5q-47mw
was published
for
cakephp/cakephp
(Composer)
Jan 20, 2023
CakePHP vulnerable to Denial of Service attack through XML payloads
High
GHSA-q79m-c546-2g63
was published
for
cakephp/cakephp
(Composer)
Jan 20, 2023
CakePHP SecurityComponent cross form submission issue
Moderate
GHSA-j9q2-f9q7-jhgq
was published
for
cakephp/cakephp
(Composer)
Jan 20, 2023
Shopware has Insufficient Session Expiration in Administration
Low
CVE-2023-22732
was published
for
shopware/core
(Composer)
Jan 20, 2023
Shopware has Improper Input Validation issue in newsletter subscription
Moderate
CVE-2023-22734
was published
for
shopware/core
(Composer)
Jan 20, 2023
CakePHP has incorrect Cross-Site Request Forgery validation
Moderate
GHSA-829q-v5g8-hhxc
was published
for
cakephp/cakephp
(Composer)
Jan 20, 2023
Insufficient output escaping of attachment names in PHPMailer
High
CVE-2020-13625
was published
for
phpmailer/phpmailer
(Composer)
May 27, 2020
PocketMine-MP vulnerable to denial-of-service by sending large modal form responses
Moderate
GHSA-7m9r-rq9j-wmmh
was published
for
pocketmine/pocketmine-mp
(Composer)
Jan 10, 2023
Cross-site scripting from content entered in the tags and multiselect fields
High
GHSA-rv3r-vqjj-8c76
was published
for
getkirby/cms
(Composer)
Aug 30, 2022
phpxmlrpc vulnerable to argument injection
Moderate
GHSA-q7qq-9gx2-ggxv
was published
for
phpxmlrpc/phpxmlrpc
(Composer)
Dec 2, 2022
personnummer/php vulnerable to Improper Input Validation
Low
GHSA-2p6g-gjp8-ggg9
was published
for
personnummer/personnummer
(Composer)
Sep 9, 2020
mezzio-swoole Applications Using Diactoros Vulnerable to HTTP Host Header Attack
High
GHSA-c8rp-cgf4-937w
was published
for
mezzio/mezzio-swoole
(Composer)
Jul 29, 2022
Islandora 2.0 before 2.4.1 could allow any user to upload content into a repository
Critical
GHSA-m58q-qq5h-mgqq
was published
for
islandora/islandora
(Composer)
Jul 21, 2022
OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor
Moderate
GHSA-6f85-3f8q-qc94
was published
for
oro/commerce
(Composer)
Jul 15, 2022
Potential XSS injection In PrestaShop contactform
High
CVE-2020-15178
was published
for
prestashop/contactform
(Composer)
Sep 15, 2020
Bypass of CMS Safe Mode Security Feature
Moderate
GHSA-q37h-jhf3-85cj
was published
for
wintercms/winter
(Composer)
Jul 15, 2022
XML-RPC for PHP allows access to local files via malicious argument to the Client::send method
Moderate
GHSA-m95x-m25c-w9mp
was published
for
phpxmlrpc/phpxmlrpc
(Composer)
Jan 11, 2023
XML-RPC for PHP's `Wrapper::buildClientWrapperCode` method allows code injection via malicious `$client` argument
Moderate
GHSA-7vcx-v65q-9wpg
was published
for
phpxmlrpc/phpxmlrpc
(Composer)
Jan 11, 2023
XML-RPC for PHP's debugger vulnerable to possible XSS attack
Moderate
GHSA-pxqj-xrv5-qvjf
was published
for
phpxmlrpc/phpxmlrpc
(Composer)
Jan 11, 2023
Improperly checked IDs on itemstacks received from the client leading to server crash in PocketMine-MP
High
GHSA-fqx3-r75h-vc89
was published
for
pocketmine/pocketmine-mp
(Composer)
Jun 7, 2022
ProTip!
Advisories are also available from the
GraphQL API