GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
41
Go
3,003
Maven
5,000+
npm
4,732
NuGet
788
pip
4,341
Pub
12
RubyGems
987
Rust
1,137
Swift
50
Unreviewed advisories
All unreviewed
5,000+
109 advisories
Filter by severity
openCart Server-Side Template Injection (SSTI) vulnerability
Moderate
CVE-2024-36694
was published
for
opencart/opencart
(Composer)
Jul 17, 2024
StrongShop v1.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability...
High
Unreviewed
CVE-2024-37621
was published
Jun 17, 2024
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
High
CVE-2024-37301
was published
for
document-merge-service
(pip)
Jun 11, 2024
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection...
Critical
Unreviewed
CVE-2024-23692
was published
May 31, 2024
Shopware Remote Code Execution Vulnerability
Critical
GHSA-83jv-4prm-34g7
was published
for
shopware/shopware
(Composer)
May 21, 2024
verbb/formie Server-Side Template Injection for variable-enabled settings
Moderate
CVE-2024-35191
was published
for
verbb/formie
(Composer)
May 20, 2024
An issue was discovered in Logpoint before 7.1.1. Template injection was seen in the search...
High
Unreviewed
CVE-2022-48684
was published
Apr 28, 2024
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a...
High
Unreviewed
CVE-2024-32406
was published
Apr 26, 2024
VFS Sandbox Escape in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows...
High
Unreviewed
CVE-2024-4040
was published
Apr 22, 2024
An issue in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via...
High
Unreviewed
CVE-2024-32407
was published
Apr 22, 2024
A improper neutralization of special elements used in a template engine [CWE-1336] in...
Moderate
Unreviewed
CVE-2023-47542
was published
Apr 9, 2024
Gibbon through 26.0.00 allows /modules/School%20Admin/messengerSettings.php Server Side Template...
Critical
Unreviewed
CVE-2024-24724
was published
Apr 3, 2024
Server-Side Template Injection (SSTI) with Grav CMS security sandbox bypass
High
CVE-2024-28116
was published
for
getgrav/grav
(Composer)
Mar 22, 2024
CMS Made Simple version 2.2.19 is vulnerable to Server-Side Template Injection (SSTI). The...
Moderate
Unreviewed
CVE-2024-27623
was published
Mar 5, 2024
NoneBot Potential Information Leak in User-Constructed Message Templates
Moderate
CVE-2024-21624
was published
for
nonebot2
(pip)
Feb 9, 2024
Ansible template injection vulnerability
Moderate
CVE-2023-5764
was published
for
ansible-core
(pip)
Dec 13, 2023
Kimai (Authenticated) SSTI to RCE by Uploading a Malicious Twig File
High
CVE-2023-46245
was published
for
kimai/kimai
(Composer)
Oct 30, 2023
OctoPrint vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
High
CVE-2023-41047
was published
for
OctoPrint
(pip)
Oct 10, 2023
Grav Server-side Template Injection (SSTI) via Twig Default Filters
High
CVE-2023-34448
was published
for
getgrav/grav
(Composer)
Jun 16, 2023
Grav Server-side Template Injection (SSTI) via Denylist Bypass Vulnerability
High
CVE-2023-34253
was published
for
getgrav/grav
(Composer)
Jun 16, 2023
Grav Server-side Template Injection (SSTI) via Twig Default Filters
High
CVE-2023-34252
was published
for
getgrav/grav
(Composer)
Jun 16, 2023
Magento Open Source allows Improper Neutralization of Special Elements Used
High
CVE-2023-29297
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio...
Critical
Unreviewed
CVE-2023-2259
was published
Apr 24, 2023
Shopware Has Improper Control of Generation of Code in Twig rendered views
High
CVE-2023-2017
was published
for
shopware/core
(Composer)
Apr 18, 2023
ProTip!
Advisories are also available from the
GraphQL API