GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,226
Erlang
31
GitHub Actions
19
Go
1,991
Maven
5,000+
npm
3,708
NuGet
661
pip
3,339
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
197 advisories
Filter by severity
CSV Injection vulnerability with exported contact lists in Mautic
Moderate
CVE-2018-8092
was published
for
mautic/core
(Composer)
Jan 19, 2021
CSV injection in Craft CMS
High
GHSA-xrpj-f9v6-2332
was published
for
craftcms/cms
(Composer)
Oct 4, 2021
•
withdrawn
Survey King v0.3.0 does not filter data properly when exporting excel files, allowing attackers...
Critical
Unreviewed
CVE-2022-26249
was published
Mar 26, 2022
RuoYi v4.7.2 contains a CSV injection vulnerability through ruoyi-admin when a victim opens .xlsx...
High
Unreviewed
CVE-2022-23868
was published
Mar 31, 2022
Improper Neutralization of Formula Elements in a CSV File in Kimai 2
High
CVE-2021-43515
was published
for
kevinpapst/kimai2
(Composer)
Apr 9, 2022
The Visual Form Builder WordPress plugin before 3.0.6 is vulnerable to CSV injection allowing a...
Critical
Unreviewed
CVE-2022-0142
was published
Apr 13, 2022
Eaton Intelligent Power Manager Infrastructure (IPM Infrastructure) version 1.5.0plus205 and all...
High
Unreviewed
CVE-2021-23286
was published
Apr 19, 2022
Lack of Neutralization of Formula Elements in the CSV API of MantisBT before 2.25.3 allows an...
High
Unreviewed
CVE-2021-43257
was published
Apr 15, 2022
Invicti Acunetix before 14 allows CSV injection via the Description field on the Add Targets page...
High
Unreviewed
CVE-2022-29315
was published
Apr 20, 2022
A remote attacker with general user privilege can inject malicious code in the form content of...
High
Unreviewed
CVE-2022-41675
was published
Nov 29, 2022
Improper Neutralization of Formula Elements in a CSV File in Gradio Flagging
High
CVE-2022-24770
was published
for
gradio
(pip)
Mar 18, 2022
The Appointment Hour Booking Plugin for WordPress is vulnerable to CSV Injection in versions up...
High
Unreviewed
CVE-2022-4034
was published
Nov 29, 2022
PowerStore SW v2.1.1.0 supports the option to export data to either a CSV or an XLSX file. The...
High
Unreviewed
CVE-2022-26867
was published
Jun 3, 2022
A vulnerability, which was classified as critical, has been found in SevOne Network Management...
High
Unreviewed
CVE-2020-36531
was published
Jun 8, 2022
Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra...
High
Unreviewed
CVE-2022-2027
was published
Jun 10, 2022
The WP-CRM WordPress plugin through 1.2.1 does not validate and sanitise fields when exporting...
High
Unreviewed
CVE-2022-1202
was published
Jun 14, 2022
The Import any XML or CSV File to WordPress plugin before 3.6.8 accepts all zip files and...
High
Unreviewed
CVE-2022-2268
was published
Jul 5, 2022
The Exports and Reports WordPress plugin before 0.9.2 does not sanitize and validate data when...
High
Unreviewed
CVE-2022-1539
was published
Jul 26, 2022
Authenticated (author+) CSV Injection vulnerability in Export Post Info plugin <= 1.2.0 at...
Moderate
Unreviewed
CVE-2022-38061
was published
Sep 25, 2022
The Request a Quote WordPress plugin through 2.3.7 does not validate uploaded CSV files, allowing...
High
Unreviewed
CVE-2022-2240
was published
Jul 26, 2022
Cross Site Scripting in Import feature in EspoCRM 7.1.8 allows remote users to run malicious...
Moderate
Unreviewed
CVE-2022-38845
was published
Sep 17, 2022
ghas-to-csv vulnerable to Improper Neutralization of Formula Elements in a CSV File
Moderate
CVE-2022-39217
was published
for
some-natalie/ghas-to-csv
(GitHub Actions)
Sep 16, 2022
CSV Injection in Create Contacts in EspoCRM 7.1.8 allows remote authenticated users to run system...
High
Unreviewed
CVE-2022-38844
was published
Sep 17, 2022
The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the...
Critical
Unreviewed
CVE-2022-3574
was published
Nov 14, 2022
ProTip!
Advisories are also available from the
GraphQL API