Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,244 advisories

Loading
Cross-site Scripting vulnerability in SimpleXLSXEx::readThemeColors, SimpleXLSXEx::getColorValue and SimpleXLSX::toHTMLEx Moderate
CVE-2024-56364 was published for shuchkin/simplexlsx (Composer) Dec 23, 2024
shuchkin
baserCMS Cross-site Scripting vulnerability in Site search Feature Moderate
CVE-2023-44379 was published for baserproject/basercms (Composer) Feb 22, 2024
Firefly III allows webhooks HTML Injection. Moderate
CVE-2024-22075 was published for grumpydictator/firefly-iii (Composer) Jan 5, 2024
Concrete CMS Stored XSS in Layout Preset Name Moderate
CVE-2023-48650 was published for concrete5/concrete5 (Composer) Feb 29, 2024
Cross-site Scripting vulnerability in SimpleXLSXEx::readXfs and SimpeXLSX::toHTMLEx Moderate
CVE-2024-55878 was published for shuchkin/simplexlsx (Composer) Dec 12, 2024
shuchkin
LibreNMS stored cross-site scripting (XSS) vulnerability in the Device Settings section Moderate
CVE-2024-53457 was published for librenms/librenms (Composer) Dec 6, 2024
YiiCMS Cross Site Scripting vulnerability Moderate
CVE-2020-21246 was published for sheng/yiicms (Composer) Jun 20, 2023
Drupal Core Cross-Site Scripting (XSS) Moderate
CVE-2024-12393 was published for drupal/core (Composer) Dec 10, 2024
MediaWiki UnlinkedWikibase Cross-site Scripting vulnerability Moderate
CVE-2024-34500 was published for samwilson/unlinked-wikibase (Composer) May 5, 2024
Ibexa Admin UI vulnerable to Cross-site Scripting in a field that is used in the Content name pattern Moderate
CVE-2024-53864 was published for ibexa/admin-ui (Composer) Dec 2, 2024
Redaxo Core CMS Cross Site Scripting (XSS) Moderate
CVE-2024-50803 was published for redaxo/source (Composer) Nov 19, 2024
auditor-bundle vulnerable to Cross-site Scripting because name of entity does not get escaped Moderate
CVE-2024-45592 was published for damienharper/auditor-bundle (Composer) Sep 10, 2024
fkropfhamer
Zenario's Tree Explorer tool from Organizer affected by Cross-site Scripting Moderate
CVE-2024-34460 was published for tribalsystems/zenario (Composer) May 4, 2024
LibreNMS has a stored XSS in ExamplePlugin with Device's Notes Moderate
CVE-2024-49758 was published for librenms/librenms (Composer) Nov 15, 2024
minhnq1618
Cross site scripting in sylius/sylius Moderate
CVE-2021-3841 was published for sylius/sylius (Composer) Nov 15, 2024
Cross-site Scripting (XSS) in Conditions tab of Pricing Rules Moderate
CVE-2023-2332 was published for pimcore/pimcore (Composer) Apr 27, 2023
nhaanhaa
Moodle Cross-site Scripting (XSS) Moderate
CVE-2024-34000 was published for moodle/moodle (Composer) May 31, 2024
UnoPim Stored XSS : Cookie hijacking through Create User function Moderate
CVE-2024-52305 was published for unopim/unopim (Composer) Nov 13, 2024
yamerooo123
Minecraft MOTD Parser's HtmlGenerator vulnerable to XSS Moderate
CVE-2024-47765 was published for dev-lancer/minecraft-motd-parser (Composer) Oct 4, 2024
Krymonota jgniecki
UnoPim Cross-site Scripting vulnerability Moderate
CVE-2024-50637 was published for unopim/unopim (Composer) Nov 6, 2024
Potential XSS vulnerability in jQuery Moderate
CVE-2020-11022 was published for jquery (RubyGems) Apr 29, 2020
masatokinugawa Churro
Rudloff
XSS in jQuery as used in Drupal, Backdrop CMS, and other products Moderate
CVE-2019-11358 was published for django (RubyGems) Apr 26, 2019
klaudialax eoftedal
Rudloff
Cross-site Scripting in Moodle Chat Moderate
CVE-2024-28593 was published for moodle/moodle (Composer) Mar 22, 2024
Symfony potential Cross-site Scripting in WebhookController Moderate
CVE-2023-46735 was published for symfony/symfony (Composer) Nov 12, 2023
maxime-aknin nicolas-grekas
Cross-site scripting vulnerability in includes/actions/InfoAction.php Moderate
CVE-2014-2853 was published for mediawiki/core (Composer) May 17, 2022
Rudloff
ProTip! Advisories are also available from the GraphQL API