Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

21,369 advisories

Loading
Froala WYSIWYG Editor XSS Vulnerability Moderate
CVE-2020-26523 was published for froala/wysiwyg-editor (Composer) May 24, 2022
MantisBT HTML Injection vulnerability Moderate
CVE-2020-25830 was published for mantisbt/mantisbt (Composer) May 24, 2022
dregad
MediaWiki Cross-site Scripting (XSS) vulnerability Moderate
CVE-2020-25828 was published for mediawiki/core (Composer) May 24, 2022
MediaWiki Special:UserRights exposes the existence of hidden users Moderate
CVE-2020-25813 was published for mediawiki/core (Composer) May 24, 2022
OATHAuth extension in MediaWiki is not implementing rate limit High
CVE-2020-25827 was published for mediawiki/core (Composer) May 24, 2022
MediaWiki Cross-site Scripting (XSS) vulnerability Moderate
CVE-2020-25814 was published for mediawiki/core (Composer) May 24, 2022
MediaWiki Cross-site Scripting (XSS) vulnerability Moderate
CVE-2020-25815 was published for mediawiki/core (Composer) May 24, 2022
MediaWiki Cross-site Scripting (XSS) vulnerability Moderate
CVE-2020-25812 was published for mediawiki/core (Composer) May 24, 2022
CSRF vulnerability in Jenkins warnings Plugin allows remote code execution High
CVE-2020-2280 was published for org.jvnet.hudson.plugins:warnings (Maven) May 24, 2022
NotMyFault
XXE vulnerability in Jenkins Liquibase Runner Plugin High
CVE-2020-2284 was published for org.jenkins-ci.plugins:liquibase-runner (Maven) May 24, 2022
NotMyFault
Missing permission check in Jenkins Implied Labels Plugin allows reconfiguring the plugin Moderate
CVE-2020-2282 was published for org.jenkins-ci.plugins:implied-labels (Maven) May 24, 2022
NotMyFault
Stored XSS vulnerability in Jenkins Liquibase Runner Plugin Moderate
CVE-2020-2283 was published for org.jenkins-ci.plugins:liquibase-runner (Maven) May 24, 2022
NotMyFault
Sandbox bypass vulnerability in Jenkins Script Security Plugin Critical
CVE-2020-2279 was published for org.jenkins-ci.plugins:script-security (Maven) May 24, 2022
NotMyFault westonsteimel
Missing permission check in Jenkins Liquibase Runner Plugin allows enumerating credentials IDs Moderate
CVE-2020-2285 was published for org.jenkins-ci.plugins:liquibase-runner (Maven) May 24, 2022
NotMyFault
CSRF vulnerability in Jenkins Lockable Resources Plugin Moderate
CVE-2020-2281 was published for org.6wind.jenkins:lockable-resources (Maven) May 24, 2022
NotMyFault
Cabot Cross Site Scripting (XSS) vulnerability via Endpoint column Low
CVE-2020-7734 was published for cabot (pip) May 24, 2022
DotPlant2 Improper Restriction of XML External Entity Reference High
CVE-2020-25750 was published for devgroup/dotplant (Composer) May 24, 2022
Arbitrary file write vulnerability in Jenkins Storable Configs Plugin Moderate
CVE-2020-2278 was published for org.jvnet.hudson.plugins:storable-configs-plugin (Maven) May 24, 2022
NotMyFault
Passwords stored in plain text by ElasTest Plugin Moderate
CVE-2020-2274 was published for org.jenkins-ci.plugins:elastest (Maven) May 24, 2022
NotMyFault
Arbitrary file read vulnerability in Jenkins Storable Configs Plugin Moderate
CVE-2020-2277 was published for org.jvnet.hudson.plugins:storable-configs-plugin (Maven) May 24, 2022
NotMyFault
Missing permission checks in Jenkins ElasTest Plugin Moderate
CVE-2020-2272 was published for org.jenkins-ci.plugins:elastest (Maven) May 24, 2022
NotMyFault
CSRF vulnerability in Jenkins ElasTest Plugin Moderate
CVE-2020-2273 was published for org.jenkins-ci.plugins:elastest (Maven) May 24, 2022
NotMyFault
Arbitrary file read vulnerability in Copy data to workspace Jenkins Plugin Moderate
CVE-2020-2275 was published for org.jvnet.hudson.plugins:copy-data-to-workspace-plugin (Maven) May 24, 2022
NotMyFault
System command execution vulnerability in Selection tasks Jenkins Plugin High
CVE-2020-2276 was published for org.jvnet.hudson.plugins:selection-tasks-plugin (Maven) May 24, 2022
NotMyFault
Stored XSS vulnerability in Locked Files Report Plugin High
CVE-2020-2271 was published for org.jvnet.hudson.plugins:locked-files-report (Maven) May 24, 2022
NotMyFault
ProTip! Advisories are also available from the GraphQL API