Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

516 advisories

Loading
Broadleaf vulnerable to Cross-site Scripting Moderate
CVE-2023-33725 was published for org.broadleafcommerce:broadleaf (Maven) Jun 21, 2023
Alluxio Cross Site Scripting vulnerability Moderate
CVE-2020-21485 was published for org.alluxio:alluxio-parent (Maven) Jun 20, 2023
Stored XSS vulnerability in Jenkins Maven Repository Server Plugin Moderate
CVE-2023-35144 was published for jenkins:repository (Maven) Jun 14, 2023
Stored XSS vulnerability in Jenkins Maven Repository Server Plugin Moderate
CVE-2023-35143 was published for jenkins:repository (Maven) Jun 14, 2023
JStachio XSS vulnerability: Unescaped single quotes Moderate
CVE-2023-33962 was published for io.jstach:jstachio (Maven) Jun 6, 2023
casid
Apache JSPWiki vulnerable to cross-site scripting on several plugins Moderate
CVE-2022-46907 was published for org.apache.jspwiki:jspwiki-main (Maven) May 25, 2023
Cross-site scripting in Liferay Portal Moderate
CVE-2023-33944 was published for com.liferay.portal:release.portal.bom (Maven) May 24, 2023
Cross-site scripting in Liferay Portal Moderate
CVE-2023-33937 was published for com.liferay.portal:release.portal.bom (Maven) May 24, 2023
Cross-site scripting in Liferay Portal Moderate
CVE-2023-33940 was published for com.liferay.portal:release.portal.bom (Maven) May 24, 2023
Cross-site scripting in Liferay Portal Moderate
CVE-2023-33938 was published for com.liferay.portal:release.portal.bom (Maven) May 24, 2023
Cross-site scripting in Liferay Portal Moderate
CVE-2023-33941 was published for com.liferay.portal:release.portal.bom (Maven) May 24, 2023
Cross-site scripting in Liferay Portal Moderate
CVE-2023-33939 was published for com.liferay.portal:release.portal.bom (Maven) May 24, 2023
Cross-site scripting in Liferay Portal Moderate
CVE-2023-33943 was published for com.liferay.portal:release.portal.bom (Maven) May 24, 2023
Cross-site scripting in Liferay Portal Moderate
CVE-2023-33942 was published for com.liferay.portal:release.portal.bom (Maven) May 24, 2023
alkacon-OpenCMS vulnerable to stored Cross-site Scripting Moderate
CVE-2023-31544 was published for org.opencms:opencms-core (Maven) May 16, 2023
Jenkins TestNG Results Plugin Stored Cross-site Scripting vulnerability Moderate
CVE-2023-32984 was published for org.jenkins-ci.plugins:testng-plugin (Maven) May 16, 2023
ONOS vulnerable to Cross-site Scripting Moderate
CVE-2023-30093 was published for org.onosproject:onos-archetypes (Maven) May 5, 2023
edoardottt
XWiki App Within Minutes app grants space admin rights that allows cross-site scripting Moderate
CVE-2023-29515 was published for org.xwiki.platform:xwiki-platform-appwithinminutes (Maven) Apr 20, 2023
org.xwiki.platform:xwiki-platform-security-authentication-default XSS with authenticate endpoints Moderate
CVE-2023-29506 was published for org.xwiki.platform:xwiki-platform-security-authentication-default (Maven) Apr 12, 2023
rekter0
XXL-JOB vulnerable to Cross-site Scripting Moderate
CVE-2023-26120 was published for com.xuxueli:xxl-job (Maven) Apr 10, 2023
Goobi viewer Core Reflected Cross-Site Scripting Vulnerability Using LOGID Parameter Moderate
CVE-2023-29014 was published for io.goobi.viewer:viewer-core (Maven) Apr 7, 2023
Goobi viewer Core has Cross-Site Scripting Vulnerability in User Comments Moderate
CVE-2023-29015 was published for io.goobi.viewer:viewer-core (Maven) Apr 7, 2023
Goobi viewer Core has Cross-Site Scripting Vulnerability in User Nicknames Moderate
CVE-2023-29016 was published for io.goobi.viewer:viewer-core (Maven) Apr 7, 2023
Apache Archiva vulnerable to privilege escalation via stored cross-site scripting (XSS) Moderate
CVE-2023-28158 was published for org.apache.archiva:archiva (Maven) Mar 29, 2023
ONOS vulnerable to reflected cross-site scripting Moderate
CVE-2023-24279 was published for org.onosproject:onos-archetypes (Maven) Mar 14, 2023
edoardottt
ProTip! Advisories are also available from the GraphQL API