GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,266
Erlang
31
GitHub Actions
21
Go
2,041
Maven
5,000+
npm
3,733
NuGet
662
pip
3,414
Pub
12
RubyGems
891
Rust
866
Swift
36
Unreviewed advisories
All unreviewed
5,000+
4,267 advisories
Filter by severity
Unhandled exception when decoding form response JSON
High
GHSA-wjfq-88q2-r34j
was published
for
pocketmine/pocketmine-mp
(Composer)
Jan 21, 2022
IBX-1392: Image filenames sanitization
High
GHSA-44m4-9cjp-j587
was published
for
ezsystems/ezpublish-kernel
(Composer)
Jan 21, 2022
Unchecked validity of Facing values in PlayerActionPacket
High
GHSA-xh99-hw7h-wf63
was published
for
pocketmine/pocketmine-mp
(Composer)
Jan 13, 2022
Book page text, count, and author/title length is not limited in PocketMine-MP
Moderate
GHSA-p62j-hrxm-xcxf
was published
for
pocketmine/pocketmine-mp
(Composer)
Jan 6, 2022
XSS vulnerability in translations
Moderate
GHSA-rrgw-3hg3-9x8c
was published
for
oro/platform
(Composer)
Jan 12, 2022
Uncapped length of skin data fields submitted by players
High
GHSA-c6fg-99pr-25m9
was published
for
pocketmine/pocketmine-mp
(Composer)
Jan 6, 2022
TYPO3 HTML Sanitizer Bypasses Cross-Site Scripting Protection
Moderate
GHSA-gqqf-g5r7-84vf
was published
for
typo3/cms-core
(Composer)
Sep 15, 2022
PocketMine-MP has improperly handled dye colour IDs in banner NBT, leading to server crash
High
GHSA-wqqv-jcfr-9f5g
was published
for
pocketmine/pocketmine-mp
(Composer)
Jan 9, 2023
Webcache Poisoning in shopware/platform and shopware/core
Critical
GHSA-r64m-qchj-hrjp
was published
for
shopware/core
(Composer)
Nov 24, 2021
Inability to de-op players if listed in ops.txt with non-lowercase letters
Low
GHSA-j5qg-w9jg-3wg3
was published
for
pocketmine/pocketmine-mp
(Composer)
Dec 16, 2021
CSV injection in Craft CMS
High
GHSA-xrpj-f9v6-2332
was published
for
craftcms/cms
(Composer)
Oct 4, 2021
•
withdrawn
XSS in richtext custom tag attributes in ezsystems/ezplatform-richtext
Moderate
GHSA-9jp8-cwwx-p64q
was published
for
ezsystems/ezplatform-admin-ui
(Composer)
Dec 1, 2021
non-admin users can create integration role with administrator role
Moderate
GHSA-243q-g9j3-qf6r
was published
for
shopware/core
(Composer)
Jun 28, 2021
Private files publicly accessible with Cloud Storage providers
High
GHSA-vrf2-xghr-j52v
was published
for
shopware/core
(Composer)
Jun 28, 2021
Any storage file can be downloaded from p.sh if full server path is known
High
GHSA-gqcf-83rq-gpfr
was published
for
ibexa/post-install
(Composer)
Sep 14, 2021
CKEditor 4 vulnerabilities in versions <4.16.1
Moderate
GHSA-cfcv-q4qq-2ph4
was published
for
pimcore/pimcore
(Composer)
Aug 23, 2021
Authenticated Stored XSS in Administration
Moderate
GHSA-f6p7-8xfw-fjqq
was published
for
shopware/shopware
(Composer)
May 21, 2021
Any storage file can be downloaded from p.sh if full server path is known
High
GHSA-2rh5-jvgx-pgw3
was published
for
ezsystems/ezplatform
(Composer)
Sep 14, 2021
User enumeration in authentication mechanisms
Low
GHSA-2frx-j9hj-6c65
was published
for
lexik/jwt-authentication-bundle
(Composer)
May 17, 2021
Content object state fetch functions open to SQL injection
High
GHSA-jpwx-ffjq-wr4w
was published
for
ezsystems/ezpublish-legacy
(Composer)
Sep 7, 2021
Canceling of orders not related to the logged-in user
Moderate
GHSA-wq3r-jwrq-xg6w
was published
for
shopware/core
(Composer)
Jun 28, 2021
Internal hidden fields are visible on to many associations in admin api
Moderate
GHSA-gpmh-g94g-qrhr
was published
for
shopware/core
(Composer)
Jun 28, 2021
Lack of Input Validation in zendesk_api_client_php for Zendesk Subdomain
Critical
CVE-2021-30492
was published
for
zendesk/zendesk_api_client_php
(Composer)
Apr 29, 2021
User can obtain JWT token even if account is disabled
High
GHSA-36mj-6r7r-mqhf
was published
for
ezsystems/ezplatform-rest
(Composer)
Sep 29, 2021
Leak of information via Store-API aggregations in shopware/platform and shopware/core
Critical
GHSA-qg7c-q3vq-rgxr
was published
for
shopware/core
(Composer)
Apr 13, 2021
ProTip!
Advisories are also available from the
GraphQL API