Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,649 advisories

Loading
Moodle reflected XSS via H5P error message Moderate
CVE-2024-43439 was published for moodle/moodle (Composer) Nov 11, 2024
Yii2 Gii Cross-site Scripting vulnerability Moderate
CVE-2022-34297 was published for yiisoft/yii2-gii (Composer) Dec 10, 2022
croogo Host header injection Moderate
CVE-2024-29643 was published for croogo/croogo (Composer) Apr 21, 2025
TYPO3-EXT-SA-2022-018: Multiple vulnerabilities in extension "Master-Quiz" (fp_masterquiz) Moderate
CVE-2022-47407 was published for fixpunkt/fp-masterquiz (Composer) Dec 14, 2022
MarkLee131
Drupal Full Path Disclosure Moderate
CVE-2024-45440 was published for drupal/core (Composer) Aug 29, 2024
cmlara longwave
OctoberCMS Cross-Site Scripting Moderate
CVE-2017-15284 was published for october/rain (Composer) May 13, 2022
Laravel Starter Cross Site Scripting (XSS) Moderate
CVE-2025-26159 was published for nasirkhan/laravel-starter (Composer) Apr 22, 2025
MantisBT vulnerable to CSRF and Open Redirect attacks Moderate
CVE-2017-7620 was published for mantisbt/mantisbt (Composer) May 17, 2022
MODX Revolution XSS via HTTP Host header Moderate
CVE-2017-9071 was published for modx/revolution (Composer) May 17, 2022
MODX Revolution cross-site scripting vulnerability Moderate
CVE-2017-9070 was published for modx/revolution (Composer) May 17, 2022
MODX Revolution Reflected XSS Moderate
CVE-2017-9068 was published for modx/revolution (Composer) May 17, 2022
TeamPass vulnerable to Cross-site Scripting Moderate
CVE-2015-7562 was published for nilsteampassnet/teampass (Composer) May 17, 2022
juzawebCMS Incorrect Access Control vulnerability Moderate
CVE-2023-46906 was published for juzaweb/cms (Composer) Jan 9, 2024
SilverStripe Subsite weakens file permissions Moderate
CVE-2022-42949 was published for silverstripe/subsites (Composer) Dec 19, 2022
PEAR HTTP_Request2 vulnerable to Cross-site Scripting Moderate
CVE-2025-43717 was published for pear/http_request2 (Composer) Apr 17, 2025
Cross site scripting in the system log Moderate
CVE-2021-35210 was published for contao/contao (Composer) Jul 1, 2021
Cross site scripting via input unit widget Moderate
CVE-2023-36806 was published for contao/core-bundle (Composer) Jul 25, 2023
Cross-site Scripting in MobileDetect Moderate
CVE-2018-25080 was published for mobiledetect/mobiledetectlib (Composer) Feb 4, 2023
Magento Improper Access Control vulnerability Moderate
CVE-2025-24436 was published for magento/community-edition (Composer) Feb 11, 2025
Magento Improper Access Control vulnerability Moderate
CVE-2025-24437 was published for magento/community-edition (Composer) Feb 11, 2025
Drupal AI Vulnerable to OS Command Injection Moderate
CVE-2025-31693 was published for drupal/ai (Composer) Apr 1, 2025
Snipe-IT allows attackers to check whether a user account exists Moderate
CVE-2022-44381 was published for snipe/snipe-it (Composer) Dec 25, 2022
Snipe-IT vulnerable to Cross Site Scripting for View Assigned Assets Moderate
CVE-2022-44380 was published for snipe/snipe-it (Composer) Dec 25, 2022
Bootstrap Cross-Site Scripting (XSS) vulnerability Moderate
CVE-2024-6531 was published for bootstrap (RubyGems) Jul 11, 2024
alexeyNeklesa-idt metametadata
Typo3 Host Header Spoofing Vulnerability Moderate
CVE-2014-3941 was published for typo3/cms (Composer) May 14, 2022
ProTip! Advisories are also available from the GraphQL API