Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3 advisories

Loading
Cross-site Scripting (XSS) possible with maliciously formed HTML attribute names and values in Phlex High
CVE-2024-28199 was published for phlex (RubyGems) Mar 12, 2024
p8 Credited to p8, joeldrapper, and willcosgrove joeldrapper joeldrapper
willcosgrove willcosgrove
Cross-site Scripting (XSS) possible due to improper sanitisation of `href` attributes on `<a>` tags High
CVE-2024-32463 was published for phlex (RubyGems) Apr 17, 2024
gregmolnar Credited to gregmolnar, joeldrapper, and willcosgrove joeldrapper joeldrapper
willcosgrove willcosgrove
joeldrapper Credited to joeldrapper
ProTip! Advisories are also available from the GraphQL API