GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,683
Erlang
29
GitHub Actions
16
Go
1,708
Maven
4,944
npm
3,473
NuGet
603
pip
2,995
Pub
10
RubyGems
826
Rust
773
Swift
34
Unreviewed advisories
All unreviewed
5,000+
2,112 advisories
Filter by severity
PHP Server Monitor vulnerable to Cross-site Scripting
Moderate
CVE-2024-5312
was published
for
phpservermon/phpservermon
(Composer)
May 24, 2024
silverstripe/framework ReadOnly transformation for formfields exploitable
Moderate
GHSA-97jm-g33h-f46g
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Cross-site scripting vulnerability in VersionedRequestFilter
Moderate
GHSA-mpqj-f4v3-334h
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Missing CSRF protection in login form
Moderate
GHSA-vj2j-6g3w-4662
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe XSS in CMS Edit Page
Moderate
GHSA-m8v7-x398-pxrf
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Hostname, IP and Protocol Spoofing through HTTP Headers
Moderate
GHSA-87pf-7x99-5xc4
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe CSRF vulnerability in GridFieldAddExistingAutocompleter
Moderate
GHSA-2hpc-mf4q-j885
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Missing security check on dev/build/defaults
Moderate
GHSA-x5w2-wcr8-9q45
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe HtmlEditor embed url sanitisation
Moderate
GHSA-qp29-wcc2-vmpc
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Form field validation message XSS vulnerability
Moderate
GHSA-j982-5jv7-v43r
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe framework is vulnerable to XSS in install.php
Moderate
GHSA-mqf5-275h-gf6r
was published
for
silverstripe/framework
(Composer)
May 23, 2024
SilverStripe Vulnerability on 'isDev', 'isTest' and 'flush' $_GET validation
Moderate
GHSA-g4hp-pfvf-vm5w
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe XSS in dev/build returnURL Parameter
Moderate
GHSA-hq4p-5mpr-jj9m
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe External redirection risk in Security?ReturnURL
Moderate
GHSA-vp8p-c6xj-xpj7
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe XSS in Director::force_redirect()
Moderate
GHSA-jqp8-v74p-g8px
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe XSS In FormAction
Moderate
GHSA-4h54-vwx9-3vr3
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe XSS In rewritten hash links
Moderate
GHSA-34q6-xqxh-gq39
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe XSS In GridField print
Moderate
GHSA-88jp-9jrv-6368
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe XSS in TreeDropdownField and TreeMultiSelectField
Moderate
GHSA-r32j-mr8p-hfp8
was published
for
silverstripe/framework
(Composer)
May 23, 2024
SilverStripe framework XML Quadratic Blowup Attack
Moderate
GHSA-g43w-98wp-m694
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe IE requests not properly behaving with rewritehashlinks
Moderate
GHSA-5f5v-5c3v-gw5v
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Forum Module CSRF Vulnerability
Moderate
GHSA-w8fq-xgvh-cxc2
was published
for
silverstripe/forum
(Composer)
May 23, 2024
Silverstripe XSS vulnerability via VirtualPage
Moderate
GHSA-r97r-64vp-fghm
was published
for
silverstripe/cms
(Composer)
May 22, 2024
Silverstripe History XSS Vulnerability
Moderate
GHSA-6hh6-59j2-qrxw
was published
for
silverstripe/cms
(Composer)
May 22, 2024
Shopware Non-Persistent XSS in the Frontend
Moderate
GHSA-jqr7-5h7r-ch8p
was published
for
shopware/shopware
(Composer)
May 21, 2024
ProTip!
Advisories are also available from the
GraphQL API