Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

19,016 advisories

Silverstripe Missing CSRF protection in login form Moderate
GHSA-vj2j-6g3w-4662 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Brute force bypass on default admin Critical
GHSA-8v6m-7f5v-hhx6 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS in CMS Edit Page Moderate
GHSA-m8v7-x398-pxrf was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Hostname, IP and Protocol Spoofing through HTTP Headers Moderate
GHSA-87pf-7x99-5xc4 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe CSRF vulnerability in GridFieldAddExistingAutocompleter Moderate
GHSA-2hpc-mf4q-j885 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Missing security check on dev/build/defaults Moderate
GHSA-x5w2-wcr8-9q45 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe HtmlEditor embed url sanitisation Moderate
GHSA-qp29-wcc2-vmpc was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Form field validation message XSS vulnerability Moderate
GHSA-j982-5jv7-v43r was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe framework is vulnerable to XSS in install.php Moderate
GHSA-mqf5-275h-gf6r was published for silverstripe/framework (Composer) May 23, 2024
SilverStripe Vulnerability on 'isDev', 'isTest' and 'flush' $_GET validation Moderate
GHSA-g4hp-pfvf-vm5w was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS in dev/build returnURL Parameter Moderate
GHSA-hq4p-5mpr-jj9m was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe External redirection risk in Security?ReturnURL Moderate
GHSA-vp8p-c6xj-xpj7 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe X-Forwarded-Host request hostname injection High
GHSA-25gq-jvx2-vg9x was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS in Director::force_redirect() Moderate
GHSA-jqp8-v74p-g8px was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS In FormAction Moderate
GHSA-4h54-vwx9-3vr3 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS In rewritten hash links Moderate
GHSA-34q6-xqxh-gq39 was published for silverstripe/framework (Composer) May 23, 2024
Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop Moderate
GHSA-f7cq-5v43-8pwp was published for github.com/traefik/traefik (Go) May 23, 2024
Silverstripe XSS In GridField print Moderate
GHSA-88jp-9jrv-6368 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS in TreeDropdownField and TreeMultiSelectField Moderate
GHSA-r32j-mr8p-hfp8 was published for silverstripe/framework (Composer) May 23, 2024
SilverStripe framework XML Quadratic Blowup Attack Moderate
GHSA-g43w-98wp-m694 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe IE requests not properly behaving with rewritehashlinks Moderate
GHSA-5f5v-5c3v-gw5v was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Forum Module CSRF Vulnerability Moderate
GHSA-w8fq-xgvh-cxc2 was published for silverstripe/forum (Composer) May 23, 2024
iFrames Bypass Origin Checks for Tauri API Access Control Moderate
CVE-2024-35222 was published for tauri (Rust) May 23, 2024
begleynk chippers
tweidinger lucasfernog
jupyter-scheduler's endpoint is missing authentication Moderate
CVE-2024-28188 was published for jupyter-scheduler (pip) May 23, 2024
krassowski Carreau
andrii-i dlqqq yuvipanda
Eclipse Ditto vulnerable to Cross-site Scripting Moderate
CVE-2024-5165 was published for org.eclipse.ditto:ditto (Maven) May 23, 2024
ProTip! Advisories are also available from the GraphQL API