GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,454
Erlang
33
GitHub Actions
22
Go
2,153
Maven
5,000+
npm
3,818
NuGet
693
pip
3,492
Pub
12
RubyGems
902
Rust
903
Swift
38
Unreviewed advisories
All unreviewed
5,000+
212 advisories
Filter by severity
CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress.
Critical
Unreviewed
CVE-2022-27858
was published
Nov 9, 2022
CSV-Safe improperly filters special characters potentially leading to CSV injection
Critical
CVE-2022-28481
was published
for
csv-safe
(RubyGems)
May 3, 2022
A improper neutralization of formula elements in a CSV file vulnerability in Fortinet...
High
Unreviewed
CVE-2023-25611
was published
Mar 7, 2023
The Hustle (aka wordpress-popup) plugin 6.0.7 for WordPress is vulnerable to CSV Injection as it...
High
Unreviewed
CVE-2019-11872
was published
May 24, 2022
CSV injection in the event-tickets (Event Tickets) plugin before 4.10.7.2 for WordPress exists...
Moderate
Unreviewed
CVE-2019-16120
was published
May 24, 2022
An issue was discovered in Joomla! before 3.9.7. The CSV export of com_actionslogs is vulnerable...
Critical
Unreviewed
CVE-2019-12765
was published
May 24, 2022
IBM Maximo Asset Management 7.6 is vulnerable to CSV injection, which could allow a remote...
High
Unreviewed
CVE-2019-4364
was published
May 24, 2022
IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 saves user-provided information into a...
High
Unreviewed
CVE-2021-39022
was published
Mar 11, 2022
CA Harvest Software Change Manager versions 13.0.3, 13.0.4, 14.0.0, and 14.0.1, contain a...
High
Unreviewed
CVE-2022-22689
was published
Feb 11, 2022
The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when...
Critical
Unreviewed
CVE-2022-3634
was published
Nov 21, 2022
The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output...
Critical
Unreviewed
CVE-2022-3600
was published
Nov 21, 2022
Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection...
High
Unreviewed
CVE-2022-44830
was published
Nov 21, 2022
In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula...
High
Unreviewed
CVE-2022-22121
was published
Jan 11, 2022
The Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list...
Critical
Unreviewed
CVE-2022-3603
was published
Nov 28, 2022
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote...
Critical
Unreviewed
CVE-2022-22425
was published
Nov 4, 2022
Auth. CSV Injection vulnerability in Export Users With Meta plugin <= 0.6.8 on WordPress.
High
Unreviewed
CVE-2022-44577
was published
Nov 18, 2022
IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2...
High
Unreviewed
CVE-2019-4071
was published
May 24, 2022
An issue was discovered in WeCube Platform 3.2.2. There are multiple CSV injection issues: the ...
Moderate
Unreviewed
CVE-2022-37786
was published
Jan 1, 2023
ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to...
High
Unreviewed
CVE-2022-40472
was published
Sep 30, 2022
Open-AudIT before 2.2 has CSV Injection.
Moderate
Unreviewed
CVE-2018-9137
was published
May 13, 2022
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in...
High
Unreviewed
CVE-2018-9107
was published
May 13, 2022
CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in...
High
Unreviewed
CVE-2018-9106
was published
May 13, 2022
CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension...
Critical
Unreviewed
CVE-2018-9035
was published
May 13, 2022
Tiki 17.1 does not validate user input for special characters; consequently, a CSV Injection...
High
Unreviewed
CVE-2018-7304
was published
May 13, 2022
Improper Neutralization of Formula Elements in a CSV File in pimcore/pimcore
Moderate
CVE-2021-37702
was published
for
pimcore/pimcore
(Composer)
Aug 30, 2021
ProTip!
Advisories are also available from the
GraphQL API