GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,741
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,249 advisories
Filter by severity
ZendFramework Potential Cross-site Scripting in Development Environment Error View Script
Moderate
GHSA-g52p-86j5-xr8q
was published
for
zendframework/zendframework1
(Composer)
Jun 7, 2024
ZendFramework potential Cross-site Scripting vectors due to inconsistent encodings
Moderate
GHSA-hg35-vqp3-fv39
was published
for
zendframework/zendframework1
(Composer)
Jun 7, 2024
ZendFramework potential Cross-site Scripting vector in `Zend_Dojo_View_Helper_Editor`
Moderate
GHSA-j543-vg33-g6vj
was published
for
zendframework/zendframework1
(Composer)
Jun 7, 2024
ZendFramework has potential Cross-site Scripting vector in multiple view helpers
Moderate
GHSA-m7hr-j867-3f34
was published
for
zendframework/zend-view
(Composer)
Jun 7, 2024
ZendFramework vulnerable to Cross-site Scripting
Moderate
GHSA-5gmf-3c43-q73v
was published
for
zendframework/zendframework
(Composer)
Jun 7, 2024
Zendframework has potential Cross-site Scripting vector in multiple view helpers
Moderate
GHSA-8q77-cv62-jj38
was published
for
zendframework/zendframework
(Composer)
Jun 7, 2024
TYPO3 Cross-Site Scripting in Frontend User Login
Moderate
GHSA-2rcw-9hrm-8q7q
was published
for
typo3/cms
(Composer)
Jun 7, 2024
TYPO3 Cross-Site Scripting in Backend Modal Component
Moderate
GHSA-7q33-hxwj-7p8v
was published
for
typo3/cms
(Composer)
Jun 7, 2024
TYPO3 Cross-Site Scripting in Online Media Asset Rendering
Moderate
GHSA-8m6j-p5jv-v69w
was published
for
typo3/cms
(Composer)
Jun 7, 2024
Cross-site scripting (XSS) vulnerability in Description metadata
Moderate
CVE-2024-37160
was published
for
getformwork/formwork
(Composer)
Jun 7, 2024
TYPO3 Cross-Site Scripting in Form Framework validation handling
Moderate
GHSA-v8m4-3w37-ghxx
was published
for
typo3/cms
(Composer)
Jun 7, 2024
TYPO3 Cross-Site Scripting in Form Framework
Moderate
GHSA-4h5c-5g25-v7fh
was published
for
typo3/cms
(Composer)
Jun 7, 2024
TYPO3 Cross-Site Scripting in Link Handling
Moderate
GHSA-xgmx-j3hv-jh9x
was published
for
typo3/cms
(Composer)
Jun 7, 2024
TYPO3 Cross-Site Scripting in Filelist Module
Moderate
GHSA-g7hw-jh4p-75wr
was published
for
typo3/cms
(Composer)
Jun 7, 2024
TYPO3 Cross-Site Scripting in Fluid ViewHelpers
Moderate
GHSA-85ch-44w7-rf32
was published
for
typo3/cms
(Composer)
Jun 7, 2024
TokenController formName not sanitized in hidden input
Moderate
CVE-2024-37156
was published
for
sulu/form-bundle
(Composer)
Jun 6, 2024
Typo3 Cross-Site Scripting in Language Pack Handling
Moderate
GHSA-259v-xm34-p7fr
was published
for
typo3/cms
(Composer)
Jun 5, 2024
Cross-Site Scripting in TYPO3 CMS Backend
Moderate
GHSA-v4qr-8h2v-qpjx
was published
for
typo3/cms
(Composer)
Jun 5, 2024
Cross-Site Scripting in TYPO3 CMS
Moderate
GHSA-5gr6-97fv-52cc
was published
for
typo3/cms
(Composer)
Jun 5, 2024
Cross-Site Scripting (XSS) vulnerability in typolinks
Moderate
GHSA-p5c5-gmj4-g48f
was published
for
typo3/cms
(Composer)
Jun 5, 2024
Cross-Site Scripting (XSS) in TYPO3 Backend
Moderate
GHSA-hq37-rfjc-mr8h
was published
for
typo3/cms
(Composer)
Jun 5, 2024
Cross-Site Scripting in third party library mso/idna-convert
Moderate
GHSA-qmwf-j7g7-f5jw
was published
for
typo3/cms
(Composer)
Jun 5, 2024
Cross-Site Scripting in TYPO3 Backend
Moderate
GHSA-86r8-4g3w-7xjp
was published
for
typo3/cms
(Composer)
Jun 5, 2024
Cross-Site Scripting in TYPO3 Backend
Moderate
GHSA-5wx6-xwxf-q8qj
was published
for
typo3/cms
(Composer)
Jun 5, 2024
Cross-Site Scripting (XSS) in TYPO3 component CSS styled content
Moderate
GHSA-8j9v-4hhh-x43c
was published
for
typo3/cms
(Composer)
Jun 4, 2024
ProTip!
Advisories are also available from the
GraphQL API