Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • L
Missing Authorization
goalgorilla/open_social<12.3.11>=12.4.0, <12.4.10Composer14 Apr 2025
  • M
Missing Authorization
goalgorilla/open_social<12.3.11>=12.4.0, <12.4.10Composer14 Apr 2025
  • M
Cross-site Scripting (XSS)
digimix/wp-svg-upload>=0.0.0Composer14 Apr 2025
  • H
Directory Traversal
yeswiki/yeswiki<4.5.2Composer14 Apr 2025
  • M
Cross-site Scripting (XSS)
concrete5/concrete5>=0.0.0Composer14 Apr 2025
  • M
Server-side Request Forgery (SSRF)
shopxo/shopxo>=0.0.0Composer14 Apr 2025
  • M
Server-side Request Forgery (SSRF)
shopxo/shopxo>=0.0.0Composer14 Apr 2025
  • M
Cross-site Scripting (XSS)
shopxo/shopxo>=0.0.0Composer14 Apr 2025
  • M
SQL Injection
joomla/database<2.2.0>=3.0.0, <3.4.0Composer13 Apr 2025
  • M
Incorrect Authorization
pixelfed/pixelfed<0.12.5Composer13 Apr 2025
  • M
Cross-site Scripting (XSS)
verbb/formie<2.1.44>=3.0.0-beta.1, <3.0.23Composer13 Apr 2025
  • M
Cross-site Scripting (XSS)
verbb/formie<2.1.44>=3.0.0-beta.1, <3.0.23Composer13 Apr 2025
  • M
Observable Discrepancy
silverstripe/framework>=4.0.0, <5.3.23Composer11 Apr 2025
  • M
Cross-site Scripting (XSS)
silverstripe/framework<5.3.23Composer11 Apr 2025
  • M
Cross-site Scripting (XSS)
yiisoft/yii<1.1.31Composer11 Apr 2025
  • H
Access of Uninitialized Pointer
rudloff/rtmpdump-bin>=0.0.0Composer10 Apr 2025
  • H
Access of Uninitialized Pointer
rudloff/rtmpdump-bin>=0.0.0Composer10 Apr 2025
  • H
NULL Pointer Dereference
rudloff/rtmpdump-bin>=0.0.0Composer10 Apr 2025
  • C
Improper Protection of Alternate Path
yiisoft/yii2>=2.0.50, <2.0.52Composer10 Apr 2025
  • L
Cross-site Scripting (XSS)
pimcore/admin-ui-classic-bundle<1.7.6Composer8 Apr 2025
  • M
Incorrect Authorization
drupal/core<10.3.13>=10.4.0, <10.4.3>=11.0.0, <11.0.12>=11.1.0, <11.1.3Composer6 Apr 2025
  • M
Cross-site Scripting (XSS)
drupal/core<10.3.14>=10.4.0, <10.4.5>=11.0.0, <11.0.13>=11.1.0, <11.1.5Composer6 Apr 2025
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes
drupal/core<10.3.13>=10.4.0, <10.4.3>=11.0.0, <11.0.12>=11.1.0, <11.1.3Composer6 Apr 2025
  • M
Cross-site Scripting (XSS)
drupal/core<10.3.13>=10.4.0, <10.4.3>=11.0.0, <11.0.12>=11.1.0, <11.1.3Composer6 Apr 2025
  • H
Incorrect Behavior Order
api-platform/graphql<4.0.22Composer4 Apr 2025
  • H
Incorrect Behavior Order
api-platform/core<4.0.22Composer4 Apr 2025
  • H
Incorrect Authorization
api-platform/graphql<4.0.22Composer4 Apr 2025
  • H
Incorrect Authorization
api-platform/core<4.0.22Composer4 Apr 2025
  • M
Information Exposure
api-platform/core>=3.2.0, <3.2.5Composer4 Apr 2025
  • M
Cross-site Request Forgery (CSRF)
concrete5/concrete5<8.5.20>=9.0.0RC1, <9.4.0RC2Composer3 Apr 2025