Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,318 advisories

Loading
TYPO3 Cross-Site Scripting in Link Handling Moderate
GHSA-xgmx-j3hv-jh9x was published for typo3/cms (Composer) Jun 7, 2024
TYPO3 Broken Access Control in Localization Handling Moderate
GHSA-772m-43f3-hmf8 was published for typo3/cms (Composer) Jun 7, 2024
TYPO3 Cross-Site Scripting in Filelist Module Moderate
GHSA-g7hw-jh4p-75wr was published for typo3/cms (Composer) Jun 7, 2024
TYPO3 Cross-Site Scripting in Fluid ViewHelpers Moderate
GHSA-85ch-44w7-rf32 was published for typo3/cms (Composer) Jun 7, 2024
TokenController formName not sanitized in hidden input Moderate
CVE-2024-37156 was published for sulu/form-bundle (Composer) Jun 6, 2024
picturestone rogamoore
Improper Authentication in CraftCMS two factor authentication plugin Moderate
CVE-2024-5658 was published for born05/craft-twofactorauthentication (Composer) Jun 6, 2024
Insecure Unserialize Vulnerability in FLOW3 Moderate
GHSA-m2hp-5x78-74mg was published for typo3/flow (Composer) Jun 5, 2024
Typo3 Arbitrary file upload and XML External Entity processing Moderate
GHSA-2p4f-vc9q-r5vp was published for typo3/flow (Composer) Jun 5, 2024
By-passing Protection of PharStreamWrapper Interceptor Moderate
GHSA-4v5g-8pq2-32m2 was published for typo3/phar-stream-wrapper (Composer) Jun 5, 2024
Time-Based Information Disclosure Vulnerability in Flow Moderate
GHSA-r6mm-wmhf-849m was published for typo3/flow (Composer) Jun 5, 2024
Privilege Escalation in TYPO3 Neos Moderate
GHSA-wr3c-6c22-m9v6 was published for typo3/neos (Composer) Jun 5, 2024
Typo3 Cross-Site Scripting in Language Pack Handling Moderate
GHSA-259v-xm34-p7fr was published for typo3/cms (Composer) Jun 5, 2024
Typo3 Broken Access Control in Import Module Moderate
GHSA-f5rr-9r84-wwqf was published for typo3/cms (Composer) Jun 5, 2024
Typo3 Arbitrary Code Execution and Cross-Site Scripting in Backend API Moderate
GHSA-hww5-6x85-mc24 was published for typo3/cms (Composer) Jun 5, 2024
Typo3 Security Misconfiguration in Frontend Session Handling Moderate
GHSA-qr5f-6fcv-w69q was published for typo3/cms (Composer) Jun 5, 2024
Typo3 Security Misconfiguration in User Session Handling Moderate
GHSA-g9rv-6g56-65h8 was published for typo3/cms (Composer) Jun 5, 2024
Typo3 Information Disclosure in Backend User Interface Moderate
GHSA-q9c4-9v5m-597p was published for typo3/cms (Composer) Jun 5, 2024
Typo3 Information Disclosure in User Authentication Moderate
GHSA-m96r-7vqm-j95g was published for typo3/cms (Composer) Jun 5, 2024
Cross-Site Scripting in TYPO3 CMS Backend Moderate
GHSA-v4qr-8h2v-qpjx was published for typo3/cms (Composer) Jun 5, 2024
Cross-Site Scripting in TYPO3 CMS Moderate
GHSA-5gr6-97fv-52cc was published for typo3/cms (Composer) Jun 5, 2024
Insecure Unserialize in TYPO3 Backend Moderate
GHSA-c7rj-92xr-wprg was published for typo3/cms (Composer) Jun 5, 2024
Cache Flooding in TYPO3 Frontend Moderate
GHSA-pw2q-qwvj-gh43 was published for typo3/cms (Composer) Jun 5, 2024
Authentication Bypass in TYPO3 Frontend Moderate
GHSA-mh3r-6cp5-hc2j was published for typo3/cms (Composer) Jun 5, 2024
Authentication Bypass in TYPO3 CMS Moderate
GHSA-6f9m-v7mp-7jjq was published for typo3/cms (Composer) Jun 5, 2024
Information Disclosure in TYPO3 CMS Moderate
GHSA-g46h-v2cc-6c94 was published for typo3/cms (Composer) Jun 5, 2024
ProTip! Advisories are also available from the GraphQL API