GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,319
Erlang
31
GitHub Actions
21
Go
2,077
Maven
5,000+
npm
3,746
NuGet
674
pip
3,435
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
38 advisories
Filter by severity
TYPO3 vulnerable to Weak Authentication in Session Handling
Moderate
CVE-2023-47127
was published
for
typo3/cms-core
(Composer)
Nov 14, 2023
Bypassing Cross-Site Scripting Protection in TYPO3 HTML Sanitizer
Moderate
CVE-2023-47125
was published
for
typo3/html-sanitizer
(Composer)
Nov 14, 2023
ckeditor-wordcount-plugin vulnerable to Cross-site Scripting in Source Mode of Editor
Moderate
CVE-2023-37905
was published
for
ckeditor-wordcount-plugin
(npm)
Jul 10, 2023
Information Disclosure due to Out-of-scope Site Resolution
Low
CVE-2023-38499
was published
for
typo3/cms-core
(Composer)
Jul 25, 2023
By-passing Cross-Site Scripting Protection in HTML Sanitizer
Moderate
CVE-2023-38500
was published
for
typo3/html-sanitizer
(Composer)
Jul 25, 2023
Cross-Site Scripting in CKEditor4 WordCount Plugin
Moderate
GHSA-m8fw-p3cr-6jqc
was published
for
typo3/cms-rte-ckeditor
(Composer)
Jul 25, 2023
Multiple vulnerabilities in extension "Newsletter subscriber management" (fp_newsletter)
Critical
CVE-2022-47408
was published
for
fixpunkt/fp-newsletter
(Composer)
Dec 14, 2022
svg-sanitizer has Cross-site Scripting Bypass
Moderate
CVE-2023-28426
was published
for
enshrined/svg-sanitize
(Composer)
Mar 20, 2023
•
withdrawn
Broken Access Control in 3rd party TYPO3 extension "femanager"
High
CVE-2023-25013
was published
for
in2code/femanager
(Composer)
Feb 2, 2023
Broken Access Control in 3rd party TYPO3 extension "femanager"
High
CVE-2023-25014
was published
for
in2code/femanager
(Composer)
Feb 2, 2023
Cross-Site Scripting in Bootstrap Package
Moderate
CVE-2021-21365
was published
for
bk2k/bootstrap-package
(Composer)
Apr 29, 2021
Insufficient Session Expiration in TYPO3's Admin Tool
Moderate
CVE-2022-31050
was published
for
typo3/cms
(Composer)
Jun 17, 2022
XSS in enshrined/svg-sanitize due to mishandled script and data values in attributes
High
CVE-2019-18857
was published
for
enshrined/svg-sanitize
(Composer)
Jan 8, 2020
ProTip!
Advisories are also available from the
GraphQL API