Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4 advisories

Loading
Winter: Reflected XSS through the search query parameter in the backend Table widget Moderate
GHSA-hq84-x37p-j6q5 was published for winter/wn-backend-module (Composer) Aug 20, 2026
NRAwwad Credited to NRAwwad
Winter: CSRF through AJAX handler names reachable as backend page actions Moderate
GHSA-p2ch-c2c3-4xm5 was published for winter/wn-backend-module (Composer) Aug 20, 2026
NRAwwad Credited to NRAwwad
Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles Moderate
GHSA-5cwr-5jxg-pcf6 was published for winter/wn-backend-module (Composer) Aug 20, 2026
NRAwwad Credited to NRAwwad
Winter: My Account preview exposes another backend user's profile by record ID Moderate
GHSA-mpmw-f6h6-3g26 was published for winter/wn-backend-module (Composer) Aug 20, 2026
NRAwwad Credited to NRAwwad
ProTip! Advisories are also available from the GraphQL API